Re: [secdir] [Cfrg] Time to recharter CFRG as a working group? Was: Re: ISE seeks help with some crypto drafts

Peter Gutmann <pgut001@cs.auckland.ac.nz> Wed, 20 March 2019 14:39 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFFB91279A8 for <secdir@ietfa.amsl.com>; Wed, 20 Mar 2019 07:39:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3hf9eAnFKjkw for <secdir@ietfa.amsl.com>; Wed, 20 Mar 2019 07:39:52 -0700 (PDT)
Received: from mx4-int.auckland.ac.nz (mx4-int.auckland.ac.nz [130.216.125.246]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F02B2127988 for <secdir@ietf.org>; Wed, 20 Mar 2019 07:39:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1553092792; x=1584628792; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=r/Me8D5nPkFjsG6pKPove5Y6QFvdciqvRCn9h/1YyUw=; b=FlpqM0IRN1S7Hb0BHiFxn6WOwdt5obGmwTz+UYAZtSAGVHXYnF2p130u vD+DF9pswYtlU3eUEGefyrj023pBPfeN3MwNODTQVe0+55Jr1zVbrSwer tUXMCgGm0omr01G/y0hYQOFvgAC8buq5KNeEX0JBeWU8XEzW8hcwfOhFi lD2AXA231zJh2AKOm4nUnpZjqURE6AufTnkqqVl3rZiWh9LsnMPAAlLD6 rtdWeMJk12ORUXbZMKOOFtnmnVXwGxXmh6siB+4bNOsNPglPU4sXmkaIu TrZONkT51Ax1/dxkMQMNxmBNYR38QJrPjusv+8JKdCTfUKJG5BUBS3KyH w==;
X-IronPort-AV: E=Sophos;i="5.60,249,1549882800"; d="scan'208";a="52434794"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 10.6.2.3 - Outgoing - Outgoing
Received: from smtp.uoa.auckland.ac.nz (HELO uxcn13-ogg-b.UoA.auckland.ac.nz) ([10.6.2.3]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 21 Mar 2019 03:39:48 +1300
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz (10.6.2.5) by uxcn13-ogg-b.UoA.auckland.ac.nz (10.6.2.3) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Thu, 21 Mar 2019 03:39:48 +1300
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.5]) by uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.5]) with mapi id 15.00.1395.000; Thu, 21 Mar 2019 03:39:48 +1300
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Tero Kivinen <kivinen@iki.fi>
CC: Paul Wouters <paul@nohats.ca>, Watson Ladd <watsonbladd@gmail.com>, Martin Thomson <mt@lowentropy.net>, denis bider <denisbider.ietf@gmail.com>, secdir <secdir@ietf.org>
Thread-Topic: [secdir] [Cfrg] Time to recharter CFRG as a working group? Was: Re: ISE seeks help with some crypto drafts
Thread-Index: AQHU3aTDUNM95/0j6k6IffzkMJOWPaYQyH0AgAFcYn2AAZTBgIAA4CSJ
Date: Wed, 20 Mar 2019 14:39:47 +0000
Message-ID: <1553092722905.88359@cs.auckland.ac.nz>
References: <1d8de489fc976b63a911573300a431d4.squirrel@www.amsl.com> <20190310182935.GE8182@kduck.mit.edu> <B876B124-7EDE-4E20-A878-3AAD3FA074BC@krovetz.net> <20190310191026.GF8182@kduck.mit.edu> <CAHOTMVJcosEgYV9caWapgyzQfh-g4k5DQry5n42bEfrkJvmdWQ@mail.gmail.com> <042b3f13-7d5a-12d7-e604-9f8cad197608@cs.tcd.ie> <CANeU+ZCmiTKfE1_YgjM6GX9ZCw_35mZoT8M-6VL72UhbenT2og@mail.gmail.com> <3FA4B2DD-334E-4C7C-A01E-6C370CAE4C00@ll.mit.edu> <2935C6E3-3AE8-4447-BA01-8DAE0410E5C6@ericsson.com> <CAL02cgSeCgAOOh3oMhJZqCGvT0F=JQ6n-bmgWYU=6hxkV+aOHQ@mail.gmail.com> <0d38eabd-6f90-2d19-3b45-f1ce19ba9b73@nthpermutation.com> <CAL02cgRVXn2U3SKhGh6biTZJKmHM6KrW6D_rVB2-ZTC5Oohh4w@mail.gmail.com> <829ca608-8d47-083e-e0a6-e7276525b080@nthpermutation.com> <5FAC333B-38EF-4F58-89FB-3DF3F774DD2C@inf.ethz.ch> <F6A7941E-17AD-4525-905B-B76E09D8E780@nohats.ca> <679B6759-5AD3-4F28-9EF4-8794F383468B@mit.edu> <CADPMZDDYNoxK1uu06MFp4==GfAmRucCXO8R63X+q6bV0=OoXwg@mail.gmail.com> <df8882e7-da71-9007-4440-5777958fd87c@gmail .com> <CADPMZDCaeN7iLuPgAe5gSQDvMRx6eGut6rqcAM7GQLWPwBFLPA@mail.gmail.com> <1552890164140.4569@cs.auckland.ac.nz> <CADPMZDC4ONMPoGfT2LAotjkbxWxr1LkOWmc735Lqc9hWCkECoA@mail.gmail.com> <CACsn0cn2yop7oD+-6jUD3LpDY85YqoPY5sqKSLBBed-m++50Cg@mail.gmail.com> <B2DC61AF-3C81-4B16-A045-E9D5D8B7F68B@nohats.ca> <1552957626423.33373@cs.auckland.ac.nz>, <23698.19223.566447.639174@fireball.acr.fi>
In-Reply-To: <23698.19223.566447.639174@fireball.acr.fi>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/ax_LzslRikcN27zk3eT-0dfjIAU>
Subject: Re: [secdir] [Cfrg] Time to recharter CFRG as a working group? Was: Re: ISE seeks help with some crypto drafts
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Mar 2019 14:39:55 -0000

Tero Kivinen <kivinen@iki.fi> writes:

>Secsh WG was active between 1997-2006. The filexfer-02 was published in 2001
>and final filexfer-13 was published in 2006, i.e., the -13 version is what
>the working group was working on. My understanding was that the issue was
>that openssh did not want to implement what was specified in the working
>group because of the issues with trademarks, personalities and things not at
>all relevant to the actual protocol development or IETF work.

I think it was more than just that, if you look at what you'd need to do for
an -02 client, so "General Packet Format" to the end of "Requests From the
Client to the Server" that's fifteen pages.  In -13 the same thing is forty-
two pages (!!), and also draws in chunks of NFSv4 by reference.  It's gone
from being a means of getting a file from A to B to trying to reinvent NFS,
with all the attendant complexity.

I can see why an implementer would want to stop at -02, which is exactly what
I did when I had to do an SFTP implementation, -13 had reached the point where
it was growing without bounds with little to no benefit from the massive
complexity being added to it.

Peter.