Crypto Appendix - Restrictions on CCM8 #2413
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
AppendixV
Appendix with crypto details
_5.0 - Not blocker
This issue does not block 5.0 so if it gets addressed then great, if not then fine.
CCM8 is currently listed as approved in the crypto appendix (a previous version had this text: “CCM-8 is included in regard to TLS cipher suite”).
CCM8 use a 64 bit MAC which is quite weak. It's supposed to be OK when used for TLS but it's not OK but not for other protocols in general:
This is not allowed in DTLS without additional safeguard.
RFC9147 (DTLS 1.3):
QUIC:
I suggest, to add a note:
Additional questions:
The text was updated successfully, but these errors were encountered: