Re: [Emu] I-D Action: draft-ietf-emu-tls-eap-types-09.txt

John Mattsson <john.mattsson@ericsson.com> Mon, 07 November 2022 13:03 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D563C1524A2 for <emu@ietfa.amsl.com>; Mon, 7 Nov 2022 05:03:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.677
X-Spam-Level:
X-Spam-Status: No, score=-2.677 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id okQHwg64OAgR for <emu@ietfa.amsl.com>; Mon, 7 Nov 2022 05:03:10 -0800 (PST)
Received: from EUR03-VI1-obe.outbound.protection.outlook.com (mail-vi1eur03on2080.outbound.protection.outlook.com [40.107.103.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52C4DC1524CB for <emu@ietf.org>; Mon, 7 Nov 2022 05:03:10 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ehKisxRrOQjLea3H29fyhPhwjRfAsf30YVbQMDG4XKn/nqUi6M/6qZ4xgzrXYCarf0hJt2YT2RXMrGcdsNQi5ZTfXTfYu4uf93PWyOva7eU1JD/v2cdIYgdQqZWVmVA6Bst9UhTkSelt7D1YfJWBPOIsWzXi1gbks3p54dRQLCTt6eTNehn4Bzwzy0RBlQYJYw5MoMxE1Tox2qFT3zFq2d+9BaThmfnVPohr4abzfs6hMtMthbxnJEVSbdiu8dbvxtA5Y6yalFYwZ3rwFXlSsiZk2uuWUzEhWKvyFaA90EI5xOvQoyPAjki30lQSVsmezFwnS/q+uMG7+xeFPzV+Fg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=30BoSTEp8+NRf4s9AJrBkb5BVpQLEXGa2oL5KG2LB7w=; b=a0c/4d7jrhrpk6gon49IV/pJB0uCJKoVdLgx65YgGOlII5etAiZLmx1KghCDjgdq19vFeb6/LJXX3ULp5HowFQDLbqUuF/nIS7RCwkPdzQCFY5sq7TRQZJ23zu/lFz9Q6IKi9mvGRXQ+VPOHeqfnxuGdpoX3UH1BEHi5cLf3jmkkFRHvvsGW8ddFxgPN0eHbSBvjvZLz2IYZNmCwXCAw3gIIlJ8Fybd5/3z5n2hZ4CeqTxCeC73Soutu0DP4pYrUOG0eVwtl3NF4jZsM+x2IZN5GFYB5hjvvQQDw1KWNiI/dCkJ6cMv+iu7ci3p/H6qdN/rg3ULd8bXOw4vIoyRZgg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=30BoSTEp8+NRf4s9AJrBkb5BVpQLEXGa2oL5KG2LB7w=; b=G1nCNfWFLtuJLLy5+Dl5e+3ABr6zi+GJvgn+waCp+il7MiMCzOeO/C2KvGCjTWVF2xoO3bl2gDeoLAefUXk4ZPxz27Fx842+Ea8xnr0JyC2vYkkKlnUGAvTvDWQSgdDQiII/ql6pVzaBQZNju/pij3W2IGyXVYWdeLOCJcI1sQo=
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com (2603:10a6:3:4b::8) by AS2PR07MB9445.eurprd07.prod.outlook.com (2603:10a6:20b:64b::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5791.26; Mon, 7 Nov 2022 13:03:06 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::4458:48c2:e76a:4057]) by HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::4458:48c2:e76a:4057%6]) with mapi id 15.20.5791.026; Mon, 7 Nov 2022 13:03:05 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Alan DeKok <aland@deployingradius.com>
CC: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, "emu@ietf.org" <emu@ietf.org>
Thread-Topic: [Emu] I-D Action: draft-ietf-emu-tls-eap-types-09.txt
Thread-Index: AQHY0mxbYWJHZ8MvtEqZnK7+dSX27K4kDzbkgAARzwCAAUsZM4AADOwAgA4zaR4=
Date: Mon, 07 Nov 2022 13:03:05 +0000
Message-ID: <HE1PR0701MB30500C1FD36C5979469E740B893C9@HE1PR0701MB3050.eurprd07.prod.outlook.com>
References: <166428153120.54333.17278955597896126770@ietfa.amsl.com> <HE1PR0701MB3050362A7979C272F7E285E989329@HE1PR0701MB3050.eurprd07.prod.outlook.com> <794E0C93-3068-4C2C-98B8-AE551D48AC00@deployingradius.com> <HE1PR0701MB3050E350E6C3A2A291AE331789359@HE1PR0701MB3050.eurprd07.prod.outlook.com> <DA174BC8-A85A-481E-9992-45BD928DB6BC@deployingradius.com>
In-Reply-To: <DA174BC8-A85A-481E-9992-45BD928DB6BC@deployingradius.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: HE1PR0701MB3050:EE_|AS2PR07MB9445:EE_
x-ms-office365-filtering-correlation-id: 0f3ec7b8-8b68-4a8e-809c-08dac0c0693a
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: vj/PO8kOTZD/f8WXUFhmZcbThXUIyFzFoGi2S8B6LoUl2Hg6xpuoopNicSDduVSuC8nHFdCUsSqwbCSbJZFQqFxi4Du5WFwBUG6ylroRZ8qznQZ30bdJXG0uIesckZp3P/ELDA7UUZKL0YWacIb74FlLOeug8lE97Iop+Ek2+VkRghTB0U/KdtBj7nwPzxxD0QMLX+3V6blO69/v+5kTrsj4xP/G5/FdIfv1Kl24JhWg2ec5MBdzGEDJE6v0u7lZX6tGG02acsfvBlMCSewAYdHWtaHjYhNx4qouIVrcyoL5VCygF5qWfhZsyuZ92EwVsvKl+8ud93xgVieXmuhyR5pt7ERX+TGWIrtQLvUhAhUHd0PMYolmDeAqU9y6XYHpSkq1H69pQjQ910b4JwpOJpWVWJl9tkZeBA0NzUCgSEQJSR157GKhoJS1AdKhVCekgCo3SR6uljqeSP6DJd205kb+HgSOF4wyVfgxw0PX71+J0WgmNsRJsDXxr/tuulqgBMVGEJk839pAKVOx5GYkyqp57768bCbt2tAA2pSmJXGbWXte9Q7ULN0uR4oPwZ5k4wEi2ihOJBJDcknCRSxwjIo0aTVmKSfHvMqjL77eGAVyThLOPs8IoVWmhnNkwCjsyZh6rH70Kdy86qHWOzpMwMCNVlKfIh+wvohnY/A5/NlC5ECyvLexMpe/xBGsHmh6O7JJt5RqJI4S6nb+kMV5gqkmSC1IMsNsGIe267hPKMLM5SllH270xjwJr9TB+KPh4oXycvNPjLXlHdo3FPJVGz3lCcITuxiPEmdGx+MBskfK4XNfFPzD6WqmOjI4lAse
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(136003)(396003)(346002)(376002)(39860400002)(366004)(451199015)(9686003)(186003)(26005)(6506007)(7696005)(53546011)(122000001)(83380400001)(44832011)(2906002)(55016003)(478600001)(8676002)(4326008)(71200400001)(6916009)(45080400002)(54906003)(52536014)(5660300002)(41300700001)(38100700002)(8936002)(91956017)(76116006)(316002)(64756008)(66446008)(66556008)(66476007)(66946007)(33656002)(38070700005)(82960400001)(86362001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: IfiCP29bmpc8lqF+0nOwns+8RU6p0BBa6S/xQ3fyUmmfE9tkX80KwOyU/Lqi4UzjnQ3re6svQ32VublVTHx7Rn7/qt1V83CPrzdg/fYLk5MODdEvp8DIaUMhrXkppfzto0bD7k6GfR0cAkeWE3YfhKELTWwxAubqaeyXfZ9GUbXtSUht7Srx8b4CuhYpWylYyy32AV6y5C4W63L/RzH9JyKuxTlZQw9OjfBN1CgXx/Fv3ak2yeL0U/JQrkumQs6t6qTjgeSFfheqRZN+yrYoZohHfNoinha+agTz3tx+ylvi2nNQzM0IP61fC+4a5Gfjjavgb7LyX2G/G6/shE2V25mJua4Fty+U4a1tMdRAcqtsk8oeDIwwndx6WMmAicEDXpxussOJP9CP8fSCaij80smT5dgxHPNR8oddwZU581rLM3CsWXfhYt/XBlaUHktTDx1BRsz7ZPXNXzLRo5Tu10pNNzvcBq/tliflkoc1ZwU3ldx64UCScUooydLqjTNA/Zm/g2Ar3YMOEoC9cqnihFiPME9XxnJ3i266ZISP0s//1GOBWiiEGZlLllmpV/0Uq/818yo7L18cEFl4pI5g5fx8KuLO6y5um3yhllQXJBV71q7NceF+umFEB2ZI5nhytScX3IoMwTtWu2rLHoghe+L82Wt9Med9c+iWrGRElo0HuSwv3Sl7W4Xik+4eyidf4UewWAnqdfAiT/yc8wODwumO3Jtxlip/ebr07tfZxfN90BErEvgz3eDRLN0+/3MCVDi8bfoytbOt+iPcm6FF4sjw3xIfzCxdAIO3JPTumDfOX1WiW160AorgjKTsYs47vNnKtG/kwTGtQevxJX4H1cu7kmf2TmEBuLz9D/sUsSBes+k1gU3IaOc9L+oWcsEaOfK/uesb7ycr+MwaItZYVhJutm+D6eRM2WvdeRZBReWjjyCoO0pQhB24wNGLt6GXwQhwqNlIObhJbQ9RBjlnVAwSh70IkUiJA5tK0obYnW6rNQkm84lkJ7TiiWhOF7YV9rItqB4CU7nRjys2bVEc87EgAgCnFJ0udaS7TqV2Wnpwy6fn2JaC25eDHQFuXYs1ySmLe6sznG6jObHE+37BBS335d5SxFvB7GagDadRPRewzNtQYeHFVwS3+iLASbZz/DoyOtWda2+6WatPlPWJrHmO2CAd5058SVTPPgl3/9cLMwXOCz8XaEzb9yvDQRtZpJ3EZgP6+vEmLj0brXoO+AT6IZ0FJJyiWPi+2vmrN1XtVpViHU/hkUs0PZ+ypYReBx1K/PlmxxyuZX++zzNT+9v4Dh/AgXfdc+2tiVDRdxULxCca0sti7xB6jS/SssDZgTpXIf+3FkuAJMSWT+FuG5PwDR+EaTX3eG/spTkhA61VkHOclQINSmODeJycG0sDlvR1k/ZI1JfTQSVDLZolHrfM6D/ju98s1fxQ8RV0FjlJW/14Lka9UazUNkeTQxbavgMOYRRDmhRS5Eg/oZjSGT79odbEr38gnaxhmr8NiTzNoEqwViqtVsaXNoHrcVS3dKlrfZuhesYqBbSTTlaQCgB3qAUoICDeJGyqxOVhvv9mKpg1pm8ukHSt1/nju8/sIpDp/x/7bNcwZh9QxoML2Ae6AbAyg8XuwYaw++bo/b8=
Content-Type: multipart/alternative; boundary="_000_HE1PR0701MB30500C1FD36C5979469E740B893C9HE1PR0701MB3050_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 0f3ec7b8-8b68-4a8e-809c-08dac0c0693a
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Nov 2022 13:03:05.7885 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: IDrrLPOivIPAgywPqoRDc2nO+MDmBZySik+T3GdQjWnsdvSbxxY0+nl4wPsxjDmVBbpUbWQziAksp7gG/x7FnNujuct6uCR4gKpae4HcRko=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS2PR07MB9445
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/B_QTIY7DWc6nw9nPJ9c8mQb6-Y0>
Subject: Re: [Emu] I-D Action: draft-ietf-emu-tls-eap-types-09.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Nov 2022 13:03:14 -0000

Alan DeKok wrote:
>  It may be worth adding a one-sentence comment on the order of:
>
> Note that this derivation depends on SHA-1, which may be formally deprecated in the
> near future.

Yes, please do.

Cheers,
John

From: Alan DeKok <aland@deployingradius.com>
Date: Saturday, 29 October 2022 at 13:07
To: John Mattsson <john.mattsson@ericsson.com>
Cc: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, emu@ietf.org <emu@ietf.org>
Subject: Re: [Emu] I-D Action: draft-ietf-emu-tls-eap-types-09.txt
On Oct 29, 2022, at 7:46 AM, John Mattsson <john.mattsson@ericsson.com> wrote:
> I don’t remember any such WG consensus (but maybe I am missing something). What I can find in the mailing list archive is that several people pointed out that moving away from SHA-1 is a good idea, that there is no need to use SHA-1, but that the final decision is Microsoft’s:

  There was no agreement to change PEAP.  There have been no recommendations to change the document to address this issue.

  An implicit consensus to do nothing is still consensus.

> Might be that we are stuck with SHA-1, but irrespectively of why that is the case, I still think that draft-ietf-emu-tls-eap-types should clearly point out the fact that PEAP 1.3 uses SHA-1. I think this is important (and unexpected) information to readers of the document and users of the EAP method. My understanding is that TEAP 1.3 is not using SHA-1.

  The document is pretty clear on how the fields are calculated:

2.5.  PEAP

   When PEAP uses crypto binding, it uses a different key calculation
   defined in [PEAP-MPPE] which consumes inner EAP method keying
   material.  The pseudo-random function (PRF+) used in [PEAP-MPPE] is
   not taken from the TLS exporter, but is instead calculated via a
   different method which is given in [PEAP-PRF].  That derivation
   remains unchanged in this specification.

  It may be worth adding a one-sentence comment on the order of:

  Note that this derivation depends on SHA-1, which may be formally deprecated in the near future.

  Alan DeKok.