Internet Engineering Task Force (IETF) S. Turner
Request for Comments: 6149 IECA
Obsoletes: 1319 L. Chen
Category: Informational NIST
ISSN: 2070-1721 March 2011
MD2 to Historic Status
Turner & Chen Informational [Page 1]
RFC 6149 MD2 to Historic Status March 2011 1. IntroductionMD2 [MD2] is a message digest algorithm that takes as input a message of arbitrary length and produces as output a 128-bit "fingerprint" or "message digest" of the input. This document retires MD2. Specifically, this document moves RFC 1319 [MD2] to Historic status. The reasons for taking this action are discussed.
2. Rationale
MD2 was published in 1992 as an Informational RFC. Since its publication, MD2 has been shown to not be collision-free [ROCH1995] [KNMA2005] [ROCH1997], albeit successful collision attacks for properly implemented MD2 are not that damaging. Successful pre-image and second pre-image attacks against MD2 have been shown [KNMA2005] [MULL2004] [KMM2010].
3. Documents that Reference RFC 1319
Use of MD2 has been specified in the following RFCs:
Turner & Chen Informational [Page 2]
RFC 6149 MD2 to Historic Status March 2011
Experimental:
4. Impact on Moving MD2 to Historic
Turner & Chen Informational [Page 3]
RFC 6149 MD2 to Historic Status March 2011 5. Other ConsiderationsMD2 has also fallen out of favor because it is slower than both MD4 [MD4] and MD5 [MD5]. This is because MD2 was optimized for 8-bit machines, while MD4 and MD5 were optimized for 32-bit machines. MD2 is also slower than the Secure Hash Standard (SHS) [SHS] algorithms: SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512.
6. Security Considerations
MD2 is different from MD4 and MD5 in that is not a straight Merkle- Damgaard design. For a padded message with t blocks, it generates a nonlinear checksum as its t+1 block. The checksum is considered as the final block input of MD2.
Turner & Chen Informational [Page 4]
RFC 6149 MD2 to Historic Status March 2011 7. RecommendationDespite MD2 seeing some deployment on the Internet, this specification recommends obsoleting MD2. MD2 is not a reasonable candidate for further standardization and should be deprecated in favor of one or more existing hash algorithms (e.g., SHA-256 [SHS]).
8. Acknowledgements
We'd like to thank RSA for publishing MD2. We'd also like to thank all the cryptographers who studied the algorithm. For their contributions to this document, we'd like to thank Ran Atkinson, Alfred Hoenes, John Linn, and Martin Rex.
9. Informative References
[HASH-Attack] Hoffman, P. and B. Schneier, "Attacks on Cryptographic
Turner & Chen Informational [Page 5]
RFC 6149 MD2 to Historic Status March 2011
[RFC1983] Malkin, G., Ed., "Internet Users' Glossary", FYI 18,
Turner & Chen Informational [Page 6]
RFC 6149 MD2 to Historic Status March 2011
[ROCH1995] Rogier, N., and P. Chauvaud, "The compression function