Re: [secdir] secdir review of draft-moonesamy-sshfp-ed25519-01

"Joseph Salowey (jsalowey)" <jsalowey@cisco.com> Fri, 30 May 2014 20:42 UTC

Return-Path: <jsalowey@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC57E1A87DB; Fri, 30 May 2014 13:42:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level:
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0odhsYbylP1a; Fri, 30 May 2014 13:42:38 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0E23C1A87CD; Fri, 30 May 2014 13:42:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1181; q=dns/txt; s=iport; t=1401482554; x=1402692154; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=Yf8v+UpTlci5V24Y1wYJjFvst+b+jOVUrQVGMp4c6Ak=; b=PFrDDC1/qzog755jXUuAM3f4YZ3eU7Z+T4qukrbmtt7pH5jbQn9mxKLf UMhycjCobtAJEdUOrqNMo1tdh3Yn9etwAfzt3p3VB28MPDeP9+KWru/pS 300cnf3CsMTf+vb8D51WujWEMKRp7Cdp05uG4mTZ8scO7u1hlRUMTlJV2 w=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Ag8FAOTsiFOtJA2J/2dsb2JhbABZgweBKsI8AYEMFnSCJQEBAQMBOj8FCwIBCBgeEDIlAgQOBYg6CNcwF44fMweDK4EVAQOZfpMtgziCLw
X-IronPort-AV: E=Sophos;i="4.98,943,1392163200"; d="scan'208";a="329289981"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by rcdn-iport-8.cisco.com with ESMTP; 30 May 2014 20:42:32 +0000
Received: from xhc-aln-x12.cisco.com (xhc-aln-x12.cisco.com [173.36.12.86]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s4UKgWmF021533 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 30 May 2014 20:42:32 GMT
Received: from xmb-rcd-x09.cisco.com ([169.254.9.239]) by xhc-aln-x12.cisco.com ([173.36.12.86]) with mapi id 14.03.0123.003; Fri, 30 May 2014 15:42:32 -0500
From: "Joseph Salowey (jsalowey)" <jsalowey@cisco.com>
To: S Moonesamy <sm+ietf@elandsys.com>
Thread-Topic: [secdir] secdir review of draft-moonesamy-sshfp-ed25519-01
Thread-Index: AQHPeWUfo5K1BZN1JUqd29NR7Q9teZtZWecAgABWFICAABeMAIAAC10AgAAdfoA=
Date: Fri, 30 May 2014 20:42:31 +0000
Message-ID: <868A3427-6B46-4110-8D4B-45857D260C1D@cisco.com>
References: <2ACBFFE4-BCEB-4F6D-A2D3-861BADF543DE@cisco.com> <6.2.5.6.2.20140530040300.0bb93070@elandnews.com> <D1342262-144C-4939-B005-5E042CAF7394@cisco.com> <20140530141618.kgnw4u9b4gw80o4s@webmail.mit.edu> <6.2.5.6.2.20140530114625.0c0d1aa8@elandnews.com>
In-Reply-To: <6.2.5.6.2.20140530114625.0c0d1aa8@elandnews.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.33.248.34]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <CE59F929DCD8674083BE1224E39AAE27@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/gskPusrx2dB8pLX9nsucEe2Wxuc
Cc: "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>, "draft-moonesamy-sshfp-ed25519.all@tools.ietf.org" <draft-moonesamy-sshfp-ed25519.all@tools.ietf.org>
Subject: Re: [secdir] secdir review of draft-moonesamy-sshfp-ed25519-01
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 May 2014 20:42:40 -0000

On May 30, 2014, at 11:56 AM, S Moonesamy <sm+ietf@elandsys.com> wrote:

> Hi Uri,
> At 11:16 30-05-2014, Uri Blumenthal wrote:
>> I personally would not accept source code as the sole specification. IETF
>> tradition has always been providing both the "verbal" description in English
>> (or as close to it as practical) *plus* a reference implementation, preferably
>> more than one.
>> 
>> Mere existence of an implementation has never been an excuse to weasel out of
>> actually documenting the protocol.
> 
> IETF tradition is not to copy SecDir reviews to ietf@ietf.org.  I agree that it is good to have a verbal description of a specification in English.  It helps to have an implementation.
> 
> The draft documents a code point assignment; it is not about a protocol.
> 

[Joe] My concern is that there is not enough information in the draft to know what goes into the hash that is the subject of the code point assignment.  Perhaps it is obvious to someone who implemented the SSH code that is not documented in this draft, but it is not obvious to me as a reader of the draft. 

> Regards,
> S. Moonesamy