Re: [openpgp] Default preferences for the future

"Mark D. Baushke" <mdb@juniper.net> Tue, 21 March 2017 13:21 UTC

Return-Path: <mdb@juniper.net>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59A7B129871 for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 06:21:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N4ys-RI6TuT3 for <openpgp@ietfa.amsl.com>; Tue, 21 Mar 2017 06:21:40 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0138.outbound.protection.outlook.com [104.47.42.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6CBF1129890 for <openpgp@ietf.org>; Tue, 21 Mar 2017 06:21:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=4e8aXWAhU2jDLzMJ1hNBGYZPRW0l8ZObZEsBt1/ZgVs=; b=NCSorwbpZGwanRfneln2xa6hIQ/Ov9ZrmwOgjf6Vu5c9Q2h4hInYQDQlVhX6Esl33SjKcg5h+cwrrpFfV97Cso+f2zX6VqX3NFQtVmKIDp1V2hJnj74FDCE8y6F8IgoHRFuM0rfzR6ElU9APZ2eBOI7wOtultcA5n9CKsCgQ1L4=
Received: from CY1PR05CA0041.namprd05.prod.outlook.com (10.166.186.179) by CO1PR05MB313.namprd05.prod.outlook.com (10.141.69.150) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4; Tue, 21 Mar 2017 13:21:32 +0000
Received: from BN1BFFO11FD033.protection.gbl (2a01:111:f400:7c10::1:192) by CY1PR05CA0041.outlook.office365.com (2a01:111:e400:c5a4::51) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.4 via Frontend Transport; Tue, 21 Mar 2017 13:21:32 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; addere.ch; dkim=none (message not signed) header.d=none;addere.ch; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BN1BFFO11FD033.mail.protection.outlook.com (10.58.144.96) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.977.7 via Frontend Transport; Tue, 21 Mar 2017 13:21:31 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 21 Mar 2017 06:20:57 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v2LDKuiR028684; Tue, 21 Mar 2017 06:20:57 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id C42B01144E; Tue, 21 Mar 2017 06:20:55 -0700 (PDT)
To: Ryru <ryru@addere.ch>, openpgp@ietf.org
In-Reply-To: <87pohbm5or.fsf@wheatstone.g10code.de>
References: <3b89c96a-0bb6-cd09-cbf7-1f9e26f04bd6@addere.ch> <52027.1490051694@eng-mail01.juniper.net> <87pohbm5or.fsf@wheatstone.g10code.de>
Comments: In-reply-to: Werner Koch <wk@gnupg.org> message dated "Tue, 21 Mar 2017 08:48:04 +0100."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.6; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk, }4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Tue, 21 Mar 2017 06:20:55 -0700
Message-ID: <78804.1490102455@eng-mail01.juniper.net>
Sender: mdb@juniper.net
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.18; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39450400003)(39850400002)(39410400002)(39860400002)(39840400002)(2980300002)(51444003)(9170700003)(105596002)(7846003)(7126002)(5660300001)(305945005)(48376002)(106466001)(50466002)(50226002)(356003)(76176999)(50986999)(81166006)(6392003)(8936002)(53416004)(76506005)(55016002)(2906002)(47776003)(8676002)(117636001)(189998001)(7696004)(2950100002)(5003940100001)(6266002)(6246003)(229853002)(53936002)(77096006)(86362001)(38730400002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:CO1PR05MB313; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BN1BFFO11FD033; 1:mfRwvvH7Rv6Yc7DyA0MOZHAgoXjQmvHLf2JCT7YgzJADk6c3BAJ3JvEMi7Kt4/gHtyWrsez/bQxZX2sezd3H/HamhvTYBMxRj0D6YqkCGzRK8i0FGkRJWDi297KxPqw2tW11k1kK/xKJM2TfGO6hh5wRjbA9UthUM0vbgAYQn0Z9QUHOLHu4TP83GVkYd+qROzBug8XNHUMzevO1LgI2FD0cgFs+gTgtfsUgNM+vp2tDWYcGTceT+euy0O3Iay3EoPor6SL/BXQH4Mk/TXq1JyDR0epL1EbTmDi4Wd7mKDjtSgdmGukrvDs8B052HyIAuNQqIFR1j9Mf6bQPJLItdV0bYvXYozle9IQ4kPrSu3ecG1nG3slSzNqVjz/HYCaPYhIXKEcpRCbBqC3qUdizQiKyF8mNk1VnIaL+3wYPuHBn2fiAyEZss2fDgI+X86k95VKpXErKTsfXoHNjmghsUQMyrxGIo7pWvGBHjt4kkM4bRw98iizi5Wb01OJjGRPAwnA7qTNUXmsrpMVQY7Nx3fojxZ4IjP351e+1MwBLuLs=
X-MS-Office365-Filtering-Correlation-Id: 20c7307c-cf4c-49be-beac-08d4705d30a8
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075); SRVR:CO1PR05MB313;
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 3:gwwZR9xY4Xks+gl2Lyn2uduHaie9RB55OT4bofiLKAvllqIdyjuv4QuTMuWXjMw1ElTl9OizX4VvqpDbznggyfc1Gzor2VKhtGojoSEyR+12JHxP2VG4opf1I+cgXbe2u2xQOTc4fOKySi/bwlgtipJvZthFbJZ+M9flFYqgjwqH59fcIqmDYQNaHzipWewYWPoUp5uR0wNi6fXeMEAuN+oP+CfusTosuyXyx7NVxu6Rr3eR0pma9IDJeCMt7j4om1671RuYtqBQoDznDnkpxMn+dQ+QP1XbArPnLJMz2OTcjAKH9aqChdoL5FURuIi6ERSe9dSiw0bUoE40BGo1vLz+HnY5Ann/Ef7ijIyUM5KQeJ7jWjf7N/ovNKQiRjccSgG6p+C0zUv7bcAEp7GIdA==; 25:5K3uxzYKzb0DPS1ZwS7/kM2vbU8CjELo/OMB3v7YyBDg9V26bCWAJA9/ktk/ub4RRPNDXwM386S3qw8ZHjrv88AcsAKI/VKK6VSf9s9uRY9QoQNeuLLMwIFDwke5xhu50/RPsFDg1L1ehujJy474zaArgAS0nVav9yzcAgx0g4rw9sWWN2DHwQPxkBStkWVwDCjOmOM5IUiphTC2uTrxQZ5o+a8nyDjQPckkvhLERjNO+rY7fMPZZWVULq6GMpNxfJR6++b2D7Bi4XJ3jo6SZJVzkPPmxzyeRbdTdt+USod7sGb0ejf3C5lQEZdVSOkX3p8K67AOw/CFK2jVAmxtVp6oCQLEEPCJ7cbGPriRPnNm10a4CRf3p1HlHL7z/9EEOqTNnLuABIZuuuj7FOBlmkWszC31wLHbQUmRQ/kU6Nes4IPEPPGXs9apnzpbshfXXkwNfOzQuhyML+Vm5fC+qA==
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 31:/vw4tuN0GVuB/hZWmpOAx4JVicT8CGfT8TLXaZkkw4pR5VmkJw4ksgZTveeCKXVYMqmgqV38cMiHQANvqxYmrrxQtpOqDz65dFD0tRiRiyk9Z51ZbFtqCr1nabBHf+0eNAEUCh5OwgzxLqrd8/yzKe4QERx+HB0ONa9AOyxRULgIXELFbElbHdJQpchGzJI2vnuGWy9adr5lfmg2WchUwUpCPYx8f4CCys3otKotFR3kXDHFYaZReCA2gHT3dUfa3TtthqiZ2/GErJW1FJ/IHA==; 20:u/GzJFskFBE7V8uZWTqEBaJ+O87Cl3KIr/O372pmgcl4kyqUrpWvyBGqgmSsxQjaMglEsvzE4YRbP+I+JtAEaH5jhsdcShgfjErtPW4iaqkeyQW6nrcJsf8DZzx8y/VwclYv5rWgpWtKZtweiZF47lEdh/YvHx/adVoDTmz+eTH3oXGWZIv13lx65NelBRgN0GIGIlcJeqwzn+YfVL79YF9xihWIdW01apJ/dghgyIesMSWYGsjA/iuqdRG0UQSyva1zF2bxd0tInDqvES4yy0deMw4usotvop76NURm2tQUOg7WxPvMpReetcSI8UlzHKlcKjR9SrUZ9cRceMzhX/Fy3JpX2QZUk3RE02MqRrjW+RjCJy2N3q0O19soqtgUcV60ibCRVVFf1u7Omd9Z5q//W7xupOBPrRYQHKAiThRrSiYrohHyI+k4HS1NyKz4e9GoeCEKW736+9VVFqmi/Fizhdgr0lpk5CRItTZAk2V8CqUDSvImMzNksWAAmJSc
X-Microsoft-Antispam-PRVS: <CO1PR05MB31348F51D5CC629A8F78E50BF3D0@CO1PR05MB313.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(138986009662008);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(5005006)(13017025)(13015025)(8121501046)(13023025)(13018025)(13024025)(10201501046)(3002001)(6055026)(6041248)(20161123558025)(20161123562025)(20161123564025)(20161123555025)(20161123560025)(6072148); SRVR:CO1PR05MB313; BCL:0; PCL:0; RULEID:; SRVR:CO1PR05MB313;
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 4:i5c0IRiLq3ZNpwGfHt8Lrd6aynnzFRkgm4KFE5K5wETH7DTP08rMtaW+/7JSs7gUmo35XhbG8xKvpCVLMyOAsudTuD/yJfuaPyjAE5J3oN7ka+v8pjqKeFoZO1yg6TDvIQFdslQpfqSu5r4JafHWp9k4BatyvlnGwXJuYYuDC8TXHC8eX8MldR5T8MsjUemJ/ZERTpA5ojds7bsaMQTCdFTziXzpaX0h0nOakg4qLww2J+VA3w5Zm7RRMScSbk27mNzH67cMQgzXk8nj7HSVEpZznfTI5UVu9tbfELh/brHp78anMtc/bmQMh3ICcZCUSvzH/51/PiqO67N3UYSz1q65f576AcutpclZ+IDQC9fT3dXcITzLos25JYZ+uoW//zH7quDxuzIPsNBPf8V7DN8FdAx9MbbLiN+B0eLw0N9DBdKYFuIA8fvQ/iu1Hvff2htqrTPaArQ1JxP4wTyY3vPxFuEf4wQpkKxju2EtNYgBjlX4a0b7bkjYIzYxgqTaZ3glRI/dYPWhTcl8i2iL3qRkno37r3pMSK84/DVo6AM7hN22qf/Nx/KLB+8A05Ar+OHe/Fy12QQtBmrL1bP4sIQucfElHZtqHUkbkxM5jy9KJE47BypQFqXVzqZg2sxFaccPnnSJuTnQxPw62fo8FMSdNW/wHysKU3pqB6XqtH4witj9eE5XsZJe0UGAML69UoZLDby2FdCYWc1IkXRsXMKWw0iXdPQhHZ/hCHZ9v7KgdgIkXRaNI0j9q9nT7YWk
X-Forefront-PRVS: 02530BD3AA
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 23:8ViNi857J5efbwKLPfjZBKUwvLb+2s+GrWiabtGcJ3X3xUF4tJzRMeZsrph2ObItgcKAQmTkJIKydwJ1fV763PDPPKditiOZJRUkLFgqEIhsAQIGSWvEU82H2/nXfbd9QzA5ZqgNX8aD9aS7PoPSp37pkoTzoO9iMkDYYvaCXD3mDYVX7McDQ5CyNJLpv4XOm1B5KVDFQDTBC+DNhgTvsAEPJijF0+szYxK82qHGjt7wenv/jVap2QEldWWvvCgcJmnmKuZtF1+q7RUSOXhjZWpkTvwi6b23oIkNwlAKTkSZiaYJQRA+Znk7CNWFIZTiXkpLJ/dzGKc7hjD3JlEYBEu9d+HDat4iqdJJbCJaMoEwcuWskh+7wr9E4HJ7oPKFYOFavZdG+vtdGn1/kJRfUXp50RhiQSmW37Xjvk9GOp+xmCPwk71eSygPbiRWtldZdvZj9Jz2Xep/Bh8umCYkNyF3HUjXTvIqMS40obLPX6MG4Rpl4QfQ4vzpZmrRYRUHYfwZaxt1JnxBITPxDyVkq4ELqVfH3PqLySFp+XAigZ8FpEYaf74uvuF4XcaYspKkYiN8KZ/B9r+fPXz4DF15MfD14cCz0mXFStvjTeuT8ZvVkorAxOJxSMf3XM94zJ1B3zqVAlbBdfxO6XLj3mG27x2GP1JDvMllDFnSyMdrr2wKI8xTijKbx9MwTiBEnHW1hM4M21AhofcNhRedDxQ2e+4sLDtEIy+ROpGPqmLQasHwOEB5vMLo6ouyiQCx1GivsWEJq/IVpD2yDJd+RLfQHiqKIKQ+lCUrlLvb+MvQ3VWitOu1N5Vz3QBdMk0xPlubVIumU9PFTn6cxglHZrfA8HLu7n98cRWBidQdWmpwXT78lp3ID9s/jYwQBg2WrjHy2TDa3NLwQTrQMRbY79QflzqRgjOxABMX/3nnXZ2qEN9Rpgm+YP1qmxrnGyy8rYCd5R2dxUzyfZSzGIITKOnAv8dK0fK93x8HAjYkfhgd0ONJkYOzSJJAcm67UzqXfaxe8GVZlFiKCGgbNKwzxCgFt+wSvwzbheupiBxvGVGcZO3lcrJJg9BeGScbhd/ssqn5RwPHJ8CACNpoWE3JYQMhdw==
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 6:gNwobZFf2nLW0YvfnppL2NPVsiWVEDue+kkUlw72l4N6fJxkK7ewAz+tpoTHbdlI/K18aeoNFWLealq+BFA05I9E4e6AnPZdD7BvNA/57WikJUQaifxDKtuEdugzm5ELVMgqHNUOdnox4mAi8Rn+ol6PBqLhZxDETYHAijfIrCvW09QXjxEhaVmwCgAyPl4OELLvdYvhryuoUWRGltP5XddCg5d69e/kKAmPURxFDaOHDvj8z+1NCo0BzTQolJaaHjHW9cqwno0yatYotjINGM23KCYXlU1+yxaf5xbYUg/Bk2KuDnMIG1REdVMBc+BNyu10il5e0PND0KlDVxhT5RdBNkDZ+JxdQ+ZgE7AyBd3I2lqvMZ+rxk4kIZsE1jEdxPSHjMxAyknGNgopnUfR1w==; 5:YQr6ptT5BgcmlwUn9qwzlrgPfeOmOuWX7UOl5NgI9+oRSLiM+AXXbd9+eK9Td5we/o00WKvQNcB4eFyufEx6t4ykTjaqTLlf8Ca5n5Z8V71HqoXTEzaIoKkxNwfb62BgBSZ+t8KGQAGYXQOiFlFh5A==; 24:+0EF2XR6ffLdYv/+o7f4/PN1dJqRppVHNOI6x68vSkkVUEVusoyhQMI6VkwmI/2pTYf/4GJtQucCkHZWpYdA2+lY7e0fhTAKCA3yuJQGPIM=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; CO1PR05MB313; 7:dtvVpT/XwqoNsOoCx7tPKThIr3x08Bf9NAbohrrJgYE1LdMPnOJ3h9UR6OLzo1/Q7G1Eph+ukPJmyD/NfoVnZ9KQLUF+Of4g4RG0Pg7pn9Dm8VvZjtJ23CVr6aLfrYuOMVMjgxuD2+YdEBCipTXcojFtYGEnEwNvNKBh4eUAPb8CegttoBgO62GMaS/KI4A8seRZ6OIFoUOVBZ0LhTsGSjC3ILKAXXmET8cpf2bkNrAC5ZZ4UrHCgTIkO/IzQuqLmc7nfHnrlJI7BR1fgyVXmtf/8U8H6I56d9KRiA4KH/SR1WdOPsg38tFyKd7GwZJfU9AEvewf+k0nUE6ixBRieQ==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Mar 2017 13:21:31.3129 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR05MB313
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/k-N01F6LFThqN4arLe6IXgW_FQM>
Subject: Re: [openpgp] Default preferences for the future
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Mar 2017 13:21:42 -0000

Werner Koch <wk@gnupg.org> writes:

> On Tue, 21 Mar 2017 00:14, mdb@juniper.net said:
> > As an editorial remark, it would be nice if rfc4880bis were to use
> > a consistent representation for the secure hash algorithm families.
> > SHA1 is sometimes written as SHA1 and sometimes written as SHA-1.
> 
> Thanks for this suggestion which I pushed right now.

Thank you.

> I have not yet looked at your other change requests, though.

Mostly I was trying to hit the SHA-1 to transition to SHA2-256.

I think TripleDES needs to go from a MUST to a SHOULD algorithm.

I think AES128 needs to be a MUST algoirthm.

I think that RIPEMD160 needs to be a SHOULD NOT algorithm.

I think that AES256 needs to be a SHOULD algorithm.

> Except for this:
> 
> > 14.3.2.  {13.3.2} Hash Algorithm Preferences
> 
> >    Since SHA256 is the MUST-implement hash algorithm, if it is not
> 
> I changed this from "SHA-1" to "SHA2-256".

Good.

Being consistent and clear is important.

	-- Mark