Re: [saag] Possible backdoor in RFC 5114

Yoav Nir <ynir.ietf@gmail.com> Wed, 12 October 2016 09:48 UTC

Return-Path: <ynir.ietf@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 50F901295F6 for <saag@ietfa.amsl.com>; Wed, 12 Oct 2016 02:48:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jED5zvRlpLh2 for <saag@ietfa.amsl.com>; Wed, 12 Oct 2016 02:48:47 -0700 (PDT)
Received: from mail-wm0-x230.google.com (mail-wm0-x230.google.com [IPv6:2a00:1450:400c:c09::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 708EA1294B6 for <saag@ietf.org>; Wed, 12 Oct 2016 02:48:47 -0700 (PDT)
Received: by mail-wm0-x230.google.com with SMTP id o81so20710369wma.1 for <saag@ietf.org>; Wed, 12 Oct 2016 02:48:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=d6ZkP5AHoWt4wEJ0JDodt01gl5G3ukrLAbQ9f/ABQQA=; b=vzmP+nXnlS0Ax4p6QjTs33DMLQcHK1oWSPwinJDbvPuu/KCyFANoC5njnJUmXGtOLX CP7UTEbPdKuYg4M9khDLn9q3lm0cna6xal09MDOaZ9RMv15dZYBpPv/2C54oCMTkIIac xkROSV5X0VTvNVJb/sH05jg+nrBLUSMwG8HZT8oNHJHGcZjBKmVlegMZjgyrza9VwtE/ Oa3GJGb57BaJo1uvz4YAJVlU7YJH9fpC+e5jLlUckrKxXIItWCkPBf8iNtiIm9T7jibk YFtsTz8SZNN+zosvkUQZD11sr0AgFr9UB8AAFNTkPzXGd/mjWztIeTpOCEhxGN08udKs SSog==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=d6ZkP5AHoWt4wEJ0JDodt01gl5G3ukrLAbQ9f/ABQQA=; b=iApvRJvTu55Olao5f5Dg6rN9K6dYEcTBv1dxyPmjJvg1xseMn9ou/Y3Gy1yASwhhSG AxNXjxL+Q8dO5b5uQ+8EE0d6koOHfcl3muzo71QtapoPFNtHBf4YBHapKA1kcC6nKiyV 3dntyU7kHNmvx5z/PJLyhG5QDTJO0GLkxLetn+Mb8P8axTYoDHrnXf+FM5GIvKeQuxnc VUHlGDZO6cTCbIyCDtiXbqodTSqXwqV3Xv8MsjBioOYxiaxpiPQoPBZZWXgGPAwa9H1A rlzWR41SmzpYH/BWfS4RrthEPJ7COb1vJMfqeKbpBrVB6NoionfgbEi5izQDKFPEDUJW SzQQ==
X-Gm-Message-State: AA6/9Rm6+mD1OZNOvm6tBlhSTRs5KSq97bGpEDejnU8Yb50Z2qgfm0Vcqf8cjf4YPj2xlg==
X-Received: by 10.194.158.193 with SMTP id ww1mr216770wjb.176.1476265725946; Wed, 12 Oct 2016 02:48:45 -0700 (PDT)
Received: from [192.168.1.13] ([46.120.57.147]) by smtp.gmail.com with ESMTPSA id n9sm1971548wmi.13.2016.10.12.02.48.44 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 12 Oct 2016 02:48:45 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 10.0 \(3226\))
From: Yoav Nir <ynir.ietf@gmail.com>
In-Reply-To: <B65455AD-F73C-40ED-B704-201B17CE1D4B@adobe.com>
Date: Wed, 12 Oct 2016 12:48:41 +0300
Content-Transfer-Encoding: quoted-printable
Message-Id: <E7602579-9288-4011-82BA-1A8D6012C4BC@gmail.com>
References: <B65455AD-F73C-40ED-B704-201B17CE1D4B@adobe.com>
To: Antonio Sanso <asanso@adobe.com>
X-Mailer: Apple Mail (2.3226)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/EW9BL391MoOESjtPmDEuSxCwGCw>
Cc: Security Area Advisory Group <saag@ietf.org>
Subject: Re: [saag] Possible backdoor in RFC 5114
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Oct 2016 09:48:49 -0000

> On 12 Oct 2016, at 10:17, Antonio Sanso <asanso@adobe.com> wrote:
> 
> hi Yoav
> 
>> IANA numbers have been assigned to them for IKE, but they have not seen widespread use
> 
> I would not be too sure about this. For example see [0]. On top Exim and BouncyCastle have RFC 5114 as default for DH. 
> And more to come…
> 

Hey, if you’re collecting them, it is possible (though annoying) to configure “group 24” on Check Point gateways ([0]).

But I don’t know any IKE implementations that use that by default.

Yoav

[0] https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk27054