Re: [CFRG] RSA PSS Salt Length for HTTP Message Signatures

"Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu> Fri, 28 May 2021 19:51 UTC

Return-Path: <prvs=5782a3b8b2=uri@ll.mit.edu>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1AD103A3397 for <cfrg@ietfa.amsl.com>; Fri, 28 May 2021 12:51:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.196
X-Spam-Level:
X-Spam-Status: No, score=-4.196 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Jq5G0p43Cdpz for <cfrg@ietfa.amsl.com>; Fri, 28 May 2021 12:51:38 -0700 (PDT)
Received: from llmx2.ll.mit.edu (LLMX2.LL.MIT.EDU [129.55.12.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D3583A339E for <cfrg@irtf.org>; Fri, 28 May 2021 12:51:37 -0700 (PDT)
Received: from LLE2K16-HYBRD02.mitll.ad.local (LLE2K16-HYBRD02.mitll.ad.local) by llmx2.ll.mit.edu (unknown) with ESMTPS id 14SJpaiL009515 for <cfrg@irtf.org>; Fri, 28 May 2021 15:51:36 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=vAAaDwOxG4+fpGEmjVKpE04wu5jK4DzOYIdihIWt6397vVIXLlpKRcNXQ60RRoUU0Mcr0mrRjSOGovUe3EEUN6CbebT5FDYapUX73Glu6Do2rOMhF554szeGsYAfKsPyhdXio+EGq9N/7JRSDgJFdPUu9hSHZwjTbOBPOCbH70+9mNmZmYrT8hiK1zbHdkTl2gfHYvKlOJMdL15CsUgbtmIG3pI+JPn5swww1tEMzkrZMQL+LFcVIbuPOhTdJlMb2J1Y7Org0WHLN0IV+rnVMBuX/dlfHDu32e3iTivM4DVluKcoaNJT3Dazl8mpU8wPhs7BKUlyk2gZVIhkHFJ+LA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vE9E2qAteYnDadFOp3ib8P+IOn86kq1ShaYC9ri+qj0=; b=gFicLZpSgiqDFsHURRzXDzl6SJNi0EP54KN8Cic2zFcm9Mhc4nHvO2Y78QmJ47B85y/ThVgoOzVQ+SxPzJ5O51vd8c9pw7bQ2KlOezn+S6ctBpMm/gZdZBgA16pacTqDdhSwpm/kZODoekIicAnWDPjhrfOTFaB4gp6J0mVwS8TO9bQz6/sR/bmkftZjXctOKfNFcr91D88WKGEn94QkHUSeJTJWvnjkbg2s0acc5XrAiyXOjUwXw9LPp6305GZrxbAz0CwDNmyAhgX9QQqMhvBnTg5llXgrEl4D1yDen94J947543O30KLqgKxQQjRQ5bqYdxd2I6uewhrSSCkSjA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ll.mit.edu; dmarc=pass action=none header.from=ll.mit.edu; dkim=pass header.d=ll.mit.edu; arc=none
From: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
To: IRTF CFRG <cfrg@irtf.org>
Thread-Topic: [CFRG] RSA PSS Salt Length for HTTP Message Signatures
Thread-Index: AQHXUnA3QL21iNhfskSrLn/LZsr7h6r2Sg6AgAGtcgCAAAJXAIAA5X8AgAAuawA=
Date: Fri, 28 May 2021 19:51:31 +0000
Message-ID: <FFEDC27C-9054-4EC0-B4F4-B0BA66CFAF13@ll.mit.edu>
References: <1EED8807-C5C5-461F-BE60-34C44791849E@mit.edu> <1BF68544-CB14-4A60-88BB-4E80E2D9A094@vigilsec.com> <CAFewVt54d6NGEYOX6Tx=gMf+p9NqTVkb9VkRxr+VZL5eDSmhmA@mail.gmail.com> <20210527232354.GY32395@kduck.mit.edu> <67015DB5-A45F-41C7-A236-C54DEB30DD8F@akamai.com>
In-Reply-To: <67015DB5-A45F-41C7-A236-C54DEB30DD8F@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.49.21050901
authentication-results: irtf.org; dkim=none (message not signed) header.d=none;irtf.org; dmarc=none action=none header.from=ll.mit.edu;
x-originating-ip: [129.55.200.20]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 89a2a998-e29f-4e02-c0c3-08d92211fdc4
x-ms-traffictypediagnostic: SN5P110MB0448:
x-microsoft-antispam-prvs: <SN5P110MB04484B94B1136B026E60134490229@SN5P110MB0448.NAMP110.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: PtHt5zMfKW5YUhfXzKjSJh7bf8KkE78mSpSeG8ewhVh0UykKfJAyyhfmPV1dquI2OVS92Lz/Yy+7gL/9531OUKYFtNSLw06QYq+f2q8hW8rQp8bziXnB8GqyQ2c2PH0JqL31jPKCFmAr9X9xCzZVGYOtFkryrDJTXKWWBCpGevAZgdXkBkmnkmPc7IKePm1bCr2gLrIVqOyFARgoAgWQgBEEOWlqZy2ToX0E0L34/D1MLKBSPvizpsJ9modJeSYLuo+sByWfXQWGZz9B9TrlpdlleS7vYBEo2D3chuIMsT62VXiuyNAKmNpYIRYejEo4f8Ld6PqLdcDJsL2nlqJ8J7mBSMsOZq+aP0VJbPNfRa+9H5gSf7o6YxbpLlVzr4hPqiQVk3+7dYdYi2gi8jhwz/9mQKN3fKsEQgATlKdrh+CY7ObhNtna1wTWz78JCCwnLCZFz5GP2yPgA2c1wi/+JCVcaYTF7B8jJ4O65kxXvQMO7lhMnXkeB99L7e9tMqjFjbIkrAMxpicv8SAHJE+CjNs9pFKyAK+LxXT/WGdGwXvraB+DGnT2V2hfDQWBxBax/Om5a6gRxckkGqTLuBAmIcEzXQOXXQc+770EMrgfQLVB9QNG5DFSdA8TJfc0xotY30d88osyz2EzZSKJL+QRiNVoo6tYNxdpX/FWwnRdgnlciAf8pOrUFwGoG+JhFr0W
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SN5P110MB0560.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(4636009)(346002)(366004)(376002)(396003)(39850400004)(136003)(66616009)(64756008)(4744005)(66476007)(966005)(66556008)(66446008)(76116006)(478600001)(66946007)(8936002)(26005)(5660300002)(99936003)(71200400001)(8676002)(2906002)(6486002)(6512007)(53546011)(86362001)(2616005)(33656002)(186003)(316002)(6506007)(75432002)(38100700002)(6916009)(122000001)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: Bi8U+GFrwmMRwR6Z8pjQ4J79BnmT0xWSAIQRfgHNS7QFsOsxCIK1aWcTOjg+e8SnjHO+S6Jn2NTOpHG1iQOa5QPFKghyKQhjT9RP5jQiwi7SRJi1dsQl7ykCOUVfXGs4kZheOxIRfXd/ZmIY64EOR20cb0QwRp7yNLTo8IqZ2byfn+gp1bfZacjoJ0Wb4gID38BMeGJ516UV4IlgmjcnAUvNqiRwPgQD97m3sqdRpa3V2aa6VHn8zdPrTHmMaQ2LHqxmcf2/9qCDIgmEuggCFvzt17i4iGj6dhoiqXXzP1GUO7S85Pz4eSi7QtiB7BBmVxvZ5xqkWekAPwGwytcjjGLXRJFODqj0wMy4hfYlZkwEIAK57ARCJ+g71n5aADiGr7GVhNecD6CTKTIjoRY4D+e0XvpD8HPLq6pWXCN/B0uTGWyX9F13Ib9bC/HUGKizjMqcFXi2MSWF6XxT0HhmMLFpJi9n1WuuHR7fM+jPTBrcV61lFw6xORBuGMRxLSXbexoELZ3QErdi0Q9zT+LkMQ1rel3wsZ1e+TkBtcpFXL7qVekpbKXMrIjrLLsIiewe+/jjMtFrWqh8Whoqm+B8mf+PiqFioLuyBxR4SfkD6aY/hymB8h/ylNuQ0feMQExkoX5/3ZqW3YhLENnnl+1Us6F3Ur/EajmVPIk07+ysIfAzLJa5EY3TEdX7SLGd5a+QGYE9XbgMnGxcRCM2WPoS4Q==
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha256"; boundary="B_3705061886_1769447260"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN5P110MB0560.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 89a2a998-e29f-4e02-c0c3-08d92211fdc4
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 May 2021 19:51:31.5774 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 83d1efe3-698e-4819-911b-0a8fbe79d01c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN5P110MB0448
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.391, 18.0.761 definitions=2021-05-28_08:2021-05-27, 2021-05-28 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-2103310000 definitions=main-2105280129
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/apXRyfpe9ISYLCnJiEeQ3C-x-fM>
Subject: Re: [CFRG] RSA PSS Salt Length for HTTP Message Signatures
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 May 2021 19:51:43 -0000

On 5/28/21, 09:21, "CFRG on behalf of Salz, Rich" <cfrg-bounces@irtf.org on behalf of rsalz=40akamai.com@dmarc.ietf.org> wrote:

>    Perhaps reconsider PSS.  https://www.metzdowd.com/pipermail/cryptography/2019-November/035449.html is excellent reading.

There is some reason in Peter's arguments - but if we start rejecting better crypto algorithms because it's possible to screw up their 
Implementation, it's unlikely that we end up in a good place. ;-)   

Brian Smith (and others) outlined a good strategy for this, and pretty much every other similar concern: fix the parameter set.