Based on certain attacks on 56-bit DES described in detail in chapter 6, it is the consensus of X9 that ANSI X9.17-1995 no longer provides sufficient key management security to protect the wholesale financial industry. Hence, X9.17 is being withdrawn.

This Guideline discusses:
  • using new technology to provide key management in support of the wholesale financial industry;
  • transitioning from X9.17 to the new technology; and
  • measures that can be taken to ameliorate the risk inherent in X9.17 during the transition period.

Please do not misunderstand the intent of this guideline. Continue to use X9.17 until a replacement is implemented. Until the replacement is implemented, there are actions that can be taken to reduce the risks associated with implementations of X9.17.