Re: [Secdispatch] [EXTERNAL]Re: Clarification Question for the Comment from Eric Rescorla (

Eric Rescorla <ekr@rtfm.com> Thu, 12 December 2019 16:52 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B71C1209CC for <secdispatch@ietfa.amsl.com>; Thu, 12 Dec 2019 08:52:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZAL8OOYC2Yh8 for <secdispatch@ietfa.amsl.com>; Thu, 12 Dec 2019 08:52:56 -0800 (PST)
Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1EF481209C5 for <secdispatch@ietf.org>; Thu, 12 Dec 2019 08:52:56 -0800 (PST)
Received: by mail-lj1-x234.google.com with SMTP id h23so3054538ljc.8 for <secdispatch@ietf.org>; Thu, 12 Dec 2019 08:52:56 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=J5UBnFnrAlPkone06+dE2r0mdDnQlpTYxM2gpmyWQw0=; b=vS0zbCrQA81XvWSWzGtWzOm9qwD4oVw6DplD0BkKHhKUeYZRDD38muf8b6HIefdRX0 ThGMj/qCKind1mVCSAyOwTHuzBvmwQ3kFlTBMPU0l1g0EXdcQlpB5H1zU9+GawIk90EC TmjstPOyACSP6n3ZP+8l9Lxm8VP2qUGJtL2B6+CthX9WbbPXTf4x9Bo0zuVQrGghvbgi ba92Dol2JVD1Agr4XDdvQqi9rDhd/AnKUvYBDwfao2yE/GabzPhrC+ujU5Tes1/e0IYu jUSU3fKiuSgK4LnlvP8882NZ2TwCkPYkGA/aBxgCpLII/eGqP/SsvIArUGYx8KxlDt6Q JGJw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=J5UBnFnrAlPkone06+dE2r0mdDnQlpTYxM2gpmyWQw0=; b=M1b9jJSW3QNwcWmAxj8kfX6O7cUziAys7A9SEQiNC8CwM2CshBIAnDIF2J+sxZsnru 5nUphrzqjiR6FD8fwrBO5lPMYoN7lcBaUZDH9SbRApAXDYzU9TY2kImU3pYEmmyUuH/z 0Livu3gCmA4nIld2rofXXK9LStw60mgSADIgKCzz0nSAFQdeTecojPfDEFiBy2kzumw1 Q6I4iX2Jn2ZuLtOhXR+tUWbpR8q6egB5Xz2Gasu4k85AazDQ0BfivFrkh+gmdpkRhwKE fh6JT5XPfdfJyTuWGraWyu7xlJdO2/7rHJ0EL9m6MTP5NR5dlwGyomFCTohi3QpkT6JW J1cg==
X-Gm-Message-State: APjAAAXnbqRZyiCBNWltyFzJQaJS6/+Q0UYxaaLi/qaheOHhDE9Y9IIY WLCbj76IBHFSgekE9Vxl9QnvX4DITEt/+gaavyHfEQ==
X-Google-Smtp-Source: APXvYqxwSDNdiXNE2C32WZl0c6kAVC4zXrMZVjOqrsM30ESZDw0hTsW7AC0K5UWKA8q5tCDxNNrxq/HaWoiHL/Vvz44=
X-Received: by 2002:a2e:9008:: with SMTP id h8mr6735745ljg.217.1576169574397; Thu, 12 Dec 2019 08:52:54 -0800 (PST)
MIME-Version: 1.0
References: <12eed4ff-edd2-7f70-9460-fc86dcbab927@openca.org> <CABcZeBPbAgBfC6Et+OKQi2=GwsyeyKEKfW5GG=StUepQwy+f0g@mail.gmail.com> <7999ebac-c9c1-eb4f-d9f7-2ba814a3b331@cs.tcd.ie> <78997490-c5ae-c856-6e26-0f79c7733ca3@openca.org> <CABcZeBM5WgpcBP4axBvzWaxKU=JA-K-4qiVxhhO1+HzFf246aw@mail.gmail.com> <MN2PR11MB3710195708AAA808B3D08EC29B580@MN2PR11MB3710.namprd11.prod.outlook.com> <2feb1778-7770-8a09-2066-a84663ff6b2e@cs.tcd.ie> <BN7PR11MB2547EA5F6DF70BC2B9C21E64C9550@BN7PR11MB2547.namprd11.prod.outlook.com>
In-Reply-To: <BN7PR11MB2547EA5F6DF70BC2B9C21E64C9550@BN7PR11MB2547.namprd11.prod.outlook.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Thu, 12 Dec 2019 08:52:18 -0800
Message-ID: <CABcZeBMu5fRazr3KS8fqAc8c9O3heBY73OfHSCYNyvrKyFrtCw@mail.gmail.com>
To: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>
Cc: Stephen Farrell <stephen.farrell@cs.tcd.ie>, IETF SecDispatch <secdispatch@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000968b2405998493d6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/pqAfpSJhn-2hDDuzDCPxVh29niw>
Subject: Re: [Secdispatch] [EXTERNAL]Re: Clarification Question for the Comment from Eric Rescorla (
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2019 16:52:58 -0000

On Thu, Dec 12, 2019 at 8:33 AM Panos Kampanakis (pkampana) <
pkampana@cisco.com> wrote:

> Hi,
>
> > Sorry if I've missed it, but who do we have that is calling for a
> post-quantum PKI solution to be developed now, but who is not promoting one
> such?
>
> We (Cisco) will need PQ PKI (not WebPKI) solution for image signing. When
> talking about chips that are designed now and will live in the field for
> decades, we would like to design today instead of wait for 2030. Note we
> are spending (not making) money on PKI, so we are not trying to corner a
> market.
>

Is there a reason why you don't want to do hash signatures?

-Ekr

I have talked to another vendor interested in them to sign its OS but I
> will not speak for them. I have also talked to at least one HSM vendor that
> has some clients asking for PQ PKI support to be added in their HSM but I
> will not speak for them either. I don't think any of these use-cases are
> trying to corner a market.
>
> Panos
>
>
> -----Original Message-----
> From: Secdispatch <secdispatch-bounces@ietf.org> On Behalf Of Stephen
> Farrell
> Sent: Sunday, December 08, 2019 9:04 PM
> To: Mike Ounsworth <Mike.Ounsworth@entrustdatacard.com>; Eric Rescorla <
> ekr@rtfm.com>; Dr. Pala <madwolf@openca.org>
> Cc: IETF SecDispatch <secdispatch@ietf.org>
> Subject: Re: [Secdispatch] [EXTERNAL]Re: Clarification Question for the
> Comment from Eric Rescorla (
>
>
> Hiya,
>
> Cutting to the nub of my concern...
>
> On 09/12/2019 01:46, Mike Ounsworth wrote:
> > I hope that doesn’t preclude a push for a more immediate solution.
>
> ISTM the "push" is less for a solution than for understandably attempting
> to corner a market. I don't think such attempts are "bad" things, but I do
> think following 'em is more likely unwise.
>
> Sorry if I've missed it, but who do we have that is calling for a
> post-quantum PKI solution to be developed now, but who is not promoting one
> such?
>
> Thanks,
> S.
> _______________________________________________
> Secdispatch mailing list
> Secdispatch@ietf.org
> https://www.ietf.org/mailman/listinfo/secdispatch
>