I am trying to build a prototype pipenet system. ver 1.1 of the model, as opposed to the original, calls for a MAC and sequence number. what are the implications of excluding the seperate MAC and simply using the sequence as the authenticator? since any decent cipher, using CBC mode, should alter the sequence regardless of its position in the cell. am i wrong on this? am i missing some relationship between a seperate MAC, a sequence and the cell? if a seperate MAC is necessary, what are alternatives to using popular HMAC's (MD5,SHA1...), since these seem too long (16bytes * #nodes). would crc32 suffice? thanx, bill p.s. feel free to shoot down any and all assumptions i have unwittingly made ;) -- Bill Ahern wahern@25thandClement.com OpenPGP Fingerprint 8CA0 D751 16ED F450 7C23 EE7C EFE5 FFE7 C0B8 0C71 "Humanity is shaped by adversity and colored by failure."