Re: Comments from the IAB on NIST SP 800-90A Proceeding

Abdussalam Baryun <abdussalambaryun@gmail.com> Thu, 24 October 2013 05:39 UTC

Return-Path: <abdussalambaryun@gmail.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF90111E82CC for <ietf@ietfa.amsl.com>; Wed, 23 Oct 2013 22:39:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.525
X-Spam-Level:
X-Spam-Status: No, score=-2.525 tagged_above=-999 required=5 tests=[AWL=0.074, BAYES_00=-2.599, HTML_MESSAGE=0.001, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VvQkRD5Ij9ox for <ietf@ietfa.amsl.com>; Wed, 23 Oct 2013 22:39:11 -0700 (PDT)
Received: from mail-pd0-x232.google.com (mail-pd0-x232.google.com [IPv6:2607:f8b0:400e:c02::232]) by ietfa.amsl.com (Postfix) with ESMTP id A356711E82D9 for <ietf@ietf.org>; Wed, 23 Oct 2013 22:39:07 -0700 (PDT)
Received: by mail-pd0-f178.google.com with SMTP id x10so1696050pdj.9 for <ietf@ietf.org>; Wed, 23 Oct 2013 22:39:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=dLgO62I18UZR4xt+JX2qMmUSt2ukUnsz7tiG7Gvjsic=; b=aVB/jTjD+g63+Fl3JNL8pwvnV1fydWVfif8wIsv7fo18n24CQBGDh5Gx6QLvBYaj/1 S7gm2MYhlFLo43A+ng6iauRkIjutN7+cYyeTiPfB0No+tg2PYO1cCbBWzVXcHtotEFGa liFpXye+OYzfnAjOyqCR6Fz2stmNUzYxpi8c/84CCh3YjXldItGbpy1SH4WHvTQ7QLUZ P8y42ai47UehyLPKVt/FrejhEgllpUM6P6zUgWCQ9PI11aK7MKwXyrwfXgEEx0PxT4/r Xga7OeCbq5c2ljvXylM0VXIKM1IpPFf4LyAM/WFaGvUdY+HZ8/z1z+jrCgEOn+1O7ncv fjbg==
MIME-Version: 1.0
X-Received: by 10.66.161.138 with SMTP id xs10mr1559091pab.56.1382593147238; Wed, 23 Oct 2013 22:39:07 -0700 (PDT)
Received: by 10.69.8.5 with HTTP; Wed, 23 Oct 2013 22:39:07 -0700 (PDT)
In-Reply-To: <0C7687D7-CFAF-4122-950D-13DCAC6A3598@iab.org>
References: <CAOW+2dukS-Zye-T9NcWnstSmydpG4YaT6bW_CKh-KYhJQfasUA@mail.gmail.com> <02364CCE-9122-4EC0-A2D8-16C3FE16245F@isoc.org> <0C7687D7-CFAF-4122-950D-13DCAC6A3598@iab.org>
Date: Thu, 24 Oct 2013 06:39:07 +0100
Message-ID: <CADnDZ8_Vor0ksG1Q+PU0QH1O-ViDbziBqNh72bw4eL1T2LCrKA@mail.gmail.com>
Subject: Re: Comments from the IAB on NIST SP 800-90A Proceeding
From: Abdussalam Baryun <abdussalambaryun@gmail.com>
To: "ietf@ietf.org" <ietf@ietf.org>
Content-Type: multipart/alternative; boundary="047d7b86e86468ff9204e9760dc8"
Cc: IAB <iab@iab.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2013 05:39:12 -0000

Hi Russ

The comment has a statement which I am against;
IETF standards depend on NIST standards and the process by which they are
developed.

The statement contradicts the first, that IETF references also other
government algorithms.
Is this a specific or general dependence? And does IETF standards
really depend on NIST standard process and development? Is the
statement talking about all IETF security standards?

Best regards
Abdussalam


On Wednesday, October 23, 2013, IAB Chair wrote:

> Today, the IAB sent comments to the US National Institute for Standards
> and Technology (NIST) in the matter of the NIST Special Publication 800-90A
> (Recommendation for Random Number Generation Using Deterministic Random Bit
> Generators) review proceeding.  In the statement, the IAB supports
> re-opening of the comment period on NIST SP 800-90A, and the IAB also makes
> recommendations relating to the review process for cybersecurity and
> cryptographic standards to enhance transparency and openness.
>
> The full statement is available from the IAB website:
> http://www.iab.org/wp-content/IAB-uploads/2013/10/IAB-NIST-FINAL.pdf
>
> On behalf of the IAB,
>  Russ Housley
>  IAB Chair
>
>