Re: Comments from the IAB on NIST SP 800-90A Proceeding

Hannes Tschofenig <hannes.tschofenig@gmx.net> Thu, 24 October 2013 07:38 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1437C11E82F9 for <ietf@ietfa.amsl.com>; Thu, 24 Oct 2013 00:38:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.616
X-Spam-Level:
X-Spam-Status: No, score=-102.616 tagged_above=-999 required=5 tests=[AWL=-0.017, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XxhMOcj2zhMb for <ietf@ietfa.amsl.com>; Thu, 24 Oct 2013 00:37:59 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) by ietfa.amsl.com (Postfix) with ESMTP id 2902711E82F3 for <ietf@ietf.org>; Thu, 24 Oct 2013 00:37:55 -0700 (PDT)
Received: from [172.16.254.200] ([80.92.115.161]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MH4Os-1VVRsB11oQ-00DlqE for <ietf@ietf.org>; Thu, 24 Oct 2013 09:37:53 +0200
Message-ID: <5268CE6A.3030904@gmx.net>
Date: Thu, 24 Oct 2013 09:38:18 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0
MIME-Version: 1.0
To: Riccardo Bernardini <framefritti@gmail.com>, "ietf@ietf.org" <ietf@ietf.org>, IAB <iab@iab.org>
Subject: Re: Comments from the IAB on NIST SP 800-90A Proceeding
References: <CAOW+2dukS-Zye-T9NcWnstSmydpG4YaT6bW_CKh-KYhJQfasUA@mail.gmail.com> <02364CCE-9122-4EC0-A2D8-16C3FE16245F@isoc.org> <0C7687D7-CFAF-4122-950D-13DCAC6A3598@iab.org> <CADnDZ8_Vor0ksG1Q+PU0QH1O-ViDbziBqNh72bw4eL1T2LCrKA@mail.gmail.com> <CABSMSPX8LcVNEfQc08Yx_73pL3DRfN_Sj09v9OdbOex7=4NNXw@mail.gmail.com>
In-Reply-To: <CABSMSPX8LcVNEfQc08Yx_73pL3DRfN_Sj09v9OdbOex7=4NNXw@mail.gmail.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:VzS9JRXN6yL4qJhp91taq6jtlvYhgE94kPexFCtWNcDn2r9fK47 AHt48TtIcBFm7k3B2XaQdxloK5Cis6+F4L2LzmnnPplPqDxtW7bs4QSjHWkp3rV0aGZbo+t tP5aJTOBMjIZQwQ4foNyOfT/J0eZXD+khL3JNtdH/S4WpCMWL/OvsJJVCxI9sy2dfGvIffH jVLCiMgztgIMVVuqXIQ7Q==
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2013 07:38:04 -0000

On 10/24/2013 09:28 AM, Riccardo Bernardini wrote:
> does IETF standards really
>>depend on NIST standard process and development? Is the statement talking
>>about all IETF security standards?


As I tried to explain in 
http://tools.ietf.org/html/draft-tschofenig-perpass-surveillance-00 the 
IETF is currently not in the business of developing cryptographic 
primitives. This work is done outside the IETF (to a large extend).

Of course, our security protocols have to use cryptographic primitives 
and there is the question where do these come from.

It turns out that there are not that many organizations in the world who 
have the necessary level of expertise. NIST is one of them.

Ciao
Hannes