RE: aes128gcm: is the 1st example wrong?

"Manger, James" <James.H.Manger@team.telstra.com> Sun, 12 February 2017 23:44 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88CC712947F for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 12 Feb 2017 15:44:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.902
X-Spam-Level:
X-Spam-Status: No, score=-6.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=teamtelstra.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eyeAqhK4XVjp for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 12 Feb 2017 15:44:23 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9DA26120726 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Sun, 12 Feb 2017 15:44:23 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1cd3mg-0004nL-98 for ietf-http-wg-dist@listhub.w3.org; Sun, 12 Feb 2017 23:42:22 +0000
Resent-Date: Sun, 12 Feb 2017 23:42:22 +0000
Resent-Message-Id: <E1cd3mg-0004nL-98@frink.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by frink.w3.org with esmtps (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <James.H.Manger@team.telstra.com>) id 1cd3mb-0004mF-Ge for ietf-http-wg@listhub.w3.org; Sun, 12 Feb 2017 23:42:17 +0000
Received: from ipxbno.tcif.telstra.com.au ([203.35.82.204]) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <James.H.Manger@team.telstra.com>) id 1cd3mU-0004G2-Eg for ietf-http-wg@w3.org; Sun, 12 Feb 2017 23:42:12 +0000
X-IronPort-AV: E=Sophos;i="5.35,155,1483966800"; d="scan'208";a="130903574"
Received: from unknown (HELO ipcbni.tcif.telstra.com.au) ([10.97.216.204]) by ipobni.tcif.telstra.com.au with ESMTP; 13 Feb 2017 10:41:37 +1100
X-IronPort-AV: E=McAfee;i="5800,7501,8437"; a="301672248"
Received: from wsmsg3702.srv.dir.telstra.com ([172.49.40.170]) by ipcbni.tcif.telstra.com.au with ESMTP; 13 Feb 2017 10:41:37 +1100
Received: from wsapp5870.srv.dir.telstra.com (10.75.139.12) by wsmsg3702.srv.dir.telstra.com (172.49.40.170) with Microsoft SMTP Server (TLS) id 8.3.485.1; Mon, 13 Feb 2017 10:41:37 +1100
Received: from wsapp5585.srv.dir.telstra.com (10.75.3.67) by wsapp5870.srv.dir.telstra.com (10.75.139.12) with Microsoft SMTP Server (TLS) id 15.0.1236.3; Mon, 13 Feb 2017 10:41:36 +1100
Received: from AUS01-ME1-obe.outbound.protection.outlook.com (10.172.101.126) by wsapp5585.srv.dir.telstra.com (10.75.3.67) with Microsoft SMTP Server (TLS) id 15.0.1236.3 via Frontend Transport; Mon, 13 Feb 2017 10:41:36 +1100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=teamtelstra.onmicrosoft.com; s=selector1-team-telstra-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=zX8CQSIX0XsL1L+Ai3WDgEeBd6HutJM/vD8QbPWH8Ug=; b=PedMsGrypWRijs4Dv9t0NpWiHqKGqABxZi+wYCFV3u+ZEzpS5AWmuAV+vjp+PXYng3wx3WXy2lG6q0C/cd9SMaYiu8etYpTw2iAp/3ANFO19OvMoKCMncS3zpC3EoFZu8pOPZfL7H+f3CqWZ/Lnyv6qbm1q9pZRXaR2bB8utbCY=
Received: from SYXPR01MB1615.ausprd01.prod.outlook.com (10.175.209.15) by SYXPR01MB1614.ausprd01.prod.outlook.com (10.175.209.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.888.16; Sun, 12 Feb 2017 23:41:35 +0000
Received: from SYXPR01MB1615.ausprd01.prod.outlook.com ([10.175.209.15]) by SYXPR01MB1615.ausprd01.prod.outlook.com ([10.175.209.15]) with mapi id 15.01.0888.030; Sun, 12 Feb 2017 23:41:35 +0000
From: "Manger, James" <James.H.Manger@team.telstra.com>
To: Martin Thomson <martin.thomson@gmail.com>, Julian Reschke <julian.reschke@gmx.de>
CC: "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
Thread-Topic: aes128gcm: is the 1st example wrong?
Thread-Index: AdJwaRiaLg2sNqShRRuJIHKdUn2T6gABvL4ABT4xjoAAB90lgAAAE/2g
Date: Sun, 12 Feb 2017 23:41:35 +0000
Message-ID: <SYXPR01MB1615A9EA6825C721A3ACCEA9E5460@SYXPR01MB1615.ausprd01.prod.outlook.com>
References: <SYXPR01MB1615D5823473E6A9B5F0C80DE57C0@SYXPR01MB1615.ausprd01.prod.outlook.com> <CABkgnnWE38wbhKfp+5nF1hfn7qH4-6Uk4QMGBKgGL6-f_em_KA@mail.gmail.com> <1459eb07-f8cb-ff90-6101-be05f80c76aa@gmx.de> <CABkgnnVVc3OvJh1ukTuaFmrbOLgEiVWSqfKGP74ct=TKxpZxTg@mail.gmail.com>
In-Reply-To: <CABkgnnVVc3OvJh1ukTuaFmrbOLgEiVWSqfKGP74ct=TKxpZxTg@mail.gmail.com>
Accept-Language: en-AU, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=James.H.Manger@team.telstra.com;
x-originating-ip: [203.41.142.254]
x-ms-office365-filtering-correlation-id: 2cc441b2-fa15-4655-2237-08d453a0aec2
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:SYXPR01MB1614;
x-microsoft-exchange-diagnostics: 1; SYXPR01MB1614; 7:fTj8dYaNPogmjPaEog5e5hHikMyABMUTrftFWNPiRqS3umSCsO4Uk36k009/wWXQ9AFdcBZcZOIwVRLgAXTxBOAv1TQCgFpEdO7izuSRJnqMWrxvyNj8IG5QcQN4/OZlTaGui2TIj9vMqs2KFRxA7D9Fw4UlUTlTChcuxUHWl8hVc0AlAD3BLoqkhydXRDJbYfxwEDeMZVxRGwzLA9DAugbY3zKsPp31/1iSRV4TfuG3+Hxg+5zf1nmzj60VX+0+1onhKIyKqNTKLYUuytPUThhZKtC31MnO20TD8Iyab9qUkldFtV5ZvhQVNO1l4f+llKMyugGCuieksPXTGMOXHbFdZtsPif8pvLF+qycpmPTdC9YBzumYkVBGH5SG6ckJ1ABcm48gFYf1/fADa0UQkROOl92eIj/noFhYx6KV0SEiEyXHIoBJU99jhSVshvnWyMosIObp0Vj9i43Ig8Dv9t5qsmts18g6mYh/f5lG/pbxL2v7IbmaLsMurLCk3BA8w1ecvetnopNhJFOXheqcRQ==
x-microsoft-antispam-prvs: <SYXPR01MB1614E651D6896F3D369053B9E5460@SYXPR01MB1614.ausprd01.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(26323138287068)(166708455590820)(272811157607776)(192278398808882)(67441168502697);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6041248)(20161123555025)(20161123558025)(20161123564025)(20161123562025)(20161123560025)(6072148)(6042181); SRVR:SYXPR01MB1614; BCL:0; PCL:0; RULEID:; SRVR:SYXPR01MB1614;
x-forefront-prvs: 021670B4D2
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(7916002)(199003)(24454002)(13464003)(189002)(377454003)(3660700001)(6436002)(66066001)(2900100001)(93886004)(86362001)(97736004)(101416001)(92566002)(33656002)(68736007)(53546003)(38730400002)(53936002)(6246003)(99286003)(74316002)(7696004)(5660300001)(76176999)(229853002)(4326007)(42882006)(2950100002)(50986999)(3280700002)(106356001)(54356999)(2906002)(6116002)(102836003)(25786008)(9686003)(3846002)(6306002)(8936002)(81156014)(81166006)(8676002)(6506006)(77096006)(189998001)(39060400001)(7736002)(55016002)(305945005)(8666007)(122556002)(105586002); DIR:OUT; SFP:1102; SCL:1; SRVR:SYXPR01MB1614; H:SYXPR01MB1615.ausprd01.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:0; MX:1; LANG:en;
received-spf: None (protection.outlook.com: team.telstra.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Feb 2017 23:41:35.6562 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 49dfc6a3-5fb7-49f4-adea-c54e725bb854
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYXPR01MB1614
X-OriginatorOrg: team.telstra.com
Received-SPF: none client-ip=203.35.82.204; envelope-from=James.H.Manger@team.telstra.com; helo=ipxbno.tcif.telstra.com.au
X-W3C-Hub-Spam-Status: No, score=-2.0
X-W3C-Hub-Spam-Report: AWL=0.100, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001, W3C_NW=0.5
X-W3C-Scan-Sig: mimas.w3.org 1cd3mU-0004G2-Eg aa2f9a1176d824c22da0dbdb2c6f6e49
X-Original-To: ietf-http-wg@w3.org
Subject: RE: aes128gcm: is the 1st example wrong?
Archived-At: <http://www.w3.org/mid/SYXPR01MB1615A9EA6825C721A3ACCEA9E5460@SYXPR01MB1615.ausprd01.prod.outlook.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/33475
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

The padding scheme has also been updated (from <padlen><data><0..> to <data><1|2><0...>). So you need new code, Julian.

-----Original Message-----
From: Martin Thomson [mailto:martin.thomson@gmail.com] 
Sent: Monday, 13 February 2017 10:32 AM
To: Julian Reschke <julian.reschke@gmx.de>
Cc: Manger, James <James.H.Manger@team.telstra.com>; ietf-http-wg@w3.org
Subject: Re: aes128gcm: is the 1st example wrong?

On 13 February 2017 at 06:47, Julian Reschke <julian.reschke@gmx.de> wrote:
> FWIW, I was able to reproduce the examples with the updated code in
> <https://gist.github.com/reschke/46659c912b426dffeac41d9a21421c95>, modulo
> the change Martin mentioned (but which I don't see in Git).

'twas on a branch.  I've merged that now.

> WRT
> <https://greenbytes.de/tech/webdav/draft-ietf-httpbis-encryption-encoding-06.html#rfc.section.3.2>:
> it would be good if the prose mentioned that this specifies a keyid of "a1"
> in the header.

Also on said branch :)