Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-crypto-03.txt

Eric Rescorla <ekr@rtfm.com> Sun, 02 July 2017 22:03 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45A5A129461 for <dcrup@ietfa.amsl.com>; Sun, 2 Jul 2017 15:03:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U5G5jGkbvM7d for <dcrup@ietfa.amsl.com>; Sun, 2 Jul 2017 15:03:36 -0700 (PDT)
Received: from mail-yb0-x22a.google.com (mail-yb0-x22a.google.com [IPv6:2607:f8b0:4002:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86A40127076 for <dcrup@ietf.org>; Sun, 2 Jul 2017 15:03:36 -0700 (PDT)
Received: by mail-yb0-x22a.google.com with SMTP id s15so16395568ybe.2 for <dcrup@ietf.org>; Sun, 02 Jul 2017 15:03:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=K1ngvSAbSYPHhSAIBVCDdmif4kvgVxdSc8iBZ0F83OY=; b=tpBus69qJR7TdURxW9AxhC/WCHYBuvmpXG62DBdbdR5F28ORno57m5wnyl11m1LOj6 vTWQVMz9sO3kzxrzQjPMSE+oUCTnLxFVljeoWUR6PpqnMMswCI0YvPtTaE2ExkToku4X 24b/D0bIWuJNu21azHlX4QWUv7EZv5SrLQ9hu1IZRbLHTpjBCwyCl/62xAR5oYLFCtTT +qD/LlOraj3GNgPD3+KlYKBmh2yvV+rNud2Vl6g4XewKf3K+pj79UWnXCUgfhhP/KMXs OYiCOgB//H8pu8hRIFmJi2nA9C+9sSrEJJrmUhlnSsENbqDOy0q//7OADV0cCIrijwPs vZow==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=K1ngvSAbSYPHhSAIBVCDdmif4kvgVxdSc8iBZ0F83OY=; b=f2HRTcoI2xxAX419XpQEsubf9zuRI1+Atmfrh13IZLSiw1OvV5ZCPEkh4Kg82u5OHU qTIwkmBJIGjQYICKSpBMdV2qzW80J+Y/VskzjEuU3bJNOzIAJxqA7CtzCNH+KQ5qI0t+ D1m92g6ZCClEZBGUm0vovu8BxniwJRU5oIgZqo2xKdhyK0klc9XVIah2b48kdT4Qgn/A NnMSLp01JoVcz03Y6zSG4/RNlhGH52A/y3HmDefeQXYImqFHt6h/N3K3NomVbkPIIJS/ LdoSZ+OBSvcqr66F4L35UMm6ocsDedQdb3DVQ8pY3JEkFiOE6pcj8rIOF4tI/2IIvgr6 Krmw==
X-Gm-Message-State: AIVw110QuOlJX7qNhi2zmNFLOMl0FUeppmwMJC0r9K7c3tOdCI0layS9 2pb9oIqT7Dg0SQZxkcm2L3CBpO39dtVo9zZzFw==
X-Received: by 10.37.42.207 with SMTP id q198mr13204323ybq.71.1499033015788; Sun, 02 Jul 2017 15:03:35 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.13.215.9 with HTTP; Sun, 2 Jul 2017 15:02:55 -0700 (PDT)
In-Reply-To: <alpine.OSX.2.21.1707021715300.73525@ary.qy>
References: <CABcZeBOs1yZ7q3oBgNeVkw=zSQb_SuS4hqK8BH0ebrD5LRYTFg@mail.gmail.com> <20170702025650.55902.qmail@ary.lan> <CABcZeBM4KEr5CEZq4t9BX50btCRPLhZBAtZN18v_6gZ5B-ni5A@mail.gmail.com> <alpine.OSX.2.21.1707012341180.70305@ary.qy> <CABcZeBOLSrYo8mEQ1evyU7CzctV0VF4r7_bX3nA0oxtHCeEgSQ@mail.gmail.com> <alpine.OSX.2.21.1707021544590.72907@ary.qy> <CABcZeBPbL9EgZhF9t6j1Nt9xU=97oNj1ssaVFaiS8Mgd573evA@mail.gmail.com> <CABcZeBP1w2GPQmfCzQnROunoeXHiB0jodYW7dY3W4tLf5GHDgw@mail.gmail.com> <alpine.OSX.2.21.1707021715300.73525@ary.qy>
From: Eric Rescorla <ekr@rtfm.com>
Date: Sun, 02 Jul 2017 15:02:55 -0700
Message-ID: <CABcZeBPu-hD+0z4_7zJuU_kUog47q6bUf3Cm76L+pyCXgkVGQw@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Cc: dcrup@ietf.org
Content-Type: multipart/alternative; boundary="001a1144184469eefd05535cd29c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/Wv1IHha1HSas0HrrFkOziZLhUTw>
Subject: Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-crypto-03.txt
X-BeenThere: dcrup@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DKIM Crypto Update <dcrup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dcrup>, <mailto:dcrup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup/>
List-Post: <mailto:dcrup@ietf.org>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dcrup>, <mailto:dcrup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 02 Jul 2017 22:03:38 -0000

On Sun, Jul 2, 2017 at 2:16 PM, John R Levine <johnl@taugh.com> wrote:

> I'd also be fine with having both representations, though I think it's
>> confusing. However, I don't think it's great to have just unhashed in the
>> future.
>>
>
> Since nobody is currently proposing that, and as far as I can tell nobody
> in this thread has ever proposed that, I really don't understand what we're
> arguing about.


I'm responding to this change:
"SIGNIFICANT CHANGE: Only RSA signatures can use key fingerprints.  Since
an eddsa key is 256 bits, and a SHA-256 fingerprint is also 256 bits,
there's no point to eddsa fingerprints, so I took them out."

My point is that you should revert it.

-Ekr



> Regards,
> John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
> Please consider the environment before reading this e-mail. https://jl.ly
>