Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519)
Dmitry Khovratovich <khovratovich@gmail.com> Tue, 28 July 2020 09:05 UTC
Return-Path: <khovratovich@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E623E3A0924; Tue, 28 Jul 2020 02:05:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7cI8SP7lka4b; Tue, 28 Jul 2020 02:05:36 -0700 (PDT)
Received: from mail-il1-x133.google.com (mail-il1-x133.google.com [IPv6:2607:f8b0:4864:20::133]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6FD03A0918; Tue, 28 Jul 2020 02:05:35 -0700 (PDT)
Received: by mail-il1-x133.google.com with SMTP id i138so9622822ild.9; Tue, 28 Jul 2020 02:05:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=gKYjbMKE36iuT52j/fp3aTrUYgtUTN2/Q2fu3ItVBS8=; b=EHq4Q5/jrI5bD6rpIhPajPfQ4Hu+v4RmuyPD7srGk/Fzk4CIP47l1geXJL9dZrzZLN by3H7lXHfbDAhUTt4Q3K9cGlc7LHa2gM2bAAJyOpY7xIQxn3fGhCPGXyoeaQY/OZ4nO+ AjaC31CiAPpSrecjsJ0QE9vsuTsXzJNacW2bmZhzN5oEN6GiFd5UVwxIGxNZ3/FNXaTh TK0oGTJ/Knb0tv9lyq+Lx0Usw2bGcyxVhPJq9BKReu48hfHhneq72YEHDT11SzInuCt5 iMOJquj81TBCP2qEj65nsn5f3svRmIv86eSfcVD6YppDxMJJCNB5NCD0VrU6ivRKsajO 9gpw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=gKYjbMKE36iuT52j/fp3aTrUYgtUTN2/Q2fu3ItVBS8=; b=WcZfMPKD751MgLsl4CnCKEtcmLsVNHX5TMAjQJ13hkACkvVJKz8OMNnBAX1eSW6SuB MysTiv2RvrkrDRpEaJJv/5ZrVtae0g/P6Sd2Zt4DwLmlD+Bk7EcVH1hwp8pxSAnrkPbM Z+V6oGwcjdf00CmZ2cDHE98UpWhx8dhp1RTvKObNCSDMQsuImK6Zq2vkVCue76tKDJWw WIC7CH/fc+hKJ97Vcn7uzz2G/Lhp6WPQNcfq0YjeR9NKqAqHRFfgwaCiUy4jzzLf0yQS BbToxIwRciPeiaMoqMvD146AAnkXoZ7CKrCwSUwx9kI6NtJz7VRmIXieZ4jZEcSafASv DOFw==
X-Gm-Message-State: AOAM532Y+gDvIJQsKVzMHDG6tAzzdouRMmVqVYzTD4HijxOTkDI3wj1N 5DiqD8HopUms7gKOcaYpPwSS2lV0fkAYO2pGIsw=
X-Google-Smtp-Source: ABdhPJw2WVTWAHnTDFhPVSJDz3yNyr3cQbIef+Pdmx2CzxWZb74Rc2cCOAumVDQyUnSv7KQkWUp30iVM2UHGCa+h0C8=
X-Received: by 2002:a05:6e02:e87:: with SMTP id t7mr11529306ilj.4.1595927134858; Tue, 28 Jul 2020 02:05:34 -0700 (PDT)
MIME-Version: 1.0
References: <20190409163213.7EFCCB80E80@rfc-editor.org> <CALW8-7LhKhH7tabJFhU+=cWcOeadbPj4JLPkuf3jgWhk-3kBEw@mail.gmail.com> <49462255-FA53-467D-92F6-D34340ABE924@csperkins.org> <CAMr0u6ktnCROFUXCt1HESYmpdsQqnVkV73vCdW1Xk-nidWoXbg@mail.gmail.com>
In-Reply-To: <CAMr0u6ktnCROFUXCt1HESYmpdsQqnVkV73vCdW1Xk-nidWoXbg@mail.gmail.com>
From: Dmitry Khovratovich <khovratovich@gmail.com>
Date: Tue, 28 Jul 2020 11:05:20 +0200
Message-ID: <CALW8-7K+Q+DbfGjurf-GxLi9ycg_Dnnpz2Czc5+_v_B0cq7kYw@mail.gmail.com>
To: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
Cc: Colin Perkins <csp@csperkins.org>, Simon Josefsson <simon@josefsson.org>, Internet Research Steering Group <irsg@irtf.org>, CFRG <cfrg@irtf.org>, sus-e@ubiquitous-ai.com, RFC Errata System <rfc-editor@rfc-editor.org>
Content-Type: multipart/alternative; boundary="000000000000f5f41105ab7cbdb9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/K4HMiSY_jjeXipWOIB8zWPqo2RA>
Subject: Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519)
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jul 2020 09:05:39 -0000
I just realized I used an apostrophe different from the one in the text, so it should be changed probably. On Tue, Jul 28, 2020 at 8:38 AM Stanislav V. Smyshlyaev <smyshsv@gmail.com> wrote: > Dear Colin and Dmitry, > > I agree with both changes (one about "S" instead of "s" in the inequality, > the other about R' instead of R to keep the same notation as in 5.1.6) > proposed by Dmitry. > > Regards, > Stanislav > > On Tue, 28 Jul 2020 at 00:52, Colin Perkins <csp@csperkins.org> wrote: > >> Thanks, Dimity. >> >> Can someone else in the RG double-check to confirm? Once that’s done, I >> can work with the RFC Editor to get correct fix recorded. >> >> Colin >> >> >> >> On 23 Jul 2020, at 13:43, Dmitry Khovratovich <khovratovich@gmail.com> >> wrote: >> >> It seems there is another typo in 5.1.7, as public key and its encoding >> are confused: >> >> Decode the first half as a >> point R, and the second half as an integer S, in the range >> 0 <= s < L. Decode the public key A as point A'. If any of the >> decodings fail (including S being out of range), the signature is >> invalid. >> >> 2. Compute SHA512(dom2(F, C) || R || A || PH(M)), and interpret the >> 64-octet digest as a little-endian integer k. >> >> 3. Check the group equation [8][S]B = [8]R + [8][k]A'. It's >> sufficient, but not required, to instead check [S]B = R + [k]A'. >> >> >> >> Should be >> >> >> Decode the first half R as a >> point R`, and the second half as an integer S, in the range >> 0 <= S < L. Decode the public key A as point A'. If any of the >> decodings fail (including S being out of range), the signature is >> invalid. >> >> 2. Compute SHA512(dom2(F, C) || R || A || PH(M)), and interpret the >> 64-octet digest as a little-endian integer k. >> >> 3. Check the group equation [8][S]B = [8]R` + [8][k]A'. It's >> sufficient, but not required, to instead check [S]B = R` + [k]A'. >> >> >> Dmitry Khovratovich >> >> >> On Tue, Apr 9, 2019 at 6:32 PM RFC Errata System < >> rfc-editor@rfc-editor.org> wrote: >> >>> The following errata report has been verified for RFC8032, >>> "Edwards-Curve Digital Signature Algorithm (EdDSA)". >>> >>> -------------------------------------- >>> You may review the report below and at: >>> http://www.rfc-editor.org/errata/eid5519 >>> >>> -------------------------------------- >>> Status: Verified >>> Type: Editorial >>> >>> Reported by: Susumu Endoh <sus-e@ubiquitous-ai.com> >>> Date Reported: 2018-10-10 >>> Verified by: Colin Perkins (IRSG) >>> >>> Section: 5.1.7 >>> >>> Original Text >>> ------------- >>> Decode the first half as a point R, and the second half as an integer S, >>> in the range 0 <= s < L. >>> >>> >>> Corrected Text >>> -------------- >>> Decode the first half as a point R, and the second half as an integer S, >>> in the range 0 <= S < L. >>> >>> >>> Notes >>> ----- >>> original document expression is ' 0 <= s < L', but it must be '0 <= S < >>> L'. upper/lower case problem. >>> >>> -------------------------------------- >>> RFC8032 (draft-irtf-cfrg-eddsa-08) >>> -------------------------------------- >>> Title : Edwards-Curve Digital Signature Algorithm (EdDSA) >>> Publication Date : January 2017 >>> Author(s) : S. Josefsson, I. Liusvaara >>> Category : INFORMATIONAL >>> Source : Crypto Forum Research Group >>> Area : N/A >>> Stream : IRTF >>> Verifying Party : IRSG >>> >>> _______________________________________________ >>> Cfrg mailing list >>> Cfrg@irtf.org >>> https://www.irtf.org/mailman/listinfo/cfrg >>> >> >> >> -- >> Best regards, >> Dmitry Khovratovich >> _______________________________________________ >> Cfrg mailing list >> Cfrg@irtf.org >> https://www.irtf.org/mailman/listinfo/cfrg >> >> >> >> >> -- >> Colin Perkins >> https://csperkins.org/ >> >> >> >> >> -- Best regards, Dmitry Khovratovich
- [Cfrg] [Errata Verified] RFC8032 (5519) RFC Errata System
- Re: [Cfrg] [Errata Verified] RFC8032 (5519) Dmitry Khovratovich
- Re: [Cfrg] [Errata Verified] RFC8032 (5519) Colin Perkins
- Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519) Stanislav V. Smyshlyaev
- Re: [Cfrg] [irsg] [Errata Verified] RFC8032 (5519) Dmitry Khovratovich