[Curdle] draft-ietf-curdle-ssh-modp-dh-sha2

"Mark D. Baushke" <mdb@juniper.net> Tue, 28 March 2017 16:54 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1680D12944B for <curdle@ietfa.amsl.com>; Tue, 28 Mar 2017 09:54:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.922
X-Spam-Level:
X-Spam-Status: No, score=-1.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id il_lBCdyIFJ2 for <curdle@ietfa.amsl.com>; Tue, 28 Mar 2017 09:54:32 -0700 (PDT)
Received: from NAM03-CO1-obe.outbound.protection.outlook.com (mail-co1nam03on0090.outbound.protection.outlook.com [104.47.40.90]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 828291279EB for <curdle@ietf.org>; Tue, 28 Mar 2017 09:54:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=RiEQseiU/SO1MDx8q7PoYut1gfd/KyOeqQSpz3z9shI=; b=SJelJLXKUl34q1rbTocmTHagc5bH9X7h6nTYkJlTY7A1kaZQH89OTTkaVghqJomCEmF5CK3ex6yoAqOxmpymfn6hl0mboF14FOJ2hFNAQp4Z6JDAiCEqbo5A3roSBMVZKGmmkXVGIx7TztSciAHUIegB5ZPC3ViHt1itSaPSt5Q=
Received: from SN1PR05CA0003.namprd05.prod.outlook.com (10.163.68.141) by BN1PR05MB309.namprd05.prod.outlook.com (10.141.63.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1005.2; Tue, 28 Mar 2017 16:54:31 +0000
Received: from BL2FFO11FD054.protection.gbl (2a01:111:f400:7c09::184) by SN1PR05CA0003.outlook.office365.com (2a01:111:e400:5197::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1005.2 via Frontend Transport; Tue, 28 Mar 2017 16:54:31 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BL2FFO11FD054.mail.protection.outlook.com (10.173.161.182) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.977.7 via Frontend Transport; Tue, 28 Mar 2017 16:54:31 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 28 Mar 2017 09:54:29 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v2SGsTUI009623; Tue, 28 Mar 2017 09:54:29 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id B85B91144E; Tue, 28 Mar 2017 09:54:28 -0700 (PDT)
To: curdle <curdle@ietf.org>
In-Reply-To: <CADZyTkmr0WF3BOBby3rObBGGQaqMUq=0Ssc7NB9PAgPFDrk7dA@mail.gmail.com>
References: <CADZyTkmr0WF3BOBby3rObBGGQaqMUq=0Ssc7NB9PAgPFDrk7dA@mail.gmail.com>
Comments: In-reply-to: Daniel Migault <daniel.migault@ericsson.com> message dated "Mon, 27 Mar 2017 18:49:31 -0500."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Tue, 28 Mar 2017 09:54:28 -0700
Message-ID: <30381.1490720068@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.18; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39840400002)(39860400002)(39450400003)(39850400002)(39410400002)(2980300002)(189002)(199003)(9170700003)(7126002)(230783001)(2810700001)(81166006)(8676002)(2906002)(105596002)(117636001)(8936002)(86362001)(106466001)(356003)(53416004)(76176999)(54356999)(50986999)(5003940100001)(48376002)(305945005)(76506005)(50466002)(189998001)(110136004)(77096006)(53936002)(5660300001)(6266002)(7696004)(38730400002)(6916009)(55016002)(2950100002)(6306002)(7846003)(47776003)(6392003)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1PR05MB309; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; MLV:sfv; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BL2FFO11FD054; 1:SHaIZRAewx5AHtN2y97PWRiQy7dKpVePQzEPiGYUHqGPcwKoSz3QmfMHoIyZiUOtaYkDdfQZhhF/WhL8UNbtZBMr4gW+sFw3GP6+yBgZueTREwIxQW8qcY6uE1T9EBBkwfYpbYas5LVpErMj9xf68eGCADLHwxq90p/Hm6sVOxbPKND7LaVPggMSvH2N2VjNPluDaVJEZti2BXOJAzbSKCmBdg8sGs/zCxpw1+wZTI1DXz2nheNDRVROKANvARs7y4zNZB2RjnhFZbiwRdAUeMRSFYKHYchmR6QnGMnJtHDTEuOMptCy+54bwohs6VkN2CBpefYf+EQyAYrP+q5qZm2+z0qHlPPXoH3C2wcNljh+5oIshoTmalQIr/XyOIRrSiuAbgpEG5MmDF4Czq/8j/aYC4Zv6wXBDsaUmsn8KtVKx0vwwnR+RiSBmxUYGIuU4cnP1ORaKshw5pLulQgU1GOtycV77ojJbRaQpHzt0VndaYzqIFUFpx0erIiqmBkTcOQ/cNTFW6R4GKHyjyXsU4986Wie/uXmBnOrcATjXMcH68V1h5uj098XwjZhmY0+
X-MS-Office365-Filtering-Correlation-Id: 27863c2c-11fd-4254-f6e4-08d475fb1abc
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075); SRVR:BN1PR05MB309;
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 3:nke52XtV7q4wnx24LNHrzegAPXAB+BPLzhKIEvNl4yEqXvzDdW4avMFknKaskSOYF4MUINLGjcEeEiQw+pJagSTSBUuXFaIRi1aMAIFlI6mLi/ayQD/6g1JFlkA1IzhT2kvUa+KVIKwggeSFmlii6O1n+RAwMtK3HTNRS2G7sO23crFY2B2pS9dIxdgPnE36oikMeTsaEhGElU8L+55GvX7K3zMF4qaxZ2bpgmiGgIDoi2yCGFypkXCaxFoMhSak6cjfTD43bEKUEM6tUAH/d/ICVCs+J2qi33WsCGawLIor6t7t60bl6iigKJc48LHh3WFE7+e3wFsbsPTP36YyjfAflrtCoCMTfolFNH1zus0MQtvJs3Na1oQImvuOFz+JZJm9scMbUItMNBcY46kx0g==; 25:kHcXCWk8hAy70zLn9SZTyhH3jOpcJhV5sjk/U8tuC1UcLk6BmAmA/j+8SGzarVldvCMVX3MpQMHj/uhpSEXUER6va9xK4a+aEklXJRB9sfMG932a+3abE8ABRtrAHRm2eOn7eVf96IZ36qP2gKSs3TrOMRsK8WaPK5bZcpHpDIBrkePKtTskUew66ddj34TYGbkWFu1xd+Tb4jK3PGgOmNCZ2pMtt9qq4cM7MyohUIINy1SYXAHDPejBc/eELmfidEDQobcJV/MlJTaQvNtXnpL8BvUT5lMMWUHtgi+i5KvMxZBzlGLNmBtQ2e9jRpjNC/vZ5w6HNNNroFo3MQblG2gjYRh5pLXzRSUp5+0anhTN7Qzj4DM8yT0hf7ggBMMXPB9Q9hKfgBqKhB2i1FA8U4utuW6QQ04eBsE2aQmcQFTMajqqQAW6PPGeg1fJoK7bZzO7y4Htv2fXY2FNFPz+TQ==
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 31:bVZdwXhGVzC07/afoBj6Mgo09c4qASW89eoXZ4rm4HYTbNc8FK9ByPASJYc046a6YJJIWwpKarMPAZGUOVC4NXVjbk8Ti9F9KiL/HcgusDYXQr0CvjEdEKRvjNRbsmCWJvghN/QdPxC00NtyG1ROXWGKN+Xqh6iOraV7AOFLDvxttiTyvw3Pfw8MmQmQ+7kfa80vUbWYt80gF9rC46MiLpxkbKHhJQUlbM+25jRzbHjK9/aJIW4qooucgk5mxEzA3t8ayIkhplk/yqfFqi4s0OrfxGnA2G33KyH4JX9kzv8=; 20:1QUAhvvpcz4TkDqbt7OZLzFQB2hjdRGnNi51Cj3VPrnnZKU+gDOZv8aShGB5UwfH1GIiWGyQ5K6i/JsOEh9NeK5IwwKnX/xMSqO9iadKXSNpr4FTOdgYzFxzEPDGF1/1eXh54Vf0EnvKtvpNN6k42GhQvQIVgE9EXdcEbex7ZvFOJCcekwodZXBP4SP7Y5FlAq6OjK04BW+lWreJGMXgym+CrA+x+qQQ5qcuiHemiH6naJEbghm9Ljuj2FyFwaQoHZzXIw+mk0lj5MKwJEksLsc/ADGjPgIQxyipxIMGoZLRALbVCgTRjiOK+1wDURSqAuXGs/4tmr3wWCNIlWzMNhq/xsvDtQ6l+xJk7zYnAMqWioP2FeHYVhOfYN86hUsrDhMg3G7U9KyVop+WmbYFimC8U3mfispBHIFg+Vs/cjFQclwsYBTQkcDVyWw/tsHHZKTnZ7/ufVM26XgyCgdzA3zCDm03ggG7iv4YXW0+8YMAF/jBmQZGHqeORswyvhqk
X-Microsoft-Antispam-PRVS: <BN1PR05MB3090373168780152547D963BF320@BN1PR05MB309.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(120809045254105)(192374486261705);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(13024025)(13023025)(13018025)(8121501046)(13015025)(13017025)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123562025)(20161123555025)(20161123564025)(20161123560025)(20161123558025)(6072148); SRVR:BN1PR05MB309; BCL:0; PCL:0; RULEID:; SRVR:BN1PR05MB309;
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 4:vOk8UYd97V3ZXvWeFdHgrC0sVIA/u2KKSWvBNveaExzp2gIWxEzEhhLDffkux9ivCFodJUEQc7k3h2fDtjvNwUipfOq08FnR/hA+gBY+tvIMXek66FAPl0sszeKm0RyOqw7izTFQJ4VDSauCUlJNv/28fp9paVSfNvwKsQtO3/yTWv5EnTJA7PvPqIDPYqvY3Ttz7e+GFlxTk+/fZuLS9wdwNlAxagU4GNrX+dO9Dwamr926dZZx7f5C6EWx2Q8lswwcJ195K1WRjtuJEDpBPYcV04kTzt5hdaHuN4KSILXl7xWyRNlLK1XHuY6pC5w32jybscKpUrMgB//csHQ3ONg09TQ4hjHPc1wVdVgD+WwX/bxjmlatv8FrpTiijlRuno6oXL/FN1UQQl8iWYUTJ8le+PNmoXuR9x979u/H3MOzrkFg0p5Z5UWK/Whmeu0M6jkfQd+MKxadzUrxNaoAuIMCby/qp/FFxABNYdZJ+hRKNHzHfBxfngp9GHhMLzL2XYmynOmH0/qCFkZWRYy4W2yjgbBQWTUoX3SKP1n+LZ40mSHRM5p3eCL+tsgjYwD1HLVkXTtHLXSEfHW1A3lUsyVg2vLQre6upPiVpcjlRwwGQohnPbVFHDCOWkLw9bZVms1VQXKjD+LsWHiWl/gCV0WXQJlLD/rRVzTi2OLxaztbGBZPMHMOr8HttWCAUExxFiBVjVuNWaLdC84iUA/qZjR/iI4MRvsT2iu1j8yu0SDAE/WKDSRTlEGa1s4rc1ieOSQ2j2VtCGq9N30b8dcxZLHbtyyrF6TXEu7zbnIFDBc=
X-Forefront-PRVS: 0260457E99
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 23:3zP1C6CZbYgHiOzol6Q2S4jW38lW2PisR9xD9t/siu+xWk3nGla8RztAhup19eXKekiCn15Mk/46wZ85Ny6m9CtBSHzIkg7BNVmGlcEjXtTRGRBRFqpes88U7+/QHlgz7kkk5Q2PinZmjWNComg7bbVBDW3Hgg6K4beFmNMtLG7PM0kUs85/AWkERbWJQgZlWVNj9v9j6aU3cghUE8VJNfk8yWtyWLTiRhSoN6Q9NKWLVujMhUrhxNRqBl5GKoHMCnwv4WTPp3PfKsdrLGIfkD8t6win614CR0xLePKfqbGG3V9Ci0+QkqfNuTMALvDLrMhyAhTJOpSb7BeRVywRGX6NN7T7hHVAeRlaUhKflVMqPfLp3O0IjzXVWXnB2Cx9bMGPOHjztT/RSXgnwkFZvK4q7cpRkU4RJ+kxO2bwLAU08LUnJ4e8wPLoWXmVIfxJUp6QysRtWYzNFDvf/ek3s0xapy1aQqWv1KJV+RvRUS31X4Zrg5K6sD2PvhR1v15hFirv8eQoYLOcf4ChbKde2nFEMHJsLg1Jr/mC3kFd63igEZcjA8Gefvir7Flbukb+jvixu0MqMQmgB4EmbnPPrRxgLN1zQ6ltzwSTnbiVArIiEfurHndJf40upoAmSG6AvG4LXqg4SQ7hAQis0ubEE00mJ70aHjZIa3wZVbUAcplUqA2yFXi119psiVBSbVTY3MIn4tCRwXw8NrCgriLZnHr/260cZyLPhccPOl6wXY1f4Ce1zdJgO8FV04YRipD/ScOhOuPFkTuQmahVzmTDw6xI//2v3pxHGirVfolfyi2eg0RiRA6h7BGqpR64ncVS9q5zG3QU1sZRJd2dVbYHi9ZNvcRWo+W5zqyfNCWc7RJ98wQJrbZh+3ag2orvZ0v9Hh7Qukp2QqgnkYHjl5evNjx/GW5alSvqv0VMh0Dy3UIHniFq9eeeGt9Nk8dRTCy33wmWIcVumyf/73V8k3a9e93369A8FTRcRvYpCtiHjex07wQJ8U6vVZYQoERJnak9hR9Km9xWL3WzLlEMb6OCWbO0fNCBCnU8/sOMkIgN0q4gBlzMF1ijEpE8l+ZH8at7u818oBHpw5nmyBNGzbYLxJ/hHe3kaX45AOBwySQdHZQ8TJSfRiiBNcUIohvWwjFjh/gy2AmZlEPTBI2ZSN2IZQ==
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 6:cElXNtWI1wwp7d3YnFhEdUzLOt3smegaDQLUNg5dBBKewiHWbfHiUFNQeNm038nZJp5pco1fTiO9ybTO66d8DmLYi7qKof/2p9geXcZmFxRRyPmEuLxYJqmPvFHn+A2t0B4W3/+45QWcKAa8l7fOC+92FgQ8fp41vXiRTLjqxcdX4mHPRNBtwwW3xd3wREAM7N3bJuZGrMw6d86GK8P2eTeKoyEr5Izx9WrazfCvdArg7uzkXByfPKDx8HQqsJhPeYrmIsYX4IVE75KSZ6ko2i8x5Xt+ca3VwwX6LcwBPqBo6A87ME0k2Gkq2pP/qUXYBq8hrpTOTS+N2yQ0QZIWx3J6tai2+smUZeCpMo8GTH+OWFf4ybTs35sHZ/ya2uJ3WAr/+ObbV9RlIdfBzSCiAp2alaHl8CZRDTu8/QM7om8=; 5:u9dZh++8RT8t2CrUZ1N/vogYynDCnLxQD/Y8D1WXdutuUNFRWj8O/bGiAyEv4hc2Y484I8liU7fZ7Pe5gFOwDJgW6bYNmymZ1ff+EMXG6O4xd1WWPi+MqOfu79mxxoubgGp2TpPwkx01VT2J5E+PFIKpTRufCh+vZr3pusnVxjA=; 24:o43pKU3d4q5b62MXtRbvQOO+tIKkfi+bZpH/zEiXi1fzCV+iwmLj2ywJ1IlYfqQ0YfRD8qEEtRRMXThYyRhnfsVwM1ULrBpUG50JWqbK+cE=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; BN1PR05MB309; 7:OISXth9lUZyhFyyvJ0JuxzIAbP7RYcF/9X0md4Q6ZfvWfRwGLNNV6pjGXqz90XRvc88PzYMIgILd3gMuOnwBJa+tiN8ZtVEkptW9qhrCOXHNUSZ0RoRmf5KPSWG/8QxZrLuoxQIPRzsuaaVa6BFDpscculpljFfkY2IeBvLaML9VvOfKIsmIMmb9RwdIXIghlOUIr0G5jzk23bez8+X8+vE7r2ilcWGPfvbQM20Rjf2QvT2L46Hbsb3S3Z9vEX7ceeu7JPXDoLDdK04Ex70xwKSFgYrW0dFFtYRMezecF/5y8Gcg6yUOxuzYkYUzMzh33TSIbIPEA+yEdwG1tKohXw==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Mar 2017 16:54:31.0355 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1PR05MB309
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/-Kl5T3MZ1KOT9IOMCDVlt0QhBps>
Subject: [Curdle] draft-ietf-curdle-ssh-modp-dh-sha2
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Mar 2017 16:54:35 -0000

Thank you Melinda for taking the minutes for the Curdle meeting 
on March 27, 2017.

https://datatracker.ietf.org/doc/minutes-98-curdle/ says:

> draft-ietf-curdle-ssh-modp-dh-sha2
> ============
> EKR: I'm surprised you're not using the ones we're
> standardizing in TLS.  Rich: we're reflecting what's in the
> deployed base.  DKG: Shouldn't use the same groups being
> specified for TLS, although we should use defined groups
> AGL: the draft is documenting reality, but why wouldn't you
> want to use the same groups?  DKG: the rules for generating
> strong groups are well-understood, but you might not want to
> use them cross-domain.  These are also same groups used by
> IKE.  Rich: will encourage discussion on the list, we'll
> pollute IKE and TLS, too.  Tero: these are the groups being
> used in IKE.  Might be premature for last call, needs
> discussion

draft-ietf-curdle-ssh-modp-dh-sha2 is using RFC 3526 MODP primes
based on "pi" instead of RFC7919 primes (TLS) based on "e".

Group modulus security strength estimates (RFC3526)
+--------+----------+---------------------+---------------------+
| Group  | Modulus  | Strength Estimate 1 | Strength Estimate 2 |
|        |          +----------+----------+----------+----------+
|        |          |          | exponent |          | exponent |
|        |          | in bits  | size     | in bits  | size     |
+--------+----------+----------+----------+----------+----------+
|  14    | 2048-bit |      110 |     220- |      160 |     320- |
|  15    | 3072-bit |      130 |     260- |      210 |     420- |
|  16    | 4096-bit |      150 |     300- |      240 |     480- |
|  17    | 6144-bit |      170 |     340- |      270 |     540- |
|  18    | 8192-bit |      190 |     380- |      310 |     620- |
+--------+----------+---------------------+---------------------+

as has been mentioned, the RFC3526 groups are all being used in IKE
and group14 has been used in SSH since RFC4253 was first approved.

RFC7919 seems to provide the following:
+-------+------------+----------+----------+
| Group | Name       | Modulus  | Strength |
|       |            |          | Estimate |
|       |            |          | in bits  |
+-------+------------+----------+----------+
|  256  | ffdhe2048  | 2048-bit |      103 |
|  257  | ffdhe3072  | 3072-bit |      125 |
|  258  | ffdhe4096  | 4096-bit |      150 |
|  259  | ffdhe6144  | 6144-bit |      175 |
|  260  | ffdhe8192  | 8192-bit |      192 |
+-------+------------+----------+-----------

All of thee groups given above are safe primes with a generator g = 2
and q = (p-1)/2.

I have no objections to adding the additional five groups to the draft
if that is desirable to the Curdle WG at large.

Would the following additions make everyone happy?

    diffie-hellman-group256-sha512
    diffie-hellman-group257-sha512
    diffie-hellman-group258-sha512
    diffie-hellman-group259-sha512
    diffie-hellman-group260-sha512

Or are there other issues to be discussed?

	Thank you,
	-- Mark