Re: [Curdle] Adoption of rc4-die-die-die document

"Mark D. Baushke" <mdb@juniper.net> Wed, 16 August 2017 19:57 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E3E11326DB for <curdle@ietfa.amsl.com>; Wed, 16 Aug 2017 12:57:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.021
X-Spam-Level:
X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id omQCmj8HiflD for <curdle@ietfa.amsl.com>; Wed, 16 Aug 2017 12:57:52 -0700 (PDT)
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (mail-sn1nam02on0113.outbound.protection.outlook.com [104.47.36.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78998132350 for <curdle@ietf.org>; Wed, 16 Aug 2017 12:57:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=KVverMi+bJPe8ecM1+CrTENLVgfYE579ntUr8ykRCGY=; b=Z8zMOMgxoxzMYp9LRs6t8tq6ZHcEio8K7lvXCne6OP2AW98kwSbd+ULOS1mB+iRgqo9x8W147tTL3hmvo60/C1VeCK7P55WMrdUt1EVgmCvIKdbpXW6oP0oUUxjbD1L7QlbqafFJ6DvKVhJ7GF+jBtxoCz15zT3/D5cPWJKgbEQ=
Received: from SN1PR0501CA0005.namprd05.prod.outlook.com (10.163.126.143) by BN6PR05MB3425.namprd05.prod.outlook.com (10.174.232.25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1385.4; Wed, 16 Aug 2017 19:57:49 +0000
Received: from CO1NAM05FT033.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e50::203) by SN1PR0501CA0005.outlook.office365.com (2a01:111:e400:52fe::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1385.4 via Frontend Transport; Wed, 16 Aug 2017 19:57:49 +0000
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by CO1NAM05FT033.mail.protection.outlook.com (10.152.96.145) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P256) id 15.1.1341.23 via Frontend Transport; Wed, 16 Aug 2017 19:57:48 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 16 Aug 2017 12:57:00 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v7GJv0Fv028627; Wed, 16 Aug 2017 12:57:00 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id 7D7C21144E; Wed, 16 Aug 2017 12:56:59 -0700 (PDT)
To: "Salz, Rich" <rsalz@akamai.com>
CC: "curdle@ietf.org" <curdle@ietf.org>
In-Reply-To: <AF662C78-D0D9-4C57-8B45-B95C2311A048@akamai.com>
References: <AF662C78-D0D9-4C57-8B45-B95C2311A048@akamai.com>
Comments: In-reply-to: "Salz, Rich" <rsalz@akamai.com> message dated "Wed, 16 Aug 2017 19:48:28 -0000."
From: "Mark D. Baushke" <mdb@juniper.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Date: Wed, 16 Aug 2017 12:56:59 -0700
Message-ID: <98476.1502913419@eng-mail01.juniper.net>
Sender: mdb@juniper.net
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39860400002)(2980300002)(57704003)(189002)(51444003)(199003)(77096006)(626005)(7696004)(69596002)(6392003)(6266002)(117636001)(230783001)(2950100002)(6916009)(86362001)(305945005)(6246003)(5660300001)(7846003)(54356999)(4743002)(110136004)(76176999)(6306002)(53936002)(50986999)(4326008)(55016002)(97736004)(189998001)(2906002)(229853002)(76506005)(50466002)(53416004)(966005)(478600001)(23676002)(8746002)(8676002)(68736007)(97876018)(81166006)(81156014)(105596002)(7126002)(8936002)(106466001)(356003)(47776003)(2810700001)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:BN6PR05MB3425; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; CO1NAM05FT033; 1:NhDvjpZggXWLmLZaJq1GyHTK64HptOzz89w8fpQ07qMose3VNdaLED8wcvnJarDn/v900wRfoojByrUAeFSo3+ASouWFN0jiNsGUV4uKvusyLYpyfNjqIFJRIWjNMzht
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: ea6067bc-21bc-4f2b-0c90-08d4e4e11267
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(300000503095)(300135400095)(2017052603157)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:BN6PR05MB3425;
X-Microsoft-Exchange-Diagnostics: 1; BN6PR05MB3425; 3:LBc+geW2KwqIMeG4kKHgONmMG3Mu2BDQwKU9xdi8Ep6Q3cXRr7EuenJcMNwMAdLm6MYSuejFX8Zazal1M5ShSK62jSJdmRS0xiE6my3DafznPTnPK5bRAS/V01dTvL+KyYtdV7lmFUL3Zl4TILrFJiGdcHAkezS33JADwbBrAkYBY3KrDNMw/b6l3o5gGwihAQNfoALGMOiuc1f3tl+jK8JSsjTyaNLmghTVG4k+vEtU3zezHp7kL98nRJ0j6rmA8anPNjP0VBe6rLcmyeu284/2lx5qNiAO2CCySwtcKkzCKbtEqoylOwEn2nhg4b2TphjexI6XzuvgTxVJsGya7AUDgPHgY+UyjlbiZ1CrHnw=; 25:KaHfrzK1CtR0btvmcE2hy+DDntpQCYh3HTuwcpx7b1tseIY4N6gUBkD28JGrjx6RqC9TMFanxlEYo/52JjgDCbcs+VsYD+z59ag1Aj/uqVmEItoJmyKVThHKHJX+o2tRCpwKXslkQ1Variz+xCYvXsuOi0ibFmyaCt/ZN1l5Zqq7qU2tlz/7A6U5kVufQjzjtq+3lrny9Buy/9S3Zp7YpH4n4TNCH0dlIBPZqFuRPfuZAP5cvW4FkUNhzaXTDyoPLbxUYQ7dmGEFTJ8j5uavAYB90mlqMHmq/hHoVzpb8anSAnQqtl0cc/turSl/pwmqD+GyEBxESWQm7tItOApz4A==
X-MS-TrafficTypeDiagnostic: BN6PR05MB3425:
X-Microsoft-Exchange-Diagnostics: 1; BN6PR05MB3425; 31:Kvrj5RjDdB7BnEJokiHIKCW/vz2PjGQCEKW+S/Ba5VbWkOzOr1TEYjqREtBqVGGk/cKoz2fJSztqfvQ3bZU72K79Rz9aUkH604MOlUCUg6wabUoHnpttIuDJId2XlK/lU1TwcU7myQW/W4KF7YiXaji1viEBuVIlF9D7+XL/BnHlZBOyHa3h31YthQvYFfRuz/JP+557AIXJSYy2RpeKuj5DOcGxcWGWSCGyS4FerIA=; 20:BbIh8MSkwlz8UsD5egjcgjRm6Jus7LWlrFbC7JZBbSJaYgoZwfOXli4pG7/4RiFjXmPIIEp3rjEgFbOKL50wnKaXMShilBvXoP2A8Cwqv/mV5Mzwgvq1Ol8G6df21+dFqErE3djc59+C4cjY+s/0k9kkN9gvS8tx+5STYKARaJHw19Fj76ZJK9IVCvItrlyIH5vdiPacc+eOEoZE0K1Xm0jUfBaDVOSSyNyA16VhUw93Hz7HRaMX+MhwDPepuoywr3fMupB1Of8wgWGJY4zb0SH6/G1dlKc95Uuh9J5ZDPJi15mKomFSn6j9t/xbICm3noWQqQ5c632xHEa1mKz3ip1HWtscCrbsj6KjpeFjuU1oP3pdWghUaaVYJUNTs9avNpjyW3VXTrzzatxnhk9Jch8f1iulML3PLzvTWfxZq5NS28msxffmqYgqF4K6Y6iFm90L667T5pmulv28nc98tD9FoExa4NBJaVwGJz23XMd7/AtYNEaZOyJhsm9m5Xvm
X-Exchange-Antispam-Report-Test: UriScan:(120809045254105);
X-Microsoft-Antispam-PRVS: <BN6PR05MB34252FC3E5AD1D2AD4B9C110BF820@BN6PR05MB3425.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(5005006)(8121501046)(13016025)(13018025)(10201501046)(93006095)(93003095)(100000703101)(100105400095)(3002001)(6055026)(6041248)(20161123555025)(20161123562025)(20161123558100)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:BN6PR05MB3425; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:BN6PR05MB3425;
X-Microsoft-Exchange-Diagnostics: 1; BN6PR05MB3425; 4:Gb+bMlY41nfbzDYIr9cAByTS+8PdZEbpLI4VA6iNo5downM7bQFuJlS9UQ/rdwauXaH7GH2cbM3jibEiJ2zCY9sljlT5aVAFRCr4ylFkwoV1rXNtRi9ubXD5IX24rUjF1BSU5o0Nmz/MWvSM8fiBD83vcwGyAspQuqjwIBB6QTQHHszIyKZGw0A2hY52bdR5UiN5L7cMyk9DmIofzuhRyrwI+LdB2OCkOZFWb6UTBGi/g829q2pUoIgQtI8tFWS6KOyMppLpYA0ZK3a8v3NSDMBX2Fom/Pw+uWkfMxgB24Q=
X-Forefront-PRVS: 0401647B7F
X-Microsoft-Exchange-Diagnostics: 1;BN6PR05MB3425;23:zsDLR3fgJbXl7Sc34dH8y243UPZR5L1Y3NwALIv7Hau9iSdDIc8sScP0qO/w0EQsW3RWPEldCxx54rCWcgbx0IAFqOo+30JylCqGzP8OM7LaIg4J9zv8JKx6IKKK0Q4h9Wsm1aOQkk4Tv1r3LGFosAr27rVcwV3xBYr34YcxVhZht3pg/6iOnWVQxKMy9EC8VD9dzqrzHs4U4u/bjY91+RAZ04nrLvYESLFtltK/3Mnqr7UDt2SLpqWwLw6iW1RTCiEVCw1MKY02isY4bSXOTZvfhSJxd68xHUGOjl5EnJoqk3uIZ2Nu+gUXQqT+6VBUbsTpjXBxs5XYBWCZzU7ZR0nzctRbiTiWRPQo4/3Q7pDPswFD3I4smgqXw6WIgDAQqBvjZQN846FyNpjOfQhyrGa3QKUlo3bpHDnsXFbDGosuuXSRfowCfAkZEYOG9ncvYzokGflFmYnrcROc/D3sPP51TtT/xaT6sPnXj1TFMeVbKB9Qz2/VX4OP7y0zILizua4lFNVigm87rSFIThck9pEH80XqVvU8EOg1kskYNfjzKHP+0caHHnp3/OFkGDcVjERbIy7J4xB0TCUtuFokq+FSzaQjfgrUjmHB1MjXZm7NjrC4uA8PzDoIOEExZpjZehZZJ5R3asWDZuc8BpCY5CsQ2NkiMTI2cl2wagw0EjJMHKeQwLaL35CjAAbc1VzPpEtrf43GC1eatzrNQcEShNM+F1dWTpcWnFoFX72og52/7yfhJrCYqULJ0dg5gnKCE063lTkLTgxSpSZts7w1pzQQaYvMTpcBpfscanb/PJTnPqi72wU3gpk8ElpxT/6lC/gog+MIaQDn/QCFWMXCZ8nW1Qk4Jw8PfCrFZgxGrVikDnozSKJGtcKDZ1NRbaBDWyIHFoXXFbs10JnkrCJp7Ndtw6cY+xdwt/IxMdEVzSSfB2MtHdTJJtBWZ683wEFS1K+K3gntCYbq3bTYmT8cVvaq64UjesWdQ/DEZ5HDRMCynQThGoskhqaafBmkFkN/mekl5mhmXS/MbvSzxn5C9soQQ2y95+rXPYSijQk50nWTSVxlkBRwMu7hD6yBb3e3e0VAcsPelJysdOLlKrScb2MD6eb2znN/FLN5Os+Adx92E+m5TWo3Z3taZobzzIUULtvsAicz3XT84u6zrG6J2/mVZZ4V8nAu3qv5mMkOkYdA8j6xgvAwuzpQi7/Dz3UylIX8+zoIOdeeg6hnSOGscEXBtcLo+SvbiI7ZcAF7e0Ve6iP+s1qaGhKbD8SeD2VT
X-Microsoft-Exchange-Diagnostics: 1; BN6PR05MB3425; 6:v8/g19QQweK4kSZT5vMYgpolgTT7uvxw1mWd6Gsk/X92xcQup4LEqhdWqEr8UkwOSeRlGjG0Qh3gAZqtQnZdKdnPZdDP43lA/XLAHlZHqUdJ1egrNLMqErhEUKDAH7xbTHlO/p2JQoZdAc9a7Shqj5wteNk7eqUz9PTCwlxNXHL4xRllVGi/dP0HGy789giK6KC9P2PLNcHUToxNZKWaqJYd0UyogMjmdOsxox0nS/2CcjmRWSOC9+xu/dSn65mLmpFawDJj0i4uhvE6uGFx1ld11k7aOIFi3DmhjTm4pXllbIteyH06nvulsc3+y+8dhbLB0pqJGVB+XiBO7wu74g==; 5:JNMrb34/ABXjel1X2xdnfu7l8tkZVJ391bVjOwDjV15Ek8iXNlSPXfwbeL/p+D5AQcuYHxH1Qs2Wj3OEVme9JZWeH7MpgwZ42ywMN94OCd/V5VmG0v7NJsRFOuJPHjnGEtDFDMwy1Q98KDTm1kTNLQ==; 24:+DMQHk6jWN7V0SK4kGb1Uq85iFhtCNN6+XPpk81C5k7BukmFdzWicJkdAj88N1/F5IY8n4PpsRaJtDNzXu8hOd/EEdP9MvY6JUsM/RI1br4=; 7:45E4OjvNbD2x3urixfpo73ZkrbQ69UTNOBDbrYfhWsHpEO4Ls2VjXfX6lH19xcqAeGebV3OYRuJZgYDmoI2VE7H1h10epInJBZxh65NAt5LdPUsX9X3RpZ5fJ51WyBWLk/w4ZGec/ZZqlivPtj8++wzQaG/aGztpSDNJVAa0IAtVvhg0h6cA6pQ/SLA4/FXQ61jC1enRtL5rXT17RCA/N7ZaV84IfIDOBwE3+4bPlIE=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Aug 2017 19:57:48.5318 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.12]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR05MB3425
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/9ZTEOuB_doF7J69rRcUygc81dfo>
Subject: Re: [Curdle] Adoption of rc4-die-die-die document
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 19:57:55 -0000

Salz, Rich <rsalz@akamai.com> writes:

> We have adopted draft-ietf-curdle-rc4-die-die-die. Full doc details
> are at
> https://datatracker.ietf.org/doc/draft-ietf-curdle-rc4-die-die-die/
> 
> There are concerns that this document is over-reaching our charter,
> and that a document to remove RC4 from all protocols is beyond our
> scope. It is hard to argue with that ☺
> 
> Should we ask to expand the charter? Daniel suggested maybe a crypto
> policy document, but that probably belongs in SAAG or even IESG.
> 
> So what should be taken out of this document so that we can move
> forward? Or should we ask for the ability to condemn RC4 for all of
> the IETF?

Yes, this is probably technically an IESG issue.

I think that means it is up to our ADs if they want to shepherd this
document to the general IESG, or split it into multiple RFCs for each
area. I am just not sure.

That said, I believe RC4 should be condemned for all of the IETF. So,
who do we need to ask for the ability to speak for all of the IETF about
the insecurity of RC4?

	-- Mark