Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Paul Wouters <paul@nohats.ca> Mon, 29 April 2024 20:30 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A48BC1840E7 for <dnsop@ietfa.amsl.com>; Mon, 29 Apr 2024 13:30:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.429
X-Spam-Level:
X-Spam-Status: No, score=-1.429 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_SOFTFAIL=0.665, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tlJGDVqmMEGL for <dnsop@ietfa.amsl.com>; Mon, 29 Apr 2024 13:30:07 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [IPv6:2a03:6000:1004:1::85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DB367C180B4F for <dnsop@ietf.org>; Mon, 29 Apr 2024 13:30:06 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4VSw1R2htzz9tY; Mon, 29 Apr 2024 22:30:03 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1714422603; bh=ST2AHjUlq6b9d28b6C2pavtVS9P7Na8lW/+b/tys5g8=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=URiSmbAts11izqOaTCglYF4qRs4dF0LadOYUa0cOiO/YvwnMawmX0NpS5nwKQ6F1V KaXGlJlaeC62+Nh2DNjsxU2ryzsP00AKlgJL0I/+w4fvqLmjVLw9+gP31h/B8q4vdV O/KY0PbXN23OwMhMKSAMAmjmbdG6wj1eV4H+jr6g=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id M5rBKeXQLbyt; Mon, 29 Apr 2024 22:30:01 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Mon, 29 Apr 2024 22:30:01 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 76C6811DD95D; Mon, 29 Apr 2024 16:30:00 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 72C6C11DD95C; Mon, 29 Apr 2024 16:30:00 -0400 (EDT)
Date: Mon, 29 Apr 2024 16:30:00 -0400
From: Paul Wouters <paul@nohats.ca>
To: Paul Hoffman <paul.hoffman@icann.org>
cc: dnsop <dnsop@ietf.org>
In-Reply-To: <DB9D1C93-95D1-4B76-AD74-4C60433D479A@icann.org>
Message-ID: <7dd5f090-b8b7-ea5e-82f2-d622298c7299@nohats.ca>
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org> <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl> <m1s1Wur-0000LDC@stereo.hq.phicoh.net> <f0f9c0ce-2911-9b4c-0d60-47c204add2d4@nohats.ca> <DB9D1C93-95D1-4B76-AD74-4C60433D479A@icann.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/oXUva4sW78UMuK5aUgtILbvYthU>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Apr 2024 20:30:11 -0000

On Mon, 29 Apr 2024, Paul Hoffman wrote:

> If the purpose of deprecating validation that involves SHA-1 is the decision by RedHat to make that entire section of the DNS insecure, the documents should say that explicitly. Conflating the pre-image weaknesses of SHA-1 and actual useful attacks on DNSSEC, and then using that conflation as the reason for the WG adopting these documents, is not useful.

Redhat is not the source of this. It is the certification people that say you
cannot use SHA1 in cryptographic functions related to authentication,
encryption, or digital signatures. And that these requirements are
getting centrally codified in an OS that cannot take DNS into account.

> (And, if anyone believes that collision reduction attacks on a hash are likely to lead to preimage reduction attacks, please look at the literature about MD5. The collision resistance has been massively reduced, and there is still zero preimage reduction after almost 20 years.)

Tony Finch and Viktor Dukovhny believe an attack with SHA1
is possible. I have not yet been convinced by them. See:
https://www.dns.cam.ac.uk/news/2020-01-09-sha-mbles.html

I agree SHA1 in DNSSEC does not pose a risk right now, but also
agree that we should push hard for people to stop creating
SHA1 based data. Last time Viktor shared data, I think SHA1
was sufficiently small that we could move forward without
breaking too much. Perhaps Viktor can share his updated
numbers with us.

Paul