Re: quic and compatibility with cryptographic implementations

Martin Thomson <mt@lowentropy.net> Sun, 26 April 2026 09:00 UTC

Return-Path: <mt@lowentropy.net>
X-Original-To: quic@mail2.ietf.org
Delivered-To: quic@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 37CD1E354EBB for <quic@mail2.ietf.org>; Sun, 26 Apr 2026 02:00:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777194016; bh=fu96nPEQcEkUfjPbItmJ81h+Ppeyp6XOyUVp2MjQJjk=; h=Date:From:To:In-Reply-To:References:Subject; b=Aushrw0vuFsKJDAHHRzC+n2BvN1zPSNAS1g4X6W2bMxrpne3mBo+YFeBu3mMzdjFV pvcyFiPR5Yb4jq01LWFH96q8gVGtfNf+/jzeBvMAXztlxw+HURCRcRfcGFn/FrobXS HrOZ1Uyf1b8Vfa9O5GdAqpE8EAaEEWkpxgY8NDKI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="FrikY6Pu"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="SbMvOK49"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2-1u7hOS_VSW for <quic@mail2.ietf.org>; Sun, 26 Apr 2026 02:00:15 -0700 (PDT)
Received: from fhigh-b5-smtp.messagingengine.com (fhigh-b5-smtp.messagingengine.com [202.12.124.156]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2A41EE354D3A for <quic@ietf.org>; Sun, 26 Apr 2026 01:59:15 -0700 (PDT)
Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id D0F797A00E8 for <quic@ietf.org>; Sun, 26 Apr 2026 04:59:14 -0400 (EDT)
Received: from phl-imap-15 ([10.202.2.104]) by phl-compute-04.internal (MEProxy); Sun, 26 Apr 2026 04:59:14 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm3; t=1777193954; x=1777280354; bh=r+GkAyILu0wc9WemTWcRV4wi39pSMZJ4X8u6tHX3Etw=; b= FrikY6PuftpPGNAmj9oYre21XnfcxGLYvCTFd2P2zuNIJ6QNVTM0Y8Z84hi87/Ep chAKkz7P3WNo2Ok9IeBwmYAdrCP7prTQ5wlfH/tXKf5O515w15dA1Ag5Cz39uzPy RxlV6CE1gxsYjB9JGlN6jxaqamdilVM3+y4B++zZnkBluVjnoOnQXrYPAv4V/0LX btVwbQDRvAfFU6/E+WICI4UuPMqFkOJXvMECCB9WnuiFG4oKhmjmHZ4Kx6V8cdyr ozS79EsWz4xQaXNwCVmdjqvWNdulnSBsbEoHLRGpOztFofTtOY8sl4xbCJ5wHWkV dToKhXIqxNeHYdRZ0msGUw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm2; t=1777193954; x=1777280354; bh=r +GkAyILu0wc9WemTWcRV4wi39pSMZJ4X8u6tHX3Etw=; b=SbMvOK49BE61zmPlB TJmCqc0BVwlqelw6JrqGdeF0+bvYoulwZYQdrNfV8GEuV8N7we+W+Q4Vx9OYd295 dKJtTHyrmAvUh88Vw4PvK/ffXlCCf/MQVOnVqSv40WFdgQVjZPM/MU8sG6yHQ7Hz WsY1JPQGaP2EaeyXKYYDb+hBQcQdCYD2CVaLCHd8ivyVnkWhjlWti7h05g0Gmfsh 0t+tMbVXoBQpuBy62mNUpYdU5K2SESf6f18Zj2gffItoNrpb4mApSLZVXvKym364 bWFj0uLSNrRxMJh+qTgaqwJct7U7EPVIzQNpL80KqYh1bY6a9spmikAce/9gm8Sw njJlQ==
X-ME-Sender: <xms:4tPtab5bFL0FuaUK_9rUAg-rXwx-q_dAzLy3to83d0pOFVD-UeOOFA> <xme:4tPtabuXzv5Xmm4UYnuvENGxnkr3KNQNR0FjvAVMroNhZmmxrFYI_8yBVZhNwLqMz Guc-g286JqYoL1y2HXyowX6HvDKS9pdgKv5j13P1LvaIycG4CAepQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefhedrtddtgdejheefjecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecunecujfgurhepofggfffhvffkjghfufgtgfesthejredtre dttdenucfhrhhomhepfdforghrthhinhcuvfhhohhmshhonhdfuceomhhtsehlohifvghn thhrohhphidrnhgvtheqnecuggftrfgrthhtvghrnhepueeludegfeelhfektdffveelge fhtefguddtfeevteettdevgefgfeeilefftefgnecuvehluhhsthgvrhfuihiivgeptden ucfrrghrrghmpehmrghilhhfrhhomhepmhhtsehlohifvghnthhrohhphidrnhgvthdpnh gspghrtghpthhtohepuddpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtohepqhhuihgt sehivghtfhdrohhrgh
X-ME-Proxy: <xmx:4tPtaZegbjXKrZhKxC3IVDsKAatDepmNNBmlmYDWVpJ3AoDKYdWUpw> <xmx:4tPtaeIeNshmx6Df1fJGhTtMAOtRvxWiHQHQtZ3PihC6Ln2d4meniw> <xmx:4tPtaYKdRM8JhG_zYWr9rNrmeL_GMNO5zHQpV6lmtv8kQjTXqwMwbg> <xmx:4tPtaYFdBz42QE9NOjjIB2j8sSR3wPCo02n5p9BPZIqKN3OgiHjZ6g> <xmx:4tPtaaWq99PKRpxMamorqIU283qYQee9U_g0sZVsNye_Dl1CZwH_5ISt>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.phl.internal (Postfix, from userid 501) id 6FE75780070; Sun, 26 Apr 2026 04:59:14 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
MIME-Version: 1.0
Date: Sun, 26 Apr 2026 18:58:36 +1000
From: Martin Thomson <mt@lowentropy.net>
To: quic@ietf.org
Message-Id: <a931377f-7c14-4cc5-a373-70cd96c7bfe3@betaapp.fastmail.com>
In-Reply-To: <CANBHLUhansrJ62U3_YGXeVa3n-hr7H00-bdNXB7D2gaRAGvTHg@mail.gmail.com>
References: <CANBHLUhansrJ62U3_YGXeVa3n-hr7H00-bdNXB7D2gaRAGvTHg@mail.gmail.com>
Subject: Re: quic and compatibility with cryptographic implementations
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Message-ID-Hash: I6P7GGHFCPXUDZKUU5S3FZZ3JH74HHNF
X-Message-ID-Hash: I6P7GGHFCPXUDZKUU5S3FZZ3JH74HHNF
X-MailFrom: mt@lowentropy.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-quic.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/k2kl2W_n5WDEZBbt3O31Ef2XBbM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Owner: <mailto:quic-owner@ietf.org>
List-Post: <mailto:quic@ietf.org>
List-Subscribe: <mailto:quic-join@ietf.org>
List-Unsubscribe: <mailto:quic-leave@ietf.org>

On Sun, Apr 26, 2026, at 11:01, Dimitri John Ledkov wrote:
> Would it help with
> interoperability with such strict cryptographic libraries if the
> destination connection ID had a recommended minimum length of 112
> bits? Note doing so is compatible with the current RFC wording as is,
> without needing a new version and a new salt value.

While you can ask people to make a value longer than 112 bits, the RFC only requires 64 bits, so those that are not updated might not meet your expectations.  So you can ask, but you will likely never cause every deployed implementation to choose 14 byte connection IDs to make your NIST FIPS requirements happy.

To be clear, this is a use of the algorithms that does not need FIPS certification.  We send the keys along with the ciphertext.  Though we can't expect every FIPS audit to appreciate this not-so-fine point, the point will remain.

> Has it been considered to upgrade this to AEAD_AES_256_GCM by default?

No.  For the same reason as above, this would not interoperate with existing clients.