Re: [Spasm] New Version Notification for draft-wconner-blake2sigs-00.txt

Ryan Sleevi <ryan-ietf@sleevi.com> Sun, 30 April 2017 23:24 UTC

Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E9E01204DA for <spasm@ietfa.amsl.com>; Sun, 30 Apr 2017 16:24:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.4
X-Spam-Level:
X-Spam-Status: No, score=-2.4 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cD0kOKqLbD60 for <spasm@ietfa.amsl.com>; Sun, 30 Apr 2017 16:24:49 -0700 (PDT)
Received: from homiemail-a25.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DFDD3129562 for <spasm@ietf.org>; Sun, 30 Apr 2017 16:22:45 -0700 (PDT)
Received: from homiemail-a25.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a25.g.dreamhost.com (Postfix) with ESMTP id CD0CA6000503 for <spasm@ietf.org>; Sun, 30 Apr 2017 16:22:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=oDY9OH1PDGI7AwLR93Di2cdmCbY=; b= eP2sEQZF2xfsoZRzRfJtt/1nqgFnskNvLqKRV2NUsyVlrpX5NiqkrnsJqj2lULME 6HZrHj9oibvIEesiH9xJj7F4tNkH71zsnh737t+lBzXjuIsoru3TucMjwtkv9V3/ PqR90NX868wC+Sav4bTPgp0x1b0VgvBqnTo4+b8+BcM=
Received: from mail-lf0-f43.google.com (mail-lf0-f43.google.com [209.85.215.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a25.g.dreamhost.com (Postfix) with ESMTPSA id 6A5186000507 for <spasm@ietf.org>; Sun, 30 Apr 2017 16:22:44 -0700 (PDT)
Received: by mail-lf0-f43.google.com with SMTP id t144so55166669lff.1 for <spasm@ietf.org>; Sun, 30 Apr 2017 16:22:44 -0700 (PDT)
X-Gm-Message-State: AN3rC/465CxX+4aE+z7aA+ue+KPo/+tYUIvl7NiqSFgmOXYIHily2eYJ JidYHB1hMPSXAVeARix7OVWNG7XZdQ==
X-Received: by 10.25.233.195 with SMTP id j64mr7833812lfk.29.1493594562530; Sun, 30 Apr 2017 16:22:42 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.25.165.67 with HTTP; Sun, 30 Apr 2017 16:22:41 -0700 (PDT)
In-Reply-To: <009101d2c1ed$85c18d70$9144a850$@augustcellars.com>
References: <149218146333.15800.10260233763572420696.idtracker@ietfa.amsl.com> <CAFTQxQtMSzVNr8oae1U6Nbu_YjkYbTDxk6FJ2FkA4yH9vGnZ0g@mail.gmail.com> <000001d2c04d$46673770$d335a650$@augustcellars.com> <F2DE7842-511B-454D-9B05-A9E44E8A34F6@vigilsec.com> <009101d2c1ed$85c18d70$9144a850$@augustcellars.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Sun, 30 Apr 2017 19:22:41 -0400
X-Gmail-Original-Message-ID: <CAErg=HGJ53zfns1sW-YvNmQSRDRq+AS1Y5=f73Rh2jHWfgzC4Q@mail.gmail.com>
Message-ID: <CAErg=HGJ53zfns1sW-YvNmQSRDRq+AS1Y5=f73Rh2jHWfgzC4Q@mail.gmail.com>
To: Jim Schaad <ietf@augustcellars.com>
Cc: Russ Housley <housley@vigilsec.com>, SPASM <spasm@ietf.org>, William Conner <wconner@google.com>
Content-Type: multipart/alternative; boundary="001a113c2c60569746054e6a9502"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/T0yLIvdY_-Wo9i1K1FGEvwLGBwY>
Subject: Re: [Spasm] New Version Notification for draft-wconner-blake2sigs-00.txt
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 30 Apr 2017 23:24:50 -0000

On Sun, Apr 30, 2017 at 4:08 PM, Jim Schaad <ietf@augustcellars.com> wrote:

> I think that that is a regrettable but understandable opinion for an
> existing signature algorithm.  I find it less convincing for a new
> signature algorithm.
>

Why is that?

Many HSMs can handle this as well - using CKM_RSA_PKCS, in which the caller
provides the encoded digest algorithm OID and hash, and the HSM performs
the overall encapsulation. This was very much at the forefront of CAs
concerns. It also simplifies implementations with many existing
cryptographic libraries.