[Dcrup] Re: [standards] [Editorial Errata Reported] RFC8463 (7930)
Steffen Nurpmeso <steffen@sdaoden.eu> Sun, 12 May 2024 00:53 UTC
Return-Path: <steffen@sdaoden.eu>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B871C14F5F7 for <dcrup@ietfa.amsl.com>; Sat, 11 May 2024 17:53:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sdaoden.eu header.b="fuDJapO/"; dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=sdaoden.eu header.b="o8An5o7K"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c-kJtUPIj1MI for <dcrup@ietfa.amsl.com>; Sat, 11 May 2024 17:53:02 -0700 (PDT)
Received: from sdaoden.eu (sdaoden.eu [217.144.132.164]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BB820C14F5EE for <dcrup@ietf.org>; Sat, 11 May 2024 17:53:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sdaoden.eu; s=citron; t=1715475179; x=1716141845; h=date:author:from:to:cc:subject: message-id:in-reply-to:references:mail-followup-to:openpgp:blahblahblah: author:from:subject:date:to:cc:resent-date:resent-from:resent-to: resent-cc:in-reply-to:references:mime-version:content-type: content-transfer-encoding:message-id:mail-followup-to:openpgp: blahblahblah; bh=waAp8G66ExBG5LRziv+PeHVvs6d8I1QptyNTXutxyiU=; b=fuDJapO/XcA9CJHkmdwTrlycnuMtgMvAaDnT13fiy/GryBUWxnmeQaLC2OrmxwddvPGcHxSs tZjrgxi0p/16LqG8qQxhcsta5BwdeizE/h/a/+uovxscWY/mC9Y+oenG0HuLCrhHzcEqJ/apOj p6lVpQ36uqJEOodmuOCkhJe7NZomQE3TflxmQT1EcNTw3hqhT1CLpsoYzlbx0Ox70ru4lUDFUx x/yVngevCl4/yLixO4Gg2g+ryp1BDoiSFC5SPIzYhWP2oLpbwtGwiAwSguM+kydLLVdwiMDYLy kL+W1i6VYnVXqT/hCEAe8QqZ7T8+Q0+QvqSE7PvbeKmIR0+Q==
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=sdaoden.eu; s=orange; t=1715475179; x=1716141845; h=date:author:from:to:cc:subject: message-id:in-reply-to:references:mail-followup-to:openpgp:blahblahblah: author:from:subject:date:to:cc:resent-date:resent-from:resent-to: resent-cc:in-reply-to:references:mime-version:content-type: content-transfer-encoding:message-id:mail-followup-to:openpgp: blahblahblah; bh=waAp8G66ExBG5LRziv+PeHVvs6d8I1QptyNTXutxyiU=; b=o8An5o7Ks65nJpf2syeDapcuKN0dZ8J2QraDTGSFmKDk+N5uswKSZC/1dm/zg+EnEVQKQN+N /u4qVevzxluNCA==
Date: Sun, 12 May 2024 02:52:58 +0200
Author: Steffen Nurpmeso <steffen@sdaoden.eu>
From: Steffen Nurpmeso <steffen@sdaoden.eu>
To: Viktor Dukhovni <viktor@dukhovni.org>
Message-ID: <20240512005258.N-lL8YIA@steffen%sdaoden.eu>
In-Reply-To: <ZkAOictS1ygyIBZe@chardros.imrryr.org>
References: <ZkAOictS1ygyIBZe@chardros.imrryr.org>
Mail-Followup-To: Viktor Dukhovni <viktor@dukhovni.org>, John R Levine <johnl@taugh.com>, RFC Errata System <rfc-editor@rfc-editor.org>, dcrup@ietf.org, Scott Kitterman <sklist@kitterman.com>, "Murray S. Kucherawy" <superuser@gmail.com>, Orie Steele <orie@transmute.industries>, Rebecca VanRheenen <rvanrheenen@amsl.com>, Steffen Nurpmeso <steffen@sdaoden.eu>
User-Agent: s-nail v14.9.24-621-g0d1e55f367
OpenPGP: id=EE19E1C1F2F7054F8D3954D8308964B51883A0DD; url=https://ftp.sdaoden.eu/steffen.asc; preference=signencrypt
BlahBlahBlah: Any stupid boy can crush a beetle. But all the professors in the world can make no bugs.
Message-ID-Hash: NFCDMFYAH7XNNHD4M2XNHMEKGNKKS5VK
X-Message-ID-Hash: NFCDMFYAH7XNNHD4M2XNHMEKGNKKS5VK
X-MailFrom: steffen@sdaoden.eu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dcrup.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: John R Levine <johnl@taugh.com>, RFC Errata System <rfc-editor@rfc-editor.org>, dcrup@ietf.org, Scott Kitterman <sklist@kitterman.com>, "Murray S. Kucherawy" <superuser@gmail.com>, Orie Steele <orie@transmute.industries>, Rebecca VanRheenen <rvanrheenen@amsl.com>, Steffen Nurpmeso <steffen@sdaoden.eu>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Dcrup] Re: [standards] [Editorial Errata Reported] RFC8463 (7930)
List-Id: DKIM Crypto Update <dcrup.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/9KTVj1Yj-nASXfsyDNUCxWtIi00>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Owner: <mailto:dcrup-owner@ietf.org>
List-Post: <mailto:dcrup@ietf.org>
List-Subscribe: <mailto:dcrup-join@ietf.org>
List-Unsubscribe: <mailto:dcrup-leave@ietf.org>
Viktor Dukhovni wrote in <ZkAOictS1ygyIBZe@chardros.imrryr.org>: |On Sat, May 11, 2024 at 10:10:39PM +0200, Steffen Nurpmeso wrote: |> Thanks a lot for spending so much time and effort to figure out |> John R's fault, your crypto knowledge and artistic is always |> amazing to read *and see*. Thank you! | |I believe you owe an apology to John Levine, and more generally would I apologise to John R Levine for the tone. |achieve better results by practicing some more humility. Your current |flame thrower on full blast approach is not productive. I cannot change my entire being though. |>|3. This is then signed with the Ed25519 key from RFC8032: |> ... |> |> Wonderful, thank you very much. So John R Levine mapped the RSA |> scheme onto Ed25519, where one first generates a message digest, |> which is then signed. | |No. You've failed to read the DKIM RFCs. All DKIM signatures No i did not. We have two hashes, one for the body, and one for the canonicalized headers. ... |Please resist any temptation to signal indignation, this matter should With RFC 8463 we have three. Because the algorithm as such performs hashing itself. Sure, SHA-512 is likely more expensive than SHA-256, it would require tests to know how much that matters given how expensive the modern algorithms are. That is to say, wether doing SHA-256 on the to-be-signed-headers and then RFC 8032 on the signature is less expensive than simply passing the readily prepared headers to the algorithm which performs digesting itself. |now be closed. Your Ed25519 signing implementation needs to hash the |message, and then sign the hash. I want to point out that this requires extra code in most implementations. --steffen | |Der Kragenbaer, The moon bear, |der holt sich munter he cheerfully and one by one |einen nach dem anderen runter wa.ks himself off |(By Robert Gernhardt)
- [Dcrup] [Editorial Errata Reported] RFC8463 (7930) RFC Errata System
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… John R Levine
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Hector Santos
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Rebecca VanRheenen
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Alessandro Vesely
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Steffen Nurpmeso
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Hector Santos
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Viktor Dukhovni
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Steffen Nurpmeso
- [Dcrup] Re: [Ietf-dkim] [standards] [Editorial Er… Viktor Dukhovni
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Murray S. Kucherawy
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Murray S. Kucherawy
- [Dcrup] Re: [Editorial Errata Reported] RFC8463 (… Orie Steele
- [Dcrup] Re: [standards] [Editorial Errata Reporte… Murray S. Kucherawy