[Dcrup] Re: [Ietf-dkim] [standards] [Editorial Errata Reported] RFC8463 (7930)
Hector Santos <hsantos@isdg.net> Thu, 16 May 2024 00:03 UTC
Return-Path: <hsantos@isdg.net>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E01A1C18DB96 for <dcrup@ietfa.amsl.com>; Wed, 15 May 2024 17:03:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isdg.net header.b="SFzj0Jit"; dkim=pass (1024-bit key) header.d=beta.winserver.com header.b="Mv5ILC+d"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Uyt4IkMi9pHy for <dcrup@ietfa.amsl.com>; Wed, 15 May 2024 17:03:09 -0700 (PDT)
Received: from mail.winserver.com (mail.winserver.com [3.137.120.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A7FD6C19ECBA for <dcrup@ietf.org>; Wed, 15 May 2024 17:03:09 -0700 (PDT)
DKIM-Signature: v=1; d=isdg.net; s=tms1; a=rsa-sha256; c=simple/relaxed; l=1738; t=1715817780; atps=ietf.org; atpsh=sha1; h=Received:Received:Received:Received:Subject:From:Date: Message-Id:To:Organization:List-ID; bh=wCZqHNBp8AKpFaM+JrYpohxtd bk9uxlrbD+hQbEN49w=; b=SFzj0JitIspPoVQCY0zNIr/fp50WPzx9rfI3xuCgw gOuJxW1gDkm9LmcyiBfec6psi8Hdojmpm2WdQ4Tb9dBYAWo5hPB+p+INMBlJg5PY gWB3jYkHtSHPKSye7m0iMPJ7HRhHYfRDUwcPg1Xgz44e6XI+Flksp/UOT954rJ/4 jE=
Received: by winserver.com (Wildcat! SMTP Router v8.0.454.14) for dcrup@ietf.org; Wed, 15 May 2024 20:03:00 -0400
Authentication-Results: dkim.winserver.com; dkim=pass header.d=beta.winserver.com header.s=tms1 header.i=beta.winserver.com; adsp=none author.d=isdg.net signer.d=beta.winserver.com; dmarc=pass policy=reject author.d=isdg.net signer.d=beta.winserver.com (atps signer);
Received: from beta.winserver.com ([3.132.92.116]) by winserver.com (Wildcat! SMTP v8.0.454.14) with ESMTP id 1850090089.1.12872; Wed, 15 May 2024 20:02:59 -0400
DKIM-Signature: v=1; d=beta.winserver.com; s=tms1; a=rsa-sha256; c=simple/relaxed; l=1738; t=1715817778; h=Received:Received: Subject:From:Date:Message-Id:To:Organization:List-ID; bh=wCZqHNB p8AKpFaM+JrYpohxtdbk9uxlrbD+hQbEN49w=; b=Mv5ILC+dLPN3/ybEDUkpvEd vNYBo1L+JTyMCMpha27N7w4QOd/w1iD1G4vJ+7si3w4hpCduPCSo6ZjfTDjEOe2S fXo3kD5hBGmXqVWimyfQk7Ztclu7Fbwi3P2YYk3G7xErRZ/eWTftzong6/aujj+c oB9kESIh+AufpmAzLIiw=
Received: by beta.winserver.com (Wildcat! SMTP Router v8.0.454.12) for dcrup@ietf.org; Wed, 15 May 2024 20:02:58 -0400
Received: from smtpclient.apple ([99.122.210.89]) by beta.winserver.com (Wildcat! SMTP v8.0.454.12) with ESMTP id 2296377355.1.12764; Wed, 15 May 2024 20:02:57 -0400
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.500.171.1.1\))
From: Hector Santos <hsantos@isdg.net>
In-Reply-To: <20240515001817.saYJ-VOe@steffen%sdaoden.eu>
Date: Wed, 15 May 2024 20:02:45 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <CDA9C77F-A74A-4303-AE9E-3E71661AA490@isdg.net>
References: <ZkAOictS1ygyIBZe@chardros.imrryr.org> <20240512005258.N-lL8YIA@steffen%sdaoden.eu> <CAL0qLwYPtxxDhYEjH0D5YkcXBf6Qy6Xcux7PdvFtwhJzpaUxyg@mail.gmail.com> <ACD165BA-9195-480E-9FA0-44A44097E6A8@isdg.net> <20240513203259.hFdFtvyd@steffen%sdaoden.eu> <ZkLM72PMJeWpet5C@chardros.imrryr.org> <20240515001817.saYJ-VOe@steffen%sdaoden.eu>
To: Steffen Nurpmeso <steffen@sdaoden.eu>
X-Mailer: Apple Mail (2.3774.500.171.1.1)
Message-ID-Hash: BSDFQ3CRRQTFF4T7CCOK4TJXYXNR2XB5
X-Message-ID-Hash: BSDFQ3CRRQTFF4T7CCOK4TJXYXNR2XB5
X-MailFrom: hsantos@isdg.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dcrup.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Viktor Dukhovni <ietf-dane@dukhovni.org>, "Murray S. Kucherawy" <superuser@gmail.com>, dcrup@ietf.org, ietf-dkim@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Errata Reported] RFC8463 (7930)
List-Id: DKIM Crypto Update <dcrup.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/5wAhpCQ8ZKBvKWWK3Vnm7BWz8k8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Owner: <mailto:dcrup-owner@ietf.org>
List-Post: <mailto:dcrup@ietf.org>
List-Subscribe: <mailto:dcrup-join@ietf.org>
List-Unsubscribe: <mailto:dcrup-leave@ietf.org>
> > |Because that's not actually accurate, due to the inclusion of the digest > |OID in the signature payload in the "single" primitive. > > ...but the above says "two hashes". But despite that. > An Ed25519 sign operation alone creates three SHA-512 digests > which are incorporated into several further calculations. Whereas > for RSA it is, to the best of my knowledge, crucial to let it pass > over as few bytes as possible (for encryption as such i think > OpenSSL will refuse to do so after a certain limit), for EC with > its embedded digests it may be more expensive but even beneficial > to push more data rounds onto the embedded digests. > So maybe, and in hindsight to the RFC that i would try to publish > in fall if i am allowed to and if the email giants still have not > moved towards this RFC 8463, it might make sense to adjust the > data-hash in that it may come from hash-alg or be included via > sig-alg. > > --steffen I don’t wish to oversimplify here, but I wonder if the confusion is with the idea that in order to support RFC8463, a complaint implementation would have to sign two DKIM signatures for backward compatibility. One DKIM signature using SHA256 and a second signature using Ed25519. No one will support exclusively Ed25519 unless dealing with highly direct 1 to 1 comm I/O with a permission-based system. In other words, supporting this crypto enhancement requires a high overhead of two signatures, The ignorant RFC8463 system (the majority) is not ready for this. One SHA256 signature is sufficient, I would not Ed25519 provides smaller keys that are more supportive by DNS Zone Managers. All the best, Hector Santos
- [Dcrup] [Editorial Errata Reported] RFC8463 (7930) RFC Errata System
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Hector Santos
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Rebecca VanRheenen
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Hector Santos
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Viktor Dukhovni
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Steffen Nurpmeso
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Murray S. Kucherawy
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Murray S. Kucherawy
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Orie Steele
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Murray S. Kucherawy