Re: [dispatch] Updating DKIM for stronger crypto

Eric Rescorla <ekr@rtfm.com> Tue, 07 February 2017 00:40 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: dispatch@ietfa.amsl.com
Delivered-To: dispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 87DDF1293E4 for <dispatch@ietfa.amsl.com>; Mon, 6 Feb 2017 16:40:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2hUca_6pvYYr for <dispatch@ietfa.amsl.com>; Mon, 6 Feb 2017 16:40:49 -0800 (PST)
Received: from mail-yw0-x22e.google.com (mail-yw0-x22e.google.com [IPv6:2607:f8b0:4002:c05::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1EDE4126D73 for <dispatch@ietf.org>; Mon, 6 Feb 2017 16:40:47 -0800 (PST)
Received: by mail-yw0-x22e.google.com with SMTP id v200so58379802ywc.3 for <dispatch@ietf.org>; Mon, 06 Feb 2017 16:40:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=ysoXmOHC2q9564wkiKLYAQE05DPzYYeXaffAyR1eTW0=; b=h+dWAI6gEFlmQ8z5V/+w1MASTSGqgtfsMdfHJZERK5fBOsyTfiEQugqriqE0ZCwBaz S6tSt/UtMYq5jFr6Gcc+Fhkq/g+j6TjLkWPPOEC/gUTs1QajaV0t1dRcS0v2Mh6mYX04 8oEZVByZkFodU4As5Ps/L9mHGv/wOZaNnnlQXlGRsjUjqzeqUjfgSQRNoUyJH+ZHXcjy oSxEOmN71oE9QHFnQn0bHsREia0LWB6pkQYWRwtOR6/fHYQMZYNxY+CJzE8FigUbT9SE 0ziRgHa++TMcs83lMABBm37eolXyeYrNqlPZyfF4HlMCjHhqXiCxvQPOZf46uNTqx47c x+Bg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=ysoXmOHC2q9564wkiKLYAQE05DPzYYeXaffAyR1eTW0=; b=II5WsM9VHBUTZ6NbLNrtralnYapxyieSJ7gAVxIVvGsM8AHEEREgHsaYm3DitWfGk0 7VWsU/eYzqSECGTEkvt3MkbqTxBA4hMPFJ1613s4pcPMAt+3N2M/CY0tYorMY89bz0YK c1W1TM19SMDgVU7wN52vJy83dACBf9VZXOb+RiYKTPHe5puW1NGty/tLKQ9kzH5jXwct XN0Ior+e1zy6ml4HOhzxJRGc0wL81MaOBB6uNAh5SKpM7WsRnpoOXfPmHldlWG1PVMjs XmzUwFjOYkB3/c3fK2rMOXYtl1oWxE1dVY2ikpNdja6Fr2sUpsyjfvZmiksSpfVFp4R4 TTww==
X-Gm-Message-State: AIkVDXKckdOa5JpuO6V8ZLdH7eiUVWT1fLZiH3gx5jpwSzrjZXIB/esWhCSioVO3n6mtQwd6avEkD+Ni0aBzJA==
X-Received: by 10.129.125.84 with SMTP id y81mr8510182ywc.120.1486428046180; Mon, 06 Feb 2017 16:40:46 -0800 (PST)
MIME-Version: 1.0
Received: by 10.13.204.80 with HTTP; Mon, 6 Feb 2017 16:40:05 -0800 (PST)
In-Reply-To: <alpine.OSX.2.20.1702061938240.23435@ary.qy>
References: <20170206020826.1108.qmail@ary.lan> <CABcZeBMgPZQhvtve85L=nC9X9WxWaRYYMSm98qbV2Fgv71GjAw@mail.gmail.com> <alpine.OSX.2.20.1702061845230.23435@ary.qy> <CABcZeBOUfiiPwSOVaakTGKvFq6ZF1NLnoKoyQ0qDiB+19=OQZQ@mail.gmail.com> <alpine.OSX.2.20.1702061938240.23435@ary.qy>
From: Eric Rescorla <ekr@rtfm.com>
Date: Mon, 06 Feb 2017 16:40:05 -0800
Message-ID: <CABcZeBPU=Wq-CO3b2CN2F0buQT2HGzDdUe9vGejBYnwgOSLWQg@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Content-Type: multipart/alternative; boundary="001a114928baadf2580547e5ffcf"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dispatch/1y_TnBQnN29DVZo4rir8LFLs4j4>
Cc: DISPATCH <dispatch@ietf.org>
Subject: Re: [dispatch] Updating DKIM for stronger crypto
X-BeenThere: dispatch@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DISPATCH Working Group Mail List <dispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dispatch>, <mailto:dispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dispatch/>
List-Post: <mailto:dispatch@ietf.org>
List-Help: <mailto:dispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dispatch>, <mailto:dispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Feb 2017 00:40:50 -0000

On Mon, Feb 6, 2017 at 4:38 PM, John R Levine <johnl@taugh.com> wrote:

>   I suppose that could work, but if we're going to open up the code, given
>>> that elliptic signers and verifiers are showing up in crypto libraries
>>> it's
>>> be a lot simpler change to DKIM.
>>>
>>
> I don't see why this would be the case. Think of signature verification as
>> a function ...
>>
>
> I meant a simpler change to the code.
>

So did I and I don't think it's "a lot simpler"

-Ekr


> R's,
> John
>