Re: [IPsec] I-D Action: draft-ietf-ipsecme-safecurves-01.txt

Yoav Nir <ynir.ietf@gmail.com> Mon, 01 February 2016 23:26 UTC

Return-Path: <ynir.ietf@gmail.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 257341B389F for <ipsec@ietfa.amsl.com>; Mon, 1 Feb 2016 15:26:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uM-L5bflICET for <ipsec@ietfa.amsl.com>; Mon, 1 Feb 2016 15:26:26 -0800 (PST)
Received: from mail-wm0-x22d.google.com (mail-wm0-x22d.google.com [IPv6:2a00:1450:400c:c09::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 833581B3891 for <ipsec@ietf.org>; Mon, 1 Feb 2016 15:26:26 -0800 (PST)
Received: by mail-wm0-x22d.google.com with SMTP id l66so93019602wml.0 for <ipsec@ietf.org>; Mon, 01 Feb 2016 15:26:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=+nMXW29Lb3TJ/fNTh2YiXvvWXsoPBX/jwpr2FvZ7f8E=; b=XNo9+dBl4pEkOMbFrkaVN0xHWeN6iUpL2SyRgJ1UzjtNrQ9khBcegwdmxgso5BpLjt rvuuSSb44NmeuhuUsB0+QIiBBX21UTJjSXr/Vu6ywIIcjfZJEBowYyWUUfuq+KzC5NgM RLY5de8DU/6lsw5KZecP9BXn6XxRmqUu+PzqtdJONS8nES7IM3iapk6ojerPjyyY6cmP RPMhVE5jgAmuHxEgpAbwD0caEW8UQV04xppy7hqUNMUQpDjCSLKmWrYFWmy/GmtWuLz8 az9eorb3rtaqDWUr107eVY8531cKUDt+H2mILlF6QSdgfMKCudOti+s6zOiTqH/oVfHj 4n4w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=+nMXW29Lb3TJ/fNTh2YiXvvWXsoPBX/jwpr2FvZ7f8E=; b=ZIxG7zsG/JpE/H8UX0s1K0HHTB3lRyyp+9syUObEEutusXpGPOnuuaUYAKp6DqsaoF gjRej2YXg7ER0TK+0llfj/UlJFDJdJ6Gx2YtzjUazEiS3rCDY+CVoaiYM+bI8rCRuqUA KXtjVF7konHrAjRYXfdKMplnMk2EBiX3vAsqR1Kcn9gtt58UYThNH7nZWHWZqXb6UguW 27g1SrobzOlYr3Z/UzJb5U+i8OnSXGpppIHtLioh8tZP9oS19f/hrvvxUEMvlgDr41VP bOWRG0OShShmf08dIdmbKWm7gov7QPy+5Sc1yXEXZWMT+VCr3nrw7cnhkpM4t4dAKiH6 KINg==
X-Gm-Message-State: AG10YOQ2D0ZxushBPEFMHavRY74dQrrXpbC1TWae2IyWVVdrbfit/bNvjo53ZUtLDjfdGQ==
X-Received: by 10.194.83.136 with SMTP id q8mr24888288wjy.51.1454369185157; Mon, 01 Feb 2016 15:26:25 -0800 (PST)
Received: from [192.168.1.13] ([46.120.13.132]) by smtp.gmail.com with ESMTPSA id t195sm13752069wme.13.2016.02.01.15.26.23 (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Mon, 01 Feb 2016 15:26:23 -0800 (PST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
From: Yoav Nir <ynir.ietf@gmail.com>
In-Reply-To: <20160201231846.14339.27829.idtracker@ietfa.amsl.com>
Date: Tue, 02 Feb 2016 01:26:22 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <994E9F5F-AA8A-49B9-9B1F-CB9F11CD004F@gmail.com>
References: <20160201231846.14339.27829.idtracker@ietfa.amsl.com>
To: "ipsec@ietf.org WG" <ipsec@ietf.org>
X-Mailer: Apple Mail (2.3112)
Archived-At: <http://mailarchive.ietf.org/arch/msg/ipsec/hQaSkDdHXpznVgwaAsFGnMHxSJ4>
Cc: Simon Josefsson <simon@josefsson.org>
Subject: Re: [IPsec] I-D Action: draft-ietf-ipsecme-safecurves-01.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2016 23:26:33 -0000

Hi.

Differences in this version:
 - Changed the reference from CFRG draft to RFC 7748
 - A few editorial fixes

The analogous TLS draft (draft-ietf-tls-rfc4492bis) is still waiting for CFRG to complete its work on signatures. 

In my opinion, we don’t have to wait. The CFRG EdDSA draft will provide formats and OIDs (I hope). RFC 7427 allows us to use signatures with only an OID and a format without needing to assign numbers or invent IKE-specific formats. We might want to mention the recommended algorithm (Ed25519 and Ed448, but not the “ph” versions) in RFC 4307bis, but I don’t think we need it here.

Given this, I think it could be time to progress this draft.

Yoav

> On 2 Feb 2016, at 1:18 AM, internet-drafts@ietf.org wrote:
> 
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the IP Security Maintenance and Extensions Working Group of the IETF.
> 
>        Title           : Curve25519 and Curve448 for IKEv2 Key Agreement
>        Authors         : Yoav Nir
>                          Simon Josefsson
> 	Filename        : draft-ietf-ipsecme-safecurves-01.txt
> 	Pages           : 5
> 	Date            : 2016-02-01
> 
> Abstract:
>   This document describes the use of Curve25519 and Curve448 for
>   ephemeral key exchange in the Internet Key Exchange (IKEv2) protocol.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-ipsecme-safecurves/
> 
> There's also a htmlized version available at:
> https://tools.ietf.org/html/draft-ietf-ipsecme-safecurves-01
> 
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-ipsecme-safecurves-01
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec