Re: [saag] SSH & Ntruprime

Michael StJohns <msj@nthpermutation.com> Mon, 25 March 2024 16:22 UTC

Return-Path: <msj@nthpermutation.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA0C6C14CE4A for <saag@ietfa.amsl.com>; Mon, 25 Mar 2024 09:22:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.906
X-Spam-Level:
X-Spam-Status: No, score=-1.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nthpermutation-com.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7Y-AZ1RUK5kh for <saag@ietfa.amsl.com>; Mon, 25 Mar 2024 09:22:13 -0700 (PDT)
Received: from mail-qk1-x734.google.com (mail-qk1-x734.google.com [IPv6:2607:f8b0:4864:20::734]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9678CC14CF1C for <saag@ietf.org>; Mon, 25 Mar 2024 09:22:13 -0700 (PDT)
Received: by mail-qk1-x734.google.com with SMTP id af79cd13be357-789db917876so278579785a.1 for <saag@ietf.org>; Mon, 25 Mar 2024 09:22:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nthpermutation-com.20230601.gappssmtp.com; s=20230601; t=1711383731; x=1711988531; darn=ietf.org; h=in-reply-to:from:references:to:content-language:subject:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to; bh=zEAt/5huzZLpPKo1MNE759Mk+RGJUbcSRlm9r40tQ0o=; b=Fajelv1suXos9QlSvrIfwihBgTHnMc75wItIKvMJ+htqjjBM4iesYnly0e/J30DFS6 OivuxWRVdbe6xtGC58cXDiKVEJtZcj3Qxn2FvQu4sNZUmbR0ZJ8wL8vb8GvClqW0M+Gw cF5Rqzy3S2ykl8DhD2QqaMvFVulBz7C9wc0iRFYbydscqtnvIB8pi/CA+XP0FPbjt1Oa PTBvwxeaVyaWflWlE90UZtX2G0IAtkg1Q6Kwyk+syocLYkhfvY49YQplgV7ChYUV2Rjq moYgFVCmMgRfYkXFml6WpHV4QCVmUf+jK5tB9C5cxf7qDEsmcXcJIJz+Rzz93Lk/tl3E m/RA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1711383731; x=1711988531; h=in-reply-to:from:references:to:content-language:subject:user-agent :mime-version:date:message-id:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to; bh=zEAt/5huzZLpPKo1MNE759Mk+RGJUbcSRlm9r40tQ0o=; b=HOZYG9s3u/AmVBMDGetriYJ53gTCQnitVTLG4OwGciqpgpe5OLeUVQ8/HAAitahzsZ UejInfi3pzxo3d5uT9flPwOnH/lMZ/i+rRcBnEAPWtVUniWjDmfpFaOK3+UNVfMpxbSP xibYTnGZIqLS/7lHYZGKqKf1Q4+GIBA+m20+mLWl+FavSlFN260EkfPUD2NQPRvVo0JJ p+LZ+NCU5OonmvWcWXhK9dRznIhOiI8TKOLcV2FuS1sPF/qlzIZuSe+H2dFMeYbzAeFe GgIbc70lJgK6rB6pCrrmAzdhdUx+6/OtyWxxDnQwFEz4yILvmiJYSNpor3+lUS3wAAtJ cHjQ==
X-Gm-Message-State: AOJu0YwAFcHyeF4NNleheMv7PNBQumc58AwR59Jy0mZ59Op6j7FzfiOS cCmess1SUlXsztYULm4kOB2t2OvAZxZNdfyAwTJTLrFYPNwg7qe7WgAaYWmWnmiIqIt2WTjRklw L
X-Google-Smtp-Source: AGHT+IFfL6w4xW0xVwC4IVEy6WAABTT6/8Ztq8BrkN3NZvRO93Sx+b+5IOnD1lzigAPvfRzGRu9FBQ==
X-Received: by 2002:a05:6214:21ac:b0:696:8feb:d554 with SMTP id t12-20020a05621421ac00b006968febd554mr3097246qvc.45.1711383730840; Mon, 25 Mar 2024 09:22:10 -0700 (PDT)
Received: from [192.168.1.23] (pool-108-31-156-76.washdc.fios.verizon.net. [108.31.156.76]) by smtp.gmail.com with ESMTPSA id jp14-20020ad45f8e000000b0069678dcab9dsm2863108qvb.16.2024.03.25.09.22.10 for <saag@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 25 Mar 2024 09:22:10 -0700 (PDT)
Content-Type: multipart/alternative; boundary="------------V6Vh72w0k8qCpGI8J8nyikdX"
Message-ID: <88a1bb16-b0ef-49b3-a661-c343b4faa7a9@nthpermutation.com>
Date: Mon, 25 Mar 2024 12:22:08 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: saag@ietf.org
References: <CABcZeBPWjXvLh06-DBO3Z0sfeb2hgzqzaSZ-J2-TZ7qesrSraA@mail.gmail.com> <D0CD341B-523B-48A0-8954-EE7F89113241@aiven.io> <AF7B6F32-9EE6-4810-A99A-833DEA917FA9@sonic.net> <CABcZeBPfXQckpZageogUxTYgX2j_Nr_O3bvf-a-x0S_82BHMxg@mail.gmail.com> <079A0AA3-FA02-440F-ABA0-6AF897570E86@sonic.net> <CABcZeBOxfYR+=61DV1XN0F9nrmbzLR2zq_ZvADw4UUy1uFafzw@mail.gmail.com> <8caa2d4d-bc80-4fcf-b8bc-839052371730@lear.ch> <CABcZeBMABJ89T0qY0-9C3xxd=mFfGyCh7_9GKbEUBm6JtR+_ng@mail.gmail.com> <6c491f5c-92da-4fb3-a8b1-da1de27b36a6@lear.ch> <CABcZeBN1w0QU6ug3LcMwC+hTMA_-iOs32FkZe+gpPuFrp1y+JA@mail.gmail.com> <64e81f68-5169-4469-b5a0-2851da912091@lear.ch> <CABcZeBOLKMJb5pw59J072FsfeMFcoz1eZYxa1qpXDLW0nAU0cg@mail.gmail.com> <7b4d38b8-b4c1-412b-8287-bd44d0c512a3@lear.ch> <CABcZeBOQYp49i_JjE7vdg6AjxwyvktW7LFTJ4Mh3jt0bmxxxDQ@mail.gmail.com> <CAN8C-_+QUpU2bTeSFmLB7v1qLirTXtypR2U7D54JeEaeKfSp+Q@mail.gmail.com> <CABcZeBNtE6PtEdmh-2rTC5y9U7yEL8JVNo1HMjZtOQw-DHjXQQ@mail.gmail.com>
From: Michael StJohns <msj@nthpermutation.com>
In-Reply-To: <CABcZeBNtE6PtEdmh-2rTC5y9U7yEL8JVNo1HMjZtOQw-DHjXQQ@mail.gmail.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/zm9jShHUybAFW9wDG2Y-zESCl3A>
Subject: Re: [saag] SSH & Ntruprime
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Mar 2024 16:22:18 -0000

Trimmed.

On 3/25/2024 12:06 PM, Eric Rescorla wrote:
>
>
> On Mon, Mar 25, 2024 at 8:28 AM Orie Steele 
> <orie@transmute.industries> wrote:
>
>     > Internet-Drafts (often referred to simply as "drafts") have no
>     formal status, and are subject to change or removal at any time;
>     therefore they should not be cited or quoted in any formal document.
>     we are the ones hosting their drafts.
>
>
> Yeah, this seems pretty speculative.
>
> Fortunately, we have a natural experiment here, because RFC 8446 
> explicitly allows the registration of TLS code points based on I-Ds, 
> so in five years I guess we can see how that worked.
>
> -Ekr
>
Hi -

I just took a look at RFC8446 and I can't find support for that claim.  
The IANA considerations section refers to RFC8126 and only 
"Specification Required" or "Standards Action" as the path to 
registration.   Searching for "ID", "I-D", "internet draft" and 
"Internet-Draft" doesn't get me anything.

AFAIK, "Specification Required" as defined in 8126 does not include 
Internet Drafts, even under the heading of "informal documentation" .  
Maybe time to ask the IANA?

Later, Mike