<div dir="ltr"><div>Hi,</div><div><b>How can a <span class="" style="" id=":2bq.1" tabindex="-1">KDF</span> implementation for IKEv2 in the
<span class="" style="" id=":2bq.2" tabindex="-1">strongswan</span> implementation case can be verified for conformance with <span class="" style="" id=":2bq.3" tabindex="-1">NIST</span>
SP800-135, please?</b> <span class="" style="" id=":2bq.4" tabindex="-1">NIST</span> Application-Specific Key Derivation Function Validation System
(<span class="" style="" id=":2bq.5" tabindex="-1">ASKDFVS</span>) discuss <span class="" style="" id=":2bq.6" tabindex="-1">KDF</span> test vectors(TV), can we test these TV against
<span class="" style="" id=":2bq.7" tabindex="-1">strongswan</span> through some test software suit provide by <span class="" style="" id=":2bq.8" tabindex="-1">strongswan</span>, if
any. <span class="" style="" id=":2bq.9" tabindex="-1">Ubuntu</span> <span class="" style="" id=":2bq.10" tabindex="-1">Strongswan</span> Cryptographic Module (
140sp2978) mentions of /<span class="" style="" id=":2bq.11" tabindex="-1">usr</span>/lib/<span class="" style="" id=":2bq.12" tabindex="-1">ipsec</span>/ikev2-<span class="" style="" id=":2bq.13" tabindex="-1">kdf</span>-<span class="" style="" id=":2bq.14" tabindex="-1">selftest</span>, which I could
not find yet.</div><div><br></div><div>SP800-135 <span class="" style="" id=":2bq.15" tabindex="-1">KDF</span> recommendation further propose usage of SP800-56C for key extraction and SP800-108 for key expansion. <b>What mode e.g counter, feedback, pipeline as per SP800-108, <span class="" style="" id=":2bq.16" tabindex="-1">strongswan</span> use for key expansion, please?</b><div class="gmail-post-text"><p>I tried to register/join through <span class="" style="" id=":2bq.17" tabindex="-1">stongswan</span> website but <span class="" style="" id=":2bq.18" tabindex="-1">login</span> registration is pending from couple of days therefore sharing here, excuse for any inconvenience, please.<br></p><p>Regards.<br></p></div></div></div>