draft-ietf-curdle-ssh-modp-dh-sha2 & draft-ietf-curdle-ssh-kex-sha2

"Mark D. Baushke" <mdb@juniper.net> Mon, 12 September 2016 15:05 UTC

Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA2FF12B9A7 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 12 Sep 2016 08:05:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.708
X-Spam-Level:
X-Spam-Status: No, score=-5.708 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-1.508, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CwzUahqsA-TU for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 12 Sep 2016 08:05:08 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B972E12B590 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 12 Sep 2016 07:35:58 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 49E5D85EA5; Mon, 12 Sep 2016 14:35:57 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8AE9384C6C for <ietf-ssh@NetBSD.org>; Mon, 12 Sep 2016 14:35:53 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 4jx3LyReterz for <ietf-ssh@netbsd.org>; Mon, 12 Sep 2016 14:35:52 +0000 (UTC)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0092.outbound.protection.outlook.com [104.47.42.92]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 3164C85E9B for <ietf-ssh@NetBSD.org>; Mon, 12 Sep 2016 14:35:51 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=B1xAwguZUkXKsuIJbSN5HmhOrDmRufgt8vEnjXfDxKA=; b=gKIEmP2O519lytZZmNznLLe+vckADGMrHAYUSqar4rqJ7ZsY1RTDtdAHMZ3BXlNfVv/ufqRa32gTGZWCk2mml270Cce5aOdA/D6AXoesPVXYk59Z5BcblliBiBzS60VpwHpuBpX1jt0PuYhaIs+4CAmUGBmRMDtHDY0sZ/Keib8=
Received: from SN1PR05CA0003.namprd05.prod.outlook.com (10.163.68.141) by BLUPR0501MB978.namprd05.prod.outlook.com (10.141.255.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.609.3; Mon, 12 Sep 2016 04:01:31 +0000
Received: from BN1BFFO11FD051.protection.gbl (2a01:111:f400:7c10::1:183) by SN1PR05CA0003.outlook.office365.com (2a01:111:e400:5197::13) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.629.6 via Frontend Transport; Mon, 12 Sep 2016 04:01:31 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BN1BFFO11FD051.mail.protection.outlook.com (10.58.145.6) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.619.6 via Frontend Transport; Mon, 12 Sep 2016 04:01:30 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Sun, 11 Sep 2016 21:01:29 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id u8C41ROO007549; Sun, 11 Sep 2016 21:01:27 -0700 (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id F0F541141B; Sun, 11 Sep 2016 21:01:26 -0700 (PDT)
To: Curdle <ietf-curdle@ietf.org>
CC: IETF SSH <ietf-ssh@NetBSD.org>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: draft-ietf-curdle-ssh-modp-dh-sha2 & draft-ietf-curdle-ssh-kex-sha2
Date: Sun, 11 Sep 2016 21:01:24 -0700
Message-ID: <35923.1473652884@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.18; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(7916002)(2980300002)(199003)(189002)(9170700003)(305945005)(356003)(87936001)(105596002)(110136002)(50466002)(86362001)(5003940100001)(229853001)(106466001)(4001520100001)(2906002)(4326007)(117636001)(53416004)(5660300001)(7126002)(8936002)(81166006)(626004)(8676002)(2810700001)(11100500001)(76506005)(50986999)(54356999)(48376002)(586003)(19580395003)(7696004)(92566002)(230783001)(15975445007)(47776003)(77096005)(189998001)(5001760100003)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:BLUPR0501MB978; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; A:1; MX:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BN1BFFO11FD051; 1:1JB8bCxNS1sbp2UZEztJLa4/QI7FUqMpE3Qpl8iYDKC4I2wWyFosRncXZ3/65MBenxh6k3AjqxjYmQn34zeKxA3A1qb2w3bC+w/tObNWTx87udqFLEVX9SS0stRAGNbyAaPttUjc3zskcvHSTx58y1SAUlfHGJJ1GojucRLbjM8rZdldDeFm8T7j6QzDKY4nQUBSuHkkixPfE8KV84Y0KFYBMfVTW67isokWB5fInD8NrGOS8Tv+ca5mmwR+nhyPJgebPQgbW1cwcQxsyuE2eRshkdojpJZRiILXpIC0yXOXBbwSs8fbHkwBoujRZu6zRulWQm2NTM50LUMlWzbJPT+T/btN63Ek7Of9L3cHSaNQiLZfF2y9vPj/by1Zr7MLqUkTANuN/7ZmVb5LVZ3tRq0aCMCnccRkrcrqjx+l3pb4e8pa94zomzCr17aCdOu5rszFNc4/cOWxwy648x8SWH3BBN127ZAMIJlbEHBHM87/KpmWYLXTIRc8wx1h8DgPL+/5Za08CP2NupNLPacTaWkeziY6ivzkkXzYj31VcNY=
X-MS-Office365-Filtering-Correlation-Id: db5799b0-207f-4df0-3d52-08d3dac17abb
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB978; 2:AIXDf8hsa5SOgxSQEWQdkjVbqBV96W01rXI9lxLB0JjNbRLLqtvriHmrWBN0sm8ZscTiRAXX8vTVbNJSJAvdmLWmAuH9MOsdX7nus89FWnneujjcBjqgO+rMiCaGAMpcwmHGUP17TfmejmCIIceHdu5Is/2ZlbLwNPdiyNdn6cmSYdtcG/0TSnmBoLhtml0E; 3:syZx9MyPBMHe0Rkdym7X6rFClZlXO7LJnIggC3nk6zeRNR4/c+AoZqL+pR9PEhK/ZsctAuDGAO2FaVwdWl8hBdiYHu4Iuper6MdR9UeY8GPKDFudSPWGq1+x5Ui8JIm2Ycc8Ju3XTONh/CSFyLA13qgQPMtAB4RQkhZI1VVZFUj6erxBGd1LQ175VtvRbfOvShpmDtmK6RlfxsROqYICk3ko8ygVgv/O9shg+NMj3jQ=; 25:QyBAlP06US8HDAggDTiHU9u9BQyhk0c0CAo+9wve5XrmVH6TVcb7GlUQkF4qf7qu9YTHWGafHhmOrDWBfJvYiWNIK4FmvHihHtqosnngA6FChTgnbPvFgEHoj6/nAeslXW53ILAPBPry45lsMY6iI0xL9ctLEUHIwK7s9ijsJP0F8u9yPA9LbHVeaymkmN6yXxkLFiRF443aVAncIOrtsisFLgaKT2Jyl/aaKqDSHooy1pGWhRhZ/RuoLfphMNFt1bOfj8h2YkxzcIe3eWrS4WzStYqdMeC5fNRbeU320h3bWk5OhIOj+70t+Tw+pb+oQ9C2RfbEdBTVy9xSzJprlgtcG6O9JvnxGOxA+PrNGJmik4rl0Ma7WmQR419yiXiPO3g584DqVbjNzy+Cn83PcypoWHrsVcis5rOEEyW/mXc=
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BLUPR0501MB978;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB978; 31:/Jmo+/zn8H1I1jzxuAohI2wk3x744sP8hKBlimZLCcUVMFfcCbczDp+wM+yb2E+sgS49Au8T3nW6MmhnYFMzY8DCpYRjhYV6TIWg4mx15ijeEKiRV/pDzuYsXRLMILFBOlAAHo9jO1z4SYIQ2pGXmrvu3mvbXE/2JBTZBIQ56VwFvol1d1KqNLDK7gacTc7AmUk+pSVN98ryeJeybp7YHDkc9PYXHG5axbVa4ZwyGws=; 20:BLKzBtrJU74pAWcrwwwrcTvqyx0Cz5LBWuX/Ir0BTNwayKmokcWCFkH6bzLEHcmBQ29mgo4xS+XFeoMMVt83jcPD0WHhG1U9TwfKnNPNGqCjMVPix/CQMXO4u8tXQDFxzMltbBNhtMI77geuxxL1C3Bdf9gaS4JSqfY4pMNEJPFUCsusIviu8kDASG/pnDVBmUMfyxL19KbIfrJ6dzhJwgA2VvI/MqQIDP/tZITsOgWl6uHYWmIwq0IA12V/IsFLtP5kRf+DxgEaDtpKgcxlEM2AHClpJWb9Tr8SCBqyHYyhaLXHfwKDjf5Vhrlw4CIEpS7S8sX9gJGnjRXhqYgmDq9OSryjnj55kNDDWDZfCOmVlaxgSTOnUCKWLT1lFl3wP3dMh48ogWULCqyLz6nriIXP+aJByX36cTANEqWj48W+O+C2TdHNAubUmcBHl3z88p2qt5RsISzy2g3Da34+ed+AbKqqUNSwDwpBTjvf1Xu84rHsoSsteCKmCWCNugsq
X-Microsoft-Antispam-PRVS: <BLUPR0501MB9786BA2723F4E8721E6E72ABFFF0@BLUPR0501MB978.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040176)(601004)(2401047)(13017025)(13018025)(13015025)(13024025)(13023025)(8121501046)(5005006)(10201501046)(3002001)(6055026); SRVR:BLUPR0501MB978; BCL:0; PCL:0; RULEID:; SRVR:BLUPR0501MB978;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB978; 4:I/CHjxrDfrpLn9eBojQNSJiOORpIFyiTpPmP/OqHyqZEa+neLdzrmdZH/yvDMxU6K32A2lx/bzKLPI/XXNTJmrX/Pc987QTat/KP8veYcmf+qOMlHAEHwKbqkcplo+cJ8yF3dyEmsK5l+e2YtijOchNu+Kqg3bgsEQmFcM146P9z9ahM1v+y2BY8GEiR8D8gs5uXHlemWOxCb35YTIZK8pfzkk+hvgbI7VNgEx7jqX0SLznk6NERkkjZF/rAZRTbtfRsK9G7lkZ3IT3MCV23kOZXw7R57tvFaKVQHTPfbaXK9tX4R51vmz27t1W08WLJLSE6rmB6mVgC8laiUYLOrlUT7O4U6DnEMarKuJFptQs04PDcYkrh91ouhelCZQStCrzX6un4quiV4xe6BwNkLMtdxKUTId/5oXaIxjbMhit8LIquJkdw9G23LTL+EQg0wTer5pdjp0IYg1lGb+2ZjaxMeIPFC4Ah2qel4oUugmVHC5VgqPx37f2xP2W3CJLs
X-Forefront-PRVS: 006339698F
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1; BLUPR0501MB978; 23:kIYqbyv6U96zGKZURncmhw37W9lUMXUXwanXlzxH?= =?us-ascii?Q?Qf7yPoDcsKl03pulCCqby+Bsx5aVPubvzCXBVWxE3OuYh8Sf3ZyyYcZARxZn?= =?us-ascii?Q?5OUHiQV14MDGad1DvTuvtbOFqIL+P2P7iUh+Dswhjxb83sLNT/CjLspxkFJw?= =?us-ascii?Q?NBu0LiGtVLkPjLiDjjUrjux+n5EdUl/fTpp8WOKNbl4LnvFS6YBwTMtVXq4w?= =?us-ascii?Q?bEzI1EawoS5fsZSR2dqjme0JVfZcK6vBSYBMXCxhK9EBSyK/TnQPqdBkhjCS?= =?us-ascii?Q?GCzZzLuQzsR0sY0dGVO0tGotmjvWIemNEHmJOtP7reaicNIbvwv5NyeI+IFp?= =?us-ascii?Q?z79sZX1tTqZsY4y9gOZAtEarj2VEYpvSYv5abrxj6N9eLlNDd2IjODF1Z21q?= =?us-ascii?Q?tYJW+AwnF2U+bWfeB4BL1tY1zO5KLEnjqcUyfSNn/5knJPov42sJSDAMU4xr?= =?us-ascii?Q?gfu0caUhTJT/K6yS8ttj9E1zEiHJNSn0FiMFBB+4G3R9n/GQ45Cd1ws08vRO?= =?us-ascii?Q?4uYZfhQ1D8pkUI0hTG5c9utZ5Nz6AtRVbi9RdDfHuADu0auI0puPdSgnwa2g?= =?us-ascii?Q?BN3SpfE/Mr6UGFeD+pLBosWpo5i1qeF5SPFntfb/nBXNpaIAZj5K/5pd4yf8?= =?us-ascii?Q?ftCiCIqoVwdMHlpERG3Pu5jE1juXHJS/Y9vE1IbOLc8XONb50q4EebefPBiD?= =?us-ascii?Q?/gZ+Tzi54Cut4QGfZsw58KNGO5h65LZy4jK84y+en32oe/ZgLiv4FZtf8sWR?= =?us-ascii?Q?iyTAtuwvsyclxJyRwmiowmRo7g5n3FILnJolz8QaVT998cxcFDPVvJgSiHiW?= =?us-ascii?Q?6tRx+TDOsRaLU9qJ7wtcaL5pdeA4YY9fmCew7LlSrhw25QGZVoSIoaUuX5rT?= =?us-ascii?Q?RY5E5fpp2Phg+Ln4SJCWJqsQtSEu/0BHSByUt6cIWapz5fawsr+yEVarakZV?= =?us-ascii?Q?RekALQsI21u0AqmwmRv5LPyY485mCOQrE8EJF9QYQlYjrtqgptJ5JDhcw28p?= =?us-ascii?Q?eg5oBqdJKq3a3B2u34yJ4KjiQ7qJwD2flGWgDXjHKBSz1gHEgWvwtHQdso9v?= =?us-ascii?Q?xmMSrzqdk9p8RfhrsiMiHzPqFIt3WRcNRuEQUkIh3S/s8oZAtg=3D=3D?=
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB978; 6:pfswD6ykpWeisyzUDB+TA+56COv+frAVEezJvDeOgSjmUOC76eqlAeCZ54FKm9Elk60VyTB7J/oKt1NpVTysN/9y4gJVIysKPo4C6k+aUKDDLmkT1an4Avz055Rq04vOf0HbD4BPXfb/pZBh86nm0iGhc21DmvazKILK385WqsvQaUUSvme0BSNvHxBNgirgrU4znMd5da/z6QlVaem/uN9RHxAOYumryIN2TVwDRfoqITsJ/AH+p5c3E9hWYlgZG9utroGOw1C+g3siHUUtcfcZhig9+SCVFcRY/DXhoGueGklMAU+6UujvP0bYy7BGmZBej117R04HiXnEy2EV4w==; 5:ideI9ZiHtLKBaeXhtRh9ljH3855NCOBBLGjNqmODYKhJ94rY0vgqyyuazxU9ookHRrJjVhE+v0nkD9eokQ2Vaqbm0lkcRahQJJFr+R9HklLazifU40Uu7GkMAaxbn38nk6PkHBJKU9WHP/Z/YnERqQ==; 24:nQSpWBRBFLINyjCQuYbX0kugRYS6KnTHNrkKKr7neNdFnYWLgJLgUAngY5d1R6axSLJ8OouD3u9yLgX6wTcBTSz7BWKDXnMF2xffLNbbPXA=; 7:nlAHV3w/TZtcsgNJ4wICEeBfUrLZOXMA5ve7+HkkxJ33/oDk565VJPSLBPuW4d9EIkxnSounN2D6Cv/F7UwGFmPHTf/XsOM34sPINWYXZ0uXass1gJO3fOz1nHvmFW/i8T4E3c54oEMlgNhHKaoUhlnoWoiqQaYwtMLq0M2Hp52/a088twyxDCLDa4mNl6WdaxtjaY2HTz4SuEJhjUzf8Y7mV3VmW8SlfD8g6Mexa74hsdSa7ycVWRjUvGHqBSV5
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Sep 2016 04:01:30.8418 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.18]; Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR0501MB978
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

I have split out a new draft draft-ietf-curdle-ssh-modp-dh-sha2 [1]
(called "new-modp" in the Reference table below) forked from the
draft-ietf-curdle-ssh-kex-sha2-04 draft. It specifies the new MOD DH KEX
Groups that use SHA-2 hashes. This edition specifies both the new
diffie-hellman-group* names of the -04 revision as well as adding the
gss-group* names.

Before I update draft-ietf-curdle-ssh-kex-sha2-05 to point to it, I
would like to take a straw poll of which algorithms (if any) should be
defined as a MUST to implement. My personal preference was just
curve25519-sha256. However, at least a few implementors have said that
they were not planning to do any ECDH implementations. So, I am guessing
that "diffie-hellman-group14-sha256" may be the only one that everyone
might be able to agree is a MUST to implement.

Key Exchange Method Name              Reference     Note
curve25519-sha256                     ssh-curves    MUST
curve448-sha512                       ssh-curves    MAY
diffie-hellman-group-exchange-sha1    RFC4419       SHOULD NOT
diffie-hellman-group-exchange-sha256  RFC4419       MAY
diffie-hellman-group1-sha1            RFC4253       SHOULD NOT
diffie-hellman-group14-sha1           RFC4253       SHOULD
diffie-hellman-group14-sha256         new-modp      MUST
diffie-hellman-group15-sha512         new-modp      MAY
diffie-hellman-group16-sha512         new-modp      SHOULD
diffie-hellman-group17-sha512         new-modp      MAY
diffie-hellman-group18-sha512         new-modp      MAY
ecdh-sha2-nistp256                    RFC5656       SHOULD
ecdh-sha2-nistp384                    RFC5656       SHOULD
ecdh-sha2-nistp521                    RFC5656       SHOULD
ecdh-sha2-*                           RFC5656       MAY
ecmqv-sha2                            RFC5656       MAY
gss-gex-sha1-*                        RFC4462       SHOULD NOT
gss-group1-sha1-*                     RFC4462       SHOULD NOT
gss-group14-sha1-*                    RFC4462       SHOULD
gss-group14-sha256-*                  new-modp      SHOULD
gss-group15-sha512-*                  new-modp      MAY
gss-group16-sha512-*                  new-modp      SHOULD
gss-group17-sha512-*                  new-modp      MAY
gss-group18-sha512-*                  new-modp      MAY
gss-*                                 RFC4462       MAY
rsa1024-sha1                          RFC4432       SHOULD NOT
rsa2048-sha256                        RFC4432       MAY

I plan to post the above table in the new
draft-ietf-curdle-ssh-kex-sha2-05 draft
after 05:00 UTC on 12 September 2016.

Of course, everyone can still lobby for changes with the Curdle group, I
just don't want to generate a huge number of revisions if possible.

	Thank you,
	-- Mark

URL: [1] https://tools.ietf.org/html/draft-ietf-curdle-ssh-modp-dh-sha2-00