]> git.ipfire.org Git - thirdparty/openssl.git/commit
doc: EVP_KDF document the semantic meaning of output
authorDimitri John Ledkov <dimitri.ledkov@surgut.co.uk>
Fri, 4 Oct 2024 22:41:44 +0000 (23:41 +0100)
committerTomas Mraz <tomas@openssl.org>
Tue, 8 Oct 2024 14:05:59 +0000 (16:05 +0200)
commit6f08353a4b816fc04ab53880855b0d79c833e777
tree512068cd3d39a1e64ae72c34e3d2d659999c5dd9
parentcdbe47bf3c02979183d1f66b42c511a18a63c61d
doc: EVP_KDF document the semantic meaning of output

Explicitely document what semantic meaning do various EVP_KDF
algorithms produce.

PBKDF2 produces cryptographic keys that are subject to cryptographic
security measures, for example as defined in NIST SP 800-132.

All other algorithms produce keying material, not subject to explicit
output length checks in any known standards.

Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/25610)
doc/man7/EVP_KDF-HKDF.pod
doc/man7/EVP_KDF-KB.pod
doc/man7/EVP_KDF-PBKDF2.pod
doc/man7/EVP_KDF-SS.pod
doc/man7/EVP_KDF-SSHKDF.pod
doc/man7/EVP_KDF-TLS13_KDF.pod
doc/man7/EVP_KDF-TLS1_PRF.pod
doc/man7/EVP_KDF-X942-ASN1.pod
doc/man7/EVP_KDF-X963.pod