Re: [saag] CFRG, CFRG crypto review panel and IETF consensus

Simon Josefsson <simon@josefsson.org> Fri, 19 April 2024 07:51 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98B56C14F5FB for <saag@ietfa.amsl.com>; Fri, 19 Apr 2024 00:51:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.098
X-Spam-Level:
X-Spam-Status: No, score=-7.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="qGKuZ05W"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="Vbekuqgf"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NEOFwX6RVaeJ for <saag@ietfa.amsl.com>; Fri, 19 Apr 2024 00:50:56 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [IPv6:2001:9b1:8633::107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4852CC14F5EA for <saag@ietf.org>; Fri, 19 Apr 2024 00:50:55 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:In-Reply-To :Date:References:Subject:Cc:To:From:Sender:Reply-To:Content-Transfer-Encoding :Content-ID:Content-Description; bh=39FhKqd0/CZW2P5S/UHGr/InBGJF6MdX7tFZSM7YMv4=; t=1713513052; x=1714722652; b=qGKuZ05WIwQfP1vShGUf9CFVNnrr8MO5/PmVbvF3qIGRW2zcps97b3g+HaDNUkZmJRlIiOLMRny n/zcYn346Cg==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID: In-Reply-To:Date:References:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=39FhKqd0/CZW2P5S/UHGr/InBGJF6MdX7tFZSM7YMv4=; t=1713513052; x=1714722652; b=VbekuqgfSGT1lqPZaPASKOi69BAKuNsVu0RSOyb3lE6gcfEtFutFWnJncDIJHIXdf8CfSh2LDy7 1tQjo5eS8L3YCL1x4/UkI0HLgpvWfh9BxmFCFal7ZSzvSZm2C9TtKkyS/wAcCZiQc1YHKV/f1UlRD Z985lJIgXVEBeZj0YOmlBEaTLDlBjrW/gp3AQ1ADDTZKC8Ii484I4bhRRmAChCzfqAQcx92w7eUsq aPOFh4C+F1Mkm++wOfWze+PmnB80HvZxcHr7bptuZCxRiTpdvAxYggqxvRRm4f9ms//ZxNvIPIhqc FP4WwaPsprGQvLbX5r7kGIGwWwhIaZFDhcPMkbuIxiEhW36I4AcvPjmLYhS57/MbprT1uXQhUDhfj t56piYbZlBgLSpOLBJ+G7LEyNaxhMIsHJ2KBRys2627XeeqoHhvyyLEpSRdozAZZoKE3pHu2f;
Received: from [2001:9b1:41ac:ff00:823f:5dff:fe09:16ac] (port=36372 helo=kaka) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1rxj1G-00Dcpn-2B; Fri, 19 Apr 2024 07:50:50 +0000
From: Simon Josefsson <simon@josefsson.org>
To: Eric Rescorla <ekr@rtfm.com>
Cc: Stephen Farrell <stephen.farrell@cs.tcd.ie>, IETF SAAG <saag@ietf.org>
References: <CACsn0cn_G=aAB_XdNrEoxfdPkKucjC4RRvNhtns=zR7bUuvYLQ@mail.gmail.com> <53ac606e-2c27-4fb9-a456-4787f1747406@cs.tcd.ie> <CABcZeBPFXOzvwLdO_KFfaWmQsGD8HcuO14X5aPap09rEHwi8Og@mail.gmail.com>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:240419:saag@ietf.org::1FiIJBIOk4cH10OU:GYJF
X-Hashcash: 1:23:240419:stephen.farrell@cs.tcd.ie::/HYmhHuPgPNIc1yf:Jxb1
X-Hashcash: 1:23:240419:ekr@rtfm.com::0ROpVFftgZdyNWT0:0KlKf
Date: Fri, 19 Apr 2024 09:50:57 +0200
In-Reply-To: <CABcZeBPFXOzvwLdO_KFfaWmQsGD8HcuO14X5aPap09rEHwi8Og@mail.gmail.com> (Eric Rescorla's message of "Thu, 18 Apr 2024 13:13:26 -0700")
Message-ID: <87ttjxg59a.fsf@kaka.sjd.se>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha256"; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/F9FxCjXAzDZ-Db78OmUg7pc5BaU>
Subject: Re: [saag] CFRG, CFRG crypto review panel and IETF consensus
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Apr 2024 07:51:01 -0000

Eric Rescorla <ekr@rtfm.com> writes:

> This is an individual submission, AD sponsorship of individual drafts
> is entirely at AD discretion, and Paul has opted not to sponsor.

Hi Eric.  That doesn't match my understanding.  The datatracker history:

https://datatracker.ietf.org/doc/draft-josefsson-ntruprime-ssh/history/

Roman has been AD shepherd since 2023-09-08 until it was changed a month
ago to Deb.  The Last Call announcement was made on 2023-09-14 and there
has been OPSDIR, SECDIR, GENARTS and IANA reviews of the document.
Roman's AD review includes a statement that he AD sponsor the document:

https://mailarchive.ietf.org/arch/msg/saag/lFnPC9QhTYiAX8dj1LyzzRw7avo/

The crypto panel review is not recorded in the datatracker nor was it
sent to document authors (otherwise we would have replied and worked on
resolving the concerns), which seems like a process concern.

/Simon