Re: [openpgp] Default preferences for the future

"Mark D. Baushke" <mdb@juniper.net> Tue, 21 March 2017 15:55 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 273B3129A9E for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 08:55:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.697
X-Spam-Level:
X-Spam-Status: No, score=-4.697 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 74GsDSM8Gl9T for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 08:55:52 -0700 (PDT)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0110.outbound.protection.outlook.com [104.47.32.110]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B90151294B7 for <openpgp@ietf.org>; Tue, 21 Mar 2017 08:55:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=XJiDS/Tg0Z8K4ZJIxiI4IbEtt9oDZqOlg6XAB+jYnrI=; b=CjQMuOQ3gYX67w//PAUtuYpijQjuCffGOVvuhU6RKwozr6uvk8zm37Z5HL1jA1mgxXfB68H/3pma9BeNtY8DfwTMND7pGYlAMoNpjyiUfqk31w4HGiaeuEyahiMpF2RRS0u+J4JauSY+rNzrVTh1JHpVh8u+e2YS9r15cHSF5L4=
Received: from CO2PR05CA0075.namprd05.prod.outlook.com (10.166.88.171) by DM2PR05MB317.namprd05.prod.outlook.com (10.141.103.151) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4; Tue, 21 Mar 2017 15:55:51 +0000
Received: from BN1AFFO11FD007.protection.gbl (2a01:111:f400:7c10::117) by CO2PR05CA0075.outlook.office365.com (2603:10b6:102:2::43) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4 via Frontend Transport; Tue, 21 Mar 2017 15:55:51 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; att.com; dkim=none (message not signed) header.d=none;att.com; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BN1AFFO11FD007.mail.protection.outlook.com (10.58.52.67) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.977.7 via Frontend Transport; Tue, 21 Mar 2017 15:55:50 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 21 Mar 2017 08:55:11 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v2LFtBsS028902; Tue, 21 Mar 2017 08:55:11 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id 0982E11446; Tue, 21 Mar 2017 08:55:03 -0700 (PDT)
To: "HANSEN, TONY L" <tony@att.com>
CC: "openpgp@ietf.org" <openpgp@ietf.org>
In-Reply-To: <56ED3B74-0BA4-4DC2-943E-B1CCD1F32AE2@att.com>
References: <3b89c96a-0bb6-cd09-cbf7-1f9e26f04bd6@addere.ch> <52027.1490051694@eng-mail01.juniper.net> <56ED3B74-0BA4-4DC2-943E-B1CCD1F32AE2@att.com>
Comments: In-reply-to: "HANSEN, TONY L" <tony@att.com> message dated "Tue, 21 Mar 2017 14:06:45 -0000."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Tue, 21 Mar 2017 08:55:02 -0700
Message-ID: <11858.1490111702@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.18; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39840400002)(39410400002)(39850400002)(39860400002)(39450400003)(2980300002)(189002)(199003)(9170700003)(50466002)(6246003)(6266002)(38730400002)(110136004)(47776003)(54356999)(76176999)(50986999)(117636001)(4326008)(106466001)(2810700001)(86362001)(55016002)(2906002)(229853002)(7696004)(105596002)(8936002)(6916009)(81166006)(2950100002)(8676002)(48376002)(53936002)(6392003)(7846003)(77096006)(5660300001)(53416004)(76506005)(5003940100001)(189998001)(356003)(305945005)(7126002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR05MB317; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; MLV:sfv; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BN1AFFO11FD007; 1:Y+DfrsWOzrg3ta20oIuJ58hGFMSciDDz0u6OaruDkZJ/f9do6z5HdQjqoYpTW8nWpx3rIraWF1fzCUvC1KUM4oFMaBIYKngssnNgObNihEghn7qRnHwqEo54BcQ7VJPnlYonzBbXW+EOJQWKhgh0HQhNY3grLmcWzhgvj3Cdsfl7GbAHjUHSVd2Iu0vvr4w3iEfNF9zgOWj3KAMOpE8xkIj4p15+NBXxNqEPry0dSh6/494tULWw/yC3VNKokveAW0NGoQfmmZQBMe40s7itH6GTqXASEvmZAoPVMbYG/ei8uhqitPLXQgPtM7iJyZy1gg+rSiwi9W7hkKFw0Qkv/7dods/97SihAu5ovuN+BHZZFKIJ207O3gkVHXL97K8VX9wqYmxVYOee11hpEckVrFChV0lPoeMaOGhjZ2nDlk4bjZ+U7WE+jKmLzhJvrfpRmhSdAema2poqp87a3aZcjRGLc8rWXXvm59rIfIIUXWAXDoHqHKp0hc1j2fkgwA6obSDvbS1mPUgpMUMc+oqjWGmCtHPyxsfxvT5fu5+11Hg5iusTVXuPou2+2DQsDMZK
X-MS-Office365-Filtering-Correlation-Id: 0e255e5f-d3fc-4956-44cd-08d47072bf80
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075); SRVR:DM2PR05MB317;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 3:5CtvmcDv6C3kJb5L3+8zG5ffeOFvnPkTY+zbjxsCkPHTcghYiXkndcYbBckVmuMvE8MoJu8DV/n+KL7oRShz14c5OK7cUR98ZlD5bgJWRdB6w6oI5UvEI7aOnRgL6GilMhopUIbzV7XmYr9UaaMtwS6iljcLAyFg86vEoTqdyRGV7+UjVBVELnPWhfyaLJvZs6nLKlP62pIKyVXoux+yWgKPWdCiFMmpTJUvVWuIN5Ax3kzO24WihQAIpArXJYLjTglzOygX35OSPUtJ+XcXTnFmgGoRDSTb/TRar+SK/c/gigKFf5PW/70K463Sfdkao4rMmG+XIs/FSq7zAzQ0kueKb9Z4KbABKN4skYvYBzKNNFenwxLDWckuu/uZqy08uUrK17OQ24cO5mJA6o+pcg==; 25:w0vtsMaDOPTX5iFpMcR0rBKhMev15WX+BPyUnu3Un+y4ZgfPCqQ4CkOHNn8WBYPLRCfz0eMeMRVJs3K8T4DbM+05IXoO5LJ8ztQuEVbICB29yE9qejcrP/DYInwVsNXmZuWKrZo0nPoO0DVGq5TgNvqKV9CrXeWE+nbA8N6iuq07R/5T97BUo1v6lfccO6pjT106h3Y8rbVtJJl9RsfHerX19vHJdG9mlqlijiFEH40CNTnEEh8e4XNoj1IJzwJBt2RC1KdMWH3TvYp5h15roOL7c7jnX72S3xHh20A/UGMGLMr1mHTyvzSzYs1k2UNQHOU2Nfyb1J2dqAjY/9VgXBiSXEyiqOxGmMORiVxEpe2JAni2tR2rOgCMMATRFYs1gFEO82uap3uNJI8VGibDG9U3CpOubwvHMmHljQRz3e4iXHiSi/6bSqHqr6w5VxBpwvK1CeBT24AOfaLRyy7tBg==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 31:oJvJjsZl9L7pzrcpu7Yl0rzsuUZaOUAQ1j5aezsgfwN9w7uQ9Th1cU4DYlJ1pwwh6ftxnvNxWfIAm8Xd3dP4CX66pkO4LbNNJ+WE0E5QpLr6AlK1TK6OkVRkfwyuO618NGseg/i63XkEK2mSZtKCCHkgNNQkl2m1EFwVG8MqWwBaCnmV2ydxsVSXH8JhgF6B5SL8TZaR6D7BaYKq5pdYoxKz4m97u/kbJfD7fGyjvQhY/G6muQceWLw+rlyE5TgE2oKMhhs9IEm0gAg/sFbxuQ==; 20:Ndfp2weIfqQ8tdiIOESI33vXl9XFNEjrTTES5LJ3N28qfi2lawD6kGwz78Vs26S8M4fxXBa3Z3gUzzQtzZ8I2ZHV0TW2kLp5bGLE+2wfa9XQOUuRpKR/2ZzaFh0TzR6VcXkceHyAopJBLQvaiBq1nSO26sMbaoHtdBZLyP1GgAltT/wZo59X2GbShTVzvoMEKvw+M7NRIuij0onC1cGaa0HwkONUtfGrDRbJg+3RrWGgJJuAd4OOdGADSj0UoJHEn/ekUcGRkNI8gso/VUBL5IVKe33y9eYpDW8rM3ph41LtEom1SeYIk2rOQw/MfmBx6VYcvjahN+WcadmO3qhh+Y7uu6TLuyTwyVgA1TmezEmNPzdezmEIlI+Tkx/0HTQXD2g5G4ZwwkV1rInRWvPjvtXiC0FyHdkGnEKaxHNfmiQAWdWJRlecsYyA3JGxrVde3km8bs3SSG8ZlMs0o9fD7jJi8IuhcmrxZlnJVwScepom1weMQ2HLcbXn54bqB18u
X-Microsoft-Antispam-PRVS: <DM2PR05MB317BDBF181C9123A50BCD30BF3D0@DM2PR05MB317.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(192374486261705)(97927398514766);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(13024025)(8121501046)(13017025)(5005006)(13015025)(13018025)(13023025)(10201501046)(3002001)(6055026)(6041248)(20161123560025)(20161123555025)(20161123564025)(20161123562025)(20161123558025)(6072148); SRVR:DM2PR05MB317; BCL:0; PCL:0; RULEID:; SRVR:DM2PR05MB317;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 4:9WmDpQ+0XnAbrdJsQRKJTxSkaq+L+VW7+NogklsSw5vuTG+9sQIxg5jPiYt+2+OIu3xneARc3llshlNYtvG/e2m3kfzX6lwo4GUf25GhpMJzsjJLAb1mYmMovYzpRMw+VFa/K67NRgyq5BQFvSizeijuAXSaHciUCYiPKaSXVt2VjrxKCtCSFDkRlo907l+8vBDZzwBSWc4Yc2Th8ebuBTLIVQk6ScR9IFaNaVPASqA+/taNF2OIgo9f66QaVS/LrZxRjQHwlaQfOpDfifFC4iQ31/EE9mHz9mbDL2LgiUlk0mLGod5wgztjAjibefKiBQV+xp5kEqepSf1dIHtHkjtiFCUVGfIQaJ/lgxaWBf5CKjLPnNSGCNcV7129SoSaQdnbnr9ldCIYbCno7BI9XF5QA5++okidq1MMp08CTbcVrb/lXiAyIWKVmcB7bdHb4MMyzyVjd0hVJZJeTXqQdJhLZzW0VFvNk1pfuvq6Ja/YlksPkPrsvHww4dimzC5vZanhIWkBG5i4fezmtLmEPbHzbhXPhTiyhxO5OBKS7/bn+4lS2c+3obWjC52yAY6DNomvS2WWTcGIoEQ3zDgWqHw3AUul1Z5LnbnLSzruJlb5qeY0wiJfg85ZZ7G8oyr7aYR9xSYU1uIOFfVrARfpXFweF0cwEdFgHqxIuGB9jyQvusrsOJJ6lkLJHXgPksFqyo7Iogj1cJzb8RYa6+zMpoVUzzdvsY73Hj/GKdIdO/n1TzC8ELwT9Miz689bqnHs/adMcDkPJpK1bM4Y1lIxVg5Rsxv4T+1oyDfPwLwX7Xw=
X-Forefront-PRVS: 02530BD3AA
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 23:M7bD+ZABDqpH+1/7e6cXfKc2p+42CIX2CMMFyjDxsawp9QriuA3l7UGCiNzPxZQm4XTybgY13oISgzYoCJowTQRyJyHORBfT3eXIEzgnqF5RuBWSzNKPoN6zkmXTa/hjH7BElKZqEr5X8jxsnnydxCYJlyjHUnyyQU4R6GiYbERBhxgDySq4+gNOPYt58q/mDtO6/LKZ/BpZxdKz4RUUEFeM8xmpGh0fjryaAkmWD/BYH1r/sCZeR9zlDE2mtZq/hotsU6HkdLEwCth+4ov0KoyZAw+/xazX/9R9Je969J+OaZFRsjOLtH6a6lJ1gc8axjGVw7bvbBZAU+PEU8GnORlbHecd/I92p0zW87MQWRnTmC+RaEAwapGS+MuIpBMqKMn5dJ1MtRQL/XmnSCpUny9FhKcXzdB+poHWQFfw04hObl8Wdqmqgohp27v43Kqe3QuHo8VPQ101H03Ot2T8Sar+WwvotWtUmz5eyZhqLgpChX6vjVl3d3/74o9/C9dcturM+aWiM6NsZWljjrJ6BaISRtWK8AaD87/5VIBuKJ+Krd2sosWu6ncrye8rk14/Aii6cT8mbNIMNAO1q9HQ/qIIV7+aM8I6GE8nnUe/68j/SSH8HW8kzVIUTYTG6cz3GSZ82rQHpHLEEJcGuANC3BvTcQlAtaNiPxVfchqbylV8oqco5wAMeYEEOqi9prjTWj5fEXLSD5BTdz/b1riprsvLj8VfL38K6daD3XFbW2dl/J3oCK5KuhOVn+NPaxxsIEWJnhMUC7IjbQ4BJ1EvyWN2Mu5TdroaSMHRLwOjCL68qjvdnzB+5vFKr9LcitdX5BPX61joo/oPEjzuoa75ecEcImGhhCHW4Wac5dTMlpROn1wFjK5VHTw0YXv0rz036tnN5zUTrkq5/6JNNJYcWZXcvWHwAe2VKiLWt68zSsAg7DKa5r/bYWGGlT3uXUmBqiS7omoT2CbfGb6QlXgXu9CyvEVCChgYTw5d4PehDXrY3zhiaWZJ562K3wX0ofQ7QJmhAi3RvKjsUPBvI5ssj9KDyBqrOB8prx5FyOYI6X8UGNx8oz2U2TAIhXWxgs7aCznswC7t0DEzno1vz6iGgTHhLB3Cc20I6AT2OXa2aNrkCsedNYxxUv6HVd5Bbmj07BNYVTRhooeCv3lGfXrM1l8sQ7B/oBw79GjFDFvhbaI=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 6:x0UBJ5AABB7P3ETLlGq8NtI92gF2Sc7SvpLpLVTSGkEHjHgo0toV+WK3ghKiInSaxJEFCQiyfQZC6dm4R310wuQJFzBgI7uH80vfE7GWa+vcZqGoKUdGhmjObTsxUCq260jEiSSTQ3MqRqLPQSEMxnGIGu1bxSZj6t9Or49XSmJgrh8A9xRn0x43QTOT0dMEMoK9SE5JvYmpYdOWkYbSBjGnPtKuoszfWKLyQ4U2tnhETt1fYh865QBOs78/URhb9/g+UbA+pFjSQQRR88iDzyHeH3Z2/de0Z6cPzLtutOqsX5YqCCr4nlbTfNWqti+JFVlxHlbEPn+y2VxmikuZOH1vSVuaRt01Quhgqq8pSHvxyJqkRbYMuJ7ecpoxuqaX44D6zS2aezcctqmLe7B/wZdofhebvtlGU8DQpV7qttc=; 5:9W1JuvFlZeZpfdZeVrAEzlNu5p4pEbiRYLxlr5MLhgjBLE+8oWml7sKJ8R4skZMojILECufYZVEvUCy6YCj6GKyLcmkchHiZOtStMrFHMpOWtji4HRzHGOnNzYrIi9Xc7no76HUmCQSm/8XSAggGNA==; 24:feU/IDf1EiNyIiNKVo+/zDKpot/jsOLfinJ9YvdOfnJdHrFZ+QFEcKtPmJVPfXcxnkCSmDC+UVk4xi5UkWvEdEcHsCboQhKYDe42QM8c0Go=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM2PR05MB317; 7:32OETokvaMy3pyEy2htb3ZutyjMNrvU1eZP7vdvCZA6miOQ8O3Y2SfAyw2toKU0t53LVDoPxjxWUuhd33ZGg731MWRgt+xEauhFMnZ2Z9QRc+CKYQpVxD60STVFkKxuMx8AZkVmZWikhgpHSfHmOuDbQrWkYrlaqlqRIveaiBa+NtsQ9zEFV0j4l+Sv2m/muGxqFmbcGRwBH+X51c+G0rIBgPDJ11KLkDlgDNwVFpWK5L0PZB+P2IdCKE1FFQzVFC6boZcrN7cW6yMm+3fjZck+eZYTSND9rsdbyfvVr7fNWq4XUGFrtWYtLT3VgYtyNU52ksPJJyQl0OJQRirxgYA==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Mar 2017 15:55:50.3463 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR05MB317
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/ZIhFm0wPr3fFLtWW1GehJx0yeiU>
Subject: Re: [openpgp] Default preferences for the future
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Mar 2017 15:55:57 -0000

HANSEN, TONY L <tony@att.com> writes:

> FIPS 180-4 also defines SHA2-512/224 and SHA2-512/256. Should they be
> added to the table?

SHA2-512/224 protects roughly 112 bits of security, so it would be fine
for TripleDES, but not much else. I would say it is not needed.

SHA2-512/256 works great on a 64-bit machine, but is a lot slower than
SHA2-256 on a 32-bit machine and protects 128 bits of security. I don't
really care if it gets used or not. I am guessing that 8-bit and 16-bit
implementations will care a lot more.

FIPS 202 also defines four cryptographic hash functions (SHA-3) and two
extensible-output functions (XOFs) called SHAKE128 and SHAKE256. All of
the SHA-3 family of hashes are very slow in software, but could be
effectively implemented in hardware. The one thing we know as a result
of the SHA-3 bake-off is that SHA-2 is a lot stronger than we thought
and we do not yet really need SHA-3. That said, if you want to add
agility to OpenPGP, you could define SHA3-256 and SHA3-512 code points.
I see little point in any of the other alternatives.

	-- Mark