NIST.SP.800-132 Section 5 mandates a minimum key length of 112 bit for the KDF . The proposed change adds an explicit check when running in FIPS mode to make sure this requirement is met.
Description
Description
Revisions and Commits
Revisions and Commits
| rC libgcrypt | |||
| rC52d48b710470 kdf:pkdf2: Check minimum allowed key size when running in FIPS mode. | |||
| rCe235f38f9b9f tests: Reproducer for short dklen in FIPS mode | |||
| rCefdc87b305ff tests: Reproducer for short dklen in FIPS mode | |||
| rC3c04b692de1e kdf:pkdf2: Check minimum allowed key size when running in FIPS mode. | |||
Related Objects
Related Objects
Event Timeline
Comment Actions
The specs https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf page 10 says specifically:
The kLen value shall be at least 112 bits in length.