Re: [Cfrg] [Crypto-panel] Fwd: I-D Action: draft-irtf-cfrg-spake2-12.txt

"Stanislav V. Smyshlyaev" <smyshsv@gmail.com> Wed, 23 September 2020 07:51 UTC

Return-Path: <smyshsv@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E18D83A0E32 for <cfrg@ietfa.amsl.com>; Wed, 23 Sep 2020 00:51:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xubbQvdh6Ji8 for <cfrg@ietfa.amsl.com>; Wed, 23 Sep 2020 00:51:40 -0700 (PDT)
Received: from mail-ej1-x62e.google.com (mail-ej1-x62e.google.com [IPv6:2a00:1450:4864:20::62e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B126F3A0E09 for <cfrg@irtf.org>; Wed, 23 Sep 2020 00:51:39 -0700 (PDT)
Received: by mail-ej1-x62e.google.com with SMTP id o8so26406434ejb.10 for <cfrg@irtf.org>; Wed, 23 Sep 2020 00:51:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=2U4qHdMK9MgXFcwuxj9YnFL9GlPEJcEt38YCfivsHH4=; b=mxXSobQgXuHjVRjAavSNtbSJ62kcif+FdbgMYP0RekY4SdhDgVSZZ1jFg03rN0k7Ny s94sAvF+G0GLglJj31SGYpwpmqJQL7OyVhiIS9Zyi0d2zAnvjwPXDCoIvMaT+NLdiCk7 H2V1ar65gdrqqJUER/K6FdqYGctg5uPxp3DR/KWpz7ZyPwm0IGUQFBaBEJYyzbFkFj1e j9V7LT4gXPHV5lTWFkgrUYSVbf/ZGU41BuQLJfCl2mb+qkFMxN9zDuWhkDjqFRRHzTao IlQi32u3NUK+gUZwIIzIH+raqTtzqQgOpvJ+LJuJy4qVmyiyDkZJaPG/GIsIK7rZWz1U vl4A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=2U4qHdMK9MgXFcwuxj9YnFL9GlPEJcEt38YCfivsHH4=; b=UKIaScKYoiRD1MJ7yORH3/uVIIYZcIxPIdFq1tUshAYAL85TML64uYt38+Jr2wpuMf 52AS3hr+ASMRTDNyHBSEGv+PSgd35ggz7oqdGxVxMPVvXjtCHKPfi80Qnzb7Vr5/lX47 5MlRyVfos+V9bxb7VlSC5qh4/B/i0AGf0lJ0/AoWj+s3wv6gmp5HtAjqXtXJa52j+JN0 BvenJD4zZYEshW1T5N9BZY4ELK8JU7An3oKJ1F93y1SlN3lXfeK6dyJ4NLBijHwr9lg2 SFv+SeKFhj9+84Jzdl7nP/IZkSN0On+wrjECPqZZEIsgagyCHgE7EN7fjWPmpym4505q 6m3Q==
X-Gm-Message-State: AOAM5339eDU/lBNMrsNhM6LKYylnto6a9gV9E7kLo+fyOlzu/10gdDFp cmb3q0heqkYaI43WQZtSQhmPQL9FPP1Ff0jATCA=
X-Google-Smtp-Source: ABdhPJy+lMELEo0KQmy9VLZsqDZ1eHEhEz0OqcZox/mzfrfLt5MZj5jCMurC7HGF73td8Prd+bqG5MDWx2Pzc1jG844=
X-Received: by 2002:a17:906:354c:: with SMTP id s12mr9290814eja.370.1600847497858; Wed, 23 Sep 2020 00:51:37 -0700 (PDT)
MIME-Version: 1.0
References: <159709115024.10897.5395496576031260366@ietfa.amsl.com> <CACsn0cmX=DWCP5gpmPbzS=UjXfkBP9ObNpmEXPddsZJHbbhC-g@mail.gmail.com> <CAMr0u6k0f52E0i0ds9gR-xJ=M69RCV1vcYZJXi4Ycyc8QtBV3w@mail.gmail.com> <A0F53C47-3D85-4070-8ED4-A86E50899D13@vigilsec.com> <5f6565e7-49cb-32c4-1873-bac014cee965@isode.com> <80792d11-5400-1c79-ac60-d28d2ae803f0@isode.com> <CAMr0u6=Qokwbe6uUPQbBk3ZO4yUzm+UJT6uUPdjaK20tR837cQ@mail.gmail.com> <BN7PR11MB26415022F5F2FB219554DC6DC15F0@BN7PR11MB2641.namprd11.prod.outlook.com> <BN7PR11MB26418931A9921C0C121703D3C1590@BN7PR11MB2641.namprd11.prod.outlook.com> <CACsn0cke00kmWXNyQ1emWoLjkY47Xx+iFaKiXwdR=gJCPcya7Q@mail.gmail.com> <AM0PR05MB4786942F46EC45406959E23183560@AM0PR05MB4786.eurprd05.prod.outlook.com> <CACsn0cnAeZ6yOrU+Z6Gjv5102dE2Ep1eo2-kz2bYmbcSAxyUGw@mail.gmail.com> <CAMr0u6n4sAowO9TiN3NNTZf-udr4P9Jx3aed=qqu0aAwOw1Nyg@mail.gmail.com> <b044274b-1df4-1637-aeb0-da808518edeb@web.de>
In-Reply-To: <b044274b-1df4-1637-aeb0-da808518edeb@web.de>
From: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
Date: Wed, 23 Sep 2020 10:49:24 +0300
Message-ID: <CAMr0u6mRPgT46Hhj+R9Marhqb1E1WHAXacbpn7a-Ffhq6xT7Zg@mail.gmail.com>
To: Scott Fluhrer <sfluhrer@cisco.com>
Cc: CFRG <cfrg@irtf.org>, Björn Haase <bjoern.m.haase@web.de>
Content-Type: multipart/alternative; boundary="00000000000073156005aff65ae4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/x25pu_rg80TqjgfaiN07pcnqXmc>
X-Mailman-Approved-At: Wed, 23 Sep 2020 00:53:53 -0700
Subject: Re: [Cfrg] [Crypto-panel] Fwd: I-D Action: draft-irtf-cfrg-spake2-12.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Sep 2020 07:51:43 -0000

Thanks a lot, Bjoern!

Scott? Are you happy with the changes?..

Regards,
Stanislav

On Mon, 21 Sep 2020 at 18:43, Björn Haase <bjoern.m.haase@web.de> wrote:

> Hello Stanislav,
>
> sorry for the late reply.
> >Scott, Bjoern, are you happy with the changes?
>
> I've only shortly reviewed the change regarding the assumption set and I
> think that the reader interrested in all of the intricated details will
> anyway have to dig through the papers., I think that the accuracy for the
> level of an RFC document to refer just to "GAP-CDH" is fine, in my opinion,
> given that the references to the papers are now integrated in the document.
>
> Yours,
>
> Björn.
>
> Am 12.09.2020 um 12:49 schrieb Stanislav V. Smyshlyaev:
>
> Scott, Bjoern, are you happy with the changes?
>
> пт, 11 сент. 2020 г. в 20:41, Watson Ladd <watsonbladd@gmail.com>:
>
>> I have just uploaded version -13 which contains suggested text from
>>
>> Michel by way of Bjorn.
>>
>>
>>
>> Given we have per-user M and N as an option I decided not to add
>>
>> per-protocol, but if Scott thinks it's a good idea I'm happy to add
>>
>> it: not sure it will be used.
>>
>>
>>
>> On Mon, Aug 24, 2020 at 9:03 AM Björn Haase <bjoern.haase@endress.com>
>> wrote:
>>
>> >
>>
>> > Dear Watson,
>>
>> >
>>
>> > If I understood correctly Manuel and Michel's proof, the reduction to
>> the GAP version of CDH problem refers only to the "perfect-forward
>> security" aspect of the SPAKE2 proofs.
>>
>> >
>>
>> > To my best knowledge, the game-based proof regarding the "only one
>> password guess per session" feature does rely on "Discrete Logarithm
>> Password-based Chosen-basis Computational Diffie-Hellman assumption"
>> (DLPWBCDH) (i.e. without the "GAP").
>>
>> >
>>
>> > IIRC there is some small margin between the CDH and DLPWBCDH but there
>> is no need for the GAP assumption when carrying out the proof in the
>> game-based models, except for the forward-security aspect which to my
>> knowledge requires the DDH oracle.
>>
>> >
>>
>> > For the UC proofs, OTOTH the GAP assumption appears to be mandatory,
>> IIUC, since this proof strategy also implies forward security.
>>
>> >
>>
>> > I'm in close contact with Michel for the CPace draft preparation and
>> I'll ask him what specific wording he would be recommending for your
>> document, the next time I'll be talking to him.
>>
>> >
>>
>> > Yours,
>>
>> >
>>
>> > Björn.
>>
>> >
>>
>> >
>>
>> >
>>
>> > Mit freundlichen Grüßen I Best Regards
>>
>> >
>>
>> > Dr. Björn Haase
>>
>> >
>>
>> >
>>
>> > Senior Expert Electronics | TGREH Electronics Hardware
>>
>> >
>>
>> > Endress+Hauser Liquid Analysis
>>
>> >
>>
>> > Endress+Hauser Conducta GmbH+Co.KG | Dieselstrasse 24 | 70839 Gerlingen
>> | Germany
>>
>> > Phone: +49 7156 209 377 | Fax: +49 7156 209 221
>>
>> > bjoern.haase@endress.com |  www.ehla.endress.com
>>
>> >
>>
>> >
>>
>> >
>>
>> >
>>
>> >
>>
>> > Endress+Hauser Conducta GmbH+Co.KG
>>
>> > Amtsgericht Stuttgart HRA 201908
>>
>> > Sitz der Gesellschaft: Gerlingen
>>
>> > Persönlich haftende Gesellschafterin:
>>
>> > Endress+Hauser Conducta Verwaltungsgesellschaft mbH
>>
>> > Sitz der Gesellschaft: Gerlingen
>>
>> > Amtsgericht Stuttgart HRA 201929
>>
>> > Geschäftsführer: Dr. Manfred Jagiella
>>
>> >
>>
>> >
>>
>> > Gemäss Datenschutzgrundverordnung sind wir verpflichtet, Sie zu
>> informieren, wenn wir personenbezogene Daten von Ihnen erheben.
>>
>> > Dieser Informationspflicht kommen wir mit folgendem Datenschutzhinweis (
>> https://www.endress.com/de/cookies-endress+hauser-website) nach.
>>
>> >
>>
>> >
>>
>> >
>>
>> >
>>
>> >
>>
>> > Disclaimer:
>>
>> >
>>
>> > The information transmitted is intended only for the person or entity
>> to which it is addressed and may contain confidential, proprietary, and/or
>> privileged material. Any review, retransmission, dissemination or other use
>> of, or taking of any action in reliance upon, this information by persons
>> or entities other than the intended recipient is prohibited. If you receive
>> this in error, please contact the sender and delete the material from any
>> computer. This e-mail does not constitute a contract offer, a contract
>> amendment, or an acceptance of a contract offer unless explicitly and
>> conspicuously designated or stated as such.
>>
>> >
>>
>> >
>>
>> >
>>
>> > -----Ursprüngliche Nachricht-----
>>
>> > Von: Cfrg <cfrg-bounces@irtf.org> Im Auftrag von Watson Ladd
>>
>> > Gesendet: Montag, 24. August 2020 14:42
>>
>> > An: Scott Fluhrer (sfluhrer) <sfluhrer=40cisco.com@dmarc.ietf.org>
>>
>> > Cc: crypto-panel@irtf.org; <cfrg@ietf.org> <cfrg@ietf.org>; Russ
>> Housley <housley@vigilsec.com>; cfrg-chairs@ietf.org
>>
>> > Betreff: Re: [Cfrg] [Crypto-panel] Fwd: I-D Action:
>> draft-irtf-cfrg-spake2-12.txt
>>
>> >
>>
>> > On Sun, Aug 23, 2020 at 3:20 PM Scott Fluhrer (sfluhrer)
>>
>> > <sfluhrer=40cisco.com@dmarc.ietf.org> wrote:
>>
>> > >
>>
>> > > I looked through it (the Crypto20 crypto conference was last week,
>> that kept me busy); it looked good, with two nits:
>>
>> >
>>
>> > Thank you very much for reviewing it so quickly!
>>
>> >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Section 3.1 states “Lets G be a group in which the computational
>> Diffie-Hellman (CDH) problem is hard”.  Actually, if you go through the
>> security proof, it appears that the slightly stronger “S-PCCDH assumption”
>> is required.  While it is plausible that, for any group where the CDH
>> assumption holds, so does the S-PCCDH assumption, however, this is not
>> proven.
>>
>> >
>>
>> > So recently
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Feprint.iacr.org%2F2019%2F1194.pdf&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=TwffvrezUzSnJeaPaahlF08H744LL1mxocrTksHdvo0%3D&amp;reserved=0
>> reduces to Gap
>>
>> > Diffie-Hellman. I think I should revise that sentence of 3.1 and
>>
>> > discuss in security considerations section exactly what is assumed and
>>
>> > that elliptic curves in the draft are widely conjectured to satisfy
>>
>> > it. Hopefully this won't confuse anyone more than necessary.
>>
>> >
>>
>> > > This draft still relies on a fixed (per group) M and N values; as we
>> have argued before, having a global N and M value menas that breaking one
>> discrete problem would mean breaking the entire system globally, and so
>> that arguably too attractive as a target.  Assuming that the authors aren’t
>> willing to use a Hash2Curve method to generate N, M values, I would
>> recommend that a paragraph be added to the document outlining the situation
>> (and perferably giving a procedure where individual protocols can select
>> their own N, M values)
>>
>> >
>>
>> > Section 5:
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.ietf.org%2Fid%2Fdraft-irtf-cfrg-spake2-11.html%23rfc.section.5&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=TSxHJGOCsecYGoYp4OwBajfg%2FXt%2F9aLbokD%2F7iKprK0%3D&amp;reserved=0
>>
>> > has M and N per user, following one of the papers in the references.
>>
>> > I think a per-protocol option makes sense to add, but it would be nice
>>
>> > to know if it would be used.
>>
>> >
>>
>> >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > From: Scott Fluhrer (sfluhrer)
>>
>> > > Sent: Monday, August 17, 2020 7:50 AM
>>
>> > > To: Stanislav V. Smyshlyaev <smyshsv@gmail.com>; Russ Housley <
>> housley@vigilsec.com>; crypto-panel@irtf.org
>>
>> > > Cc: Alexey Melnikov <alexey.melnikov@isode.com>; cfrg-chairs@ietf.org
>>
>> > > Subject: RE: [Crypto-panel] Fwd: [Cfrg] I-D Action:
>> draft-irtf-cfrg-spake2-12.txt
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > I’ll take a quick look at it.
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > From: Crypto-panel <crypto-panel-bounces@irtf.org> On Behalf Of
>> Stanislav V. Smyshlyaev
>>
>> > > Sent: Monday, August 17, 2020 4:40 AM
>>
>> > > To: Russ Housley <housley@vigilsec.com>; crypto-panel@irtf.org
>>
>> > > Cc: Alexey Melnikov <alexey.melnikov@isode.com>; cfrg-chairs@ietf.org
>>
>> > > Subject: Re: [Crypto-panel] Fwd: [Cfrg] I-D Action:
>> draft-irtf-cfrg-spake2-12.txt
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Dear Russ, dear Crypto Panel experts,
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Any volunteers for a quick review of the updated version of the
>> SPAKE2 draft (before commencing a RGLC)?
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Regards,
>>
>> > >
>>
>> > > Stanislav
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > On Tue, 11 Aug 2020 at 20:02, Alexey Melnikov <
>> alexey.melnikov@isode.com> wrote:
>>
>> > >
>>
>> > > On 11/08/2020 17:47, Alexey Melnikov wrote:
>>
>> > >
>>
>> > > Hi Russ,
>>
>> > >
>>
>> > > On 11/08/2020 17:43, Russ Housley wrote:
>>
>> > >
>>
>> > > > We recommend the following two protocols to be selected as
>> «recommended by the CFRG for usage in IETF protocols»: one balanced PAKE -
>> CPace, and one augmented PAKE - OPAQUE.
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > What was the point of the selection process if we are going to
>> publish the ones that were not selected too?
>>
>> > >
>>
>> > > It is needed by Kitten WG for one of Kerberos documents. The idea is
>> to publish it with a disclaimer that it predated PAKE selection process and
>> was not selected as one of the finalists.
>>
>> > >
>>
>> > > To clarify: we don't intend to publish any other PAKE candidates that
>> weren't finalists.
>>
>> > >
>>
>> > > Best Regards,
>>
>> > >
>>
>> > > Alexey
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Russ
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > On Aug 11, 2020, at 10:57 AM, Stanislav V. Smyshlyaev <
>> smyshsv@gmail.com> wrote:
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Dear Crypto Panel experts,
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Could someone please take a quick look at the updated version (taking
>> into account the reviews made during the PAKE selection process)?
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > Regards,
>>
>> > >
>>
>> > > Stanislav (on behalf of CFRG chairs)
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > ---------- Пересылаемое сообщение ---------
>>
>> > > От: Watson Ladd <watsonbladd@gmail.com>
>>
>> > > Дата: пн, 10 авг. 2020 г. в 23:29
>>
>> > > Тема: Re: [Cfrg] I-D Action: draft-irtf-cfrg-spake2-12.txt
>>
>> > > Кому: <cfrg@ietf.org>
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > This fixes the comment on missing identities received during the PAKE
>>
>> > > competition which was the only one I found.
>>
>> > >
>>
>> > > I think it's ready for RGLC.
>>
>> > >
>>
>> > > On Mon, Aug 10, 2020 at 4:27 PM <internet-drafts@ietf.org> wrote:
>>
>> > > >
>>
>> > > >
>>
>> > > > A New Internet-Draft is available from the on-line Internet-Drafts
>> directories.
>>
>> > > > This draft is a work item of the Crypto Forum RG of the IRTF.
>>
>> > > >
>>
>> > > >         Title           : SPAKE2, a PAKE
>>
>> > > >         Authors         : Watson Ladd
>>
>> > > >                           Benjamin Kaduk
>>
>> > > >         Filename        : draft-irtf-cfrg-spake2-12.txt
>>
>> > > >         Pages           : 16
>>
>> > > >         Date            : 2020-08-10
>>
>> > > >
>>
>> > > > Abstract:
>>
>> > > >    This document describes SPAKE2 which is a protocol for two
>> parties
>>
>> > > >    that share a password to derive a strong shared key with no risk
>> of
>>
>> > > >    disclosing the password.  This method is compatible with any
>> group,
>>
>> > > >    is computationally efficient, and SPAKE2 has a security proof.
>> This
>>
>> > > >    document predated the CFRG PAKE competition and it was not
>> selected.
>>
>> > > >
>>
>> > > >
>>
>> > > > The IETF datatracker status page for this draft is:
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-irtf-cfrg-spake2%2F&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=lfQZ%2Bk58AZtuJDwwoL3kp9h%2B1t6eVh%2BO4IhcPF%2BJA9k%3D&amp;reserved=0
>>
>> > > >
>>
>> > > > There are also htmlized versions available at:
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-irtf-cfrg-spake2-12&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=M%2B1R6InBuduuxEehA%2Fmz99McvXt8KnILIj9S2bRBifs%3D&amp;reserved=0
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-irtf-cfrg-spake2-12&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=9IrixLVgOePrXOr4FXNIgwa8x9Jgpldlq5tr55o%2FGgI%3D&amp;reserved=0
>>
>> > > >
>>
>> > > > A diff from the previous version is available at:
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Frfcdiff%3Furl2%3Ddraft-irtf-cfrg-spake2-12&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=TI3p%2F1EM4Un4No8%2BEY6KsExVBQyMXIlg6OzWoZFi8%2FU%3D&amp;reserved=0
>>
>> > > >
>>
>> > > >
>>
>> > > > Please note that it may take a couple of minutes from the time of
>> submission
>>
>> > > > until the htmlized version and diff are available at tools.ietf.org
>> .
>>
>> > > >
>>
>> > > > Internet-Drafts are also available by anonymous FTP at:
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=ftp%3A%2F%2Fftp.ietf.org%2Finternet-drafts%2F&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691624309&amp;sdata=JLdVl7lCQLtmHJiKclYtzm81ubwwTgRe29PJMfhIPtY%3D&amp;reserved=0
>>
>> > > >
>>
>> > > >
>>
>> > > > _______________________________________________
>>
>> > > > Cfrg mailing list
>>
>> > > > Cfrg@irtf.org
>>
>> > > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691634306&amp;sdata=oteAqHxVYJtxizv9OX5GP3qfiAuWTpgeZXxZPIlj3z8%3D&amp;reserved=0
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > --
>>
>> > > "Man is born free, but everywhere he is in chains".
>>
>> > > --Rousseau.
>>
>> > >
>>
>> > > _______________________________________________
>>
>> > > Cfrg mailing list
>>
>> > > Cfrg@irtf.org
>>
>> > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691634306&amp;sdata=oteAqHxVYJtxizv9OX5GP3qfiAuWTpgeZXxZPIlj3z8%3D&amp;reserved=0
>>
>> > >
>>
>> > > _______________________________________________
>>
>> > > Crypto-panel mailing list
>>
>> > > Crypto-panel@irtf.org
>>
>> > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcrypto-panel&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691634306&amp;sdata=w0Bf%2F8e3bInXUJ8FckOi5dK%2FRPdY879EkrXP02iaSR4%3D&amp;reserved=0
>>
>> > >
>>
>> > >
>>
>> > >
>>
>> > > _______________________________________________
>>
>> > > Cfrg mailing list
>>
>> > > Cfrg@irtf.org
>>
>> > >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691634306&amp;sdata=oteAqHxVYJtxizv9OX5GP3qfiAuWTpgeZXxZPIlj3z8%3D&amp;reserved=0
>>
>> >
>>
>> >
>>
>> >
>>
>> > --
>>
>> > "Man is born free, but everywhere he is in chains".
>>
>> > --Rousseau.
>>
>> >
>>
>> > _______________________________________________
>>
>> > Cfrg mailing list
>>
>> > Cfrg@irtf.org
>>
>> >
>> https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&amp;data=02%7C01%7Cbjoern.haase%40endress.com%7C8359743fd98a4c38077608d8482b33bd%7C52daf2a93b734da4ac6a3f81adc92b7e%7C1%7C1%7C637338697691634306&amp;sdata=oteAqHxVYJtxizv9OX5GP3qfiAuWTpgeZXxZPIlj3z8%3D&amp;reserved=0
>>
>>
>>
>>
>>
>>
>>
>> --
>>
>> "Man is born free, but everywhere he is in chains".
>>
>> --Rousseau.
>>
>>
> _______________________________________________
> Cfrg mailing listCfrg@irtf.orghttps://www.irtf.org/mailman/listinfo/cfrg
>
> _______________________________________________
> Cfrg mailing list
> Cfrg@irtf.org
> https://www.irtf.org/mailman/listinfo/cfrg
>