Re: [Dcrup] I do not like the dcrup ECC document

Russ Housley <housley@vigilsec.com> Sun, 09 July 2017 20:57 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9AF8C12F290 for <dcrup@ietfa.amsl.com>; Sun, 9 Jul 2017 13:57:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LpedITqlPSlK for <dcrup@ietfa.amsl.com>; Sun, 9 Jul 2017 13:57:41 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73EEA12EC18 for <dcrup@ietf.org>; Sun, 9 Jul 2017 13:57:41 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id D4B41300545 for <dcrup@ietf.org>; Sun, 9 Jul 2017 16:57:40 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id ERX9M5fEFMuJ for <dcrup@ietf.org>; Sun, 9 Jul 2017 16:57:39 -0400 (EDT)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 4C4E7300268; Sun, 9 Jul 2017 16:57:39 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <20170709203414.90415.qmail@ary.lan>
Date: Sun, 09 Jul 2017 16:57:37 -0400
Cc: dcrup@ietf.org, Rich Salz <rsalz@akamai.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <3A2ECF01-E8A0-4E11-9E3F-6A67C5198ACC@vigilsec.com>
References: <20170709203414.90415.qmail@ary.lan>
To: John Levine <johnl@taugh.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/3HUqOO3b__hdOV3dxmhHPxmtqkQ>
Subject: Re: [Dcrup] I do not like the dcrup ECC document
X-BeenThere: dcrup@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DKIM Crypto Update <dcrup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dcrup>, <mailto:dcrup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup/>
List-Post: <mailto:dcrup@ietf.org>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dcrup>, <mailto:dcrup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 09 Jul 2017 20:57:43 -0000

John:

> In article <14cd0f4ff66348e495e0a7d0da8adc0e@usma1ex-dag1mb1.msg.corp.akamai.com> you write:
>> Speaking as an individual, I think the draft-ietf-dcrup-dkim-ecc is wrong.
>> 
>> It specifies curve P256 and ECDSA.
> 
> Here's what -03 says:
> 
> 3.  EdDSA-SHA256 Signing Algorithm
> 
>   The eddsa-sha256 signing algorithm computes a message hash as defined
>   in section 3 of [RFC6376], and signs it with Ed25519, the EdDSA
>   algorithm using the edwards25519 curve, as defined in in RFC 8032
>   section 5.1 [RFC8032].  The signing algorithm is PureEdDSA as defined
>   in RFC 8032 section 4, since the input to the signing algorithm has
>   already been hashed.  The DNS record for the verification public key
>   MUST have a "k=eddsa" tag to indicate that the key is an EdDSA rather
>   than RSA key.
> 
> If that's not right, please send text.

PureEdDSA does not take a hash as input, it takes the whole to-be-signed content.

Russ