Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)

"Mark D. Baushke" <mdb@juniper.net> Mon, 15 February 2016 09:36 UTC

Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4EC31A6FD7 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 15 Feb 2016 01:36:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.906
X-Spam-Level:
X-Spam-Status: No, score=-1.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.006] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Nb0Y3JvZPCZR for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 15 Feb 2016 01:36:54 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F1CA1A0197 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 15 Feb 2016 01:36:54 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 2E60C85EFC; Mon, 15 Feb 2016 09:36:44 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id D0CD585EFA for <ietf-ssh@netbsd.org>; Mon, 15 Feb 2016 09:36:40 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id R_vFVEhLTXMm for <ietf-ssh@netbsd.org>; Mon, 15 Feb 2016 09:36:40 +0000 (UTC)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0759.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc09::759]) by mail.netbsd.org (Postfix) with ESMTP id 0C84285EF6 for <ietf-ssh@netbsd.org>; Mon, 15 Feb 2016 09:36:36 +0000 (UTC)
Received: from DM2PR0501CA0029.namprd05.prod.outlook.com (10.162.29.167) by BY2PR05MB112.namprd05.prod.outlook.com (10.242.38.27) with Microsoft SMTP Server (TLS) id 15.1.403.16; Mon, 15 Feb 2016 09:36:33 +0000
Received: from BL2FFO11FD050.protection.gbl (2a01:111:f400:7c09::154) by DM2PR0501CA0029.outlook.office365.com (2a01:111:e400:5148::39) with Microsoft SMTP Server (TLS) id 15.1.409.15 via Frontend Transport; Mon, 15 Feb 2016 09:36:33 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; josefsson.org; dkim=none (message not signed) header.d=none;josefsson.org; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BL2FFO11FD050.mail.protection.outlook.com (10.173.161.212) with Microsoft SMTP Server (TLS) id 15.1.415.6 via Frontend Transport; Mon, 15 Feb 2016 09:36:32 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Mon, 15 Feb 2016 01:36:17 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u1F9aGD63631; Mon, 15 Feb 2016 01:36:16 -0800 (PST) (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id 8AAF81144F; Mon, 15 Feb 2016 01:36:15 -0800 (PST)
To: Damien Miller <djm@mindrot.org>
CC: denis bider <ietf-ssh3@denisbider.com>, Niels Möller <nisse@lysator.liu.se>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, Simon Josefsson <simon@josefsson.org>, ietf-ssh@netbsd.org
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
In-Reply-To: <alpine.BSO.2.20.1602151851550.4613@natsu.mindrot.org>
References: <223360780-3264@skroderider.denisbider.com> <86136.1455402404@eng-mail01.juniper.net> <alpine.BSO.2.20.1602151851550.4613@natsu.mindrot.org>
Comments: In-reply-to: Damien Miller <djm@mindrot.org> message dated "Mon, 15 Feb 2016 19:00:54 +1100."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.6; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk, }4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Mon, 15 Feb 2016 01:36:15 -0800
Message-ID: <35014.1455528975@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1; BL2FFO11FD050; 1:f7M4DIrC63b5kfVgLjOpYdEDmb+8QoJiLl8KBi6mso2zBtXMpDkM5GbVB/VXQU4IAdJohwWIegI5tUaYLUL+6rvqmFQmeWpPznYRBstMigXr7zWfdAcp36Fo16UH9C0psxJERx3x+PSd+kIufh8FRV2F5GRYiLUy9amtVgGpl4lxIbx3a9zp3AmWBrkuKPNV31iw3CpebrGOawlBO/oD/WkF4M8drPYKXZ3MRgrDCTLKyVv2FaPl+w2BbEOMG887/ntQMUlPR1tP9d6w4ngXwppIa0kGOu/hVEPGxaF/ZmkyRthZ3FnzXNX8abAqk2V1K/aiAOZonCPfsITFFz09tyaiGPdaBTjk0UBjJby8ZzeLDv5bnIjiroxJHdt97G4RYC6aQlzvgrwrvjRloMmPYDpCHnUSA89m7lqSz69SKK0=
X-Forefront-Antispam-Report: CIP:66.129.239.18; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(2980300002)(24454002)(199003)(189002)(2906002)(4326007)(47776003)(2950100001)(86362001)(586003)(117636001)(50226001)(230783001)(189998001)(53416004)(1096002)(1220700001)(2810700001)(50466002)(6806005)(76506005)(15975445007)(105596002)(11100500001)(77096005)(92566002)(19580395003)(5001960100002)(5003940100001)(110136002)(87936001)(5003600100002)(106466001)(50986999)(19580405001)(48376002)(76176999)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:BY2PR05MB112; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; MLV:sfv; A:1; MX:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BY2PR05MB112; 2:XtKyElF4HvBp1qUK6ey8NYLA43GDE4YF78ohNwhNv474FkmtKEiBIFcvB7YwTnYlaIMHdbKqjKs9qWFDG9D92qbwFjSnKzvR2Gk4TLU8ovpTVu1ukdNeDWXsDlHUr+dGmxSzu8nVdKGy1zRgsSdLRA==; 3:oLwrKH85uCsDKMhE6ZTkoZAkTgY4owFL6pYOKut0ZP+PvkEzRvDXo6XrpPh+UTCJ473q8rl9z8FBNG6xuAJLEU8cIGzWT6m2t44b9ihMgplqpEpWV7GvcmMZP++SfH3dKIqhMmAnhFBCD9NFV9KHRw4C25BQybQ7ueK3L2lAP9GU2/5GlhF5bOifTN+e7dEwCfWHiwjUrlO+KCCMy9DRww7BBhBgRhyCEQGSP+jyWgE=; 25:ijHAbylCpAxILnfwYATdabIlMHahNqLBJKpKyJr2P87g/y/mrN/R7PIJnn79lSfHIiUsHORDsSxPAQXnXfvsWBGkKhyDT1h1vEs35K3k1W6tqYQNF/mP0bldM/phM0EqjwQe0PEoRvccfWOSlCWu3r94MWLfNTQ4ZPoT8uutwSHy+rq1A/aTb8Es7PzoQ2Tod18YnJJ5MzQJKATpF5VUgxIy5j+3dmT6tik0vpVdgdp3TgGOZf94SrZT9+St3NgLvax8vtWdQqbhRCuPd+JAw9gSzs2UM8GtFLb/cAClJixxr/bQrC1/u2CbI8rCj8vP
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY2PR05MB112;
X-MS-Office365-Filtering-Correlation-Id: 1dac64ff-4ed4-4ee9-29ae-08d335eb7d93
X-Microsoft-Exchange-Diagnostics: 1; BY2PR05MB112; 20:vx8XHDlMJI8t7737j6UM7ErYATd0IEOrebKe/e6H803l2ZRNAMOKpmQSodVZQPxvpwi8+sZazCxPWA2Ly9wseksSF6of7vMPJgoiqc42/eX45VDNOrKZEZ4ZRe6VFjncDRnPi3T5/0BZ0HR58Gi2MoKTXkZ4GCDC5cuZL7njR2Krgng3AumVdG09XJEhtgLZ2WnF5M3m+T4qqyNwbRooBgNhZ+rXpIjePLJAhS3hPDJzy+D68jIVCvIvh36ledhzb4jCqZlg5wovMCFCXPXfqAWLNZvp/qnDy9aiS8is4aqI41SwwtXa7al5GDzE1v2A9XMJveO7SBo/7qSnRQem3nlYrbZ0SlCrW61U3ZBOCKnbYq9jwBOFC6VVm/gNjCI5ATz3vtLQeYZf+c+GbzzfF+0LmeyKj6yIofTOzSxhDmf2p7quwJ69BLov6LW4qIVWNkuXvoVo4T34ZLaRooVEuiV2Qdm7M1CZoEjiStT8sRIKmoB0tryMQjnRC3yKA89V
X-Microsoft-Antispam-PRVS: <BY2PR05MB112C8AAFED4954C7DBCD146BFAC0@BY2PR05MB112.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(13018025)(13017025)(13015025)(13023025)(13024025)(8121501046)(3002001)(10201501046); SRVR:BY2PR05MB112; BCL:0; PCL:0; RULEID:; SRVR:BY2PR05MB112;
X-Microsoft-Exchange-Diagnostics: 1; BY2PR05MB112; 4:ySAeeJ8hxKFHqeNB30kLGqZh/pYn/oX9TkmxcBd7Pbsw7QVauh1b/yAacZMw28IGFrN/sE78qhYAHJYvRqa5QTgqVtH5xFLy7yKMKKtJYMYbeOUJTVfqCQemR3al9wz5uXK4fubqGyyTDyF2UVKBSCDXyvGAhMZTA1n7ForMD9UHolA3eoSNlgKf04NMUCBRK6Ih/UkuZG3Mj1g9Xx5NyGAl1GDHhgNdVzDPRqeqRoTIh9koyr+c7311G3bt3FfY88RFkt81NkmXhj3fuDMY+/z+yWaPIuA/RvN4Jbnt2M439goS1aTZyveb//t/ae8GAUgUPL+J28vyL0kQbUpYhnwxRMXeJUGX/Y3Hv+JEN6yh2i4n+/kRUrY+mIxfPh3hZ6X+DnAwCAPJ6K1K9AhNn7D+ViEKL4fkZ42Uw/Ql/s7vBzQfewz+KFdHUsTFyQa7m/CxQzny2QXLOjD8cqa0uw==
X-Forefront-PRVS: 08534B37A7
X-Microsoft-Exchange-Diagnostics: 1; BY2PR05MB112; 23:Zukq6OQgYNBVwh1QWrBzgCk6MOwWONEl3nJNMpKuCfVk/xSnw1z1qL1cKOotxXXaeKLYN1DfFpby/7RiY3qRqQJlRXLlXx0PXoGAga40ea+OM/Sy5ZIE+KhO+KJmogns//kdsSjo7lbsdJWAPekM4ZNo200BRHnWoIYApsBFEft42nK5usSEOqG4+bk1iid2HCWfwNIebdkSruS68oeIz+Nbumf7xQde/SBNEKP+KZAQJ5R6fz7Zh0GCun4SMCeFF/axgHL8j8b7HDrMnIRq3cOWhYa6ssC5Qw2pRxXAGHyuIfRMj0F4HbszvoTk0IVIqAncc/leeneDN2FYIqdhrDjH+ouOyP119+3oGAPrXYs0Zul7tLg7WDbt8zVvFkjFoq8IdjTEa5+XnGxuYels+NAZTlg/PkPv8TV5l7LF/ZJUCUHyxJRDYM3RFe7Vj6U7g+ykc+mzoSwGwrMDaJDzEf9P4Oq1x5DPYdel/rFsCmgFtLFIG8uCOns36Q590ABTUl+oiqGSF+F7RpwBZ0QONVbBcIy5BaRxI9Rkv7s7u2yCrKxaIfHMWlwJjv9P7ZQC6FeRa/18yJGhCByy7jg62CcG1JNm4nbRBrzqBrKKskO3vMCozmSn2uXKL+XJ4yscdbbKhR1H6bGIp846gHOLJ7bxUFXI05XP9kR/NLssvDNU1B+OMSvrv8lFBaY10zeJyfMYt9hUDQski4Lz0BNhSlRbUWwWMUEUVuN0oRt+R8CUJEXqZu0Wf9oet4y5SNQGkFY6cFAZcjl/HR2SeBGgP79k7iBjJyU/77CsLVsE/A9eTukdJrcN7ZAWiDcWlz6dZBvsK6nE8N9titE7AsM+fGlRDGVHeeP4+wJokaLcoapEFQvsLVN4SHTcrpdVz01P7elhALFGV79fHjKKJnOiSWHFzRDmd7izbLB8u6O+haOH3Qm1skpuHoqmIO4P+Tpfprx/gn5//FuHao4K5bOw+YDXQNvavfNmJnAYVkiFtWxJOc90YbsohyT5iJNlyse9wxN2hX1Ih2gfeDBz96x24YwTDpcyu6alj+qdHImhreY=
X-Microsoft-Exchange-Diagnostics: 1; BY2PR05MB112; 5:Nv5LygOkIYV5ebDKibDukGioejzGFrLCb0VxkIiyEaAV1wSzOw+BvRamLA8uI6aJAbAthYKYvuG1sf75+4eLVJSA1XlYcXnHklBP8IwKbmAZa2Bw144jkIICUYHjPTjo81TK5DZrbfpRGj9ZirpvoQ==; 24:BLADrShKcj0XjZ6/kIeu76xi2PHESQTVY3LDEMJQktE0cVEmlmWHEoxlgp03T+illzkFvv3u6+eyJc1Kr06R5jCvCLnQaR1pgqzULS1WuiU=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Feb 2016 09:36:32.6167 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2PR05MB112
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Damien Miller <djm@mindrot.org> writes:

> On Sat, 13 Feb 2016, Mark D. Baushke wrote:
> 
> > https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2/
>
> IMO curve25519-sha256 should be a MUST, if not immediately then soon.
> It's already supported under the curve25519-sha256@libssh.org alias by
> a few implementations.

Good point. I have moved curve25519-sha256 to MUST.

> This paragraph:
> 
> >  The group15, group16, group17, and group18 names are the same as
> >  those specified in [RFC3526] as 3072-bit MODP Group 14, 4096-bit MODP
> >  Group 15, 6144-bit MODP Group 17, and 8192-bit MODP Group 18.
> 
> is incorrect: group 14 is 2048 bits, not 3072. Group 15 is 3072 bits,
> not 4096. Group 16's length is not described (4096 bits). 17 and 18 are
> correct.

Thank you for reporting this. I have updated the text in my copy and
removed group15 and group17 from the list.

I have submitted the new edition to 
https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2/
it should propagate shortly.

> I think the table of "Group modulus security strength estimates" should
> have a reference - are these from NIST SP800-57?

Actually, I do mention that I got the information from RFC3526,
but I will make that more explicit and also point to RFC3766
for making the security strength calculation in person.

	Thank you,
	-- Mark