Re: [openpgp] Default preferences for the future

"Mark D. Baushke" <mdb@juniper.net> Tue, 21 March 2017 18:03 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 114F9129C5D for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 11:03:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8fP9A1IDBWI6 for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 11:03:04 -0700 (PDT)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0113.outbound.protection.outlook.com [104.47.32.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD213129C5E for <openpgp@ietf.org>; Tue, 21 Mar 2017 11:03:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Ze25erh/37JzLtJBn9SEOOsBZ4ECQAAhiC2TKRcnaCc=; b=DQdVOraNkawo+jSHhSxrqsuVOO8Oat5csdejSD3m7pNNTdnJoQTXbU3ZARixD0nJU8RmN07U68Z4X0iw+7KqWGU1cIvs2IO0irupxDIsrYFgfwR+GDVjyH8HvkXNiozkRqW+6fRjkRZjXRkVt0L7Zun3H7F2PLbjef6wwkt6KiQ=
Received: from BY2PR05CA022.namprd05.prod.outlook.com (10.141.250.12) by SN1PR0501MB1757.namprd05.prod.outlook.com (10.163.130.24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4; Tue, 21 Mar 2017 18:03:02 +0000
Received: from BN1AFFO11FD034.protection.gbl (2a01:111:f400:7c10::128) by BY2PR05CA022.outlook.office365.com (2a01:111:e400:2c5f::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4 via Frontend Transport; Tue, 21 Mar 2017 18:03:02 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; addere.ch; dkim=none (message not signed) header.d=none;addere.ch; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BN1AFFO11FD034.mail.protection.outlook.com (10.58.52.158) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.977.7 via Frontend Transport; Tue, 21 Mar 2017 18:03:01 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 21 Mar 2017 11:03:00 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v2LI2xfx028536; Tue, 21 Mar 2017 11:02:59 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id B20EE11446; Tue, 21 Mar 2017 11:02:57 -0700 (PDT)
To: "Robert J. Hansen" <rjh@sixdemonbag.org>
CC: openpgp@ietf.org, 'Ryru' <ryru@addere.ch>
In-Reply-To: <00c101d2a269$056003d0$10200b70$@sixdemonbag.org>
References: <3b89c96a-0bb6-cd09-cbf7-1f9e26f04bd6@addere.ch> <52027.1490051694@eng-mail01.juniper.net> <87pohbm5or.fsf@wheatstone.g10code.de> <78804.1490102455@eng-mail01.juniper.net> <00a901d2a24b$3f1d7df0$bd5879d0$@sixdemonbag.org> <11503.1490111087@eng-mail01.juniper.net> <00c101d2a269$056003d0$10200b70$@sixdemonbag.org>
Comments: In-reply-to: "Robert J. Hansen" <rjh@sixdemonbag.org> message dated "Tue, 21 Mar 2017 13:31:47 -0400."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.6; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk, }4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Tue, 21 Mar 2017 11:02:57 -0700
Message-ID: <28290.1490119377@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.18; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39860400002)(39850400002)(39410400002)(39840400002)(39450400003)(2980300002)(189002)(199003)(9170700003)(38730400002)(110136004)(305945005)(6266002)(47776003)(6392003)(7126002)(50466002)(50986999)(356003)(5003940100001)(77096006)(76176999)(2906002)(229853002)(53936002)(7846003)(106466001)(53416004)(2950100002)(117636001)(7696004)(93886004)(6246003)(50226002)(5660300001)(8936002)(81166006)(8676002)(2810700001)(189998001)(76506005)(55016002)(54906002)(48376002)(4326008)(86362001)(6916009)(105596002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR0501MB1757; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; MLV:sfv; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BN1AFFO11FD034; 1:uvpzSDC6Cmv95gF3qnHcKP5zqmho8ht2dXr/3HQkdSDiiy95edk7w3rFvsVaCv3JCiEXmtm8OoWfdl1ZdUJDOPe5bhrhGyE4lez122zs54MuEzdQwgzS49uURA9EqOcqtW4vq3C4w9O3d/0crxJ4N99Avj70QQNttX86sJj2LuE/1brjU7vmruQriV0s7rZ71bBhc0n8Ei3kh+PD6QoQqP2jD87gc/7feHhjcHxhmBuKYFFkwO1uMCMFejetf7HyEojq3imb07AhFygtGiy9Uf2AZpG2mngS9H7H0fs0o/zBgIJOzJIJKhZmRNBrwnTMbvRlUN426iPA9VZFzc7IVXGriaxDXV/46y53PAA0qi0PpGjwlWeZDxxPOWKOZZl9xV1GZ6VRmZzcAG3L+dLacJwMxX2TWucP4pgtQRdW5E/vjwf0WDkWkqfVqB25qZp2fawyyTHtGwJNfERiyfyT6jP284m+xRrs2CMUPPO3FErTARz/E0Uy0NiBRyf2L/iq3RBmae21M1sfU4wr6HlP9Br8hsBKvmD3Z7M2c4yKWzlv1VmArBzzMY/xcTC5+wuwUotkvgDDM4HjMHcJh8cjyQ==
X-MS-Office365-Filtering-Correlation-Id: 5fcd5ef8-dbd0-40bf-147f-08d470848426
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075); SRVR:SN1PR0501MB1757;
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 3:EaSJoKnB7FHkoYab419Q6chvbfQCoDXq5SL4NU807XEBLuAkIuZz7Jois6p+fPGj2PrcavGpOwUAlA8QL/SiefJkWgjoOp0T00lHUFhBb08GUK5uGbDtxlR10A3thFMbZTxhGXdVePA4OMMLsz6Bs80ZHsGK2a33Nrf3UUn/NOTn9LhyarO9WJ+VeveYUH06kA4rmIRTxXasCEjP1DoKcIyc/73vdi9ctT4x7rOjwJCbu5IzurvA834Ad1BjGjqx82t4u2UAt8w+gf1LUjnkZW7E60Y7a40+yn36MgewvcOLD0aNvsBLX32rD68ig0VIpDGT1tULUiKPxBoGGbopJHCdkr64MUg9xoSU06gW0PeEVJTYIhr/lKswTQ7pcXtn3vSiJkZ/cvW2Pm7ZWT9Idg==; 25:ri1CXPAEIylOm0QtBLDYwqR1l5mHFaaqcSROLRKa/XB6zF1eSzvXjsKKYHbbVYWNZs7LKsAhRpV1Qwb1CUwWVQBply4/7ZwjFKP20PhLip16CTtKtlxFYyEziDwDnLgBDuz9ob5psIkaYaFAXeQiGyvybHyv06//0kmHrjkkzsD1NXnyRk7A0YbGY3lRqluadXYLNQQraz+f98NNKQW6UsMViVHchuGLhN/aX4HfFONlj0qX6aPEGBULhn4kIl1IMLlxzj3l9hHEYc8AysNXt7iYHGdLgBNIOazBKj3lNoZ+KtYh5KUrMciES7D4RtuDMz0fdkjD0kxpXXnZidU72OOWne7sGlGCTtrZ7vAGgNh09Svry7D5Iyf0gcw58jGbE6pIdwwEGScYYQG+YlP4EMRcXZYC1FFDg/djY6dPbh9T8wI1SHPX2gol+MQR2fy4dhMZ25JcV2a6BnHmDWBWFQ==
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 31:aAPIPK0oYmNCVSjNyoPDR+gCNbyyB6J1tVGI3+ULN5BD+1dKCyTUephp/PpGu8IsYkzN4xhEqh189rS3OicihoTwGid0W2RgZ18xpzH2SgGPTe8DRAAiU91SZZxojKlSS0vbILJlIQiFhdnQBkQraTTCCgiX7UAh34wUakWpBqBVHcHjkbYgDDNyJcRdbJg21M7KbAmJEDhzsWRCEaV2YqjYFtjOk7qcedAStRllui1q1B47DTah8Fwx2rfolX12V0a/diJkzMOiF3N7Ts2YBA==; 20:/91bG3hY4F4fZPp3Gt/YDBflvX0H5dzxy+GReUqMtYJ+tyZJeG7f1VliJLJZDXGaVgJBS/mxnxmwZVr5dgL4XOCRGszKE4P3qIo6HNwDT/0i6zmetF25/V4lyaQ1LpS0ur0cbvzF3BOpQCYMbOYFiSgDQniLxD4SsSxXJo0cD0m3eIIyCMAL0Q/hnXS8TQFZH2JDopzPiHakr914Z2NNGEF0iP3ZOP0V+04x9ALYH0RxLEVLDkFNCnre7Cx0cprnCsE1HBXgQE2ILEkAuGlyjWaFng6pV/tIALRIUmkWbbOtgMEBsiCrHbBUihAFzExYBVtvatGt2x/JBuI8pVmv0Uj+9haftuqCrpK4yoKtADI4fayi7ZObYemXvD00ilipW05KX+9046GuPaXUEatKM6mk1kicrAm+EFGX4Mxr+okuKejxwRNc5IT9iR03sqdGpNI3OqZA6a80ghQ9mCVkpf/plI7wxqJlbRlgrJ3ZUOrMEY7oWPTDti72lMmryx87
X-Microsoft-Antispam-PRVS: <SN1PR0501MB1757934945CB3F410819924ABF3D0@SN1PR0501MB1757.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(13015025)(5005006)(13017025)(13018025)(13023025)(13024025)(10201501046)(3002001)(6055026)(6041248)(20161123560025)(20161123562025)(20161123555025)(20161123558025)(20161123564025)(6072148); SRVR:SN1PR0501MB1757; BCL:0; PCL:0; RULEID:; SRVR:SN1PR0501MB1757;
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 4:3ppzV8JbByxKpkDr5jxa0FtBbvIjhNZMYXBctURmrGrvOkw+kKIzpivLpCM4l3S4Z3C7/6d3k12r/vsmgb68JZ2wfmjN+zRK+7S1gx3eOjqTHurN08M8vveskVQFuDeLZ9zjHNnvq2jV2JxwEXpJg63fGFVRFzfK0C2ylffY1XwSi5f5G2t2Wz++/rE42sM9DjWHwJIDcT17kmsAF5kP/GDoW8rMSmwtk1//gU6w3KMoA5nQrhL2XvTx2rRTKip9qOXuMRMUeaM7bCGTTES1OxsM68o1ThifImQSTFNIDcuXvDwlM7+Jrx8VxsN1T6gbMPGcjiGzii8SJqhxpj9ANHvx8hMaJivXx52jTvx4dJ+j8rF+82fL+ErDaOa91lYXatx7iqIAzFq1yAZ2YSvFBD2of160Y1ZpLBWPI646aZ6LX1KAJTZZn2KvcFj6T9ZL1J15GlkdniZChfNrT3Cjj9i0FF6uEIz22jpYlYQU10GOCoNsTp07/PKMnowN2f/NfG6bhXYndNjeztso539G4hNhU/Avv1WuvtE+tgPspuPVgDp9pGSPXU60eOi6t1zLP9XwQnoRrHfDBudd8q5HvgtvTaeBN12oRjiM1fB6jqNT3dDndPLRH6cWahBhXhF+Bn5riXlAPRapgKiwhZ07lTaesExWWRgEUo+qkVqWtyA8hlMKjtk9I1lGRNcBhUR2xcJCKsTUlfeeLlBMImV7Qg==
X-Forefront-PRVS: 02530BD3AA
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 23:AM9HoLCLs9pZxRzGOYzy1AVJ5B1LOQeS3VFCyE+2e0YjIALp1ikFQRh4mObGJ7T8gfcdjQop243g2HCK9+QMfkSbmx5uVIq9pteFWj0HC6pGE1CS5jOj969kZVGEZ1u3CXENWalboNamL0ZBLtupPV86FNyjeMf1DZupIZiswPkRebYI1aBhoSvkHUiIbTtlxLcT67Jea8dxzI/ilEE1ha/Vtuzuew8vKiR7QnXEkq1zCSq15zfAwkMGbTkSVRxjuKd9ywiM8cragmmNbp+RO7ZJtUCSbgy2GQhVqvDAHFvaXOdkGtEA5iRso/nI9NHIcBqtSsHlOlsYj/n3NKs6jtU8HbHrOUFj+Cmo0A6bm1rAnS2nx3UqYv1vRX9WZGlrCuoGT2fOPg0UasCzIyXGHNe3N3mBTWQNP3IG4QOJxlQkxD/lEQh3/7aFzwxfmtbNvNrGC1gV1sT+UqNzDbFFaxYp+8ClyScuy3Lyu6VzOn1yIHZZ0WNIWu55JAbaNFS/gNrrJZARPMbw8If6jJ3Ybi2h0RwdUuJzyKkTHHhxuJE3qFtr5CrYQ5/zxLPW0cTN3ZZi4DGZF0+G9LGAclHE23mjJYuEP2qqN6xJk4VxUgah+07xitdmsIx+DIysfrMbM6PlLyNkp8whsSwlabqVJxV6tcokIEcuqFM0Lv0geWxlO+xs31YM/YqXPM3DWwvvPVSsvQFjvAUEl1EjJiMh/MeegwORrqF1A7xYCklsscU96tPdgUOHozjsZ1A2J2PDUcOT4KvkAsYWTTjx4aym/KuTEglLQcJYvv3srQh8jH1smiYCCB3pOhfhhSrQBreUkPJaEhSGhAESZsFRgjMyEx40ZNNGTxxP6qteRnCz3qJ+klkxbuxuDy+o0OfJgpXmPpHf7wgF9CEpPb6FXJwmWp/q/XxRCvIe9fyeyseeGRmeKlDC3OILEigqmb75YDPSIFPMeEsP6U5M5XuvhEW0c3Iz+YshAw4VhFGRrbpfG04ZVjZQ6+upseg46PFSlWMUutpEIRxRLnMqAVQYHKt/BPT1SkfFzv22Zrr08DlzQQMGn1MDDPawm5zHbMakRDZ2VmsmlwGMq7DQdR18IUqaP8WrTvVPO2bVLMYBjYxvi1UwrJZl1je6wYA7zonp9z2rAPE13EyEx25mHMusd8SWrw73vmKncrAyQOdSJ70qqJcUWxj+38a47ZQvAehNbrbBLhvtlBL/W6OuagxzVR69Zg==
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 6:5y7Vd/CSfzsLJinEBb8gyFzAOtW52ZdC3mTu10F37ucNQY/G60QJSJIbmdepEvS8j0+DUGOXT5R6FNK35KhBxvXJhWhgver/knImFsak7Ws6+e/dR1DDUxSMDrQFc/MP7Z+Qw9yfq60kR12+tVV3gTCQc//CiGNYV4Cm53mID6CgNIPR1pkrHW8a/qHk70xvyY5HM2M4w2RtIMTrxvkswIXvlVfgumGowEddy6nuMQe2m0ml+51GclbvH18MZdqsAQLRhP2l006NlEtvY37JEaMT9PQseg/k3iedjOlFoTcaHEQPJYB9LC3LKm7jm2+Zbl+RIbwqmsolqAB/Q3AvDauAk8okS4Qgo0lCW+ybSq6VblYrjnTrEfih4lMtJaXGpEYKjdys+JhiN4/6c8i3cmpcwn5NuuXpPoa4uSe/jIU=; 5:mpLw3eeZcP3jxMze8CWxZBJB2Rb2mc3tMQ4pochf+mXannNJQ5ORrFNYG0otUOj76wqNUq3Zcm1VWJvd0OUDZNK2gOeryWpAMsxk+wmiiy+CgftjrdRrUkKpYkxjbq4BB3VtlXkqCBLOGqA1Qn5RSQ==; 24:B5lcgYS5oaiqZ0RoeUvV//Ur45dg0/WihDDCxeLjnvbqPj7LfzIbpBR+pC+7A09WJ3QXxZLx98Rh1jxoTkyqwaYzuXbVh3fbdLqwhO7Akbg=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB1757; 7:ohjQfwD96CHLVJFS4+LnIvHMcQ5xQZkMHUlujY/OOEPaX8ZLFznGOVP7JBA9wrxRrbyU1fWRyjV6H0nCkTckWGX5H6WeppbaHcWEYXET7crZDR+oFzuojjkpd2Gy9oGX8LIN5hKQCEBm5+fLwBU0wmcdYa27/X8GL/vVOvBcbvQ9lzU66RN/oXV5WMj6vSEVrmzruVO6uTJ9vGJgYAVewoU/tCWcYyUQ/hPmXZO4R17F/N9s80ngB4TDccyX7kDg8jNUi8t+3JmpANpUNt5FKaKIeH29FMNTfk8v0fgrZj8pFbNkPfaGlZjhabqimdSGPfpP6oogjOxQMf9pmUM67Q==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Mar 2017 18:03:01.7576 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR0501MB1757
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/37ev3eo_mMFUSjOhvWs6H-CGMHk>
Subject: Re: [openpgp] Default preferences for the future
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Mar 2017 18:03:06 -0000

Robert J. Hansen <rjh@sixdemonbag.org> writes:

> > To get the most out of AES256, one needs enough entropy to properly seed
> > a PRNG to get 256 bits out of it... [good explanation snipped]
> 
> Built-in hardware random number generators are increasingly commonplace
> nowadays.  See, e.g., Ivy Bridge and later architectures.

Tell the Linux kernel folks to trust RDSEED or RDRAND instructions...
:-) Right a GNU/Linux user should use rng-tools to inject entropy into
the kernel by grabbing bits out of the RDRAND or RDSEED instructions.

	-- Mark