[jose] OPEN: RSA-OAEP/RSA-PSS default parameters

Karen O'Donoghue <odonoghue@isoc.org> Wed, 24 October 2012 10:36 UTC

Return-Path: <odonoghue@isoc.org>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF06621F8B86 for <jose@ietfa.amsl.com>; Wed, 24 Oct 2012 03:36:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.265
X-Spam-Level:
X-Spam-Status: No, score=-103.265 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i4P6etkGsTNz for <jose@ietfa.amsl.com>; Wed, 24 Oct 2012 03:36:02 -0700 (PDT)
Received: from smtp166.dfw.emailsrvr.com (smtp166.dfw.emailsrvr.com [67.192.241.166]) by ietfa.amsl.com (Postfix) with ESMTP id 37CFF21F8A6A for <jose@ietf.org>; Wed, 24 Oct 2012 03:36:02 -0700 (PDT)
Received: from localhost (localhost.localdomain [127.0.0.1]) by smtp6.relay.dfw1a.emailsrvr.com (SMTP Server) with ESMTP id C7D92270871 for <jose@ietf.org>; Wed, 24 Oct 2012 06:36:01 -0400 (EDT)
X-Virus-Scanned: OK
Received: by smtp6.relay.dfw1a.emailsrvr.com (Authenticated sender: odonoghue-AT-isoc.org) with ESMTPSA id 3EFAB27087A for <jose@ietf.org>; Wed, 24 Oct 2012 06:36:01 -0400 (EDT)
Message-ID: <5087C490.1000706@isoc.org>
Date: Wed, 24 Oct 2012 06:36:00 -0400
From: Karen O'Donoghue <odonoghue@isoc.org>
Organization: ISOC
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:16.0) Gecko/20121010 Thunderbird/16.0.1
MIME-Version: 1.0
To: jose@ietf.org
References: <4E1F6AAD24975D4BA5B168042967394366877956@TK5EX14MBXC285.redmond.corp.microsoft.com>
In-Reply-To: <4E1F6AAD24975D4BA5B168042967394366877956@TK5EX14MBXC285.redmond.corp.microsoft.com>
X-Forwarded-Message-Id: <4E1F6AAD24975D4BA5B168042967394366877956@TK5EX14MBXC285.redmond.corp.microsoft.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: [jose] OPEN: RSA-OAEP/RSA-PSS default parameters
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: odonoghue@isoc.org
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Oct 2012 10:36:02 -0000

Folks,

The results of this poll were:
7 YES - SHA1 (and mgf1SHA1) should be the default parameters for these algorithms
2 NO - SHA1 (and mgf1SHA1) should not be the default parameters for these algorithms
4 DISCUSS - More discussion is needed

Based upon these results, I do not believe that a reasonable consensus call is possible
yet. This issue remains open. Please comment on the mailing list and be prepared to finalize
resolution in Atlanta. Thanks to all who participated in this poll.


Thanks to all who participated in this poll.

Karen O'Donoghue (writing as working group co-chair)

-----Original Message-----
From: jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] On Behalf Of Karen O'Donoghue
Sent: Wednesday, August 29, 2012 2:30 PM
To: jose@ietf.org
Subject: [jose] (REDO) POLL: RSA-OAEP/RSA-PSS default parameters

Folks,

Given the confusion around the original version of this poll, I'd like to try again.

The basic question is unchanged, the room count from Vancouver has been corrected, and a clarification regarding the status of SHA1 in the OAEP specification has been added.  For those of you who voted and feel you may have misunderstood the question or voted incorrectly, please feel free to update your answer.

Question:
Should SHA1 (and mgf1SHA1) be the default parameters for these algorithms?
Note:  These are the default parameters specified in RFC 3447, Section A.2.1, and are widely deployed.

Room vote:  5 yes, 0 no, 3 discuss

Thanks,
Karen
_______________________________________________
jose mailing list
jose@ietf.org
https://www.ietf.org/mailman/listinfo/jose