Hi, I just noticed that for HMAC-SHA3-224 and HMAC-SHA3-256, the current testvectors (and the fuzzing) do NOT test ANY case where the key is larger than the blocksize and thus first needs to be hashed. The thing is, SHA3-224 has a blocksize of 144 bytes and -256 has a blocksize of 140 bytes while the largest key used (supposedly "Larger Than Block-Size" according to the plaintext) is actually 131 bytes. Regards, Pascal van Leeuwen Silicon IP Architect, Multi-Protocol Engines @ Verimatrix www.insidesecure.com