Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usage-00.txt
"Rose, Scott" <scott.rose@nist.gov> Mon, 05 June 2017 16:21 UTC
Return-Path: <scott.rose@nist.gov>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94ABC129B47 for <dcrup@ietfa.amsl.com>; Mon, 5 Jun 2017 09:21:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1xbxRS_R81fI for <dcrup@ietfa.amsl.com>; Mon, 5 Jun 2017 09:21:33 -0700 (PDT)
Received: from wsget2.nist.gov (wsget2.nist.gov [IPv6:2610:20:6005:13::151]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 75215129B44 for <dcrup@ietf.org>; Mon, 5 Jun 2017 09:21:33 -0700 (PDT)
Received: from WSGHUB1.xchange.nist.gov (129.6.42.34) by wsget2.nist.gov (129.6.13.151) with Microsoft SMTP Server (TLS) id 14.3.319.2; Mon, 5 Jun 2017 12:21:28 -0400
Received: from postmark.nist.gov (129.6.16.94) by mail-g.nist.gov (129.6.42.33) with Microsoft SMTP Server id 14.3.319.2; Mon, 5 Jun 2017 12:21:30 -0400
Received: from [129.6.140.7] ([129.6.140.7]) by postmark.nist.gov (8.13.8/8.13.1) with ESMTP id v55GL8EF019409 for <dcrup@ietf.org>; Mon, 5 Jun 2017 12:21:09 -0400
From: "Rose, Scott" <scott.rose@nist.gov>
To: dcrup@ietf.org
Date: Mon, 05 Jun 2017 12:21:08 -0400
Message-ID: <A5830D7B-CC95-4296-99B6-B4A1BE5CF617@nist.gov>
In-Reply-To: <149619233095.19793.14947085917778354002@ietfa.amsl.com>
References: <149619233095.19793.14947085917778354002@ietfa.amsl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Mailer: MailMate (1.9.6r5347)
X-NIST-MailScanner-Information:
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/hBjO2p5b9xitdXDdNf_UHpwLtuE>
Subject: Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usage-00.txt
X-BeenThere: dcrup@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DKIM Crypto Update <dcrup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dcrup>, <mailto:dcrup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup/>
List-Post: <mailto:dcrup@ietf.org>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dcrup>, <mailto:dcrup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jun 2017 16:21:37 -0000
I’ve read the draft and I admire the willingness to plant a stake in
the ground in making rsa-sha1 obsolete.
I think it would help to be more explicit about which requirement
applies to which role (implement vs deploy/administrate). For example:
3 DKIM Signing and Verification Algorithms
This section replaces [RFC6376] Section 3.3 in its entirety.
DKIM supports multiple digital signature algorithms. Two algorithms
were defined by [RFC6376]: rsa-sha1 and rsa-sha256. Signers MUST
implement and sign using rsa-sha256. Verifiers MUST implement rsa-
sha256 and MAY implement rsa-sha1 for backwards compatibility.
The rsa-sha1 signing algorithm is obsolete and MUST NOT be
used.
3.1. The rsa-sha1 Signing Algorithm
This algorithm is obsolete and MUST NOT be used by signers.
This doesn’t change the main idea, but calls out the fact that
rsa-sha1 will be sticking around for a period of time as administrators
are not going to read this doc and/or not going to change things that
are working for them now.
Scott
On 30 May 2017, at 20:58, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the DKIM Crypto Update of the IETF.
>
> Title : Cryptographic Algorithm and Key Usage to
> DKIM
> Author : Scott Kitterman
> Filename : draft-ietf-dcrup-dkim-usage-00.txt
> Pages : 5
> Date : 2017-05-30
>
> Abstract:
> The cryptographic algorithm and key size requirements included when
> DKIM was designed in the last decade are functionally obsolete and
> in
> need of immediate revision. This document updates DKIM
> requirements
> to those minimaly suitable for operation with currently specified
> algorithms. This document updates RFC 6376.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-dcrup-dkim-usage/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-dcrup-dkim-usage-00
> https://datatracker.ietf.org/doc/html/draft-ietf-dcrup-dkim-usage-00
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> Dcrup mailing list
> Dcrup@ietf.org
> https://www.ietf.org/mailman/listinfo/dcrup
===================================
Scott Rose
NIST ITL
scott.rose@nist.gov
+1-301-975-8439
GV: +1-571-249-3671
===================================
- [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usage-0… internet-drafts
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Kurt Andersen
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Martin Thomson
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Martin Thomson
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Martin Thomson
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Martin Thomson
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… John Levine
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Rose, Scott
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Russ Housley
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Rose, Scott
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Murray S. Kucherawy
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Jim Fenton
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman
- Re: [Dcrup] I-D Action: draft-ietf-dcrup-dkim-usa… Scott Kitterman