Re: [Suit] Hash Algorithm Identifiers (was: [Cbor] Packed CBOR review)

Russ Housley <housley@vigilsec.com> Thu, 17 June 2021 13:43 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 442693A202A for <suit@ietfa.amsl.com>; Thu, 17 Jun 2021 06:43:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F9RXgWDM77Kn for <suit@ietfa.amsl.com>; Thu, 17 Jun 2021 06:43:12 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D69593A2021 for <suit@ietf.org>; Thu, 17 Jun 2021 06:43:12 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 1F0A9300BFC for <suit@ietf.org>; Thu, 17 Jun 2021 09:43:11 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id fiFoZGgb1vIJ for <suit@ietf.org>; Thu, 17 Jun 2021 09:43:05 -0400 (EDT)
Received: from a860b60074bd.fios-router.home (pool-141-156-161-153.washdc.fios.verizon.net [141.156.161.153]) by mail.smeinc.net (Postfix) with ESMTPSA id 19644300BF5; Thu, 17 Jun 2021 09:43:04 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.21\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <70FD08DA-73E0-433E-8F91-2A73D55219B5@arm.com>
Date: Thu, 17 Jun 2021 09:43:04 -0400
Cc: suit <suit@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <376C695D-5B83-4C33-A972-647D614CB8F9@vigilsec.com>
References: <8713C3AB-71C0-4EC0-8977-15F80EC11309@arm.com> <212CE7EA-73BC-47BF-B192-D2D523F4A376@tzi.org> <33C84949-0F9C-432C-9C94-DE2C9EE17976@arm.com> <3F367A6D-5CAD-474F-AFEE-DF1AC9A34135@tzi.org> <146F670A-48EA-4A90-B77C-4CCC535F1DB1@arm.com> <6195BD3A-A031-47BD-866E-AF3D4D423A0B@tzi.org> <70FD08DA-73E0-433E-8F91-2A73D55219B5@arm.com>
To: Brendan Moran <Brendan.Moran@arm.com>
X-Mailer: Apple Mail (2.3445.104.21)
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/U3VYuQSwqEa-6kWk_GSHuvIGAj8>
Subject: Re: [Suit] Hash Algorithm Identifiers (was: [Cbor] Packed CBOR review)
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Jun 2021 13:43:18 -0000

This makes sense to me. Using the same IANA registry is highly desirable.

Russ

> On Jun 17, 2021, at 9:31 AM, Brendan Moran <Brendan.Moran@arm.com> wrote:
> 
> cose-wg has now finalised a set of algorithm identifiers for digests. SUIT’s digest container predates this work, but now that draft-ietf-cose-hash-algs is in the RFC Editor’s queue, I think it might make sense to replace the suit-digest-algorithm-id with a COSE Algorithm Identifier.
> 
> Best Regards,
> Brendan
> 
>> On 17 Jun 2021, at 12:33, Carsten Bormann <cabo@tzi.org> wrote:
>> 
>> I thought COSE did: https://datatracker.ietf.org/doc/draft-ietf-cose-hash-algs/
>> (in RFC editor queue; registrations already done) did this:
>> 
>>  | Name        | Value | Recommended |
>>  |-------------|-------|-------------|
>>  | SHA-1       |   -14 | Filter Only |
>>  | SHA-256/64  |   -15 | Filter Only |
>>  | SHA-256     |   -16 | Yes         |
>>  | SHA-384     |   -43 | Yes         |
>>  | SHA-512     |   -44 | Yes         |
>>  | SHA-512/256 |   -17 | Yes         |
>>  | SHAKE128    |   -18 | Yes         |
>>  | SHAKE256    |   -45 | Yes         |
>> 
>> Grüße, Carsten
>> 
> 
> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
> _______________________________________________
> Suit mailing list
> Suit@ietf.org
> https://www.ietf.org/mailman/listinfo/suit