Re: [DNSOP] [Last-Call] [secdir] Secdir last call review of draft-ietf-dnsop-server-cookies-04

Eric Rescorla <ekr@rtfm.com> Sat, 05 December 2020 18:59 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD81C3A074B for <dnsop@ietfa.amsl.com>; Sat, 5 Dec 2020 10:59:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9NUpZt6dnaTx for <dnsop@ietfa.amsl.com>; Sat, 5 Dec 2020 10:59:17 -0800 (PST)
Received: from mail-lf1-x130.google.com (mail-lf1-x130.google.com [IPv6:2a00:1450:4864:20::130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EECD33A0766 for <dnsop@ietf.org>; Sat, 5 Dec 2020 10:59:16 -0800 (PST)
Received: by mail-lf1-x130.google.com with SMTP id l11so12372528lfg.0 for <dnsop@ietf.org>; Sat, 05 Dec 2020 10:59:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=+Y/NZITf/yqVml9sTuFJ9ZdqXkbpFTLZHUBv8OLEsWg=; b=GWcgFhuelKbr7ijaY5ECiaZ4amvt1fRHwiOP2Jn7OGmEyWCbYqyeHP8reI2jmaJM1Q cdzCFAfdN+PdGK/vmnL386w5C5N62e8aRvCPUw9kkjfIxkC6zS1F6Wu7vIsWqv55l+l6 ytTSzVjXN0QmqM0D/Pbwxv/NP0sEMduNv1NOPtYJU8NeCg+2VPDQRZgbiLdT6g8RwHM4 soiDmKFXlLCXu8icL0EKmszLwdoE95uEXvmzYlTohgZuqnlj099LRJVYv8ouZW+3Az+h XYHWJnv0PR2LcepJnZ7md9B/xdt+pcTvGIwYm7ezbAMPBgUW6WRvRndv1Tp2wOVznRLW kfbA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=+Y/NZITf/yqVml9sTuFJ9ZdqXkbpFTLZHUBv8OLEsWg=; b=Ln/JB/k/Sc8/IArlar8QLWbKMsGREmZ2MHkG7mY8tBdukxGyaqhwtB9bfeX8vIoT1A wYY8CPDEIRrzxZGG5I/jRYsz7SgVAJpOmKSeHvckLktKHIMmJ19ymvbheXyF0HF60xHO paL6w8bHQmaseEcXGmsRXNrrOpToua8ECpBtBcgWIoOuZB5XArX0SIrOSlXuvBzz24Ci SCNNQStHkExnTQAWBZYwyGmkn68H2/4jG7EPupX+yn8b8Ixo0OLAzmSoPPkKs532mVg0 lXoAAzeoLgGR2YGzxHIwjdgivOItLMoIlOiztKklEruNNvUE+2PhXUqnxI4SLAaE4qjf OLvA==
X-Gm-Message-State: AOAM531uYcI8zDPZIk2AAzpNRn5L0Wsg45Paiac/npg9mvzwox1HythF DDazoHbRCelyZB/y2qonmdUCGJ7KiSK2M0AKaPlsHQ==
X-Google-Smtp-Source: ABdhPJw453E+pvza93ecJbOEqYnkjc2Dodat3F4YnA8MILQGLwK+dh8Gg2vhZQASEeD33xIN7/zqIOqz4QeGhThqAK0=
X-Received: by 2002:a05:6512:368a:: with SMTP id d10mr5510438lfs.579.1607194755036; Sat, 05 Dec 2020 10:59:15 -0800 (PST)
MIME-Version: 1.0
References: <160693121881.9413.5642470305677631145@ietfa.amsl.com> <17AFD6F5-11DA-41BC-8C37-E1893648041D@isc.org> <CABcZeBPRn3aTBsApawvk_Ecyzdbi+SX9=b74y0_uhYx_Y8p-5w@mail.gmail.com> <51A61472-45D7-4133-80BC-1F470B5CBD84@isc.org> <20201204203635.GS64351@kduck.mit.edu> <320692C5-9C47-4CE6-8D6C-A62C2B50728F@akamai.com>
In-Reply-To: <320692C5-9C47-4CE6-8D6C-A62C2B50728F@akamai.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Sat, 05 Dec 2020 10:58:38 -0800
Message-ID: <CABcZeBOQXcihkksYGa1Khc0ZZgvb-EJ3iy5S9MEQVeL95pohqQ@mail.gmail.com>
To: "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>
Cc: Benjamin Kaduk <kaduk@mit.edu>, Ondřej Surý <ondrej@isc.org>, "last-call@ietf.org" <last-call@ietf.org>, "draft-ietf-dnsop-server-cookies.all@ietf.org" <draft-ietf-dnsop-server-cookies.all@ietf.org>, dnsop WG <dnsop@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000758c5305b5bc3052"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/otonqOkT_uWjUMxr01kch-1Rhek>
Subject: Re: [DNSOP] [Last-Call] [secdir] Secdir last call review of draft-ietf-dnsop-server-cookies-04
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 05 Dec 2020 18:59:20 -0000

On Sat, Dec 5, 2020 at 6:58 AM Salz, Rich <rsalz=40akamai.com@dmarc.ietf.org>
wrote:

> There is a fair amount of academic study around SipHash, and while
> everyone can make mistakes, its creators have a pretty good reputation. I
> don't think we can say SipHash is unknown in the industry.
>
> The TLSWG made it a practice to ask CFRG to "approve" all crypto it used
> (except perhapd HKDF, but that's a side note). The DNSOP has no such
> practice.
>

I recognize that this is a bigger issue, but I believe this should be the
practice for the IETF as a whole and I would encourage the SEC ADs to work
to make it so.

-Ekr



> If SECDIR or the Ads thinks SipHash isn't good, it would be great to hear
> reasons.  I haven't heard any yet.
>
>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
>