Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Paul Wouters <paul@nohats.ca> Mon, 29 April 2024 20:00 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6304C18DB92 for <dnsop@ietfa.amsl.com>; Mon, 29 Apr 2024 13:00:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.431
X-Spam-Level:
X-Spam-Status: No, score=-6.431 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_SOFTFAIL=0.665, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AhFeoMeP8SMw for <dnsop@ietfa.amsl.com>; Mon, 29 Apr 2024 13:00:44 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CCBDC1840F3 for <dnsop@ietf.org>; Mon, 29 Apr 2024 13:00:44 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4VSvMY6ftFz7YY; Mon, 29 Apr 2024 22:00:41 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1714420841; bh=In3QBVc//5x5yvYlFDvQ4gNRjRL+FzaSZjntKlsQtU8=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=j3MjCwlxff/pINOYRbRISE7VnyRYvnN3Ut7dgQG/Qibc8qurlRx2RAK/JpNYSzsh6 cAoOPasgx0EoBuwhK9zyv3B6ZbQ987l0+/0fD3zhQNDLeXlRMZFSEjVGoFCicJpCaM qRlgemu9di2+NXwRLwfHhVVIW9rq3NcRxZ9bJqf0=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id S0hMuroCfY_k; Mon, 29 Apr 2024 22:00:41 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Mon, 29 Apr 2024 22:00:40 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id BB10B11DD8F6; Mon, 29 Apr 2024 16:00:39 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id B78F311DD8F5; Mon, 29 Apr 2024 16:00:39 -0400 (EDT)
Date: Mon, 29 Apr 2024 16:00:39 -0400
From: Paul Wouters <paul@nohats.ca>
To: Philip Homburg <pch-dnsop-5@u-1.phicoh.com>
cc: dnsop@ietf.org, Joe Abley <jabley@strandkip.nl>
In-Reply-To: <m1s1Wur-0000LDC@stereo.hq.phicoh.net>
Message-ID: <f0f9c0ce-2911-9b4c-0d60-47c204add2d4@nohats.ca>
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org> <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl> <m1s1Wur-0000LDC@stereo.hq.phicoh.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/pL06-pJkPD3HrTSMt0NaYPSnUzU>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Apr 2024 20:00:48 -0000

On Mon, 29 Apr 2024, Philip Homburg wrote:

> As far as I know there is no second pre-image attack on SHA1, and there
> will not be one in the foreseeable future.

Correct.

> So if we deprecate SHA1 for validators, and assuming validators will follow
> this advice, and some platforms already stopped validating SHA1, then there
> may be zones that are mostly secure today that become insecure or bogus
> when we are done with the draft.

The advise is split between producing SHA1 signatures and consuming SHA1
signatures, and those timings do not have to be identical.

That said, a number of OSes have already forced the issue by failing
SHA1 as cryptographic operation (RHEL, CentOS, Fedora, maybe more). So
right now, if you run DNSSEC with SHA1 (which includes NSEC3 using
SHA1), your validator might already return it as an insecure zone.

I think a MUST NOT for signing with SHA1 is a no-brainer. The timing for
MAY on validation should be relatively short (eg 0-2 years?)

For NSEC3 requiring SHA1, that will depend a bit on whether DNS
validators have rewritten their code to allow the use of SHA1 on
those systems where it is disabled for "cryptographic reasons". I'm
not up to date on it, but my suggestion on adding SHA2 for NSEC3 so
far is not well received. Getting a list of the main resolvers (services
and software) and whether they properly support NSEC3 w SHA1 would
be helpful in making such decisions.

Paul