Re: I-D ACTION:draft-schaad-dhsign-00.txt

EKR <ekr@rtfm.com> Sat, 14 November 1998 01:37 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.8.5/8.8.7a) with ESMTP id UAA11828 for <pkix-archive@odin.ietf.org>; Fri, 13 Nov 1998 20:37:54 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id PAA01121 for ietf-pkix-bks; Fri, 13 Nov 1998 15:41:58 -0800 (PST)
Received: from speedy.rtfm.com ([208.217.207.133]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id PAA01117 for <ietf-pkix@imc.org>; Fri, 13 Nov 1998 15:41:52 -0800 (PST)
Received: (ekr@localhost) by speedy.rtfm.com (8.9.1/8.6.4) id PAA19896; Fri, 13 Nov 1998 15:46:40 -0800 (PST)
To: "Jim Schaad (Exchange)" <jimsch@exchange.microsoft.com>
Cc: "IETF-PKIX (E-mail)" <ietf-pkix@imc.org>
Subject: Re: I-D ACTION:draft-schaad-dhsign-00.txt
References: <2FBF98FC7852CF11912A0000000000010ECB5A96@DINO>
From: EKR <ekr@rtfm.com>
Date: Fri, 13 Nov 1998 15:46:39 -0800
In-Reply-To: "Jim Schaad's message of "Fri, 13 Nov 1998 12:04:29 -0800"
Message-ID: <kjhfw3xijk.fsf@speedy.rtfm.com>
Lines: 29
X-Mailer: Gnus v5.6.43/XEmacs 20.4 - "Emerald"
Sender: owner-ietf-pkix@imc.org
Precedence: bulk

"Jim Schaad (Exchange)" <jimsch@exchange.microsoft.com> writes:
> This draft is referenced from the new CMC draft so it should be of interest
> to the readers of that draft.
Jim, 
First, a meta-comment:
Why do we need this at all? DH keys are suitable for computing
DSA signatures. Wouldn't it be simpler just to compute a DSA
signature over the data? This would eliminate the need for a common
group between the sender and recipient.

Secondly, I don't believe that the ephemeral scheme is strong.
Provided that the attacker has access to the triplet
g,p,Ys (sender's public key), it's trivial for him to compute
a private key Xe such that he knows:
  
Ye^Xe = g^(XsXe) 

This allows him to forge any number of signed messages
Remember, computing the DH shared secret requires access
to only one of the DH private keys.

I hesitate to bring this up because I'm sure I'm missing something
really obvious, but I sure can't see what it is.

Confused,
-Ekr

-- 
[Eric Rescorla                                   ekr@rtfm.com]