Dave,
Perhaps there can be a discussion of Triple DES. I'm interested in
seeing us choose a specific format so we can experiment with it. It's
probably premature to consider such a choice as a standard, but it's
worth converging on a specific choice if we can.
As I recall, there is moderately broad consensus on EDE with two keys,
the same IV, and single-loop CBC. However, Carl Ellison has argued
vigorously that single-loop CBC is inherently inefficient for hardware
implementation and triple-loop CBC is the right choice.
Wasn't this discussed at the last meeting, and the RSA folks were
going to do a little analysis? If there are results, it would be
worth hearing about them.
Thanks,
Steve