Re: [Curdle] Martin Duke's No Objection on draft-ietf-curdle-ssh-kex-sha2-19: (with COMMENT)

Martin Duke <martin.h.duke@gmail.com> Tue, 20 July 2021 03:35 UTC

Return-Path: <martin.h.duke@gmail.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A54783A09F5; Mon, 19 Jul 2021 20:35:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.087
X-Spam-Level:
X-Spam-Status: No, score=-2.087 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, T_SPF_TEMPERROR=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KDSrBWbURuq9; Mon, 19 Jul 2021 20:34:55 -0700 (PDT)
Received: from mail-io1-xd2b.google.com (mail-io1-xd2b.google.com [IPv6:2607:f8b0:4864:20::d2b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3DA773A09F1; Mon, 19 Jul 2021 20:34:55 -0700 (PDT)
Received: by mail-io1-xd2b.google.com with SMTP id z17so15866188iog.12; Mon, 19 Jul 2021 20:34:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=2Jc1c8Oup9QZHNkFCpx3KHLSuyM7kQwWi0Rzd9q4Fj0=; b=fdEsZe05YbpwkihH7mC7cdQkqPQjztOx37cCPOYsZ/4IPLsL47Av5FiWPcYn9z1YW0 GX8NR8lAJq8oVGiKNXOKSc2PLFYjXEVEzSRFxNe+vNOt6yHv/OKTTTv7bn4E6rGJgzc0 X4OJ6YncKJJ6m4nVBw+BxJDUVEw+NMS75NdLo8kHn0bF5LFeid1GYUJfQtmzbMg8umbD nAsafIFEhPXvajBDD71pptBaWxnSC9G/m7W0YiCZJyESBLmKjGFeL2w0HLbRm/+aC1UL /4d8R3PFzvu58hXyxgbui77/cNNRYgtJfAJ4advAdp/Ifv/aXNXBV0KYA/me6tWGxNDF YqBA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=2Jc1c8Oup9QZHNkFCpx3KHLSuyM7kQwWi0Rzd9q4Fj0=; b=fZzvdnTm7ryhAcL24Ax2af/zy6fV1Cc9sqe4CSHx1nB/IbfrDaq72i/B+Es/hVSBLp ZvZrgIexR0B7Ozk/7nEIUfSDjduMRtdec43z6Ka2Bz+2ZQS3H1pJc+F6MHZ1Vq8z2zLp Qd9En/11gvxSGyAYI5RA36xBYazaZzr2D2Sbx9oAXD8Qdx3TbbwWy7h3Hlzuk08rh6YC mdrtU44c7Pw3hAiqcI0KU3TaMZ+r/tPNzvP+3GeGqE/2EL6k1oFmk279U1eCHb5dAOlZ OtJQJCUT/MHd69cYBi2thSz/Ku6e8s3FC7R/bv8QcoXoA+A66XSWxrqmIy04wQKuI1DW aGsQ==
X-Gm-Message-State: AOAM532ndLVChFMwPue1c4akiZtMhehKUuXxKR6SbnTrfR2KVUTnvxfo +JEPDAB2yd9dWvaka5WMvtEzGMqt20uFhT11vWs=
X-Google-Smtp-Source: ABdhPJyKF65WtyXyP2Jam6koZNe5TflejcLtUnliyBmubmwBGF/sXR7euCZ1uDw0gx9r6KFEBEf+Q+4W4QdDzt0cXyU=
X-Received: by 2002:a05:6638:130d:: with SMTP id r13mr13732104jad.103.1626752094018; Mon, 19 Jul 2021 20:34:54 -0700 (PDT)
MIME-Version: 1.0
References: <162559729948.22061.17056492277505762376@ietfa.amsl.com> <34EAEB90-4DFF-4BC1-8468-1A8769761710@gmail.com> <CAM4esxShhg1AsBaASQ-31AikJZ=ZMxVUMCHzN_xGjxqTWAKYeA@mail.gmail.com> <146487EC-5B09-4FED-A87C-9525B9149434@gmail.com>
In-Reply-To: <146487EC-5B09-4FED-A87C-9525B9149434@gmail.com>
From: Martin Duke <martin.h.duke@gmail.com>
Date: Mon, 19 Jul 2021 20:34:41 -0700
Message-ID: <CAM4esxSq9bPddhBP0mjfGJV1fungyVXzpB2aGX6=qcvPfhA2yA@mail.gmail.com>
To: Mark Baushke <mbaushke@gmail.com>
Cc: draft-ietf-curdle-ssh-kex-sha2@ietf.org, curdle-chairs@ietf.org, curdle@ietf.org, Daniel Migault <mglt.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000b3a0cc05c785bcfb"
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/IBgBO2DZPO-92IU7N5CdTzCMgkc>
Subject: Re: [Curdle] Martin Duke's No Objection on draft-ietf-curdle-ssh-kex-sha2-19: (with COMMENT)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jul 2021 03:35:01 -0000

Yes, that scratches my itch

On Mon, Jul 19, 2021, 19:59 Mark Baushke <mbaushke@gmail.com> wrote:

> Hi Martin,
>
> On Jul 19, 2021, at 7:36 AM, Martin Duke <martin.h.duke@gmail.com> wrote:
>
> SHA2-256 is a reasonable hash for use in both the KDF and integrity check.
> It is reasonable for both gss and non-gss uses of curve25519 key exchange
> methods.
>
>
> Ah. I think I understand your confusion. That said, it is not an integrity
> check, rather it is a way of ensuring that the session integrity is
> maintained across many different rekeying events. As such, something like
> this may be closer to what you want:
>
>             SHA2-256 is a reasonable hash for use in both the KDF and
>             session integrity. It is reasonable for both gss and
>             non-gss uses of curve25519 key exchange methods.
>
> A similar paragraph is provided for the SHA2-512 hash.
>
>         Be safe, stay healthy
>         -- Mark
>
>
>
>