Re: [TLS] PR for PSS support

Joseph Salowey <joe@salowey.net> Tue, 15 September 2015 21:21 UTC

Return-Path: <joe@salowey.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 439111B2A54 for <tls@ietfa.amsl.com>; Tue, 15 Sep 2015 14:21:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.978
X-Spam-Level:
X-Spam-Status: No, score=-1.978 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GOSg4JbdrMww for <tls@ietfa.amsl.com>; Tue, 15 Sep 2015 14:21:40 -0700 (PDT)
Received: from mail-lb0-f170.google.com (mail-lb0-f170.google.com [209.85.217.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 617221B2A57 for <tls@ietf.org>; Tue, 15 Sep 2015 14:21:40 -0700 (PDT)
Received: by lbbmp1 with SMTP id mp1so92934401lbb.1 for <tls@ietf.org>; Tue, 15 Sep 2015 14:21:38 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=uwoT/n7v8wlaj8JkANyljCAAa6SXuk4sKlyj+CkR0hg=; b=ljcQA8/oyBlt2V5wjjJw64tlQieuOiUCLmaS5AasNDJltlqi8kkpmGYElgF2vE23Bb zTFYAEA16LQFKK9fg+5ZdH4A6atnnz3YAMOxYqjazV8x9TjI+QX1zcPPEylGaSvK5NcX hJnvN6551jfFXGLmHITm2G84RRZ8GQcpAFuap4SLw1yrWYyQntHKLhGTiJ0ca1JxN69P sfLbCdmIdWBABYey+g0mRZUjmhNkv7faF2n+sP9+KLN9cTEnSBQlOpUNxPXjXnAO9AWh N0e50oQbppEyzQkepi6sa0aazqsqB5ervokmETEXzmhRFzVP0r5Kr96mCmtU0vWg74/g tPkA==
X-Gm-Message-State: ALoCoQlKcvYF6joSz+pd6ZZMZKdtOlmP/K/31IRzjmb/tHTbiEgSn+Cc/4+d1bT0De/3znhuM3FB
MIME-Version: 1.0
X-Received: by 10.152.26.135 with SMTP id l7mr24982536lag.59.1442352098608; Tue, 15 Sep 2015 14:21:38 -0700 (PDT)
Received: by 10.112.2.1 with HTTP; Tue, 15 Sep 2015 14:21:38 -0700 (PDT)
In-Reply-To: <CABcZeBPT8CVai9B8pWju58mKnv0aHYet12Cbrf2ZjAgjJXvs7w@mail.gmail.com>
References: <CABcZeBPT8CVai9B8pWju58mKnv0aHYet12Cbrf2ZjAgjJXvs7w@mail.gmail.com>
Date: Tue, 15 Sep 2015 14:21:38 -0700
Message-ID: <CAOgPGoDAPR9QAB_BXeTEJ_cU38wjeyFAC3J8auxskjw5xMF7rg@mail.gmail.com>
From: Joseph Salowey <joe@salowey.net>
To: Eric Rescorla <ekr@rtfm.com>
Content-Type: multipart/alternative; boundary="089e0160c2be7a987a051fcfc407"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/sbqDcQL8mikVth7RQoPWv1GreJo>
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] PR for PSS support
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Sep 2015 21:21:42 -0000

I looks like we have consensus to move forward with this PR (PSS), please
apply the change.  I think Russ's suggestion improves the text.

Thanks,

Joe

On Thu, Sep 10, 2015 at 1:18 PM, Eric Rescorla <ekr@rtfm.com> wrote:

> https://github.com/tlswg/tls13-spec/pull/239
>
> Based on the WG discussion, I've created a PR for adding support for PSS.
> The basic tactic I took is:
>
> - All in-protocol RSA signatures (i.e., in CertificateVerify) are PSS
> - You must use MGF1 with  the same hash as you used for the content.
> - I added a rsa_pss SignatureAlgorithm field.
>
> The impact of this is that endpoints can sunset support for RSASSA-PKCS1
> by omitting it from SignatureAlgorithms.
>
> Note that I didn't deprecate SHA-1 (something Hanno suggested) but I expect
> to in another PR based on WG consensus.
>
> Please take a look.
>
> -Ekr
>
>
>
>
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>
>