Re: [Dcrup] I-D draft-ietf-dcrup-dkim-crypto-06

denis bider <denisbider.ietf@gmail.com> Wed, 22 November 2017 11:19 UTC

Return-Path: <denisbider.ietf@gmail.com>
X-Original-To: dcrup@ietfa.amsl.com
Delivered-To: dcrup@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B0B512426E for <dcrup@ietfa.amsl.com>; Wed, 22 Nov 2017 03:19:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.698
X-Spam-Level:
X-Spam-Status: No, score=-2.698 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OzDgQy9gBBKW for <dcrup@ietfa.amsl.com>; Wed, 22 Nov 2017 03:19:29 -0800 (PST)
Received: from mail-lf0-x22e.google.com (mail-lf0-x22e.google.com [IPv6:2a00:1450:4010:c07::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E935A127522 for <dcrup@ietf.org>; Wed, 22 Nov 2017 03:19:28 -0800 (PST)
Received: by mail-lf0-x22e.google.com with SMTP id x68so17815828lff.0 for <dcrup@ietf.org>; Wed, 22 Nov 2017 03:19:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=rn2Ppm5fBY74yJFXqcYp/NIrdl18NOHX8gJ9FA9vpEY=; b=ALOIfBQgpGM1Z6pkSgKgKoM5OV+PL9FRfBhL8tm+ZjgXr3c2yPp9U76uAyixODQAl6 UznmRGaPDgo/tpr0kr5MbF33NFxZ9otfFfzdvTtvK9sTpwGVpU+I9GZvLnmJuHUv1vBX 3IqUlaB2g4Sd4yWY8JM578MaDYW5Omv2yPaVkM78q7KGhDWOzWC1ZGitd3O2pfgYAgHG NlKScitPjJfYWt/sW2qROzRzrWmdQeZevnG+vvoowmKYEDhR3a9tcjgzQsabwIpO3NZJ uh/9yoQPR1TaU9QnQkyH+BqSzHHbljYIg5EBEaRthqb0lP4SvUqz22dWPvrGA+W5/Adi X+MQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=rn2Ppm5fBY74yJFXqcYp/NIrdl18NOHX8gJ9FA9vpEY=; b=g2S5Mk3EjQcFIuadRkeRCyQnQgkHDSW7IItpbok0syHTmaB6IwyUycuTkOOymBNLkY FeQJtHe+A3TV9uTyEXF7Jp3om839r3qn42y6Jmz3nqPjUp7atSyjSzXUVs3Qg8nA5mkS AG6BLBpwkTdWxA8RzK4aR0siPQJoGLpyaurwL4ebY0sCluvLldm0pQsbdZ6F1aFPhFKw E/W6FlgA+IZXOTQB3slgALwxiQVjynlnMEMQKCslxL/dIZPM3rVwaDJRUqiJaNVhM316 /FnSxAFk/zTzORmGWzoQGnr+V4tpnfvBkttOFlv01liMP2vKB3kJFeQ0AjeW41vJGg4S BhEw==
X-Gm-Message-State: AJaThX5w4kljRNbHfDee7WZ3yZm2PHLTDi7bJGeRd+5+pzmZ/Zf5/05l ZzY+28z59mhUa+HR2zAqLGD0TEqNJDLPh6udxUs=
X-Google-Smtp-Source: AGs4zMYPttCpOSpwxXjNSU7Ah2zZGV3G1tUjAHP+8pGsq2jzE0MTVMQRjybRLiEemewBLNvSUWvgFeJxYef6iuhVphs=
X-Received: by 10.46.34.196 with SMTP id i187mr6304453lji.106.1511349567291; Wed, 22 Nov 2017 03:19:27 -0800 (PST)
MIME-Version: 1.0
Received: by 10.179.2.3 with HTTP; Wed, 22 Nov 2017 03:19:26 -0800 (PST)
In-Reply-To: <f5c2b166-f69b-b9da-779d-f7cc2b3428a5@wizmail.org>
References: <20171122043553.9264.qmail@ary.lan> <f5c2b166-f69b-b9da-779d-f7cc2b3428a5@wizmail.org>
From: denis bider <denisbider.ietf@gmail.com>
Date: Wed, 22 Nov 2017 05:19:26 -0600
Message-ID: <CADPMZDAXQ=5xfvvu3gUSfWkQGpSLWhQAS9T-ruFHMgQiy8a8=g@mail.gmail.com>
To: Jeremy Harris <jgh@wizmail.org>
Cc: dcrup@ietf.org
Content-Type: multipart/alternative; boundary="f4030439e19417045a055e907e4b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/ocOwJPubdbok7HVWMwc0-rxs7FU>
Subject: Re: [Dcrup] I-D draft-ietf-dcrup-dkim-crypto-06
X-BeenThere: dcrup@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DKIM Crypto Update <dcrup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dcrup>, <mailto:dcrup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup/>
List-Post: <mailto:dcrup@ietf.org>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dcrup>, <mailto:dcrup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Nov 2017 11:19:32 -0000

Jeremy,

I believe the exact thing you describe (whether to pass original headers to
the library to hash and sign) was discussed in many back-and-forths. That
is the obvious alternative to re-hash, so the entire discussion was about
that, vs. re-hash.

denis


On Wed, Nov 22, 2017 at 3:25 AM, Jeremy Harris <jgh@wizmail.org> wrote:

> On 22/11/17 04:35, John Levine wrote:
> > In article <00d888c1-64c9-9f26-0426-fbbb17fc5bdc@wizmail.org> you write:
> >> On 21/11/17 22:03, John Levine wrote:
> >>> Keeping in mind that you're responding to a message I wrote two months
> ago ...
> >>>
> >>> In article <383fef94-84c4-9b54-5566-a6fa1279aa38@wizmail.org> you
> write:
> >>>> Wouldn't it be more aesthetically pleasing to decouple, for dkim
> >>>> a=ed25519-sha256 signing, the hash used for the body (sha256 as
> >>>> specified by the 'a' tag) from the hash used for signing headers
> >>>> (sha512, I think, but whatever the libraries have tied to
> >>>> Ed25519 signing)?
> >>>
> >>> No.
> >>
> >> I think you need to further support your position.
> >
> > You might want to review some of the 100 messages posted to this list
> > since the one you were responding to.
>
> > PS: look for the ones about many libraries don't plan to provide the
> > pure version of ed25519, and how we agreed to deal with that.
>
> I already did.  All assumed immediately the re-hash, once it was
> accepted that we had no chance of the libraries providing a pure
> signing facility.  I didn't see one that suggested that the headers
> be passed in original unhashed form to the library hash-and-sign.
>
> Is your position "it's too late, we already decided"?  You
> final sentence above implies that, but perhaps I misread you.
> --
> Cheers,
>   Jeremy
>
> _______________________________________________
> Dcrup mailing list
> Dcrup@ietf.org
> https://www.ietf.org/mailman/listinfo/dcrup
>