RE: [office] Default encryption algorithm concerns

From
Hanssens Bart <>
Date
2010-05-11T18:12:19+00:00
ID
Thread
RE: [office] Default encryption algorithm concerns
Rob,

+1 on AES (See also OFFICE-2264 :-) and SHA-2

Nothing wrong with Blowfish AFAIK, but security policies probably mandate
the use of AES

> I don't think we want to require that package producers support the legacy
> method, especially if it is known to be weak.  So I suggest eliminating
> that bullet paragraph altogether, or require the use of SHA2/AES128 if
> there is consensus to have that be the "default" algorithm

Best regards,

Bart