draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)

"Mark D. Baushke" <mdb@juniper.net> Wed, 13 January 2016 09:21 UTC

Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B75A1A1F02 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 01:21:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id knZe8BtyRGXO for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 01:21:23 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E82AB1ACCFF for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 01:21:22 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 3CC8685EEE; Wed, 13 Jan 2016 09:21:21 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E060F85E94 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 09:21:18 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id rwyIlzif71QR for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 09:21:18 +0000 (UTC)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0787.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc09::787]) by mail.netbsd.org (Postfix) with ESMTP id 4CED484CE5 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 09:21:14 +0000 (UTC)
Received: from BL2PR05CA0035.namprd05.prod.outlook.com (10.255.226.35) by DM2PR0501MB1389.namprd05.prod.outlook.com (10.161.224.11) with Microsoft SMTP Server (TLS) id 15.1.361.13; Wed, 13 Jan 2016 09:21:11 +0000
Received: from BL2FFO11OLC009.protection.gbl (2a01:111:f400:7c09::120) by BL2PR05CA0035.outlook.office365.com (2a01:111:e400:c04::35) with Microsoft SMTP Server (TLS) id 15.1.365.19 via Frontend Transport; Wed, 13 Jan 2016 09:21:11 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.19) smtp.mailfrom=juniper.net; cs.tcd.ie; dkim=none (message not signed) header.d=none;cs.tcd.ie; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.19 as permitted sender)
Received: from p-emfe01b-sac.jnpr.net (66.129.239.19) by BL2FFO11OLC009.mail.protection.outlook.com (10.173.160.145) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 13 Jan 2016 09:21:10 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01b-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 13 Jan 2016 01:21:09 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0D9L6D51978; Wed, 13 Jan 2016 01:21:07 -0800 (PST) (envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1]) by eng-mail01.juniper.net (Postfix) with ESMTP id 2451311446; Wed, 13 Jan 2016 01:21:06 -0800 (PST)
To: ietf-ssh@NetBSD.org
CC: Niels Möller <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, denis bider <ietf-ssh3@denisbider.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
X-Phone: +1 408 745-2952 (Work)
X-Mailer: MH-E 8.5; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk, }4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Wed, 13 Jan 2016 01:21:06 -0800
Message-ID: <95389.1452676866@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1; BL2FFO11OLC009; 1:PiM7vAn2o6RARULRmghf93YXR+R7bO7YUNqXRAS6Y4ygv2eJa2q5LDnMUCjb9HGiCH8JiL7ZdMkYI8zOstEzpilX4HdWVGE79AW9wUiHEhOmNPvw8keA+uwZTzsycKJUkRaIBaH3ZebNcLnWBUJbfUp5KCTRE1UeaINh/2iF/spmly00o9sZmuaU6aENrkvllze19MhASw3W87SnoIc+ghOzpYqyX74XSRgKwoW+XIq1fxhFcPr2dBrtyLKteLct4W9kWvtMjHIbhWstBUr2RdJSn2YPlVF77K0ALjDRJq4+Spzm5s4BS4ZTSXXvBjE42ntmrnZGL1io3fUEJW1uZmr1X/kl29AP7YU+NepsBYAGqqoCN3+rEcA7jC4SWbnzK85MoYB71BvcxTXFEhvMHg==
X-Forefront-Antispam-Report: CIP:66.129.239.19; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(2980300002)(189002)(199003)(86362001)(5003600100002)(77096005)(53416004)(19580395003)(4326007)(5001960100002)(105596002)(230783001)(76506005)(47776003)(6806005)(106466001)(11100500001)(586003)(15975445007)(92566002)(50226001)(87936001)(81156007)(97736004)(2351001)(48376002)(1096002)(189998001)(110136002)(5003940100001)(229853001)(117636001)(50466002)(1220700001)(50986999)(2906002)(69596002)(7059030)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0501MB1389; H:p-emfe01b-sac.jnpr.net; FPR:; SPF:SoftFail; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 2:7Sqa037HNaRtEZAC3RSC+3W6lwzaAAFy7igLN2PG0ci+AebiOxK+yoHejKHxG4eBB9UAjft9W8zs8/PenFa+r5XB26xNfYARHSdIFS98aK/BLrylaPXCFy8VELtwMAwmgC05EAam0zxrmYMS7dyNZw==; 3:M3Q3/dgqKR/T8B0FZvuEVhzjWxQjnV1pM36qdQldqHCfPq2YWtx0/j2UaBmngNb/pQqrYgE6cxwhxYyLo2MGpHj2qCmWRVZu8FFEZeSJPTOrRmzKGlEhAMAvdyGfzH8ptjDc1Bvy/Wk9un3+x+fgyfbWOwXahaPSbv8swRFtygplxuv/eoaRPowStcs9tfsPpCcjw7TGHPAwAtUi5TCot245ow4ls3tgBHfqikCldfE=; 25:kmRyoNcI1Uxy1DaBdKkXjDLyXuwcTGyLHZEJw4tHNn4ENb4Q8B82BouG7zBIisznEzl+WUYqAUnCCkR2HbZ8V1O263wCeKoY2+dyv3tM90TZnx4Wm2RVO17CmI9FY/5cnhpQ2qHLfYrmShBes3TRg+whYSGGX9RbNygHqqZuSOBxhvfxjBXojA5l6ER6r1g5KkoVh4Yw/YdmAR3+BKHCUH6IVz3AcnAMXuH7vGJRjO1nwR+oLJyt1rV+RlY8TKvk
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-MS-Office365-Filtering-Correlation-Id: e9b75bc7-e1b3-46a4-5941-08d31bfae084
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 20:30uBPJPu+o8dCRqBRmcKM0b3LKMuzXCCS2HptM2GdKTSP9D5Kcd9laDep5aeU+iClNZrxIH1+hyPOW9L3qq696rDj4OkIQMZ1XxFdSAmV3vXOl0W0duOMjJ0hV/rRYytplaMPk2A/xwp95F5LkbTBKGexF3VYKFcJashY5Qx5k3WhCTJMynqgX1xxeHZDwMuh7ALNWEv3K56W61yR/bFY7BLZDbpSCMqBTBp7NKMywqVIfsiMGjIuLshHmVO4tv1VciSvSG31PB2JgnU0jSiNYpnRNF4AI3z1PySL5SCofpFMlEyZh4JSr2tVtAMd28rrEQLX+EMLx/PX2gSxehA4v7yfaRzLCEKqo0dkJrJ0z6hvIHGi2hbHwXY4aSsO9Li2zYOeOgMO2dWGoD3NOSyGldoqxicITpJMnWgXXhz2TGVdh3PZOixkUMrRH7RUW87z23LJ/90mSnEfIExEcfQt99ZHOnBmAQ8iS62xQzrA8QifplZ3YFV3lC5yvFMYUU9; 4:dXL+iuD0E5QWaXj+m9eDv+u1dRLGKXqRCIDHtJzlow9SGEilhnWW/OeE6r850MC2btQuHEmOyENvUq6M9FHTBr3OR+3C54DO5mgvFlYxQSLdp+LBT0xXhLKyt/ohghrH6C84nXWT34naY65jr0cV/krhVbKD0RVIQj1V2hN1y9TVR2y9RPGHH1Pgqm7ekuDJveCTO6sjtRN0W02x7UwX5Qf3k6Nf3aGPYAwqXbihWs1DCneUfpAR+0kGZIhe+KJeowHXxSc8UGhbZVC5LGvgvAX7eBygslkuZnTSh7o2c8P0yQI1c21V9obJueOyXpne8cSkOoEFnWwJgp9Jttp6+1PyGe7NUbRwjIr7ufuSGTJ6aek1+u/UvA7sjKWftpU5dRClZ6j/WqXpENPjw+8GVhT+VJX4DCZjCYC4kK4BLuUlQMnOKUuVl2JxIUWlmF0t
X-Microsoft-Antispam-PRVS: <DM2PR0501MB1389B658E919EDC7399FA704BFCB0@DM2PR0501MB1389.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(2401047)(5005006)(13015025)(8121501046)(520078)(13018025)(13017025)(10201501046)(3002001); SRVR:DM2PR0501MB1389; BCL:0; PCL:0; RULEID:; SRVR:DM2PR0501MB1389;
X-Forefront-PRVS: 08200063E9
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 23:OVkgbBLFcj4tY8vN14YlrjYhsftfAO0p3Eg3iBSzgL/tKID5H5ROB8xDJ635/YlKytwMGzpr8NqlbQm1oDcJmaZAulDm+cpE9eCa9KrtyLkndHhmqpqfMs2alureDBTHTjalN5l2JEQdLJ8cnPhYRNEDScvKnBVOu4cXBueRjXRRPXIK4V/igaamwGIqlhhoV6tOeZ7mq4b9sPWvJ0F7UnaE8BSVrUk6G7SPdM6GRuYimyDbvfL2DXmKm0qQo1hadXCLk2Cw48DfJ+dp/lh4/67bJO80rbRisB1Gpwk8AZjw3JhAiGZ+sR0zhivO+tzwkcv0PG1+kS2/r67ia4N32KJUyGCKdvFuYOp6rR6aUczK9tFR7oQSjZoeMG7nUNtLx/F+RaRgu14VcSFIbXXQihIsRrOq0bpRqNRbewV+aXAsXqN1cWTYSmzR5+oYl8skQd7ShctbyJ5nfa6GtJYYPJxrlmVpltzXZ4zl3PGNqOwOyzUNEqUz6aBG9osbXr/TT9Xwi2KxMxFT3bIxf8fDQOxkvQEiDb0PnZaQagvjKOb1GJk0Z6Z8gMZ/cb5zt2PSdXbp0Wtf4V6VBGUn2im1jkdvnVAY5RiT0y1H4H5q5ZwktofBgdSr6/31sJxwJ3x9Jhmwd0B7mI6wNr99nUEBQ3Py3Rrp7IkAhY3OK6+Qhk3XZorYEsgUSs3LnPPv2xtS3CjnkLel3+cNLBZnbqJzDc/lpioTmdDZnSbTiKcoYf5ra2a+QjarYXN6/tZ2IxxRuBAAZX/5x8jtHvKHuyMLso9HeZ8+urZyQbNORBcAIF++uKqv0wf8U/zImQBQMnD/TFgahwya4qMKMDmUW1KZOIjUHHsp2lsxuOR/j4ACvsimdiuJI0kMQN7X5Zrs9rZkrbO/R1cuC4kB1iDrwSZYSXjRASN9iAVDi9uiiFABD28IU1nHPP6/WXxh7bk+owue5/jHAxvZkjx0Z/CLkEHpkjTAtUL6KJtcu1Jw44hwPSi88b9C461Cxx14i3HqDMvUDvI04E2P6YpkDv2DXa785xoTfVBGB4YtLv9YFg221V4=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0501MB1389; 5:c0kz6jX6xGPPYG9BCVDoXgXXpjwz8ARRMvx1naASPlwJD27EiK0lnCMqf5alCLA7F+1Qmsn6Xtc0wG33fddJIDsofGwAMKf3YcX7REOz3goKBOLvqgWjCIveGfrRQR/uMtx669WmBdSfW6wPhIK/yw==; 24:NoTzh+cwdhHFpfbChr8lFToQz1NCAAVHzwlLgtdVVk2FsWPrfIgwGEgeOd/Ss/CzYGxkmZil1oEcRmQrIoj5abyuFVm2brOVyFLqr1pPcPU=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jan 2016 09:21:10.8327 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.19]; Helo=[p-emfe01b-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0501MB1389
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi,

URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2

I believe that OpenSSH and Dropbear SSH have both implemented interoperable
versions using the current 01 version at this point in time.

I would be interested in hearing if any other implementations have
adopted these new DH groups.

Are there any additional comments or changes needed for the draft before
we can move to the next step in the process?

Hmmm... What is next? Getting 'AD is watching' or is it getting a
document shepherd?

	Thank you,
	-- Mark