Re: [TLS] Another IRINA bug in TLS

Aaron Zauner <azet@azet.org> Thu, 21 May 2015 13:54 UTC

Return-Path: <azet@azet.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B57CD1A0173 for <tls@ietfa.amsl.com>; Thu, 21 May 2015 06:54:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5gb9CwVu1llo for <tls@ietfa.amsl.com>; Thu, 21 May 2015 06:54:15 -0700 (PDT)
Received: from mail-wi0-f174.google.com (mail-wi0-f174.google.com [209.85.212.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6DC4A1A0163 for <tls@ietf.org>; Thu, 21 May 2015 06:54:15 -0700 (PDT)
Received: by wichy4 with SMTP id hy4so14833549wic.1 for <tls@ietf.org>; Thu, 21 May 2015 06:54:14 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type; bh=X6H/IQ5RxwK/rUgxO5PzJ8vppjk1RnYe0I0pxRd7mbA=; b=Lte8Qw5SMi8OI6J54+24oNYTyp+2Q9vqCGgNSh71bInNgngb/usMNB01Xv39yhdgSh TeS0mrBHCtU4WNGdzDiFuX1r3GMOZ4pDYpM/t1bBE4AvunvlmpF5VDq6+efeNia0Elmh ZDvMs5PDqxGdJf6mxWKY/af1GDZJFDaq/HHXxMINZMfUw+FPMc+ZZqVIlPNmW87B4q8x AHXyKA1XCdfDaRk1eODmP4QX1U7+MSJ7468ifkSO11rpV63CLXBIFA2mCmzGmvGeppvg nOJOLzzFt8euEA8RYYHfkUsvrGdWe7YF1f8SQ5OLTalq6bTMV4mXkiv9L+iUuURCrJGj z6/A==
X-Gm-Message-State: ALoCoQl0NDCNgaFdtHmKdkEDv9FZgFLI0BYW5XQ6c71bHtJ3hojRJrDW6NKumeROPElMRW+FZH0a
X-Received: by 10.180.73.236 with SMTP id o12mr52593796wiv.56.1432216454190; Thu, 21 May 2015 06:54:14 -0700 (PDT)
Received: from [10.60.20.24] ([193.170.94.190]) by mx.google.com with ESMTPSA id fb3sm2977485wib.21.2015.05.21.06.54.11 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 21 May 2015 06:54:11 -0700 (PDT)
Message-ID: <555DE380.1020906@azet.org>
Date: Thu, 21 May 2015 15:54:08 +0200
From: Aaron Zauner <azet@azet.org>
User-Agent: Postbox 3.0.11 (Macintosh/20140602)
MIME-Version: 1.0
To: Nikos Mavrogiannopoulos <nmav@redhat.com>
References: <CACsn0ckaML0M_Foq9FXs5LA2dRb1jz+JDX7DUej_ZbuSkUB=tQ@mail.gmail.com> , <1432134170.2926.9.camel@redhat.com> <9A043F3CF02CD34C8E74AC1594475C73AB027EED@uxcn10-tdc05.UoA.auckland.ac.nz> <555D90F6.10103@redhat.com> <1432195799.3243.18.camel@redhat.com> <555DBCE6.7080308@redhat.com> <1432206909.3243.45.camel@redhat.com> , <555DBF7E.9050807@redhat.com> <1432207863352.27057@microsoft.com> <555DC498.2000109@redhat.com>, <1432209104.3243.65.camel@redhat.com> <1432211226723.39265@microsoft.com> <555DDD4A.4040206@azet.org> <1432216095.3243.70.camel@redhat.com>
In-Reply-To: <1432216095.3243.70.camel@redhat.com>
X-Enigmail-Version: 1.2.3
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="------------enig760B637B1CB2DA8A19A820E9"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/386VcQXDyyz5elElY-jmRcjYwoI>
Cc: Florian Weimer <fweimer@redhat.com>, "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Another IRINA bug in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 May 2015 13:54:16 -0000


Nikos Mavrogiannopoulos wrote:
> The "safe primes" is only a name. There are safe primes for DH that are
> not in the "safe primes" category. The primes used in DSA are such ones.
> 

Ok, let's assume "safe primes" means sophie germain primes in this
thread. :)

Aaron