Re: [Spasm] New Version Notification for draft-wconner-blake2sigs-00.txt

Brian Smith <brian@briansmith.org> Mon, 01 May 2017 19:42 UTC

Return-Path: <brian@briansmith.org>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1844F1286B1 for <spasm@ietfa.amsl.com>; Mon, 1 May 2017 12:42:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=briansmith-org.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jSXGY6jWHcgY for <spasm@ietfa.amsl.com>; Mon, 1 May 2017 12:42:07 -0700 (PDT)
Received: from mail-io0-x231.google.com (mail-io0-x231.google.com [IPv6:2607:f8b0:4001:c06::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC6AE129465 for <spasm@ietf.org>; Mon, 1 May 2017 12:39:25 -0700 (PDT)
Received: by mail-io0-x231.google.com with SMTP id a103so127779522ioj.1 for <spasm@ietf.org>; Mon, 01 May 2017 12:39:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=briansmith-org.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=qjvagKUWLnRO72TJtzKMYTypiI6eAOGLIxIjrgGfVXM=; b=JPv8bf5Oqsn3YViOfw3t9bAP57Vs3YoVz+9ayexan7XqjnAooK7hKZAj4GtwgU8IAp hqPS5WRCkbiZcPDBRS79MhpTDKoeDodeKICjlACNUolnfVmXoay5G6fMuaoYNqwJOp6m /WYIWjLcE4hyUlWLOM7x4QfY951OwjVhyn+1sc8CF/JFirOyVFfbBaggHeR2M6p5RhMe kUVlVog4NO6a/Gg6vkay2sTTMCz019Z5GA84xmlnpz9PUQcAD6FXF17QZ/fdBhyt5LIb o5BPrYg5LUCRuWP5nzP/ePmDSrJEKPZwhKef/i2dGG4l0YAysEDHmlHOoMKrMK8N5CuF L2Kg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=qjvagKUWLnRO72TJtzKMYTypiI6eAOGLIxIjrgGfVXM=; b=asa0aYYCIxESxgGyKUE1hCCRMORDs+qpym48vumHrHZienpICurlT2XSIlubs1zIqg lBXROV42ndYf7sIQa+uyNrKLuyZcRFh86a94HeykEBq289ateHdbCjvakxGj7YEbRGqB EqFJ+bOwdcUkH9ajD0k8AePGtO99tBpB+y3B3Gf2F4qTdhzhTp3LZ8mOWewzo5sSA4j/ fyAilOq/TeJdJ2KWFsz4j3RddKIoqiN1l6hlIBreX5emAKxKviNrTv20+7oDIHbcvhg9 E7rpSmPmvOvXoWVFsbFwXJqW5Vrx2E0FkuXe9tzunE2GLhnUcygpBL6ByutW3eQUBiMi JwGQ==
X-Gm-Message-State: AN3rC/5BMzDmeVFhfbs6chBFX63et2Jga0JUOBs6wvn9sohh6UizvUDf vmygPqiT/c95rBn6DJbCi3p9AkaijhhS5Xg=
X-Received: by 10.107.12.22 with SMTP id w22mr23772886ioi.209.1493667564995; Mon, 01 May 2017 12:39:24 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.36.77.84 with HTTP; Mon, 1 May 2017 12:39:24 -0700 (PDT)
In-Reply-To: <CAErg=HGJ53zfns1sW-YvNmQSRDRq+AS1Y5=f73Rh2jHWfgzC4Q@mail.gmail.com>
References: <149218146333.15800.10260233763572420696.idtracker@ietfa.amsl.com> <CAFTQxQtMSzVNr8oae1U6Nbu_YjkYbTDxk6FJ2FkA4yH9vGnZ0g@mail.gmail.com> <000001d2c04d$46673770$d335a650$@augustcellars.com> <F2DE7842-511B-454D-9B05-A9E44E8A34F6@vigilsec.com> <009101d2c1ed$85c18d70$9144a850$@augustcellars.com> <CAErg=HGJ53zfns1sW-YvNmQSRDRq+AS1Y5=f73Rh2jHWfgzC4Q@mail.gmail.com>
From: Brian Smith <brian@briansmith.org>
Date: Mon, 01 May 2017 09:39:24 -1000
Message-ID: <CAFewVt5KACAHXEnk+zSPKr=ns8AV_0qfo1xyxkEweQ36ASbVfw@mail.gmail.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
Cc: Jim Schaad <ietf@augustcellars.com>, SPASM <spasm@ietf.org>, Russ Housley <housley@vigilsec.com>, William Conner <wconner@google.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/C81W5Y5oK9FfZxmbsB-toyssX6Y>
Subject: Re: [Spasm] New Version Notification for draft-wconner-blake2sigs-00.txt
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 May 2017 19:42:09 -0000

Ryan Sleevi <ryan-ietf@sleevi.com> wrote:
> > Jim Schaad <ietf@augustcellars.com> wrote:
>>
>> I think that that is a regrettable but understandable opinion for an
>> existing signature algorithm.  I find it less convincing for a new signature
>> algorithm.
>
> Why is that?
>
> Many HSMs can handle this as well - using CKM_RSA_PKCS, in which the caller
> provides the encoded digest algorithm OID and hash, and the HSM performs the
> overall encapsulation. This was very much at the forefront of CAs concerns.
> It also simplifies implementations with many existing cryptographic
> libraries.

According to the draft itself, the motivation for the draft is to have
a backup in case of a failure of a cryptographic algorithm,
specifically one or more of the SHA-2 algorithms. It seems likely that
the PKCS#1 signature scheme will fail before any of the SHA-2
algorithms fail.

Accordingly, I agree with Jim. Extending PKCS#1 with any new digest
algorithms is a bad idea. Let's get rid of PKCS#1. Instead, it would
be better to specify a deterministic full-domain-hash signature scheme
instead of PKCS#1, alongside RSA-PSS.

FWIW, some PKCS#11 modules also implement the RAW RSA mechanisms,
which allow RSA-PSS and other (in particular, deterministic
full-domain hash) algorithms to be implemented. There's really not
much advantage to a HSM implementing CKM_RSA_PKCS for arbitrary digest
algorithms, but not implementing the RAW RSA primitive.

Note also that some modules may implement CKM_RSA_PKCS, but whitelist
the digest algorithms that are supported for use with it.

Cheers,
Brian
-- 
https://briansmith.org/