Re: [openpgp] Virtual interim moved to early February 2023 (new poll)

Aron Wussler <aron@wussler.it> Tue, 17 January 2023 15:55 UTC

Return-Path: <aron@wussler.it>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8957AC151701 for <openpgp@ietfa.amsl.com>; Tue, 17 Jan 2023 07:55:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wussler.it
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XPKCLzI0geo7 for <openpgp@ietfa.amsl.com>; Tue, 17 Jan 2023 07:55:24 -0800 (PST)
Received: from mail-4018.proton.ch (mail-4018.proton.ch [185.70.40.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F499C151716 for <openpgp@ietf.org>; Tue, 17 Jan 2023 07:55:23 -0800 (PST)
Date: Tue, 17 Jan 2023 15:55:04 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wussler.it; s=protonmail; t=1673970920; x=1674230120; bh=vMRUujL8+LSvWJxLRBCxneVC8rC+R8liQ5pA84XrqKM=; h=Date:To:From:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=CR3MEn8Fv+rh59W3IVhj+VOvBSzArnjleFo4b4J7zx8bD9NvA2jF838OsOXCG5tO6 3fiS51YS0KE9CgcZwnopsV8itXaPda9VvpCLJV8ByfOOoz1SD9em4wm0F9mZ1DVGXk MTxP0+QnEbiWgB7KpgurcJbI+jjEj5XY8UxrUsG5VP4VLrfohng09X7gBHWlvOFUfD zn8DF54VhPQ+szgeOHOOHiNj2fCKn0vZl/honez2ssdPkVoK5Ffkkxud1w5lXQmR0j Bb49wQk+uZ+Qtu7VIloEihodpreNybMOLTOjEXqcVpXXY7lC91V/osG1i9Tn6B/Wrm UWuxOekLuR/PA==
To: "openpgp@ietf.org" <openpgp@ietf.org>
From: Aron Wussler <aron@wussler.it>
Message-ID: <23Vh7_iHjaGb78WI9X6iSwSisyxhzZ5UiuzJkBHLWrTmBcbB5l46SgEdOkrNhPxE-kuaDkr0VmUC_90AIk3mpmXnoO0ZVkgDLq0TW4oVTAE=@wussler.it>
In-Reply-To: <874jsq6v1c.fsf@fifthhorseman.net>
References: <87edsp4qr4.fsf@fifthhorseman.net> <_r2BYn9nVeZoeorKTcnPxvn9IM694HW7PLo9Xkr7wk6ICZerqNQzyKDHLvSL9Bo_7uPIGTMWcyXory1MELfBgyoj2DckGfbl3o8WS4V9dAs=@wussler.it> <87ilh67cvh.fsf@fifthhorseman.net> <874jsq6v1c.fsf@fifthhorseman.net>
Feedback-ID: 10883271:user:proton
MIME-Version: 1.0
Content-Type: multipart/signed; protocol="application/pgp-signature"; micalg="pgp-sha512"; boundary="------f0484ba9b8a1534ae2d9a507b987e60e576c7f62135a5f2d3193ab8575c1bdbe"; charset="utf-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/2ARmtv3UNcP3YtNGKP4XxHtXX2w>
Subject: Re: [openpgp] Virtual interim moved to early February 2023 (new poll)
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jan 2023 15:55:29 -0000

Hi all,

Thank you for organizing this meeting.

Unfortunately, I can't promise I will be able to attend this date, as I will have very poor connectivity until Feb 19th.

I'll prepare here a recap of the issues that I raised on the list (and turned into PRs) that are still open, with some comments about them:

- [!216] fixes a reference, and is just cosmetic.

- [!219] binds the salt size to the signature hash. I know it's time to get things done rather than proposing changes, but this will bite us back if we'd like to introduce it later with PQ. I agree with Justus that an octet size is indeed important there if we want to have it variable, and this is not present in the current format.

- [!222] introduces a non-revoking "superseded-by" signature. I really care about this one, and I think it's a great way forward to tackle v4/v5 migration. I know DKG is not the biggest fan of fingerprints, but it would directly address [!64].

- [!223] removes the padding for v5 ECDH, since a checksum is already included in the wrapping. This was born out of curiosity when asking why is that checksum needed on the list. I tried implementing it, and don't think it's necessary. It adds non-trivial complexity to the code because of version handling, and we'll survive encrypting one block of AES too much.

- [!224] fixes repeated bytes in the test vectors. If you decode the armoured ciphertext below you'll see that this is just a mistake.

Looking forward to get this crypto-refresh out!

Cheers,
Aron

And for the very creative links:
[!64] https://gitlab.com/openpgp-wg/rfc4880bis/-/issues/64
[!216] https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/216
[!219] https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/219
[!222] https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/222
[!223] https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/223
[!224] https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/224

--
Aron Wussler
Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930



------- Original Message -------
On Monday, January 16th, 2023 at 22:15, Daniel Kahn Gillmor <dkg@fifthhorseman.net> wrote:


> Hey folks--
> 

> On Mon 2023-01-16 09:49:54 -0500, Daniel Kahn Gillmor wrote:
> 

> > Thursday, Jan 19th at 14:00 UTC
> 

> 

> I take it back. This proposed interim is far too close to "now" to be
> fair to folks who are looking for an event formally scheduled well in
> advance.
> 

> This is my own fault for falling behind on following up for the poll
> during the holidays.
> 

> If we want a virtual interim, we should have a set date at least two
> weeks in advance, so i am setting up another poll for the first full
> week of February. Stephen or I will report the conclusion of the poll
> by the end of Friday, this week (Jan 20th), so please respond as soon as
> possible.
> 

> https://framadate.org/8TXl8RWamaLeAWD6
> 

> Apologies for the whiplash,
> 

> --dkg
> _______________________________________________
> openpgp mailing list
> openpgp@ietf.org
> https://www.ietf.org/mailman/listinfo/openpgp