Re: [kitten] New EncTypes?

Benjamin Kaduk <kaduk@MIT.EDU> Thu, 19 November 2015 02:39 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C78341B3BB0 for <kitten@ietfa.amsl.com>; Wed, 18 Nov 2015 18:39:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.786
X-Spam-Level:
X-Spam-Status: No, score=-4.786 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.585, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vuOdRCSZJKbc for <kitten@ietfa.amsl.com>; Wed, 18 Nov 2015 18:39:12 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D9B571B3BAF for <kitten@ietf.org>; Wed, 18 Nov 2015 18:39:11 -0800 (PST)
X-AuditID: 12074424-f79216d00000156e-4f-564d364d5ffb
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 3C.E6.05486.D463D465; Wed, 18 Nov 2015 21:39:09 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id tAJ2d9WR013570; Wed, 18 Nov 2015 21:39:09 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id tAJ2d5TE026486 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 18 Nov 2015 21:39:08 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id tAJ2d5OR009225; Wed, 18 Nov 2015 21:39:05 -0500 (EST)
Date: Wed, 18 Nov 2015 21:39:05 -0500
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "Henry B (Hank) Hotz, CISSP" <hbhotz@oxy.edu>
In-Reply-To: <FEF7E228-3AF4-4D12-B4B0-CFB935B5ABB5@oxy.edu>
Message-ID: <alpine.GSO.1.10.1511182134350.26829@multics.mit.edu>
References: <FEF7E228-3AF4-4D12-B4B0-CFB935B5ABB5@oxy.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-1880486494-1447900745=:26829"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmpmleLIzCtJLcpLzFFi42IR4hTV1vU18w0zuHTa2OLjvYUsFkc3r2Jx YPJYsuQnk8fWpr/MAUxRXDYpqTmZZalF+nYJXBnnV1xiKrjKX3H+5zKmBsYvPF2MnBwSAiYS z7a0skPYYhIX7q1n62Lk4hASWMwkMbf7AiuEs5FRYvH9B4wgVUICh5gkbqxJhUg0MEocu9rN BJJgEdCWeHN9JzOIzSagIjHzzUY2EFtEwFBi+sqJrCA2s4ClxN5FP4HqOTiEBZQlXnxTAglz ClhLnGrYwQYS5hVwlFjwKAlilZXE96uHwKaICuhIrN4/hQXE5hUQlDg58wkLxMRAiZvHVzBP YBSchSQ1C0kKwlaXaHxwlg3C1pa4f7ONbQEjyypG2ZTcKt3cxMyc4tRk3eLkxLy81CJdc73c zBK91JTSTYygsGZ3UdnB2HxI6RCjAAejEg/vhlM+YUKsiWXFlbmHGCU5mJREeXvOAYX4kvJT KjMSizPii0pzUosPMUpwMCuJ8JZdAsrxpiRWVqUW5cOkpDlYlMR5N/3gCxESSE8sSc1OTS1I LYLJynBwKEnwupj6hgkJFqWmp1akZeaUIKSZODhBhvMADX9jAlTDW1yQmFucmQ6RP8WoKCXO +00dKCEAksgozYPrBaed3UyqrxjFgV4R5k0FWcEDTFlw3a+ABjMBDT7R4AkyuCQRISXVwMiz KuepwvxynYw+qYZHE95FzDZ+FZEumqz9Xz5sb/JyX4MQyaKmkt1z38bvurcu4PosxqiNhVcF j+rkS7xWPT/luYbIBDatGUYMTvvtGKVXH8oO50ucw9NxU3R/Y7Ko2LRH/sFfNs9931Ugnfmi d92NvLc/8rXvi7etNtBdX72Tyz/mIM8xDyWW4oxEQy3mouJEAIlbljcWAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/sfNeWJK8lfZgDKccnbU0yBg5vlM>
Cc: "kitten@ietf.org <kitten@ietf.org>" <kitten@ietf.org>
Subject: Re: [kitten] New EncTypes?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Nov 2015 02:39:14 -0000

On Wed, 18 Nov 2015, Henry B (Hank) Hotz, CISSP wrote:

> It seems to be time to do housecleaning on algorithms selections. Is anyone interested in adding a new enctype to Kerberos?
>
> Why (else)?  Speaking strictly for myself, I’d like to see a
> mandatory-to-implement enctype that shares *nothing* with the current
> aes-sha1-hmac stuff. I’m speaking purely strategically and not from any
> mathematical suspicion of weakness. If someone discovers something
> fundamentally wrong with the math behind SHA1 or AES, then it might take
> out SHA2 or Camellia as well.
>
> I have nothing specific against the “suite-B” proposal, but they’re not
> what I’d like to see. I assume the NSA is too busy riding the “post
> quantum” horse away from their DRBG fiasco to help finish it.
>
> Just to throw some straw (just straw, not an actual strawman) on the
> table, how about something that uses one of the European stream cipher
> finalists with SHA-3?

I had heard mutterings elsewhere about a chacha20-poly1305 sort of thing,
which seems potentially interesting to me.  The real question is whether
implementors would pick up such a thing, and whether we can get consensus
for MTI.

There are public commitments to funding at least one implementation of the
aes-cts-hmac-sha2 proposal, but I don't think I've heard anything one way
or the other about a completely novel enctype.


> Finally, is anyone interested in doing a die-die-die draft for triple-des, or rc4?

There is already
https://tools.ietf.org/html/draft-kaduk-kitten-des-des-des-die-die-die-00

-Ben