[DNSOP] Re: Questions before adopting must-not-sha1

Petr Menšík <pemensik@redhat.com> Mon, 18 November 2024 14:55 UTC

Return-Path: <pemensik@redhat.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4A3A2C14F6FA for <dnsop@ietfa.amsl.com>; Mon, 18 Nov 2024 06:55:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.253
X-Spam-Level:
X-Spam-Status: No, score=-2.253 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=redhat.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y57kO7h06J0G for <dnsop@ietfa.amsl.com>; Mon, 18 Nov 2024 06:55:38 -0800 (PST)
Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 588C3C14E513 for <dnsop@ietf.org>; Mon, 18 Nov 2024 06:55:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1731941737; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=S/zLrbmBBD8sJczdWiJJBP0vZWkgwAMHqIZ2PGld7A4=; b=IdemsNf8VQVrqTX9WTdiTnEPGUb8u9xpEtWOv6WuHmnfxFFlfkJbFvkua8ErEiyVLJzXny 1lqNQo2BbRRVv2ALXSALYirHo1PH/rvp/sWzdE3QDMgqKplJtdj3Vhy0DwIdunmLGdpiUP t3QOzS5GwYV+4ulfPLuKcOkDquWUQNQ=
Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-25-24NeYJ0rP8eIOOTHRDQOtg-1; Mon, 18 Nov 2024 09:55:35 -0500
X-MC-Unique: 24NeYJ0rP8eIOOTHRDQOtg-1
X-Mimecast-MFC-AGG-ID: 24NeYJ0rP8eIOOTHRDQOtg
Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-38233ea8c1bso1041677f8f.0 for <dnsop@ietf.org>; Mon, 18 Nov 2024 06:55:35 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1731941734; x=1732546534; h=in-reply-to:autocrypt:from:content-language:references:to:subject :user-agent:mime-version:date:message-id:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=S/zLrbmBBD8sJczdWiJJBP0vZWkgwAMHqIZ2PGld7A4=; b=boKjosx8RLYZnAlRCRYZu1hYPvzb6lb2kVBnQB7IQBsKNctN5ultMyQ760adc361rU mrulZNpgQuEvm1+/jl78yuATSo17+kni/dQxhuizSaos57qBxHGoo11PxYwqSlZQXBCw 9qA3XsOqKdkTSZ5vIRPxjksvtv+GC3PoaDBj7ZJcPK+8OwmytXgmPBGBaFW/038vrmkq /0gxBNYn2WBBnw/S+JISBsa14G5UEN3Ng31oUR177TNtNI2NtUtJueRd3kt+jEV3cFan z76HJgC2z00GANBUZA13wFQhM9OPS2aD2E6yLvWWieYAbyB4M1G/ZLCHpReDv9cs0lQc H1oA==
X-Gm-Message-State: AOJu0Yyl2wILdVrvAPJPy1QSv+BxkxMG+1Y4kGNmou4h3aajZd5hu+kW 8UjUL634dMOaNOKiHkhe4c3j8qaN/osokopOLNdGc44uSIIKXngg7Kxz9IYmgaToOivJKRrBvHk 1cloB2aMgkNh/uWB/AlhL6y+oTo7c0A7erTVbe+ikCJ5iVJpiD59C2nOY2HIX2qFiaTbghsDri+ 0BdmJXmrNR++b3m0yY9rbdVzBEW0Y=
X-Received: by 2002:a05:6000:188d:b0:382:2e9e:d695 with SMTP id ffacd0b85a97d-3822e9eda77mr11178700f8f.24.1731941734103; Mon, 18 Nov 2024 06:55:34 -0800 (PST)
X-Google-Smtp-Source: AGHT+IE3FDv16cgnP9y0yGyjFHgMqni0WC/sKdByuR6UwYfJkZRDLC8JjcVQJmm1C1BAdT9GOeEOGQ==
X-Received: by 2002:a05:6000:188d:b0:382:2e9e:d695 with SMTP id ffacd0b85a97d-3822e9eda77mr11178662f8f.24.1731941733619; Mon, 18 Nov 2024 06:55:33 -0800 (PST)
Received: from [10.43.2.229] (nat-pool-brq-t.redhat.com. [213.175.37.10]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-3823f72441bsm5636341f8f.101.2024.11.18.06.55.32 for <dnsop@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 18 Nov 2024 06:55:33 -0800 (PST)
Message-ID: <c751bcd8-9374-4d98-b46b-d8e378ab31e0@redhat.com>
Date: Mon, 18 Nov 2024 15:55:32 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: dnsop@ietf.org
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org> <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl> <m1s1Wur-0000LDC@stereo.hq.phicoh.net> <f0f9c0ce-2911-9b4c-0d60-47c204add2d4@nohats.ca> <DB9D1C93-95D1-4B76-AD74-4C60433D479A@icann.org> <7dd5f090-b8b7-ea5e-82f2-d622298c7299@nohats.ca> <ybl7cgejxcr.fsf@wd.hardakers.net> <4907A4B7-1EAE-460D-91E8-4F7D292C7302@icann.org> <ybl34r2jv3n.fsf@wd.hardakers.net> <0334D9C1-F066-460A-893B-C4075FD0BE07@icann.org> <0e5914c7-d3fa-443c-8099-1b5bad39a50e@redhat.com> <m1tBFqG-0000LkC@stereo.hq.phicoh.net> <929e319c-7797-45ac-bdae-ed76d7659e23@redhat.com> <m1tCgx2-0000LZC@stereo.hq.phicoh.net> <ff43e5c5-ad80-b618-24fe-ffec6d128630@nohats.ca>
Content-Language: en-US
From: Petr Menšík <pemensik@redhat.com>
Autocrypt: addr=pemensik@redhat.com; keydata= xsDNBF17vwQBDACso9gM0++XOzm/b//dGE1bgYyIch8xqCDHe2YXDUL2a65LCmNQUnS7PTxf 8psG4DdBayWlRvA/33L3YQD8gULaZX/KsHbSQov4Np4E2rG9PCljcDqHFCKjHEmmzQ86Z4+r euHoTwUpEroz2xa1XAIsy4fjqro0GHc6H3BVwXQ8Vfrmllq6tW+ubegI/tZSDDfOlnkHyMsh /mX893qn1Sb+A/RqyDDV6voAv4YfoNJyDfBB0jMshEiSLO+S0vspw42ElbAdLO6SHOX8Dy/a yPVTGDe2Jopy3YrbUWtu5HIs8X0vsKbF6tegO1l/m1y3t2Aa153k6NKOWv+79iNiY2ygGefm o1TRzlS/d+xacOxnGO3RCSlvm3xDEUuqNqrSQNF2yVRYAMwh75VWefeTu+/erXR4MGDpTTSA Ebaen0+uuiG4LGCNzZdYOyj7OMHW14e9JX4eujP0DtoJC9TWpDwHwbApbf83ZdmxxrU4yTPi 7fkXe4qkPulRFV7LOmlkAAUAEQEAAc0jUGV0ciBNZW7FocOtayA8cGVtZW5zaWtAcmVkaGF0 LmNvbT7CwRQEEwEIAD4CGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQTfz5CNt8h+jlKZ JbxJMcpbbJ/FywUCZPHFVgUJCzhtUgAKCRBJMcpbbJ/Fy1fxC/47crKpMrPsX0LHs05fpiS+ tgemYCvezN0So0x9Wc0Otl7L4qa2y4IiCfIS6G8gNEClEuatI1xfFVMxCU+BYFw5NRXNSZj+ 2Pb4DS69lhGJoFctwJ8mPIhPOr9SDQKAYw0EPbk+nWXB4fo3cKKN/EbKD++a/lLOecajGoF1 3N27l6fyfZHxm1tM/6TSm/2QyAau6MF6k9o4gA9/VjV6PYNKehicO7CkKO820F3OazPW9iFp dsmscKOEb79xZOq/W6vTPisHreBM7oB129PZxJrhOks3F/gfxG62kAUBGezFgFqWu4IFhsnM cMBokXUd6yurRBndljG0lW/P1pIH6TIrnCYzQ8XVA4hZFhfWdlCJqcPrbaQocnKzOdaa/fe3 xQHRiHOvvRvTkBCLFYcLVqXvWcAlj8jgsCbM3lakVPBLAYDjUdTqwrnTQ+vgJtx/4OCQuGkr 6sEKUQvxl/mWrN7+ThZJQ0ITWbP1ay5MA6QGulo2PyH5nV8/A6dnjS+M6UbOwM0EXXu/BAEM AMe+2Xxem4Uzjy2MG9cT3aX7suGVCgYmJV2CACSMncqN2MC0PjxGiV37wv+Cyq9QaOF/MiuF 568YYim2Cz1RURRjDxDeslMqj+6NKwepwABPTdlGOOvnMBmH5gfBeBJuRcx+1cHVTHBpoSTi waDUg+rtyfRXZYCGqvG9fUcJzWeCkiYbqaLHzxt9sTPhAv3rE0MdGib8Igg86Txge3b55i/7 MbYGtw+lqtVoYpsV1LoqfoQgW8j0Ac1Objch34iKvbAR75z6dJ1Tg5aFJyhYCbB8NwrE31Pd aXUHyr47y3IoNXNlc0s7dg542OA6m2FkvQYgfbZlQb66J0PTAl31zvYN/G2C024DDqU1wOpV hn1RYkoc0UTAse2IdP/t2mqE4me2gZ7NrjWwFSzXlGIh08T7KxHLrGtA3Mm2I3XnPHO1ppf6 xBoeGMfESeNfoR8sGWOnYyd52CKdnp7DtJ3TlGLlafnkauwHrHnHdkJb4pkKjXKavKy/DjUG yWG74jexhwARAQABwsD8BBgBCAAmAhsMFiEE38+QjbfIfo5SmSW8STHKW2yfxcsFAmTxxYsF CQs4bYcACgkQSTHKW2yfxct9DAv/YIBB1dENrLjMhh+Y11s++p2VFeP4gxawrrXc6tXRcfXj aEvubqNTG34HIUhIIFKbl7S4HGLFhcCtLdzn6nW3e/jH6Gen2InSLHyHVUpt8U0ysSKFoTpM BgP95IWYhx2I3FtKBpjSmTx/Vwdgf1D2QBBLwEWFYazuUIVY8IxwWOlfwpN56jujdSPrcxZD HGDz5gBKy9bKaoTQT6IZXHTanTi7XVJShtWJsX9pot3dPMi+5W+mTaocEc+gnPyEKI9WoQJ/ Ow5At3mQqJ1CEaRF4BXDK0bXIzOrejHDhv4n3RSrvnFlV2e+BcbfS7uj4rYRPsjZ4nffFpog CiM0Yg6RihUbZ8h6BMghOt0F07LAV3ISpaPeVsp4F6pnFedS5NgMufiBSopSJTc8wLked9E3 PlSxMeSMfi21E/eLg024Wx2c9JdKNFrYGEkgdr+w9WBA7AMKFCIQKDAwb3vPgxO3owDNC+ka AJs6m+d2kZSDzqUdFMZLrqbp0vt3GnIF8l3Y
In-Reply-To: <ff43e5c5-ad80-b618-24fe-ffec6d128630@nohats.ca>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------fl9FNAhbntJMqW7iBuoJjvoD"
Message-ID-Hash: P4A4Y6K6G5DBN22FDABBGARZGXFSNGRI
X-Message-ID-Hash: P4A4Y6K6G5DBN22FDABBGARZGXFSNGRI
X-MailFrom: pemensik@redhat.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Questions before adopting must-not-sha1
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/idso7qOrlp8WWEb-KxHdxIeoJPA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On 18. 11. 24 15:37, Paul Wouters wrote:
> On Sun, 17 Nov 2024, Philip Homburg wrote:
>
> [indeed a bit offtopic]
>
> Correct, it is now compiled using --disable-sha1. I think it would be
> better to enable this again, assuming unbound now has proper code to
> detect if sha1 is failing or not during runtime. Then the
> crypto-policies can be used to enable this again. If this was a
> dedicated container/host, it could simply use:
>
> update-crypto-policies --set LEGACY
If the whole talk were about complaining of actually worsening overall 
security, then using LEGACY should not be proposed to improve that. If 
you can, use DEFAULT:SHA1. The method with custom OPENSSL_CONF is the 
most secure way I know, because it still won't allow SHA1 in TLS, but 
allow it only for generic signature verification, like in DNSSEC.
>
> It seems "sha1_in_dnssec" has been obsoleted. I do not know what this
> was done, I think it was a perfectly fine method to create a crypto
> policy submodule only enabling sha1 for DNSSEC.
>
> Paul

There is no way an user can signal into OpenSSL library that he wants it 
used for DNSSEC verification (or signing) only. Therefore you cannot 
demand DNSSEC submodule itself. But I think crypto team could have made 
submodule allowing just generic SHA1 signature verification, where not 
other uses of SHA-1. You know those people more than I do. They are not 
DNSSEC supporters and have kind of hard stance to SHA-1. They say nobody 
should use it anymore and do not want to invest more resources to make 
it better.

Regards,
Petr

-- 
Petr Menšík
Senior Software Engineer, RHEL
Red Hat, http://www.redhat.com/
PGP: DFCF908DB7C87E8E529925BC4931CA5B6C9FC5CB