Re: [Curdle] call for adoption for draft-mu-curdle-ssh-xmss-00

"Salz, Rich" <rsalz@akamai.com> Thu, 21 November 2019 21:38 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C21AE120121 for <curdle@ietfa.amsl.com>; Thu, 21 Nov 2019 13:38:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zhOeh94Z0S2i for <curdle@ietfa.amsl.com>; Thu, 21 Nov 2019 13:38:57 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D3E15120132 for <curdle@ietf.org>; Thu, 21 Nov 2019 13:38:57 -0800 (PST)
Received: from pps.filterd (m0050093.ppops.net [127.0.0.1]) by m0050093.ppops.net-00190b01. (8.16.0.42/8.16.0.42) with SMTP id xALLaA9G023472; Thu, 21 Nov 2019 21:38:55 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=jan2016.eng; bh=R2d21A8abC5InXpN6KjU6Droce9xJ71szHRyd6eizU0=; b=PpENjfKIJSBYqNAZoiraimWku5IDBHgcrLheehlNnYAdeVu/U3XHXDAGIPRjLwVAuVCA 38lh6YlYHDs3eS3SNmtWFr3BFEZWNvrxwfxv+3WmhSf3MzSIVf/JGScfYQUHBAax++PS 5b0X+v6MKHW5GqhPmDf9axfXegBSPfY5GX2hqDyjSZtL0KyC+NwSS3ZAqkYMAHmvM3tv JXOzwp2uReywCy21/90ziCTZZKXkmjYTWMS5AkKw/RElPfZfnQgmU44VW3tSFpWR2MDv LpqDd+1f81RWV4uFJHSDFF6SBUXNBgaDyA8YYoG9ORttztnFux7tDDBggOs0OfrnTIf6 ow==
Received: from prod-mail-ppoint6 (prod-mail-ppoint6.akamai.com [184.51.33.61] (may be forged)) by m0050093.ppops.net-00190b01. with ESMTP id 2wcq3dum1r-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 21 Nov 2019 21:38:54 +0000
Received: from pps.filterd (prod-mail-ppoint6.akamai.com [127.0.0.1]) by prod-mail-ppoint6.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xALLW5pa011538; Thu, 21 Nov 2019 16:38:53 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.57]) by prod-mail-ppoint6.akamai.com with ESMTP id 2wadaxx36d-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Thu, 21 Nov 2019 16:38:53 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb1.msg.corp.akamai.com (172.27.123.101) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 21 Nov 2019 16:38:52 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Thu, 21 Nov 2019 16:38:52 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>, denis bider <denisbider.ietf@gmail.com>
CC: curdle <curdle@ietf.org>, Daniel Migault <daniel.migault=40ericsson.com@dmarc.ietf.org>
Thread-Topic: [Curdle] call for adoption for draft-mu-curdle-ssh-xmss-00
Thread-Index: AQHVn7AwtLfMiEtp6EiXR15bcEPe5aeUqXQAgAAIrgCAADevAIACGNwA
Date: Thu, 21 Nov 2019 21:38:52 +0000
Message-ID: <C6CDAE9F-E1FD-4F64-BBCB-E7A03E414C75@akamai.com>
References: <CADZyTknBW54_qM627mYSdF7qKpcU4xrpS4jh4Os_hmqd2mn9ww@mail.gmail.com> <BN7PR11MB2547E06E6CE37E4BD7300977C94F0@BN7PR11MB2547.namprd11.prod.outlook.com> <CADPMZDAkBXSLpsiN9XNFJCPStn+vX4-6yuG_towbROjhLv50ow@mail.gmail.com> <BN7PR11MB25470BC21C29CA4412E9778AC94F0@BN7PR11MB2547.namprd11.prod.outlook.com>
In-Reply-To: <BN7PR11MB25470BC21C29CA4412E9778AC94F0@BN7PR11MB2547.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1f.0.191110
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.216.91]
Content-Type: multipart/alternative; boundary="_000_C6CDAE9FE1FD4F64BBCBE7A03E414C75akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-21_06:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=716 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1911140001 definitions=main-1911210179
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-21_06:2019-11-21,2019-11-21 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 adultscore=0 spamscore=0 impostorscore=0 phishscore=0 suspectscore=0 mlxscore=0 clxscore=1011 bulkscore=0 lowpriorityscore=0 priorityscore=1501 mlxlogscore=692 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911210179
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/Qt1xWNoyr7G_0pZ_xiAYXG7YaQ8>
Subject: Re: [Curdle] call for adoption for draft-mu-curdle-ssh-xmss-00
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Nov 2019 21:38:59 -0000

Speaking as an individual, I am opposed to adoption of this draft.

The IETF has pretty much decided to wait until the NIST post-quantum crypto process is finished.


  *   SSH is rife with short, ad-hoc sessions in practical usage; as well as long sessions that can last many days.

Yes, and  for this reason, and because NIST explicit said that this will be part of the PQ process, adoption is premature. The NIST link mentioned (https://csrc.nist.gov/Projects/Stateful-Hash-Based-Signatures) explicitly talks about the problems and concerns of managing the state.

                /r$