Re: [TLS] Proposal to deprecate sha1 and md5 for digital signatures in TLS 1.2

Hubert Kario <hkario@redhat.com> Tue, 14 May 2019 11:24 UTC

Return-Path: <hkario@redhat.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 921DA12006B for <tls@ietfa.amsl.com>; Tue, 14 May 2019 04:24:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level:
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OoiXHZpoRB7K for <tls@ietfa.amsl.com>; Tue, 14 May 2019 04:24:38 -0700 (PDT)
Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 99E771200A4 for <tls@ietf.org>; Tue, 14 May 2019 04:24:38 -0700 (PDT)
Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.phx2.redhat.com [10.5.11.23]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id C2F70307EA86; Tue, 14 May 2019 11:24:37 +0000 (UTC)
Received: from pintsize.usersys.redhat.com (unknown [10.43.21.83]) by smtp.corp.redhat.com (Postfix) with ESMTP id 0866219C70; Tue, 14 May 2019 11:24:36 +0000 (UTC)
From: Hubert Kario <hkario@redhat.com>
To: tls@ietf.org
Date: Tue, 14 May 2019 13:24:35 +0200
Message-ID: <2977635.mFCBgFvPmQ@pintsize.usersys.redhat.com>
In-Reply-To: <CAOp4FwTNiTg+g2utyst330bc14-Q-_A2z1QEHi_FEMv14wa=iA@mail.gmail.com>
References: <CAOp4FwRNxx2+MdSqHcrqgA0KkNMaQ29H8K4WBFDAw2AhL+3NKA@mail.gmail.com> <528b8748-6f99-4167-9075-891286b8bc26@www.fastmail.com> <CAOp4FwTNiTg+g2utyst330bc14-Q-_A2z1QEHi_FEMv14wa=iA@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="nextPart2201379.uxvmKTXWxM"; micalg="pgp-sha512"; protocol="application/pgp-signature"
X-Scanned-By: MIMEDefang 2.84 on 10.5.11.23
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.44]); Tue, 14 May 2019 11:24:37 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/nb5LteAIgtwod3-6S9Pz5E-mpoE>
Subject: Re: [TLS] Proposal to deprecate sha1 and md5 for digital signatures in TLS 1.2
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 May 2019 11:24:40 -0000

On Tuesday, 14 May 2019 08:34:38 CEST Loganaden Velvindron wrote:
> Latest draft is here:
> https://www.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-04.txt

why did you drop SHA-1 from Section 4 and 5?

the note about SHA-1 in HMAC applies to ciphersuites, to state explicitly that 
ciphersuites like TLS_DHE_RSA_WITH_AES_128_CBC_SHA are _not_ deprecated by it

SKE and CV don't use HMAC

-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 115, 612 00  Brno, Czech Republic