[openpgp] Re: pure vs. pre-hash in FIPS 204 and 205
Daniel Huigens <d.huigens@protonmail.com> Mon, 26 August 2024 12:03 UTC
Return-Path: <d.huigens@protonmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBDB9C1840CF for <openpgp@ietfa.amsl.com>; Mon, 26 Aug 2024 05:03:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.104
X-Spam-Level:
X-Spam-Status: No, score=-7.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=protonmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Y6ZEZzsAlOX for <openpgp@ietfa.amsl.com>; Mon, 26 Aug 2024 05:03:16 -0700 (PDT)
Received: from mail-4316.protonmail.ch (mail-4316.protonmail.ch [185.70.43.16]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7E089C180B79 for <openpgp@ietf.org>; Mon, 26 Aug 2024 05:03:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1724673794; x=1724932994; bh=fZ4ekzQDCz2sV8NMEG/xHxlcR8MHNPOORhafXTsIeAs=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=dxSoV459NhOmGuosg0tRcUgE/8LPSFQCUA/mSjnXM5HAx9oSL+yxeyoUYqNSPPlEp slEJwKlvqDwNPeqatg77svQLDzgLxMHS65VlmFUNmndVSr3uVVtSFe3BzgfkoWUtgg 7U7oN1e5zJo8sAgZvG7RCChNPHNd+NwErXOTYeGl5k8lOdgD+PEaMuBL3uzJZghsfi Csv4mOFMEar/zPyLTzk8KQ37VfFIZxUqLhLV/F8bKORG/VZ/d9+9Lid1Qj5bBvj22+ cPGYXP0T2SRq0tpdIYnnXJKyKKkofiLa01QPZjIZ2qZ8CpK2OBJ8f91sE/LJ8LxjwE nf6VorrQ9UKJw==
Date: Mon, 26 Aug 2024 12:03:09 +0000
To: Falko Strenzke <falko.strenzke@mtg.de>
From: Daniel Huigens <d.huigens@protonmail.com>
Message-ID: <v5eqMUObGSgNbVEkuZMzQQpjPMtpLJqZbplsVHbCVVowsABLrzOX2Pv6wBnVFMtr4MjzMw9qGk8LAatAaTNm7fxha6aSGT8Kc5ihj8WDGQ0=@protonmail.com>
In-Reply-To: <5e4fd25f-3f2d-4263-a9f6-4370f308c90e@mtg.de>
References: <fb9f748b-2024-4de1-849a-e52880c9a241@mtg.de> <87plpvwrcj.fsf@europ.lan> <5e4fd25f-3f2d-4263-a9f6-4370f308c90e@mtg.de>
Feedback-ID: 2934448:user:proton
X-Pm-Message-ID: 4d9717cc4c19102468976695f9003cbbcc8f5ad6
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1_hI08RCm51kDJpCggfPnMjqtiWcOroRDZyT5uao0cc"
Message-ID-Hash: FH22X5JSRUPYG5FK4XPZ5IJ5QODCABYM
X-Message-ID-Hash: FH22X5JSRUPYG5FK4XPZ5IJ5QODCABYM
X-MailFrom: d.huigens@protonmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Justus Winter <justus@sequoia-pgp.org>, "openpgp@ietf.org" <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: pure vs. pre-hash in FIPS 204 and 205
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/SkQXjpaVVjYg4Wgi6DG80IYJUWg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi Falko, On Monday, August 26th, 2024 at 13:25, Falko Strenzke wrote: > In order to do it compliant with RFC 8032, it would have to be done by using the HashEdDSA variant and providing the message hash from the protocol laver to the signature function as PH(M). By no means any double hashing occurs anywhere, as both you and Daniel have claimed. This probably the source of the misunderstanding, which happens when replacing the message M with Hash(M). There is no variant in RFC 8032 that takes PH(M) and returns Ed25519ph over it. One could imagine such a construction, but it's not what RFC 8032 specifies; there, PH(M) is computed internally in Ed25519ph, not externally in the application. Note that section 5.1.6 says: > The inputs to the signing procedure is the private key, a 32-octet > string, and a message M of arbitrary size. For Ed25519ctx and > Ed25519ph, there is additionally a context C of at most 255 octets and a flag F, 0 for Ed25519ctx and 1 for Ed25519ph. Furthermore, the "rule" you've stated that the message can not itself be a hash, I can't find in RFC 8032, in fact the section 8.5 that I quoted before essentially contradicts it. Of course doing so does have security implications, but those have been considered. Best, Daniel
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Justus Winter
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Phillip Hallam-Baker
- [openpgp] pure vs. pre-hash in FIPS 204 and 205 Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Justus Winter
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Akhil CM
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Phillip Hallam-Baker
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Phillip Hallam-Baker
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Phillip Hallam-Baker
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Simo Sorce
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Falko Strenzke
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Andrew Gallagher
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Simo Sorce
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Simo Sorce
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Daniel Huigens
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Simo Sorce
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Simo Sorce
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Steffen Nurpmeso
- [openpgp] Re: pure vs. pre-hash in FIPS 204 and 2… Steffen Nurpmeso