Re: [secdir] Secdir review of draft-ietf-jose-json-web-algorithms-31

Mike Jones <Michael.Jones@microsoft.com> Tue, 23 September 2014 23:08 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C70981A891B; Tue, 23 Sep 2014 16:08:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.901
X-Spam-Level:
X-Spam-Status: No, score=-0.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_SUMOF=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QHLD_iClh8Ky; Tue, 23 Sep 2014 16:08:35 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0103.outbound.protection.outlook.com [207.46.100.103]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0645E1A895E; Tue, 23 Sep 2014 16:08:34 -0700 (PDT)
Received: from CO2PR03CA0051.namprd03.prod.outlook.com (10.141.194.178) by CY1PR0301MB1212.namprd03.prod.outlook.com (25.161.212.146) with Microsoft SMTP Server (TLS) id 15.0.1034.13; Tue, 23 Sep 2014 23:08:33 +0000
Received: from BN1AFFO11FD059.protection.gbl (2a01:111:f400:7c10::134) by CO2PR03CA0051.outlook.office365.com (2a01:111:e400:1414::50) with Microsoft SMTP Server (TLS) id 15.0.1034.13 via Frontend Transport; Tue, 23 Sep 2014 23:08:12 +0000
Received: from mail.microsoft.com (131.107.125.37) by BN1AFFO11FD059.mail.protection.outlook.com (10.58.53.74) with Microsoft SMTP Server (TLS) id 15.0.1029.15 via Frontend Transport; Tue, 23 Sep 2014 23:08:11 +0000
Received: from TK5EX14MBXC286.redmond.corp.microsoft.com ([169.254.1.23]) by TK5EX14MLTC103.redmond.corp.microsoft.com ([157.54.79.174]) with mapi id 14.03.0195.002; Tue, 23 Sep 2014 23:07:31 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Charlie Kaufman <charliekaufman@outlook.com>, "secdir@ietf.org" <secdir@ietf.org>
Thread-Topic: Secdir review of draft-ietf-jose-json-web-algorithms-31
Thread-Index: Ac/EILVlvaO6koWmSBq1KV+ptV1KBQC8PqQwBBxUMCA=
Date: Tue, 23 Sep 2014 23:07:30 +0000
Message-ID: <4E1F6AAD24975D4BA5B16804296739439BA6EF7C@TK5EX14MBXC286.redmond.corp.microsoft.com>
References: <COL401-EAS1838D8ED8A7323D3422439EDFD80@phx.gbl> <4E1F6AAD24975D4BA5B16804296739439AE76076@TK5EX14MBXC294.redmond.corp.microsoft.com>
In-Reply-To: <4E1F6AAD24975D4BA5B16804296739439AE76076@TK5EX14MBXC294.redmond.corp.microsoft.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.54.51.78]
Content-Type: multipart/alternative; boundary="_000_4E1F6AAD24975D4BA5B16804296739439BA6EF7CTK5EX14MBXC286r_"
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:131.107.125.37; CTRY:US; IPV:NLI; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(438002)(377454003)(51914003)(199003)(189002)(77982003)(4396001)(31966008)(74502003)(92566001)(95666004)(46102003)(86362001)(74662003)(68736004)(69596002)(92726001)(77096002)(85852003)(81542003)(76482002)(83072002)(81342003)(97736003)(80022003)(15975445006)(79102003)(19580395003)(10300001)(120916001)(2501002)(6806004)(19580405001)(85306004)(21056001)(107046002)(90102001)(19617315012)(44976005)(512954002)(81156004)(19300405004)(85806002)(551984002)(66066001)(106466001)(2656002)(76176999)(16236675004)(20776003)(84326002)(15202345003)(99396002)(104016003)(83322001)(19625215002)(64706001)(55846006)(87936001)(54356999)(86612001)(33656002)(84676001)(551544002)(50986999)(230783001)(71186001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR0301MB1212; H:mail.microsoft.com; FPR:; MLV:sfv; PTR:InfoDomainNonexistent; A:1; MX:1; LANG:en;
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:CY1PR0301MB1212;
X-O365ENT-EOP-Header: Message processed by - O365_ENT: Allow from ranges (Engineering ONLY)
X-Forefront-PRVS: 0343AC1D30
Received-SPF: Pass (protection.outlook.com: domain of microsoft.com designates 131.107.125.37 as permitted sender) receiver=protection.outlook.com; client-ip=131.107.125.37; helo=mail.microsoft.com;
Authentication-Results: spf=pass (sender IP is 131.107.125.37) smtp.mailfrom=Michael.Jones@microsoft.com;
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/kB4McbPpZXbkOYyIrUgVW_DQmGA
Cc: "iesg@ietf.org" <iesg@ietf.org>, "jose@ietf.org" <jose@ietf.org>
Subject: Re: [secdir] Secdir review of draft-ietf-jose-json-web-algorithms-31
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Sep 2014 23:08:39 -0000

Thanks again for your review, Charlie.  The proposed resolutions below have been applied in the -32 draft.

                                                                -- Mike


From: jose [mailto:jose-bounces@ietf.org] On Behalf Of Mike Jones
Sent: Tuesday, September 02, 2014 6:39 PM
To: Charlie Kaufman; secdir@ietf.org
Cc: draft-ietf-jose-json-web-algorithms.all@tools.ietf.org; iesg@ietf.org; jose@ietf.org
Subject: Re: [jose] Secdir review of draft-ietf-jose-json-web-algorithms-31

Thanks for the useful review, Charlie.  Responses and proposed resolutions follow inline.  Working group - please review.

From: Charlie Kaufman [mailto:charliekaufman@outlook.com]
Sent: Saturday, August 30, 2014 12:12 AM
To: secdir@ietf.org<mailto:secdir@ietf.org>
Cc: draft-ietf-jose-json-web-algorithms.all@tools.ietf.org<mailto:draft-ietf-jose-json-web-algorithms.all@tools.ietf.org>; iesg@ietf.org<mailto:iesg@ietf.org>
Subject: Secdir review of draft-ietf-jose-json-web-algorithms-31

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written primarily for the benefit of the security area directors.  Document editors and WG chairs should treat these comments just like any other last call comments.

This document sets the initial IANA registry values for the labels to be used to specify choices of cryptographic algorithms in the context of the JSON Web Encryption, JSON Web Signature, and JSON Web Key documents (parallel I-Ds). Some aspects of how the algorithms are used are specified here; others aspects reference other documents.

The issues I found with this document (all of which are minor):

Section 3.4 line 4 says Elliptic Curves are generally faster to execute (for equivalent security) than RSA. While that is true for private key operations (and even more dramatically so for key generation), it is generally not true for public key operations. This is a nit in the text since these trade-offs are well understood.

What if we were to change the phrase "with greater processing speed" to "with greater processing speed for many operations"?

Section 4.5 Direct Encryption: It might be too late to change existing implementations, but it generally a good idea when using pre-negotiated keys to include some key identifier in the header to remove ambiguity in the case where there are multiple pre-negotiated keys (perhaps because they are in the process of being updated and they are not atomically updated on both ends of the connection).

The "kid" (Key ID) header parameter defined in the JWE spec already enables this to be done.

Section 5.1: I don't believe the pairings of AES128/HMAC-SHA256, AES192/HMAC-SHA384, and AES256/HMAC-SHA512 are "natural" in the sense of providing equivalent cryptographic strength. Without the HMAC, they would, but I believe HMAC-SHA256 is generally believed to have 256 bits of cryptographic strength, making it suitable for pairing with any of the three AES key sizes. The choices of the longer SHA2 variants are conservative, however, and so do no harm if these pairings are already in widespread use.

They are in use and are the pairings chosen by David McGrew, a just departed CRFG chair, and Kenny Paterson, a current CRFG chair, in draft-mcgrew-aead-aes-cbc-hmac-sha2.

Section 5.2: Similarly, it is not appropriate to have the length of the Message Authentication Code (MAC) reflect the key length, since it does not affect cryptographic strength but rather the strength against on-line MAC guessing attacks. For this purpose, 128 bits is generally considered adequate for all key sizes and many implementations truncate this to 96 bits or even 64. Again, the current specification is conservative (if slightly wasteful of bandwidth), and so does not harm if this is already in widespread use.

(Same answer as to the previous comment)

Section 5.2.2.1 says "The number of octets in the input key K is the sum of MAC_KEY_LEN and ENC_KEY_LEN." I believe it would be better to say something like "MUST BE the sum". The text goes on to say that the two keys must not overlap, but it is also important that an implementation not tolerate a gap between the two keys is a too large key is provided.

OK

Section 5.2.2.2 says the authenticated decryption operation has four inputs... . I believe it has a fifth: the IV. Alternately, the IV is pre-pended to the ciphertext (and hence implicitly included in 'E').

Agreed the IV is a fifth input.  I'll make this change.

Section 5.3 specifies AES/GCM in much less detail than the description of AES/HMAC in Section 5.2. Is this because the referenced document [NIST.800-38D] includes all the needed details (like use of PKCS7 padding)?

Yes

Section 6.2.1.1: Because of the controversy over NSA allegedly planting backdoors in the "NIST curves" listed, there is a growing demand that additional curves be supported. You might want to specify how additional curves can be specified in-line and/or how to get additional curves added to the IANA registry.

Agreed.  We can tweak the IANA language in this section (and possibly others using similar language) to be clearer on this point.

Section 8.7: I believe the advice in this section is too strong. It is generally considered secure to encrypt multiple data sets with the same key so long as the IV is correctly chosen and it is also generally considered secure to encrypt the same data set with multiple different keys. There are many scenarios in which this is nearly impossible to avoid. It is important that when encryption multiple data sets with the same key that the IV be chosen appropriately - which is very challenging when using GCM as noted in section 8.4.

The current language was added to resolve issue #28 http://trac.tools.ietf.org/wg/jose/trac/ticket/28 and is a result of a good bit of discussion with Michael Peck, Jim Schaad, and others in the working group on the JOSE mailing list between June 2013 and August 2013, with the issue being closed by Jim in October 2013.

I recognize that of the problem here is that the security considerations actually vary by algorithm and yet this subsection is trying to provide general guidance.

Is there a specific wording change that you'd like to propose that would weaken the advice when it's OK to weaken it, but not in any other circumstances?

Section 8.8: I believe the advice in this section is too weak. It is generally bad practice to derive cryptographic keys from passwords as passwords almost never have adequate entropy. Where possible, it would be better to have a strong (i.e. randomly chosen) cryptographic key associated with an entity and then use the password to acquire that cryptographic key. There are a number of means for doing that, including having the strong key encrypted with the password (or XORed with it) stored someplace the entity can access it, by having a server that will return the key based on a provided password, or with a strong password authentication protocol. Deriving the key from a password using PBES should be a last resort and demanding a longer password to derive a 256 bit key is only fooling yourself... you are never likely to get more than 64 bits of entropy.

Note that password-based encryption, as used by this specification, does employ a randomly chosen content encryption key, and uses the password-based encryption only to encrypt the CEK.  Does that alleviate your concerns?  If not, could you supply specific proposed wording changes that would?

                --Charlie

                                                                Thanks again,
                                                                -- Mike