Re: aes128gcm: is the 1st example wrong?

On 13 February 2017 at 19:53, Martin Thomson <> wrote:
> On 13 February 2017 at 19:09, Julian Reschke <> wrote:
>> So... where do I get the padding length from under the new format?
> You count from the end of the plaintext.  All the zeros are padding.
> The first non-zero octet (starting from the end) is the end of the
> padding and should be 0x01 (regular) or 0x02 (last record).

Disallowing 8bit data seems undesireable.

Received on Thursday, 16 February 2017 01:07:49 UTC