RFC 7539, "ChaCha20 and Poly1305 for IETF Protocols", May 2015
Note: This RFC has been obsoleted by RFC 8439Source of RFC: IRTF
See Also: RFC 7539w/ inline errata
Errata ID: 4700
Publication Format(s) : TEXT
Reported By: Martin Thomson
Date Reported: 2016-05-24
Verifier Name: Lars Eggert
Date Verified: 2016-06-08
Section 2.8 says:
The output from the AEAD is twofold: o A ciphertext of the same length as the plaintext. o A 128-bit tag, which is the output of the Poly1305 function.
It should say:
The output from the AEAD is the concatenation of: o A ciphertext of the same length as the plaintext. o A 128-bit tag, which is the output of the Poly1305 function.
Section 2.1 of RFC 5116 defines the AEAD interface, and that interface produces a single output, C (or an error).