[Cfrg] Ed25519 to be approved for FIPS use?

Tony Arcieri <bascule@gmail.com> Wed, 09 August 2017 03:52 UTC

Return-Path: <bascule@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7F07D12702E for <cfrg@ietfa.amsl.com>; Tue, 8 Aug 2017 20:52:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ac6b10p3ntnb for <cfrg@ietfa.amsl.com>; Tue, 8 Aug 2017 20:52:46 -0700 (PDT)
Received: from mail-yw0-x232.google.com (mail-yw0-x232.google.com [IPv6:2607:f8b0:4002:c05::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8B991124BAC for <cfrg@irtf.org>; Tue, 8 Aug 2017 20:52:46 -0700 (PDT)
Received: by mail-yw0-x232.google.com with SMTP id l82so33013700ywc.2 for <cfrg@irtf.org>; Tue, 08 Aug 2017 20:52:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=/IuePjjOdaCXgChUfSH/I1hizaEx67jkM00uw4FsdaY=; b=en6zdL7xDKl4IGBR0Flh5ZBWHHggm+ifAWFDIdoQFXPRJ7C2Rx9TJzsqvvKCXtF8GC zWbEuXtQDxXO6WN0OZ9Fo4Xv9iPpFUap8O1617EIj9ej+hIrZ5XwjFfx72DxQiOgJ8X9 +E+hPDJucN4oim+J4nsbQ1aqiLXvYArGwWKBX+3f57SbCLqCjS0EB1tEBTB/GXY2v1kG yf039i+/1Lredcu64ghCB+LYlT1AiQ16F+2CI+VmiH/TXvyL2DuNG96BT3hwG8TDnR5z aTkEF56iylydp3GyASLySBuULLZaZDTvwI1LuxUbdlSwjEpienXEKdkVtHu70Pw6u5dq k05w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=/IuePjjOdaCXgChUfSH/I1hizaEx67jkM00uw4FsdaY=; b=XhcJrVc7rPf7g990r5YqchQFZzoe20V7yHhlEWHkc6U6HW5BttXa/PF5gL+fGNeCXk BpjHVgm255W5R/5yDQgmzlbpphMDHogcoqPwd45d6uJjEwobSko9B/0GSu+HLSfZOv0D 5uZQrkOvTmdeQeo71pv4POlHarwG1NTW1hegh6dGNEQoZLv3QndtmKda/+OxcZNvTb/u 6mGfLNWdYh1N1j3iaUMkj4fVvGzD4o9t6YUPebvaR50LP4oA3Nv/mIk1InYmzqGqFPy+ R/pKGROFs1N8hrjvnx+KPE4vCADMR9F2fhQqlAmdwlpo0a6bljLQrRmV3pXOvk+S3r9P UxBw==
X-Gm-Message-State: AHYfb5hGGReSXUDQfZ8yOaHe4sPXkS/6mfXGFqYQdO2mTrXQ8kFLJNT0 tSQ0XH73Uqvl5vP9+lA252/l3tai1Vascz0=
X-Received: by 10.129.197.73 with SMTP id o9mr5242460ywj.183.1502250765586; Tue, 08 Aug 2017 20:52:45 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.170.132 with HTTP; Tue, 8 Aug 2017 20:52:25 -0700 (PDT)
From: Tony Arcieri <bascule@gmail.com>
Date: Tue, 08 Aug 2017 20:52:25 -0700
Message-ID: <CAHOTMVJ8U5=qzbOz9kUnCZBmJp57XDE0+UWvTsxhH5j_BxZn-A@mail.gmail.com>
To: "cfrg@irtf.org" <cfrg@irtf.org>
Content-Type: multipart/alternative; boundary="94eb2c1a4f383f1d6b05564a037a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Fn8nyD8DWhBDfpCDbc0euRj33Ag>
Subject: [Cfrg] Ed25519 to be approved for FIPS use?
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Aug 2017 03:52:48 -0000

I saw this message from Phillip Hallam-Baker on CA/Browser forum and
thought it might be of interest to people here too:

https://cabforum.org/pipermail/public/2017-July/011663.html

---------- Forwarded message ----------
From: Phillip Hallam-Baker via Public <public@cabforum.org>
Date: Thu, Jul 20, 2017 at 2:56 AM
Subject: [cabfpub] Curves Ed25519 may appear as NIST recommendations
To: CA/Browser Forum Public Discussion List <public@cabforum.org>

FYI: From the IETF meeting

In DCRUP today a NIST employee withdrew a proposal to add the P256 curve to
DKIM on the grounds that it is ‘likely’ that the Ed25519 (and possibly
Ed448) signatures will be approved for at least some purposes in a FIPS.

There are many ways that this could not happen. Not least the lack of a
director of NIST. But if it does, it would be a positive outcome. I really
don’t much care which ECC curves we use so long as we all decide to use the
same curves everywhere.