Re: [Curdle] Kathleen Moriarty's Yes on draft-ietf-curdle-ssh-dh-group-exchange-05: (with COMMENT)

"Mark D. Baushke" <mdb@juniper.net> Wed, 20 September 2017 16:34 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C367313319E; Wed, 20 Sep 2017 09:34:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.021
X-Spam-Level:
X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u-PcI0zDjMWA; Wed, 20 Sep 2017 09:34:21 -0700 (PDT)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0125.outbound.protection.outlook.com [104.47.34.125]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAB8813420B; Wed, 20 Sep 2017 09:28:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=e1eBaT0HclULuf4S6bhJqHXVjK6uxp4zDZVjl/aIsXw=; b=Mwai4iB7UAamPzEAW+TiGGQpywMpZh4OAFMWCRYXXeqk4MtySup+gI7vfbNGNzU8yptD0wnTAH+XBClO/wm9qivmDjP7KafNqTJX9oCuQIvP5GReHC07yBeJZ83hikycgFkmT6xK4n+RJbZvJkT8K+liI7+SxbsMJvxn9kns/Ug=
Received: from SN1PR05CA0034.namprd05.prod.outlook.com (10.163.68.172) by CY4PR05MB3605.namprd05.prod.outlook.com (10.171.244.162) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.77.5; Wed, 20 Sep 2017 16:28:53 +0000
Received: from BY2NAM05FT063.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e52::207) by SN1PR05CA0034.outlook.office365.com (2a01:111:e400:5197::44) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.77.5 via Frontend Transport; Wed, 20 Sep 2017 16:28:53 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.12) smtp.mailfrom=juniper.net; gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by BY2NAM05FT063.mail.protection.outlook.com (10.152.100.200) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P256) id 15.20.56.11 via Frontend Transport; Wed, 20 Sep 2017 16:28:52 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 20 Sep 2017 09:28:01 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v8KGRxUi008525; Wed, 20 Sep 2017 09:28:00 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id 6F9761144E; Wed, 20 Sep 2017 09:27:59 -0700 (PDT)
To: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
CC: "Salz, Rich" <rsalz@akamai.com>, Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com>, Loganaden Velvindron <logan@hackers.mu>, draft-ietf-curdle-ssh-dh-group-exchange <draft-ietf-curdle-ssh-dh-group-exchange@ietf.org>, curdle <curdle@ietf.org>, curdle <curdle-chairs@ietf.org>, The IESG <iesg@ietf.org>, Daniel Migault <daniel.migault@ericsson.com>
In-Reply-To: <CAHbuEH7O=v2k7UWH-nw-+G80oW7q-pK=F7vxB91BfLRuGsXCJw@mail.gmail.com>
References: <CAHbuEH7O=v2k7UWH-nw-+G80oW7q-pK=F7vxB91BfLRuGsXCJw@mail.gmail.com>
Comments: In-reply-to: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com> message dated "Fri, 15 Sep 2017 16:41:38 -0400."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Wed, 20 Sep 2017 09:27:59 -0700
Message-ID: <21187.1505924879@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39860400002)(346002)(376002)(2980300002)(189002)(199003)(5003940100001)(8936002)(2950100002)(47776003)(6916009)(189998001)(4743002)(97876018)(81166006)(81156014)(356003)(54906003)(16586007)(8676002)(316002)(86362001)(6246003)(50466002)(76176999)(50986999)(53936002)(54356999)(68736007)(7696004)(48376002)(117636001)(305945005)(5660300001)(2810700001)(7126002)(229853002)(55016002)(106466001)(105596002)(76506005)(2906002)(53416004)(4326008)(39060400002)(230783001)(6392003)(69596002)(7846003)(6266002)(77096006)(97736004)(478600001)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR05MB3605; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BY2NAM05FT063; 1:kGuW/oef1hrwTo909B0CcwmddEmKdwbOvkWLwqGVASMLwZcA6tfXYAG+ysCjKJOrXFZ7e/E+ggqxltHxZxY57+61GlxekJxuVMz8f4hOLeyBoR865X0gffExYm2rhk6g
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 2f28a345-fc4e-42b9-b029-08d50044aea6
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:CY4PR05MB3605;
X-Microsoft-Exchange-Diagnostics: 1; CY4PR05MB3605; 3:VPU6dUVQMvQzmwVrTlJevEvH/i8P7o7dzbvUIO8gymaOpsTOm4nWsnU+k7dhBa+q39TrfCr15wKskQYchaC382XOPLSm6mXPRGSG0QmDFxsGbK9VSVCkevfzHMJgFXrm5ZaTLHvNark3O95KGXD6VI/2lvi/jLY/wL7PeE79t5B/6XU+x53JaZAyaczvsus8O2+RnYgkLMuabsNAbw+/zeLufErObzqnFjoWXtBdIseBEgbjY16yklN739bOC1FxK1AVMqR4pPVAafHAHN58FoV/d9PAj6fMCLGgfaZW7AiZL4Tc3jpW2jN09Qpi2X6X5UF6hpMbrJZwsKuGdZ4P3cEkfvzRCSWmcLjoKm3fbUU=; 25:6c8pOlAhv8lTq/Hr56ycDVYrOFoiAuQ2PNy0HKEdUSn2ro8i8rPMXvoqaoD3hHxQ9x9pv3GNXoYjmmvNJvsLe7/Q6V6oKQz7R6MIl8DywMdB2//4KnSL8gcbXbm5Lytm/gp0ijCu08j2mVisJQ0AqpPV1uCCyWI6EYNL0wygM+bl/wKsRjAm5RMUAAh2iN56/2Db1Fc16oESW2ymgtvafBU0ZoVm9FzwaxV1MfJ9klqs0x0G1w4qnWF9GzUtMqw4NGRhTXPGFSdE9dzAefmX/aXk1TeU2WGKCgkj9cIycUZk+RKHkmrfVBFZt3wxT21mFNlFZLnClgplErMslAICIw==
X-MS-TrafficTypeDiagnostic: CY4PR05MB3605:
X-Microsoft-Exchange-Diagnostics: 1; CY4PR05MB3605; 31:NLJi6FKpS7ODnAf9xkdLdLzdqiPKHXulzKHnJJwRtCYhPQLMcrn0adYnPiGSwGNCePheNYKxsJHnc2SfYj3n6659cUg+Aek9fV7nqXq4ciqYmzuHpyNv1DCnk42XuUis5QFukExw13VweRJ7sSDK+yj+ZfjvbXfjCiEHxwleN1VjUXxaHnVCJyFERHh6UD5fUAgGDUT7nhWgD31L+Dv5mkHyROmz1m0V8BtD0moJBoM=; 20:6U/C6eIU+ferb/NDudxpVXLropcWZSYuwNeqTvpgxBQARHhBVf0Ag0VrMZ4HB6jNcYsWV/BM4UBzw1T36aq99Vtai0GGggcj5WY8MahhIff/4oauGm+Xt27DC9DAQrbhYpXTgRCv+RQzzvAE4Dyfbkv1qIao5Kqk4OofdsESB8+01fg24s9BEIGGT5LdCnRWoHhUvhiQFiru9q0/SR2mq0YOd6oWr+vkJgjmYAZgo6OrQN66h0wBPKJq4sQZt/WAHttypFki86UbN3Bua1hU8pcjxfzwuMai21+/h+oqHGhXjE1V/O3MeF78r3tzw4BMGGEJcK1foIpUQmdFWUBKQ42aMrz88D7s4kB1rDCOw4D9zd9gkcr572/6z2M4JoFI7rOf8xs7dvFdfwXCl+VJcuZsSt8YdbETbujNER3yc8qevs0HxXEdcEdPmLBnRjZp6p4qNtjhv0V1qd6rxQu5r/HGY2KNMllHAGzObiNO87mpGhwPzJecm06h/i5gXc0T
X-Exchange-Antispam-Report-Test: UriScan:;
X-Microsoft-Antispam-PRVS: <CY4PR05MB3605193CC6E5BA306B15B5C2BF610@CY4PR05MB3605.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(93006095)(93003095)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(6041248)(20161123558100)(20161123555025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123564025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY4PR05MB3605; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY4PR05MB3605;
X-Microsoft-Exchange-Diagnostics: 1; CY4PR05MB3605; 4:oaaqeSuPbU1kriAQUvzYpeIZipQbMnlBYIgmPvTPrMTrmXgZvIOpB6T6GSel7o/J1WU+bxnPyTum9ok06GMZOiWL/nRh9IvnG+90bbrGc/WKN25kHO1FzlMcYpWyBSiluV9wfEii9NTcY6iBjOO2tVuDdu5nembgV/Pjgmc3f6Gqxe0FDliHSIEOOajv6O2ppwRAwbYPcgZknnCnzsoAqhW0mM4wQ8d6ryEwYX8ssoRm9uQ8kWrICOl9wvsVcCmo
X-Forefront-PRVS: 04362AC73B
X-Microsoft-Exchange-Diagnostics: 1; CY4PR05MB3605; 23:p9YTV03CBhgcQ9CVoAsIOcUt3YoanCrTe5adZmB/Yso2ZEqWuWFUovkW8sPiyH89+TzZ05CFGxNcrWohOkkdKxRfu7kpbTDxISQg7JycZVu6wMLMfhlmM6Ndf3wpkpy8X+m83aTKtRERSnX4LdKbtn1QkCGRbPUeTEIA/HoQGx88HmlgKYKHtGx636PUDfdwNWuNXzfqP+fqggZ7T98ZO1L6/5rVLuZcW0+7O0KXHOJWBYXFEAwwi1I29CS9j8DmUPBOAy/6MrU0PF4Amg1Su6U8/h+YIRtQ4p7kLTQzIQodijSpGI/tu6pqoeEUUoqunvFtNeXK5J4LHYAhOTvrgsr5i/IIfu4K6uNg7NE2K9q/E/CaH8EvvCpraxKh7h9N+8GdcH5fmLan0Wyo38egTbZ/6d3HS7HvSglCUkKb7rE1JHTw39ej7qh2BylifTCXUomf99dI7IaFl6uhujhX2shpAp5V2WbWNnhfttK0dhiF48csCzSPLbUM3jT4ARhRKLuhu+7wFsBYsQmNcux+5cST4Ddw1rRqEbLlsSMof3HIdMqicftU8C74Ux1WhEpiTpVIr8uJg/TPlN2ncJKl0ObG/OWXKpkCscEyrAyx8kz0uZ6rcveX/abaaCfRc6pXfvoVU0v1uuvg95i9rSTQ1n7XbhsNIP03AG1THzDP5tnvuSnKEs+mc+aiCWGSSKG6x75UVYmzbJKqMJ1ysIAGUHJfFiiIkvdBXL1IiQu47VCw65wMc2MG4LFGsZnVeQvaUwWXfzaqb870zPyiCBfqcQQI0P6ZLag4XutdtZFIcc44Z+XR8eQxayQwMT8+1g6haGpYhsEqGhXTFsBAEmqaMpX1xgd1m+w5InJOVF9e11T9zQoDjMx3UKniyj1Wzcz7nVpY+bQ5fSnkCx6oEGAt4O710qE7m6CpbSpikP2Pg/bxq68LG7hHgXHbWnjJWCLWGMYiUrelqHKGq0F4bW4POqLzJ1Sw7ul7PB1Ah6+L16dvNAzK7Syvlomr11TUa0hQdeGm3C9LTuWk92Hsh0RjZTmIukrj1UbcoGxLzo2K/3nV1Ls+NmBlNtYq1oks1GOOrc2Y8DT7BrJBr/GvyWXEa8urctl3XnmO9/DCgRH40VlkCMeO8/osfmebAyTMz4Gbkg5sQwzNCYd0oxQ4+x4zKlVSCTxg6KddNnWbWDgMnq2OXWgFy5B7qj1XYkQbf92j92R6uwcR+sD1qoxvnSF8Sm9AytPv3ey1MbQsHnyY8NTVJC6ObTBY9OchVX3+19wCCwGUDmxrgQKjhxv7yPk6EQ==
X-Microsoft-Exchange-Diagnostics: 1; CY4PR05MB3605; 6:hfqaBKu4YXjg9qWY0pHvTSMmOqnFSLnDSPxTmUxPjtnisXh7gEdr+NGX1zvriejuro0cFeqyc0+6n8HM1ukzENijRZa0GKK7WuzEqjO7nJMOt2P/nBwXkS/ozfYmPrEufowkaJdv4YSqB0YnOlR4w6/Vkz+WdRYGelbx2uuDDwegDLL1WyK1B+etN2K6ldF3WxRRJwgQrwss9RTT9QtwLTxoLBdohCNZYNui7JcqZqFSsjrzwX0ZbNaFnCLyg/gkjtdgykR+7PAdvXCa8WTSF+82P5Ugv13d8yn2e+SIKgsCZK9AEUUKAxvUjMf5eXQsiya6kxuYLjlZKVP94oOMVw==; 5:bGQFGHMns8TY2bua7pSe8A3QG4PFQejPS1cz8JwVFcz9Qg8jcQPaFTY/hK2Wq3FasLF822L6gIh0DE/eRTQOyOuiSSCyGAVotHqiwYBaEVwT5sLyrIQzQ4uyUOVCaBJ7bqGY/1BqqzyDlEZUqOvg9Q==; 24:4KgbzRJFXg2gmC47jWI/ueG4As3kTo+iqiMkj+GbG2Mxq6QsTnzR3GldpE9Cff9bLp4xkhBC/sOK6mGlZttSCRScTyCA4QkBsohe5bkEmeA=; 7:L5HSMK7lPfJgTdyFx2kF8mhsXSXZVarVpuos1d3qGLf3XknMpwD9DLOlN51h9oW6nBqlNQfKU3ZFQtnMjJyrgkktzYx2etwe5Usy35IfWrD+ro5KVQE1I9VAEb/IMTji25/SkgjLeccWQL7SLJTOADbgWSy7PQThmPB2dO7UwWMUU1Soyxhs6r1YD/c0HB2+VQRTP0if29W2EJxiMtnHpMtZixLcThd77IrBQHfyqCY=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Sep 2017 16:28:52.8541 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.12]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR05MB3605
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/iLEHSeoj1DFSBGERw7SLNiGig6M>
Subject: Re: [Curdle] Kathleen Moriarty's Yes on draft-ietf-curdle-ssh-dh-group-exchange-05: (with COMMENT)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Sep 2017 16:34:23 -0000

Hi Kathleen,

Aside: Regarding SHOULD+ and SHOULD- in IETF drafts...

    The draft-ietf-curdle-ssh-kex-sha2-08.txt edition of that document
    defined and used SHOULD+ and SHOULD-, but many reviewers did not like
    them. So, I removed them from the draft-ietf-curdle-ssh-kex-sha2-09.txt
    edition.

Regarding the language in the current draft...

The primary author of draft-ietf-curdle-ssh-dh-group-exchange-05 is
Loganaden Velvindron.

I believe that he is the one who should make any changes to the
document to address comments provided in this review process.

I have no objections to suggesting that MIN value SHOULD be 2048
and that n SHOULD be 3072 or be capable of being set to 3072 by
an implementation as 2048 is not expected to need to be updated
within the next five years, perhaps abruptly. I actually think
that this would be a good idea.

Does this make sense to anyone else?

	Thanks,
	-- Mark