NAME | SYNOPSIS | DESCRIPTION | ATTRIBUTES | SEE ALSO
strmod/encrdes
This module implements the United States Data Encryption Standard ("DES") for IPsec. encrdes uses cipher-block chaining ("CBC"), as per RFC 2405 and has the following properties:
64 bits. 56 bit key, plus 8 parity bits. 7 bits of key are followed by one bit of odd parity. For example, the 56-bit key FF FF FF FF FF FF FF would be encoded as FE FE FE FE FE FE FE FE. encrdes supports weak-key checking and parity-fixing to aid pf_key(7P).
64 bits.
DES with an actual key strength of 56 bits is only available inside the United States. DES has an effective key strength of approximately 56 bits and is only available inside the United States. DES cannot be realistically weakened for use outside the United States..
See attributes(5) for descriptions of the following attributes:
ATTRIBUTE TYPE | ATTRIBUTE VALUE |
---|---|
Availability | SUNWcryr (32-bit) |
SUNWcryrx (64-bit) | |
Interface Stability | Evolving |
ipseckey(1M),attributes(5),ipsec(7P),ipsecesp(7P),pf_key(7P)
Madson, C., and Doraswamy, N, RFC 2405, The ESP DES-CBC Cipher Algorithm with Explicit IV, The Internet Society, 1998.
NIST, FIPS PUB 46-2: Data Encryption Standard, December, 1993.
NAME | SYNOPSIS | DESCRIPTION | ATTRIBUTES | SEE ALSO