[Lurk] lurk integration with openssl

Daniel Migault <daniel.migault@ericsson.com> Fri, 20 April 2018 18:26 UTC

Return-Path: <mglt.ietf@gmail.com>
X-Original-To: lurk@ietfa.amsl.com
Delivered-To: lurk@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78E56126B72 for <lurk@ietfa.amsl.com>; Fri, 20 Apr 2018 11:26:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0TTLxY2uhSQs for <lurk@ietfa.amsl.com>; Fri, 20 Apr 2018 11:26:30 -0700 (PDT)
Received: from mail-lf0-x22d.google.com (mail-lf0-x22d.google.com [IPv6:2a00:1450:4010:c07::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52EFA127863 for <lurk@ietf.org>; Fri, 20 Apr 2018 11:26:30 -0700 (PDT)
Received: by mail-lf0-x22d.google.com with SMTP id o123-v6so3826828lfe.8 for <lurk@ietf.org>; Fri, 20 Apr 2018 11:26:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:from:date:message-id:subject:to:cc; bh=sqoX+oYjG9IUnzn/kRzq//Ix3KUNtJJZbSPIQC3H2RE=; b=rHvrWcxOHq9yvWZajHgJACPSbAEOSN1/WQ9Lu7Q8gOOm4r2y38/vADxr4MXUXYJeWA zVZG7rDJot+xOvlykXseDpVv3d8L1RxYOAcGJEC7SstF6kXYja2jaHfzKp3/7GLZokyG T4R/64YAXkc/vX25XMsdSvhC7Ip0aVits1ufFGN0QuVMgNGDNIXNOzhz5vsmwnd4NXI3 lisTzsuztcvor5iLZnWbs3LtagBXP6tWEN9SIc5IRtFb9gH2U6IfYh7gAaFvIm4aw9LI 91ovzs+XIXn54ZMe66NnszFOZEAdCyAfjHP9swRML140qENOMfzo+nQsow2HG8hOVK1p ZgMQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:from:date:message-id:subject :to:cc; bh=sqoX+oYjG9IUnzn/kRzq//Ix3KUNtJJZbSPIQC3H2RE=; b=pJYr9+yytd75sTx9ICKT450wGxGZcyMH9VxTZhWnOE1Be8JgDNTyufgByCI6awKcF6 lltYoF/crifqiRkAUHMeIpeiwOPigMJnpUg8hkfDXprrScXjLUp+b+IlPbj+HVkEJlpI oY1UrY6+PAzGD7c+RTD7+LVdfgbCpqaj7tWMR5Ax/SIE6S0iiT5OupchPrRRH1VlcI8N /7mKLoHJC8HcAUaPDRB6gy0a1qdAWLDJXy3h+DKC8QOJE7xShpRr4Dlto3BCs/wmHL65 r2zg6rNvpNNdMLukBQQ42g8SLyMY5KUj8GJXE4nybX1kspHiOEhRchfM/ODLgK/Ira69 /i0g==
X-Gm-Message-State: ALQs6tAuEj6j/vPcLGkTfj9gUP6gAt+kZSBng8/PVVqBDZ3bjXf+Lj4P yUjtDNAwkOPJUPQUeLMZ1ilD7cV6jk4YMkZ9ZVr7ZQ==
X-Google-Smtp-Source: AB8JxZoyncSMHJQcZoA5FeGzDboZIblT3o4UtrITkAZExl/6HkXtJO/qCw8dAng2s6b81rdBJc90l9ULRZzijr2hdO8=
X-Received: by 10.46.153.73 with SMTP id r9mr3307281ljj.7.1524248788595; Fri, 20 Apr 2018 11:26:28 -0700 (PDT)
MIME-Version: 1.0
Sender: mglt.ietf@gmail.com
Received: by 10.46.78.10 with HTTP; Fri, 20 Apr 2018 11:26:27 -0700 (PDT)
From: Daniel Migault <daniel.migault@ericsson.com>
Date: Fri, 20 Apr 2018 14:26:27 -0400
X-Google-Sender-Auth: b-xrt63eLqJZggvIg2_m_9yf850
Message-ID: <CADZyTkmgW89C_hEYbuM2iVRADLGt47q2SMDqbWXMVLiYo9VtSw@mail.gmail.com>
To: Jesús Alberto Polo <ietf@jesusalberto.me>
Cc: LURK BoF <lurk@ietf.org>
Content-Type: multipart/alternative; boundary="883d24f1a9ac97fa9d056a4bd3ca"
Archived-At: <https://mailarchive.ietf.org/arch/msg/lurk/6zjxLuH7D9P98ANU5rGkQLo58Uc>
Subject: [Lurk] lurk integration with openssl
X-BeenThere: lurk@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Limited Use of Remote Keys <lurk.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lurk>, <mailto:lurk-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lurk/>
List-Post: <mailto:lurk@ietf.org>
List-Help: <mailto:lurk-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lurk>, <mailto:lurk-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Apr 2018 18:26:33 -0000

Hi Jesus Alberto,

There have been some discussions regarding the integration of lurk with
openssl during the hackathon, so feel free to share your concerns on the
mailing list.

Here are some links you might find of interest:

https://www.agwa.name/blog/post/protecting_the_openssl_private_key_in_a_separate_process
https://www.agwa.name/blog/post/titus_isolation_techniques_continued

Yours,
Daniel