Re: [secdir] [IPsec] [Last-Call] Secdir last call review of draft-ietf-ipsecme-qr-ikev2-09

"Panos Kampanakis (pkampana)" <pkampana@cisco.com> Fri, 27 December 2019 04:13 UTC

Return-Path: <pkampana@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 502B712004E; Thu, 26 Dec 2019 20:13:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.502
X-Spam-Level:
X-Spam-Status: No, score=-14.502 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=fmICZQ7a; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=rz8iZvX4
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lgT5BsYRB7kO; Thu, 26 Dec 2019 20:13:28 -0800 (PST)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 41D7812001E; Thu, 26 Dec 2019 20:13:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7297; q=dns/txt; s=iport; t=1577420008; x=1578629608; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=6FX2rp36r9enI/zdOktm4/aGXrKhGM9lZnYiobw8OQo=; b=fmICZQ7aWA1ftwZDRntCWbZgvw9kOugYI6J+T21ZEaHgZVqeLBdHenSt Ff9nYK8hQyINromh4zljMWtxip2WA0cOG53VeEXX838rhi2dYIgSb4mlf Qv2U3ex87fk9dq70aDUuHpQm29mINAbbzrGoo/Kl7SAZba02z4o+9mTIJ 4=;
X-Files: smime.p7s : 4024
IronPort-PHdr: 9a23:vnUnOhHt9Ou/EocxSBDg0Z1GYnJ96bzpIg4Y7IYmgLtSc6Oluo7vJ1Hb+e4z1Q3SRYuO7fVChqKWqK3mVWEaqbe5+HEZON0pNVcejNkO2QkpAcqLE0r+eebpZikiFcJLfFRk5Hq8d0NSHZW2ag==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CuAACqgwVe/4MNJK1kHAEBAQEBBwEBEQEEBAEBgWoFAQELAYFTUAVsKy0gBAsqh04DiniCX5gJgS6BJANUAgcBAQEJAwEBGAsKAgEBhEACgh8kNgcOAgMNAQEEAQEBAgEFBG2FNwyFXgEBAQECAQEBEAsjAQEsCwEEBwQCAQgRBAEBHhECJQsdCAIEAQ0FCAYUgwGBeU0DDhEPAQIMn1wCgTiIYYIngn4BAQWEfxiCBQcDBoE2AYFSikYagUE/gRFHgh4uPoJkAQGBZRWDK4IslxmXfgqCNINhgjeGVolGmleOUppWAgQCBAUCDgEBBYFZAjCBWHAVO4JsUBgNjRI4gzuFFIU/dIEokiYBAQ
X-IronPort-AV: E=Sophos;i="5.69,361,1571702400"; d="p7s'?scan'208";a="391285807"
Received: from alln-core-1.cisco.com ([173.36.13.131]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 27 Dec 2019 04:13:25 +0000
Received: from XCH-ALN-010.cisco.com (xch-aln-010.cisco.com [173.36.7.20]) by alln-core-1.cisco.com (8.15.2/8.15.2) with ESMTPS id xBR4DPb8012752 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Fri, 27 Dec 2019 04:13:25 GMT
Received: from xhs-aln-001.cisco.com (173.37.135.118) by XCH-ALN-010.cisco.com (173.36.7.20) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 26 Dec 2019 22:13:24 -0600
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 26 Dec 2019 22:13:23 -0600
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Thu, 26 Dec 2019 23:13:23 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=iPLfbFYCFMY80Dfh7KTX/xbDpnOhQ+sAVPRQEYjjbUNv7SijSVmAeOFtEFSB4mZoSnTZDXtdwdVyNlcjkHclb10yq2bNOm5aHxcsJCthC5yVK9TcGblPACJqNH6azht3DLJ2t7O6Fdp5Wr9MWS6LFRCKKB50EUtsjilr94jGfq9ctKrUJVYf2lYGMPuFBLfsao5jT5KcyOyvdH4lQU5jU3tzTc0VFGx/KlERnmZcpQhRXIKiU0OhpFzhiwrXbMZScF20xbmnqjVcXk8B6CwQi4GbGVDu5oTlL335F3SAqwWiVIm1RICJN3bQLMgBKvoXJoW+pob+HVHIpex+8HsnSw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lWR6Lfx8rnN3P01Q11KHEuu4VxOm+krUPqUioIlaFKc=; b=iKIoClP3bmiJijYsZGzokhC+m0EXbgfdoh9ief0kTK5u0MTY9G71q/QAVeA6r4JTvUotouCcCXpdyUN0VVF+VtNZ5y8oDQZcAgrLPrj7IAXwo65FacYToXmtFUxWneZLR4guLlaxFelkxliyGWOBlVclVIPg2p9hel+uFtryWVjVwfsyd07sGgjn3FqxDM0WEwYerDHd2H5yyXnQBFc0SGIk9+LGEBVmVnU3gTsx5VlRqw4Dr4i+bqLnDJBlO78bM/KBcSNBhxeaAKbda5DE8N9pfvOImh0Ht9BopK4kJwkSoWl34Nec62VsgPKOZcI99JrWkZ63m4rypxHi0CUz1Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lWR6Lfx8rnN3P01Q11KHEuu4VxOm+krUPqUioIlaFKc=; b=rz8iZvX4j2YJ3mUFNDr6qgNlPJdKS15TqdKlhbwffPgW/WsrBEJM+qVfh5uyfLuaQt7D3/zOW4N27JlgcNh3lsqtPc59Zp3i/TVVtZzy9ZHM3ujj6vYxMYcooaS16nCjDuv5PGAqOZKH3PAkkdtgulxJV/0rXBC+LyPHG101Y3g=
Received: from BN7PR11MB2547.namprd11.prod.outlook.com (52.135.255.146) by BN7PR11MB2563.namprd11.prod.outlook.com (52.135.244.33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2581.11; Fri, 27 Dec 2019 04:13:23 +0000
Received: from BN7PR11MB2547.namprd11.prod.outlook.com ([fe80::e03c:e55a:c03f:5f4f]) by BN7PR11MB2547.namprd11.prod.outlook.com ([fe80::e03c:e55a:c03f:5f4f%7]) with mapi id 15.20.2581.007; Fri, 27 Dec 2019 04:13:23 +0000
From: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>
To: Paul Wouters <paul@nohats.ca>, Valery Smyslov <svan@elvis.ru>
CC: "ipsec@ietf.org WG" <ipsec@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "draft-ietf-ipsecme-qr-ikev2.all@ietf.org" <draft-ietf-ipsecme-qr-ikev2.all@ietf.org>, 'secdir' <secdir@ietf.org>
Thread-Topic: [IPsec] [Last-Call] [secdir] Secdir last call review of draft-ietf-ipsecme-qr-ikev2-09
Thread-Index: AQHVvBYgaemvAijUV0anuRMjqrab/afNX7Lw
Date: Fri, 27 Dec 2019 04:13:22 +0000
Message-ID: <BN7PR11MB25473E6E47CB550630875A06C92A0@BN7PR11MB2547.namprd11.prod.outlook.com>
References: <003901d5bb48$cfc21460$6f463d20$@smyslov.net> <8A4F97F4-723E-41C8-B4F6-C6D65F0BC848@mit.edu> <008601d5bb53$75269480$5f73bd80$@elvis.ru> <alpine.LRH.2.21.1912261257070.11522@bofh.nohats.ca>
In-Reply-To: <alpine.LRH.2.21.1912261257070.11522@bofh.nohats.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=pkampana@cisco.com;
x-originating-ip: [2001:420:c0c4:1003::61]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 54f4d2da-3812-489a-09c7-08d78a831d32
x-ms-traffictypediagnostic: BN7PR11MB2563:
x-microsoft-antispam-prvs: <BN7PR11MB25634794A1EDC40C52B2B51FC92A0@BN7PR11MB2563.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0264FEA5C3
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39860400002)(396003)(136003)(346002)(366004)(376002)(13464003)(189003)(199004)(86362001)(52536014)(4326008)(66616009)(66946007)(66476007)(66556008)(66446008)(64756008)(186003)(76116006)(2906002)(5660300002)(71200400001)(33656002)(316002)(81156014)(9686003)(81166006)(55016002)(54906003)(8676002)(8936002)(7696005)(478600001)(110136005)(53546011)(6506007)(966005); DIR:OUT; SFP:1101; SCL:1; SRVR:BN7PR11MB2563; H:BN7PR11MB2547.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: oRtAfOzVSJjzMxKXMNvvaBekBzUupkLCwkXNNJ3UYJ3OaZ08pWYTbvKOfTmP6xRUnePBDy6JIEWjZWw/SXkNXqxnuuhS6q6/BGyJd1JCs5jiRsQb4MrfWJPhGQ9YGfxooS5fvAClJLV5m3v0UTAIYYv828BXvCRPjWzWBWwB6xOvGMEHo11zwK6bg1K5hKPdhpPcRnGqn5Sz06Cxn3aX6HURhko0Jgh8forXufvT19MNMLQnmGL27bsd02/juz3GK6AZh5LXBNxQp9EA0xEb3oXVKVH2EH81QmdAINBPisETBkJGMyAwodyKbX7L0W5rkfOOo/whTE+A8RUjuTeY+S+tyOMTikmrcenou+xYGJiDuZXf0U+FdKODlH8i7E3cTEcM1eiiyj/SeQ9T0K87xj01qw4IvVOloSuJbJArO3rxczbkuKV9+4P//ec3Y+yBtZp7gra7sj+3haHx9gMbjt3l0okgY92AMlZFjVcUQGoSpYwz69xdjvO4CblEj9BjhI4hewAEO9p76Zotdv2puyNzSeIcUJfwVo3Ni+TxSyk=
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_0026_01D5BC42.103C7A40"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 54f4d2da-3812-489a-09c7-08d78a831d32
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Dec 2019 04:13:22.7873 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: qfTBsDZer67e0xoS0Rp1eu04xcpM1m239WscX4H99KAwbdA4nUT+PmFG+C+sTwq3ItXYBjXnGkiydjAwifcdCg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN7PR11MB2563
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.20, xch-aln-010.cisco.com
X-Outbound-Node: alln-core-1.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/S2e9lIAnVPOkZnbChXfv6HFyeaU>
Subject: Re: [secdir] [IPsec] [Last-Call] Secdir last call review of draft-ietf-ipsecme-qr-ikev2-09
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Dec 2019 04:13:30 -0000

To make sure we mention the NIST PQ Level categorization (that will not
change as the NIST PQ Project progresses), I was thinking we could add
something in the Sec Considerations section like 

   [...] Because of
   this, the user SHOULD ensure that the post-quantum preshared key used
   has at least 256 bits of entropy, in order to provide 128 bits of
   post-quantum security.  That provides security equivalent to Level 5
   defined in the NIST PQ Project Call For Proposals [NISTPQCFP]. 


-----Original Message-----
From: IPsec <ipsec-bounces@ietf.org> On Behalf Of Paul Wouters
Sent: Thursday, December 26, 2019 12:58 PM
To: Valery Smyslov <svan@elvis.ru>
Cc: ipsec@ietf.org WG <ipsec@ietf.org>; last-call@ietf.org;
draft-ietf-ipsecme-qr-ikev2.all@ietf.org; 'secdir' <secdir@ietf.org>
Subject: Re: [IPsec] [Last-Call] [secdir] Secdir last call review of
draft-ietf-ipsecme-qr-ikev2-09

On Wed, 25 Dec 2019, Valery Smyslov wrote:

> Uri, I don't mind referencing NIST levels, but I'd like to first hear 
> from my co-authors,
> 
> who are definitely more experienced in cryptography and in NIST levels 
> than I am :-)

I don't think mentioning the NIST competition is useful. Per definition,
that is incomplete preliminary data.

Paul

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec