Re: [TLS] RFC 4492 and HSM

Watson Ladd <watsonbladd@gmail.com> Tue, 22 April 2014 04:09 UTC

Return-Path: <watsonbladd@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 204F01A002F for <tls@ietfa.amsl.com>; Mon, 21 Apr 2014 21:09:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8MRg3lhmD_yJ for <tls@ietfa.amsl.com>; Mon, 21 Apr 2014 21:09:50 -0700 (PDT)
Received: from mail-yk0-x22f.google.com (mail-yk0-x22f.google.com [IPv6:2607:f8b0:4002:c07::22f]) by ietfa.amsl.com (Postfix) with ESMTP id C56051A0040 for <tls@ietf.org>; Mon, 21 Apr 2014 21:09:50 -0700 (PDT)
Received: by mail-yk0-f175.google.com with SMTP id 131so4110773ykp.20 for <tls@ietf.org>; Mon, 21 Apr 2014 21:09:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=SgOjlGbPdyTpeJwGYF1pBHfsy+deZsiKriVvIWjJ+yg=; b=qFZWAx1vqJOiqkDRY8U5KCGjx72TeJ/rfBDCVsSzNKURS/SdRC2XHYsgz66E+G5eek RJl+/XQcBzm8Ih1gcg1BIF8pwigR00GBNRjNAlF5uwRkTBczetFL0tvmvD9ON0g9KlyK LgmB853O9TRf3lDql5mPnFwCcbl2G26tCGGsGI31THBTSHtzqLfI8+8Wk5PU59O0ByPW HYZ428ALSoCfkpDGgU7Ma3gc4O4u1gb9V4pnMG+lNhXWsyYw1SVJzawM0eCyO5K5y+WX C4EtznyVcAXcZq6yJkJn5LIJtwyssOvmhGgSsbNSSBIez4A9vQoXK6wVdylzmcCF21OH Xekw==
MIME-Version: 1.0
X-Received: by 10.236.86.113 with SMTP id v77mr634101yhe.125.1398139785533; Mon, 21 Apr 2014 21:09:45 -0700 (PDT)
Received: by 10.170.63.197 with HTTP; Mon, 21 Apr 2014 21:09:45 -0700 (PDT)
In-Reply-To: <5355EAF4.1020603@fifthhorseman.net>
References: <CACsn0c=eV9NODQ8t5N0kjxB4_fC4kz__DH0POvhsd0g3SvGSMg@mail.gmail.com> <5355EAF4.1020603@fifthhorseman.net>
Date: Mon, 21 Apr 2014 21:09:45 -0700
Message-ID: <CACsn0c=ScFuMNgDS5UyLxk4-xBchvKH_G7O5m4LmhyNcEExLMQ@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Content-Type: text/plain; charset="UTF-8"
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/ghWDRdQTR9CTPiZGtLD3QFip9yg
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] RFC 4492 and HSM
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Apr 2014 04:09:57 -0000

On Mon, Apr 21, 2014 at 9:07 PM, Daniel Kahn Gillmor
<dkg@fifthhorseman.net> wrote:
> On 04/21/2014 09:00 PM, Watson Ladd wrote:
>
>> RFC 4492 specifies an ECDSA signature of the server's curve parameters
>> and ephemeral point, but not any fresh data. As a result the ephemeral
>> exponent is equal in sensitivity to the long-term exponent of the
>> ECDSA key, forcing an HSM to protect both, and thus do three
>> exponentiations per connection.
>
> It looks to me like RFC 4492 specifies that the data signed includes
> both the ClientHello.random and the ServerHello.random:
>
>  https://tools.ietf.org/html/rfc4492#page-20

This is correct. I was confused because section 2.2 says the
parameters are signed, but doesn't mention the fresh data.
Ignore previous email.

Sincerely,
Watson Ladd


-- 
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin