Last Call: <draft-ietf-curdle-ssh-dh-group-exchange-04.txt> (Increase SSH minimum recommended DH modulus size to 2048 bits) to Proposed Standard
The IESG <iesg-secretary@ietf.org> Sun, 16 July 2017 09:09 UTC
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: ietf-announce@ietf.org
Delivered-To: ietf-announce@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id A43401318AA; Sun, 16 Jul 2017 02:09:21 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Subject: Last Call: <draft-ietf-curdle-ssh-dh-group-exchange-04.txt> (Increase SSH minimum recommended DH modulus size to 2048 bits) to Proposed Standard
X-Test-IDTracker: no
X-IETF-IDTracker: 6.56.0
Auto-Submitted: auto-generated
Precedence: bulk
CC: ekr@rtfm.com, draft-ietf-curdle-ssh-dh-group-exchange@ietf.org, Daniel Migault <daniel.migault@ericsson.com>, curdle-chairs@ietf.org, curdle@ietf.org, daniel.migault@ericsson.com
Reply-To: ietf@ietf.org
Sender: iesg-secretary@ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <150019616166.8774.5393420529621277591.idtracker@ietfa.amsl.com>
Date: Sun, 16 Jul 2017 02:09:21 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-announce/6c_ZK7BASAuQiFoHStXuVuHj_oI>
X-BeenThere: ietf-announce@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-announce/>
List-Post: <mailto:ietf-announce@ietf.org>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 16 Jul 2017 09:09:22 -0000
The IESG has received a request from the CURves, Deprecating and a Little more Encryption WG (curdle) to consider the following document: - 'Increase SSH minimum recommended DH modulus size to 2048 bits' <draft-ietf-curdle-ssh-dh-group-exchange-04.txt> as Proposed Standard The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the ietf@ietf.org mailing lists by 2017-07-30. Exceptionally, comments may be sent to iesg@ietf.org instead. In either case, please retain the beginning of the Subject line to allow automated sorting. Abstract The Diffie-Hellman (DH) Group Exchange for the Secure Shell (SSH) Transport layer Protocol specifies that servers and clients should support groups with a modulus length of k bits, where the recommended minumum value is 1024 bits. Recent security research has shown that a minimum value of 1024 bits is insufficient against state-sponsored actors. As such, this document formally updates the specification such that the minimum recommended value for k is 2048 bits and the group size is 2048 bits at minimum. This RFC updates RFC4419 which allowed for DH moduli less than 2048 bits. The file can be obtained via https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-dh-group-exchange/ IESG discussion can be tracked via https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-dh-group-exchange/ballot/ No IPR declarations have been submitted directly on this I-D.