Re: [DNSOP] FIPS 140-3 mode on RHEL 9 and RSA validation of <2048 keys

Bill Woodcock <woody@pch.net> Mon, 25 April 2022 10:45 UTC

Return-Path: <woody@pch.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 465653A1735 for <dnsop@ietfa.amsl.com>; Mon, 25 Apr 2022 03:45:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.042
X-Spam-Level:
X-Spam-Status: No, score=-1.042 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_SOFTFAIL=0.665, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (public key: not available)" header.d=pch.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Gp59SIRLOGwa for <dnsop@ietfa.amsl.com>; Mon, 25 Apr 2022 03:45:12 -0700 (PDT)
Received: from secmail.pch.net (secmail.pch.net [206.220.231.87]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 05B8B3A11C2 for <dnsop@ietf.org>; Mon, 25 Apr 2022 03:45:11 -0700 (PDT)
Received: from secmail.pch.net (localhost [127.0.0.1]) by secmail.pch.net (Postfix) with ESMTP id 4Kn1qq2j6hz4xJJh for <dnsop@ietf.org>; Mon, 25 Apr 2022 03:45:11 -0700 (PDT)
Authentication-Results: secmail.pch.net (amavisd-new); dkim=pass reason="pass (just generated, assumed good)" header.d=pch.net
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=pch.net; h= x-mailer:to:references:message-id:date:in-reply-to:from:subject :mime-version:content-type; s=dkim; t=1650883510; x=1653475511; bh=cIsgYG8m1fwB++h5nXhU8cxl7jSoBkg87mMRsl8WDMs=; b=d5HXkHgmQXwL 5LgLbjqVSw2t+xRZRj7tZZCRuFCvHXp+8x/G2QdkLR1i8t/4wKmK3aMPM0zKCaT2 okAOyykpw71SIe7m40UXQB3aratZWOGpvhvzAysiAdzpZ7X2DZye/f9gSZaT4UOn K6dn9F+99wBVZ3+0f/tj2QTZvn7zfrLuxCTa6UFTeRY5BlfkZDVM0sjp1c2gHE8i nVtWN8P9CFVR5nKqHWx98pCgmZjuWRMlyMIMHR0DfhokgORe8Fzj1U2MRKtZ+Ybm UMCIQcnRTnBt6ZZXvw3A8WeMi2GnY+MMbk1X/SqSNoAMI7KIibzLUcJu9vz9gusj VMLoE8D4wQ==
X-Virus-Scanned: amavisd-new at secmail.pch.net
Received: from secmail.pch.net ([127.0.0.1]) by secmail.pch.net (secmail.pch.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 8Ys-3BQY3ikU for <dnsop@ietf.org>; Mon, 25 Apr 2022 03:45:10 -0700 (PDT)
Received: from smtpclient.apple (unknown [69.166.14.6]) by secmail.pch.net (Postfix) with ESMTPSA id 4Kn1qp1TBJz4xJJf; Mon, 25 Apr 2022 03:45:10 -0700 (PDT)
Content-Type: multipart/signed; boundary="Apple-Mail=_7389C342-3381-4448-90FF-A23958F26921"; protocol="application/pgp-signature"; micalg="pgp-sha256"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.80.82.1.1\))
From: Bill Woodcock <woody@pch.net>
In-Reply-To: <356059e5-e973-3d6c-569c-9ff9d9fe16e6@redhat.com>
Date: Mon, 25 Apr 2022 12:45:07 +0200
Cc: "dnsop@ietf.org" <dnsop@ietf.org>
Message-Id: <06915BF1-86CA-4554-B3F5-82CCFFBF78E5@pch.net>
References: <356059e5-e973-3d6c-569c-9ff9d9fe16e6@redhat.com>
To: Petr Menšík <pemensik@redhat.com>
X-Mailer: Apple Mail (2.3696.80.82.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/fmVwSAj0EEgM08FsJADgpQl4O9s>
Subject: Re: [DNSOP] FIPS 140-3 mode on RHEL 9 and RSA validation of <2048 keys
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Apr 2022 10:45:16 -0000


> On Apr 25, 2022, at 11:20 AM, Petr Menšík <pemensik@redhat.com> wrote:
> I think the only good way would be starting considering shorter keys as
> insecure in FIPS mode.

Agreed.  We’ve been using 2408-bit ZSKs for more than ten years now.  It’s definitely time to sunset acceptance of shorter keys at this point.

                                -Bill