Re: New 12288 and 16384 bit groups

Trevor Perrin <trevp@trevp.net> Mon, 17 March 2003 22:25 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA04828 for <ipsec-archive@lists.ietf.org>; Mon, 17 Mar 2003 17:25:56 -0500 (EST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id PAA10833 Mon, 17 Mar 2003 15:22:41 -0500 (EST)
Message-Id: <5.2.0.9.0.20030317121818.00bbbc38@postoffice.pacbell.net>
X-Sender: trevp@postoffice.pacbell.net
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Mon, 17 Mar 2003 12:26:26 -0800
To: ipsec@lists.tislabs.com
From: Trevor Perrin <trevp@trevp.net>
Subject: Re: New 12288 and 16384 bit groups
In-Reply-To: <20030317090840.GF24659@apb.cequrux.com>
References: <15987.33466.200314.637791@tero.kivinen.iki.fi> <5.2.0.9.0.20030313161341.02e2bd30@postoffice.pacbell.net> <15987.33466.200314.637791@tero.kivinen.iki.fi>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

At 11:08 AM 3/17/2003 +0200, Alan Barrett wrote:

>On Sat, 15 Mar 2003, Tero Kivinen wrote:
> > All the groups in the draft-ietf-ipsec-ike-modp-groups-05 are proven
> > to be safe primes (i.e both the p and the (p - 1) / 2 are proven to be
> > prime). The ECPP/primo certificates can be found at
> > http://ftp.ssh.com/pub/ietf/ecpp-certificates/ (that url used to be in
> > the draft, but was removed because url's are not stable enough to be
> > used as references (that url is going to be stable :-)).
>
>Perhaps the IANA or the RFC Editor (or both) would be willing to keep
>stable copies of supporting documentation that's too large (or otherwise
>inconvenient) for inclusion in an RFC.
>
>If so, then I'd suggest keeping the "ftp.ssh.com" URL in the draft, with a
>note saying that it should be changed to an "iana.org" or "rfc-editor.org"
>URL before publication as an RFC.

And even if not, maybe the draft could have a note that the primes are 
proven to be safe primes, and that certificates do exist (and if there was 
a website with links to them, with keywords like "IKE primes" and "ECPP 
certificates", they'd turn up on google easily enough)..

Trevor