At 4:00 PM -0500 11/13/08, Russ Housley wrote:
Wouldn't it be much simpler to say that the key wrap algorithm must be the
same as the content encryption algorithm? Yes, one *might* want a keywrap of
greater strength as you have above, but that forces implementations to have
tables of what "greater" means. Saying they need to be the same is much more
straight forward.
The keysize could be the same, but the mode will probably be different. One
would not want to use AES Key Wrap for the content.
Sorry, of course. I meant "same underlying encryption function", not "same
algorithm".