Re: [secdir] secdir review of draft-moonesamy-sshfp-ed25519-01

S Moonesamy <sm+ietf@elandsys.com> Fri, 30 May 2014 22:22 UTC

Return-Path: <sm@elandsys.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B63E1A0379; Fri, 30 May 2014 15:22:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.441
X-Spam-Level:
X-Spam-Status: No, score=-2.441 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, RP_MATCHES_RCVD=-0.651, T_DKIM_INVALID=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QxMTeBLwgRAp; Fri, 30 May 2014 15:22:55 -0700 (PDT)
Received: from mx.ipv6.elandsys.com (mx.ipv6.elandsys.com [IPv6:2001:470:f329:1::1]) by ietfa.amsl.com (Postfix) with ESMTP id 31DC81A0262; Fri, 30 May 2014 15:22:55 -0700 (PDT)
Received: from SUBMAN.elandsys.com ([197.224.140.99]) (authenticated bits=0) by mx.elandsys.com (8.14.5/8.14.5) with ESMTP id s4UMMUQp006917 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 30 May 2014 15:22:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=opendkim.org; s=mail2010; t=1401488564; bh=67I5WXe1tL10Tt6T5NYcHikBhPp3AQUX+C0h2ZiObwk=; h=Date:To:From:Subject:Cc:In-Reply-To:References; b=RG2QmtSZDhtNB89F36oLCWy8fL5F4/l42XS0usa8JB0gNqNfvohX1yTOasayqYjYg gqtFee6SyvJQHvVsgq2N+Q/P0hxBWtCbQjGodJerYUjSZj8XekuqtizIU675A4/MF9 qFnj7xnHnuYx4JSyUwkotoFCIwH88VXYKrLsBKQ8=
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=elandsys.com; s=mail; t=1401488564; i=@elandsys.com; bh=67I5WXe1tL10Tt6T5NYcHikBhPp3AQUX+C0h2ZiObwk=; h=Date:To:From:Subject:Cc:In-Reply-To:References; b=2CIiRDw3+sxgdYIhQu30/Ahhu/wZUAxX5BuOCEyW1WZdF60MMbCeszbbg6oP+uZCy Ucndyws2wbx436D6QtvoPFJQ7lor5x55nemLZucHfCqHqfkM0m1g97Q63dErvBXvvA 6AluewFNfRA9qJyswbXfglBbIvb2vVDrgjwM0vdA=
Message-Id: <6.2.5.6.2.20140530135131.0c7bdba0@elandnews.com>
X-Mailer: QUALCOMM Windows Eudora Version 6.2.5.6
Date: Fri, 30 May 2014 15:22:26 -0700
To: "Joseph Salowey (jsalowey)" <jsalowey@cisco.com>
From: S Moonesamy <sm+ietf@elandsys.com>
In-Reply-To: <868A3427-6B46-4110-8D4B-45857D260C1D@cisco.com>
References: <2ACBFFE4-BCEB-4F6D-A2D3-861BADF543DE@cisco.com> <6.2.5.6.2.20140530040300.0bb93070@elandnews.com> <D1342262-144C-4939-B005-5E042CAF7394@cisco.com> <20140530141618.kgnw4u9b4gw80o4s@webmail.mit.edu> <6.2.5.6.2.20140530114625.0c0d1aa8@elandnews.com> <868A3427-6B46-4110-8D4B-45857D260C1D@cisco.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/8uR1RgfBC9BzT8ydaXFmXk3cBe4
Cc: iesg@ietf.org, secdir@ietf.org, ietf@ietf.org, draft-moonesamy-sshfp-ed25519.all@tools.ietf.org
Subject: Re: [secdir] secdir review of draft-moonesamy-sshfp-ed25519-01
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 May 2014 22:22:56 -0000

Hi Joe,
At 13:42 30-05-2014, Joseph Salowey (jsalowey) wrote:
>[Joe] My concern is that there is not enough information in the 
>draft to know what goes into the hash that is the subject of the 
>code point assignment.  Perhaps it is obvious to someone who 
>implemented the SSH code that is not documented in this draft, but 
>it is not obvious to me as a reader of the draft.

That's a fair point.  I propose adding the following text in Section 
2 as a warning to the reader:

   The format of the ED25519 public key with SHA-256 fingerprint is
   not documented in an authoritative specification.

Regards,
S. Moonesamy