Re: [Curdle] Call for Adoption

"Mark D. Baushke" <mdb@juniper.net> Wed, 13 January 2016 16:50 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D9891B2F24; Wed, 13 Jan 2016 08:50:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hnfdsIHKaqOP; Wed, 13 Jan 2016 08:50:43 -0800 (PST)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0148.outbound.protection.outlook.com [207.46.100.148]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1A441B2AD6; Wed, 13 Jan 2016 08:50:43 -0800 (PST)
Received: from BLUPR05CA0048.namprd05.prod.outlook.com (10.141.20.18) by DM2PR0501MB1389.namprd05.prod.outlook.com (10.161.224.11) with Microsoft SMTP Server (TLS) id 15.1.361.13; Wed, 13 Jan 2016 16:50:42 +0000
Received: from BL2FFO11FD038.protection.gbl (2a01:111:f400:7c09::195) by BLUPR05CA0048.outlook.office365.com (2a01:111:e400:855::18) with Microsoft SMTP Server (TLS) id 15.1.365.19 via Frontend Transport; Wed, 13 Jan 2016 16:50:42 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.19) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.19 as permitted sender)
Received: from p-emfe01b-sac.jnpr.net (66.129.239.19) by BL2FFO11FD038.mail.protection.outlook.com (10.173.161.134) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 13 Jan 2016 16:50:41 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01b-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 13 Jan 2016 08:50:05 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0DGo2D11978; Wed, 13 Jan 2016 08:50:02 -0800 (PST) (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id C4A1111446; Wed, 13 Jan 2016 08:50:01 -0800 (PST)
To: Daniel Migault <daniel.migault@ericsson.com>
In-Reply-To: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
References: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se> <65770.1452699581@eng-mail01.juniper.net> <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
Comments: In-reply-to: Daniel Migault <daniel.migault@ericsson.com> message dated "Wed, 13 Jan 2016 16:31:39 +0000."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Wed, 13 Jan 2016 08:50:01 -0800
Message-ID: <85658.1452703801@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1; BL2FFO11FD038; 1:1uCcf1y8H/SHvTk0KhcFewyKSn6uygL0xIdM51mMtNWExlcI/3tH5q7ZgDy3qRFXkLShpW6lFjC1wWmQXCaDxqqgu3LmmrR7E20oaOdotPtjvfivBmq8ccOouhgv3RWVDMOh6/jDwg98AvaPPCy24RcoZzeJCxv/6gWiClaq22ja24sSdp65nrL0lrVieAyJHACCnp6DObsgQ12r390kamQaUuk/d52+yIlaexIc515l2ou7T3NKpXASReG6b+gn0YU10MBSw0fRmdV/zDO4mIeo+3DGXBP4HNzP3+T3SsDOdjSx+0/8ohqLgHotX09Qn462ILJYIt8SnG/1KlM/VeuUeHt9erzJhSImVlot2pF3MxJw+AsBscAjYVJWzwsCCkT+V/Rt1IQT8GeAMzUxo1Q7tHj8ui4qzf+Sb/Wxbl4=
X-Forefront-Antispam-Report: CIP:66.129.239.19; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(979002)(6009001)(2980300002)(51914003)(189002)(199003)(86362001)(5003600100002)(77096005)(19580395003)(4326007)(54356999)(2950100001)(53416004)(6806005)(76506005)(47776003)(105596002)(5001960100002)(106466001)(19580405001)(11100500001)(586003)(15975445007)(92566002)(81156007)(87936001)(5003940100001)(97736004)(48376002)(117636001)(50466002)(110136002)(1096002)(189998001)(76176999)(2906002)(1220700001)(50986999)(69596002)(42262002)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0501MB1389; H:p-emfe01b-sac.jnpr.net; FPR:; SPF:SoftFail; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 2:WnyqhCDGaP764tN0s3ozYkQCNbp3i70AxsCqiaKWdNjEy3hRDBObdorwqQZfFQ3hMqGCx3op2S9hX29MtB2KofVBp22v2pST9mby0xwIEkuOEmr9SUV/J4xKk/GwYQlWtO4hu6Z/Rbx6s3TIWigslw==; 3:nmAn5g9tqe7z7LuiT/W650LH7G3rtFs3X4B4r6B3Tu6jx7iLjZzf+vsJQB6jAmWWXHJi/EMRqpR0T7ExCM7jU8v9+5RD0FL93GYZVzIQw3/eiAvCsiMeUGwkOpIhE4oUcngeqEA5780oeQje9RTWfZQmg65gN6Mjq4HPjT8bqgk7ovct1XxC2WduRZfKcLNfz3oVz06ABK3nrRlJcijZPOgygbFZZ+44XOkLiN3I3Xc=; 25:GMgooY8AqLI2SQg/VlOahFoQeO59A2r4Sj7PysEPMF622zg+ijD874VxzhGJJPNmMKkvsN4q3BCu1iMWzqACCU9b/DPqP7SePUhC7pOWOGB+FG0AiRO2HDwbctroQYOsiCMUXHk96V3T27W8+GGYBCpbTT6oNcM5Yii49bHne6yVZkYqnN5iWdWZwQea1efJy5YSBssftpROGVYLPf5BmFUJy9cwbE+gzZ23oOeTe05kycjeDazjsa/MppYOQKYi
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-MS-Office365-Filtering-Correlation-Id: 89e43c2d-6e2b-4e2c-183e-08d31c39ac31
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 20:mOfaI3rJEqHihH5mw+AQRvgAFEYma0ChPtjHqgIsAldKGzr6CoqcGbRG/njbtBxTVnr9QnJgm3vt5Lp9hkVkIXIZjUCgE9+12iNUM+VnADz/NdvfaCUcFKHEWCe6KoLXsQc14Tc5zryzNWCWjb7hQlKqsyOfOEXb1NzaZmiDzOMgt7+vvrw4N3SQM7kiz4QRmRj3IgRdmgEqtHEHnv1KXUTE+UUhbQ2Akgj0Hi7Zlj9wUwUkp2qe9MzhFY/v7jx/hFC+mtKNtLGOqVkDBF/457QnSo5xlUv4UYQavoAgsy8Nen1B+LZq5r0fJDnovuRdjTtXcwbhJUwmAj+nzTvqKOz41HDbg+fVy1HoaoSyNyRA5SpB3Nm/h36iKAkrGpZPZZ1uefw3lCe4qTi1fb0XoUZFRRsZLk6G6UhpqLA9IeOfvbLw0npLDqy27IXJJbh/KO2V3E4tFe1kFe/B6gSnlLHo566iZaAx2pKsRiph4w5QPbPJ5KjhkAvK4O/7rG1y; 4:3oiH6poWFT01yudN14PQfeXVTJyzURdPPPoxltLurQtSyhsBNibv/Qepn98pEe1gYH+T3fZABjgsR4u9qvIElO72XYJTsEMHWesGWfgYalpAE/YCNsogqdSRZR6Inl6BIEFK7HBoYeYKmU04bhep3F5A58hKXMAtx57+USn5oyIkAS2S3r73yutvXnNGkcxEG29C3K0Ppk+9k/KSr37h80ZiLH4CMb9xbFXLKuLYIPtVs0DgrD6Qw3CHKWgT3BCiwbuxe77NGKnL79i2i8/JGAq181lQqw6nDAZYgmJ7+HFC22F8tlgxjq6F8TdqOGfxcuXvE0qKr42gGBzDW3Xx7Wf1crJyQi/MvoszotAop3u3HGaFmE8UO3Bw7RGfcn4koJSv3vK/nZuymE4bjL5pl4CZoMiGRY3wmp2V8FVyZyBiUZ7th6RmMJivBhG0FWqi
X-Microsoft-Antispam-PRVS: <DM2PR0501MB13898DC5223078E74BE5E55ABFCB0@DM2PR0501MB1389.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(13015025)(8121501046)(520078)(13018025)(13017025)(10201501046)(3002001); SRVR:DM2PR0501MB1389; BCL:0; PCL:0; RULEID:; SRVR:DM2PR0501MB1389;
X-Forefront-PRVS: 08200063E9
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 23:OTlbZwH5x1PS3Uyfk7vq8Cd8NPKu+PMkmEVLeZx8RwjCD5EvxksSZki5CqUJVD5K/FLLy639hFBmLHinyUUjVyK22mzGJN4KqIdzJGrlT8BAyxGOt596aGk6LTERVjwcl3C6CWWIbAz1LsogEScxeg8Eqy/um17xsThgzMz2u88tielKFtxKgaC95nZJf3/HoVULHY4+xyFBJT5/+7dNGJbo8ytCDjOC6x3moaNKYfCP3ih+0LNokiQ2++uM1GCwcBomjEYc74hwSHKQGSMmzZ3cSkn/sGMaan+hRVj2OqbLJvqkekKyUig0PTs7WwYa7MHY7lB/wG8WCGqnSFkWA89PWNrfd2vsf6zd8A8TX9UCoxWeo1XGzKQJHeC8tfEMIGx/I9WT+OE3mPwsrdVbLB07BA4YsZUy3erZlG6x/OOmOkjvyJyxf26LYCIMDGnYUZRtjgp7hpZCLhJJytLC7rjjiMuO8ItBucNHYXDN9BuweF/jCuVBdpfZ75jt6A+b25E+n+7wgawlszFF9BbGWQH7XLmvpravT7QQDpcS+BrELVctU8mjZnnbZvAetNJJ68BS5PztAVTeB/CmBt0StYFjrw3Ji0UuY/mUOM+9ApM6IZx0V1OXcqvC7OBM2x7xcshtDEpzu9S+OXfqkNdIljkLy7rlRpt6EVDN5bPZN/GWGCGTliE2WyC5ndjEg2ol1oKnJM5YOLklcB/xp1q030Xp7B7/bw7iO2fst7byFO6pasnBOFwqm0aLlun1yFAaHZ16D4c8gE8Jcrl1Rroal4estZpacTTCndCBRgcnihCOnWNzRbXkfhxFoQEmAZDmApOGlpW0CMiy6vqejLPCZZK6ilhuawIeNDSASImYC5ihOurE044IN1Opmt/rIXhYlRJb9ynfw6Cnh5TcCMpaWOOHNSHiYTnpK/9mRn4MyT4r0ZBYczAgrFTHkFrmnYd/tut9O3kWLem1hwfsiKg+bvY0RTbuCyoMRYG0e7/5QcFdUQHqY52uWNL2hd+m6hlhhHyuh4vTXpYmDfVS9GnP9Za1XbeiKYmEfRZ1ggYCUjvIBktQONa6Sh96cailqNmHgskQdqUejkd2xsZkYZP7wUoIXuWT6wHHLngvBDZD4kK0ro8DF1ac4qmne6qGhUXkaijAhAGQ67Ov1Ag2pMWWVA==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 5:hgXySkb7nWyt9OzzD+5x2bpjiD6sSrcDBMT5X7+NK+4196oxa4DvcHx/NxEVmGSC5dnqTH905hQl+JWS9/5p+oirR/Y4PlwpxksEXm2jaJ4mxz/+8xJRygQJqfSYpvtuszjVi672q8dkGzC6kh3FIw==; 24:cMlxeb23HYuEyXeMlIlGTm14NtBWrQoSfLNv07zs+b+us2bAR3sM+QnMIfAzOed18qdDp2uAuSB44s8AhR2+FPmPTpQmViezTYDH7Rh9QNI=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jan 2016 16:50:41.3396 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.19]; Helo=[p-emfe01b-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0501MB1389
Archived-At: <http://mailarchive.ietf.org/arch/msg/curdle/AJ3sw1VoOlTSO19jbdHWpls6PvM>
Cc: "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, Curdle <curdle@ietf.org>, Curdle Chairs <curdle-chairs@ietf.org>
Subject: Re: [Curdle] Call for Adoption
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Jan 2016 16:50:50 -0000

Daniel Migault <daniel.migault@ericsson.com> writes:

>  Thanks for the suggestion. I think it falls into the scope of the WG.

Thank you.

>  The question I would have is whether it would make sense to extend the 
>  document to the crypto suites others than DH - i.e. encryption mac.  

I am not sure if this is the best course.

There are other SSH drafts also in draft by other authors

  https://datatracker.ietf.org/doc/draft-ssh-ext-info
  https://datatracker.ietf.org/doc/draft-rsa-dsa-sha2-256
  https://datatracker.ietf.org/doc/draft-bjh21-ssh-ed25519

which are working in this area of SSH already.

>  This would result in a document providing cryptographic 
>  recommendations for SSH and have this document regularly updated as 
>  crypto evolves. Any opinion ?

Coming up with RFC 4250bis, RFC 4242bis, RFC 4253bis, and RFC 4254bis
would be a lot of work and keeping them regularly updated would be
non-trivial.

I am open to suggestions for additions or changes to
https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2 
as long as the ietf-SSH group wants that to happen.

Does any one else have any opinions on this topic?

	-- Mark