[Babel-users] Blake2S, blake2B or neither?  [was: rather than ripemd160...]
    Juliusz Chroboczek 
    jch at irif.fr
       
    Sat Dec  1 19:47:53 GMT 2018
    
    
  
>> Where is Blake2S-based HMAC defined?  RFC 7693 merely says
> Section 3.3 simply says:
>    If a secret key is used (kk > 0), it is padded with zero bytes and
>    set as d[0].  Otherwise, d[0] is the first data block.  The final
>    data block d[dd-1] is also padded with zero to "bb" bytes (16 words).
Thanks, that was the bit I'm missing.
With that info, I have no objection to making Blake2S RECOMMENDED in
Babel-HMAC.  I'm still waiting for more opinions before I make up my mind.
-- Juliusz
    
    
More information about the Babel-users
mailing list