Re: [Cfrg] Fwd: New Version Notification for draft-irtf-cfrg-cipher-catalog-00.txt

Simon Josefsson <simon@josefsson.org> Tue, 06 March 2012 13:16 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DD07621F88C4 for <cfrg@ietfa.amsl.com>; Tue, 6 Mar 2012 05:16:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.874
X-Spam-Level:
X-Spam-Status: No, score=-101.874 tagged_above=-999 required=5 tests=[AWL=-2.764, BAYES_00=-2.599, FH_HOST_EQ_D_D_D_D=0.765, HELO_MISMATCH_COM=0.553, HOST_EQ_STATICB=1.372, SARE_SUB_RAND_LETTRS4=0.799, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wYlcBkcULm39 for <cfrg@ietfa.amsl.com>; Tue, 6 Mar 2012 05:16:56 -0800 (PST)
Received: from yxa-v.extundo.com (static-213-115-179-173.sme.bredbandsbolaget.se [213.115.179.173]) by ietfa.amsl.com (Postfix) with ESMTP id 1B8A421F88E1 for <cfrg@irtf.org>; Tue, 6 Mar 2012 05:16:55 -0800 (PST)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by yxa-v.extundo.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id q26DGeV3021663 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Tue, 6 Mar 2012 14:16:42 +0100
From: Simon Josefsson <simon@josefsson.org>
To: David McGrew <mcgrew@cisco.com>
References: <20120306013557.28230.85978.idtracker@ietfa.amsl.com> <E3D654EE-65DF-47EC-8218-368DCE5803DE@cisco.com>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:120306:mcgrew@cisco.com::4RkbzqEHu6Ii7BFx:0det
X-Hashcash: 1:22:120306:cfrg@irtf.org::7MRmC5MEj8yhOrmD:E77q
Date: Tue, 06 Mar 2012 14:16:40 +0100
In-Reply-To: <E3D654EE-65DF-47EC-8218-368DCE5803DE@cisco.com> (David McGrew's message of "Tue, 6 Mar 2012 07:05:24 -0500")
Message-ID: <87lind50p3.fsf@latte.josefsson.org>
User-Agent: Gnus/5.130003 (Ma Gnus v0.3) Emacs/24.0.93 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: clamav-milter 0.97.3 at yxa-v
X-Virus-Status: Clean
Cc: cfrg@irtf.org
Subject: Re: [Cfrg] Fwd: New Version Notification for draft-irtf-cfrg-cipher-catalog-00.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Mar 2012 13:16:57 -0000

David McGrew <mcgrew@cisco.com> writes:

> Hi,
>
> the initial version of "Ciphers in Use in the Internet" is now
> available at
> <http://tools.ietf.org/html/draft-irtf-cfrg-cipher-catalog-00>.  Sean
> and I ask for your review, constructive criticism, and input.  Some
> parts of the draft need more detail and organization, but it should be
> in sound enough shape for review.
>
> If you have text to contribute, that would be appreciated, especially
> if you can supply citations for the more consequential statements.

Hi.  First an editorial issue, but one that affects readability
negatively: there appears to be many '!' and other characters inserted
at various points in the document.

Section 5.5 on Blowfish says "supports keys lengths 32,64,96,!, and 448"
however blowfish supports variable-length keys between 1 and 448 bits.
It also says 'IETF use includes None'.  Blowfish is mentioned in the
following list of RFCs.  I have not verified how many of them make any
normative use of the reference though.

rfc2367.txt rfc2407.txt rfc2409.txt rfc2440.txt rfc2451.txt rfc2628.txt
rfc2786.txt rfc2828.txt rfc3211.txt rfc3316.txt rfc4037.txt rfc4250.txt
rfc4251.txt rfc4253.txt rfc4301.txt rfc4306.txt rfc4344.txt rfc4718.txt
rfc4880.txt rfc4949.txt rfc5201.txt rfc5202.txt rfc5374.txt rfc5996.txt
rfc6020.txt rfc6071.txt rfc6476.txt

Section 6.3 on RC4 could say that RC4 has been claimed to be a
registered trademark, similar to what is said about RC2.

/Simon