Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519)

Dmitry Khovratovich <khovratovich@gmail.com> Tue, 28 July 2020 09:05 UTC

Return-Path: <khovratovich@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E623E3A0924; Tue, 28 Jul 2020 02:05:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7cI8SP7lka4b; Tue, 28 Jul 2020 02:05:36 -0700 (PDT)
Received: from mail-il1-x133.google.com (mail-il1-x133.google.com [IPv6:2607:f8b0:4864:20::133]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6FD03A0918; Tue, 28 Jul 2020 02:05:35 -0700 (PDT)
Received: by mail-il1-x133.google.com with SMTP id i138so9622822ild.9; Tue, 28 Jul 2020 02:05:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=gKYjbMKE36iuT52j/fp3aTrUYgtUTN2/Q2fu3ItVBS8=; b=EHq4Q5/jrI5bD6rpIhPajPfQ4Hu+v4RmuyPD7srGk/Fzk4CIP47l1geXJL9dZrzZLN by3H7lXHfbDAhUTt4Q3K9cGlc7LHa2gM2bAAJyOpY7xIQxn3fGhCPGXyoeaQY/OZ4nO+ AjaC31CiAPpSrecjsJ0QE9vsuTsXzJNacW2bmZhzN5oEN6GiFd5UVwxIGxNZ3/FNXaTh TK0oGTJ/Knb0tv9lyq+Lx0Usw2bGcyxVhPJq9BKReu48hfHhneq72YEHDT11SzInuCt5 iMOJquj81TBCP2qEj65nsn5f3svRmIv86eSfcVD6YppDxMJJCNB5NCD0VrU6ivRKsajO 9gpw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=gKYjbMKE36iuT52j/fp3aTrUYgtUTN2/Q2fu3ItVBS8=; b=WcZfMPKD751MgLsl4CnCKEtcmLsVNHX5TMAjQJ13hkACkvVJKz8OMNnBAX1eSW6SuB MysTiv2RvrkrDRpEaJJv/5ZrVtae0g/P6Sd2Zt4DwLmlD+Bk7EcVH1hwp8pxSAnrkPbM Z+V6oGwcjdf00CmZ2cDHE98UpWhx8dhp1RTvKObNCSDMQsuImK6Zq2vkVCue76tKDJWw WIC7CH/fc+hKJ97Vcn7uzz2G/Lhp6WPQNcfq0YjeR9NKqAqHRFfgwaCiUy4jzzLf0yQS BbToxIwRciPeiaMoqMvD146AAnkXoZ7CKrCwSUwx9kI6NtJz7VRmIXieZ4jZEcSafASv DOFw==
X-Gm-Message-State: AOAM532Y+gDvIJQsKVzMHDG6tAzzdouRMmVqVYzTD4HijxOTkDI3wj1N 5DiqD8HopUms7gKOcaYpPwSS2lV0fkAYO2pGIsw=
X-Google-Smtp-Source: ABdhPJw2WVTWAHnTDFhPVSJDz3yNyr3cQbIef+Pdmx2CzxWZb74Rc2cCOAumVDQyUnSv7KQkWUp30iVM2UHGCa+h0C8=
X-Received: by 2002:a05:6e02:e87:: with SMTP id t7mr11529306ilj.4.1595927134858; Tue, 28 Jul 2020 02:05:34 -0700 (PDT)
MIME-Version: 1.0
References: <20190409163213.7EFCCB80E80@rfc-editor.org> <CALW8-7LhKhH7tabJFhU+=cWcOeadbPj4JLPkuf3jgWhk-3kBEw@mail.gmail.com> <49462255-FA53-467D-92F6-D34340ABE924@csperkins.org> <CAMr0u6ktnCROFUXCt1HESYmpdsQqnVkV73vCdW1Xk-nidWoXbg@mail.gmail.com>
In-Reply-To: <CAMr0u6ktnCROFUXCt1HESYmpdsQqnVkV73vCdW1Xk-nidWoXbg@mail.gmail.com>
From: Dmitry Khovratovich <khovratovich@gmail.com>
Date: Tue, 28 Jul 2020 11:05:20 +0200
Message-ID: <CALW8-7K+Q+DbfGjurf-GxLi9ycg_Dnnpz2Czc5+_v_B0cq7kYw@mail.gmail.com>
To: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
Cc: Colin Perkins <csp@csperkins.org>, Simon Josefsson <simon@josefsson.org>, Internet Research Steering Group <irsg@irtf.org>, CFRG <cfrg@irtf.org>, sus-e@ubiquitous-ai.com, RFC Errata System <rfc-editor@rfc-editor.org>
Content-Type: multipart/alternative; boundary="000000000000f5f41105ab7cbdb9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/K4HMiSY_jjeXipWOIB8zWPqo2RA>
Subject: Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519)
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jul 2020 09:05:39 -0000

I just realized I used an apostrophe different from the one in the text, so
it should be changed probably.

On Tue, Jul 28, 2020 at 8:38 AM Stanislav V. Smyshlyaev <smyshsv@gmail.com>
wrote:

> Dear Colin and Dmitry,
>
> I agree with both changes (one about "S" instead of "s" in the inequality,
> the other about R' instead of R to keep the same notation as in 5.1.6)
> proposed by Dmitry.
>
> Regards,
> Stanislav
>
> On Tue, 28 Jul 2020 at 00:52, Colin Perkins <csp@csperkins.org> wrote:
>
>> Thanks, Dimity.
>>
>> Can someone else in the RG double-check to confirm? Once that’s done, I
>> can work with the RFC Editor to get correct fix recorded.
>>
>> Colin
>>
>>
>>
>> On 23 Jul 2020, at 13:43, Dmitry Khovratovich <khovratovich@gmail.com>
>> wrote:
>>
>> It seems there is another typo in 5.1.7, as public key and its encoding
>> are confused:
>>
>> Decode the first half as a
>>        point R, and the second half as an integer S, in the range
>>        0 <= s < L.  Decode the public key A as point A'.  If any of the
>>        decodings fail (including S being out of range), the signature is
>>        invalid.
>>
>>    2.  Compute SHA512(dom2(F, C) || R || A || PH(M)), and interpret the
>>        64-octet digest as a little-endian integer k.
>>
>>    3.  Check the group equation [8][S]B = [8]R + [8][k]A'.  It's
>>        sufficient, but not required, to instead check [S]B = R + [k]A'.
>>
>>
>>
>> Should be
>>
>>
>> Decode the first half R as a
>>        point R`, and the second half as an integer S, in the range
>>        0 <= S < L.  Decode the public key A as point A'.  If any of the
>>        decodings fail (including S being out of range), the signature is
>>        invalid.
>>
>>    2.  Compute SHA512(dom2(F, C) || R || A || PH(M)), and interpret the
>>        64-octet digest as a little-endian integer k.
>>
>>    3.  Check the group equation [8][S]B = [8]R` + [8][k]A'.  It's
>>        sufficient, but not required, to instead check [S]B = R` + [k]A'.
>>
>>
>> Dmitry Khovratovich
>>
>>
>> On Tue, Apr 9, 2019 at 6:32 PM RFC Errata System <
>> rfc-editor@rfc-editor.org> wrote:
>>
>>> The following errata report has been verified for RFC8032,
>>> "Edwards-Curve Digital Signature Algorithm (EdDSA)".
>>>
>>> --------------------------------------
>>> You may review the report below and at:
>>> http://www.rfc-editor.org/errata/eid5519
>>>
>>> --------------------------------------
>>> Status: Verified
>>> Type: Editorial
>>>
>>> Reported by: Susumu Endoh <sus-e@ubiquitous-ai.com>
>>> Date Reported: 2018-10-10
>>> Verified by: Colin Perkins (IRSG)
>>>
>>> Section: 5.1.7
>>>
>>> Original Text
>>> -------------
>>> Decode the first half as a point R, and the second half as an integer S,
>>> in the range 0 <= s < L.
>>>
>>>
>>> Corrected Text
>>> --------------
>>> Decode the first half as a point R, and the second half as an integer S,
>>> in the range 0 <= S < L.
>>>
>>>
>>> Notes
>>> -----
>>> original document expression is ' 0 <= s < L', but it must be '0 <= S <
>>> L'. upper/lower case problem.
>>>
>>> --------------------------------------
>>> RFC8032 (draft-irtf-cfrg-eddsa-08)
>>> --------------------------------------
>>> Title               : Edwards-Curve Digital Signature Algorithm (EdDSA)
>>> Publication Date    : January 2017
>>> Author(s)           : S. Josefsson, I. Liusvaara
>>> Category            : INFORMATIONAL
>>> Source              : Crypto Forum Research Group
>>> Area                : N/A
>>> Stream              : IRTF
>>> Verifying Party     : IRSG
>>>
>>> _______________________________________________
>>> Cfrg mailing list
>>> Cfrg@irtf.org
>>> https://www.irtf.org/mailman/listinfo/cfrg
>>>
>>
>>
>> --
>> Best regards,
>> Dmitry Khovratovich
>> _______________________________________________
>> Cfrg mailing list
>> Cfrg@irtf.org
>> https://www.irtf.org/mailman/listinfo/cfrg
>>
>>
>>
>>
>> --
>> Colin Perkins
>> https://csperkins.org/
>>
>>
>>
>>
>>

-- 
Best regards,
Dmitry Khovratovich