
From nobody Thu Feb  2 21:13:48 2017
Return-Path: <brian@briansmith.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E00E129ACD for <curdle@ietfa.amsl.com>; Thu,  2 Feb 2017 21:13:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=briansmith-org.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2ODF0HoGnphJ for <curdle@ietfa.amsl.com>; Thu,  2 Feb 2017 21:13:45 -0800 (PST)
Received: from mail-it0-x236.google.com (mail-it0-x236.google.com [IPv6:2607:f8b0:4001:c0b::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3219D129BAD for <curdle@ietf.org>; Thu,  2 Feb 2017 21:13:45 -0800 (PST)
Received: by mail-it0-x236.google.com with SMTP id r185so5121560ita.0 for <curdle@ietf.org>; Thu, 02 Feb 2017 21:13:45 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=briansmith-org.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=GZ7ObE0gCXFaEbOATxaXmiSa/MhPAzSCs2O4atbfvfU=; b=bBMh4FeNAulD3GAelutbJg5L1MzY9vV4LEK+MT7BYzxGxyYTfg3Tvk++gD6bHL4voH 083uhO9fIm/0MqFbGt7MchcE9AS1hLYQ347QoaJVHMCyJ9CA95rrdIIT0cj09EoQMRAb XjjW9nHMBnCQhWAAVSLebh12ljk32UoxQLqfzsUirVxoGlLrz5BRNIAe5WlVfQzAMEZ1 gO2FsmahnxUs23rjYULXVTdZDduU1lworeyEGCWzF33vKYNNjDAQd5rX4SrOlTF1ykQm bhCId1o8KXuCwr5e11xMOw/p9Q6hyqMHsKUyjoo9wFdlbukuAeEmGN3iLxWSRT+qc5kn dMgQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=GZ7ObE0gCXFaEbOATxaXmiSa/MhPAzSCs2O4atbfvfU=; b=BATKWyaoWeDiXD9Un7JawPybctuoLOvO26rJK3Fnd9fSBeq97lCdN+75Qo2s6DkKd4 SVktFOL73mVbPHMMdXBqtTH1rxOsiLxO1C5UsRxsw2HMUE7slP0AaQlQSuJQfSi2ZTyX AyolITsg8lkF6ujfpMqHqbv6bMDqZpQ0Hc5qfTxThair5jWHPLdc+i6VcAmVBcblI2Ah mp45Yz7CP6R6hL40cfPMyzddzsIz7aPGJcnfyhWnDRq5Y8Gvf2QQkmPT4vJ7BUXHlWt4 IdQr1w1f5uYXCo34fiGEi/aOSJ+IQYruNY6+ambnVGu60AX9ltXP0bGTica5y2CdpLac aWvw==
X-Gm-Message-State: AIkVDXIz7W7Vn9flIlhzV2tNisfTgpEyJ6zPgGvTz4uHPlVZMLrPdbScwLiPCLNEpvTBa49wNybG0t75zS/73w==
X-Received: by 10.36.17.7 with SMTP id 7mr827428itf.113.1486098824434; Thu, 02 Feb 2017 21:13:44 -0800 (PST)
MIME-Version: 1.0
Received: by 10.36.65.206 with HTTP; Thu, 2 Feb 2017 21:13:43 -0800 (PST)
In-Reply-To: <1485685950.1687.1.camel@redhat.com>
References: <D4701965.2CFAB%qdang@nist.gov> <1481295892.20432.16.camel@redhat.com> <0e1701d254c6$46509670$d2f1c350$@augustcellars.com> <1481788992.2779.15.camel@redhat.com> <CAMm+LwjaTJp3JeJCTqj2Fag9mMKCUk+jE6aJMsBy=b++miu9jQ@mail.gmail.com> <CADZyTknQYmOXi+zG4f4GyC4Opquc7SkLOMads9vLbQrhg-2hdg@mail.gmail.com> <CAFewVt77331=DU2hdZtK1x8qreHp-31Cahmhea75KsU3uCkgbw@mail.gmail.com> <1485685950.1687.1.camel@redhat.com>
From: Brian Smith <brian@briansmith.org>
Date: Thu, 2 Feb 2017 19:13:43 -1000
Message-ID: <CAFewVt6StNUUF-31nboMcs-5Gmyxhb9666wUr9+HQR_n9zS-aQ@mail.gmail.com>
To: Nikos Mavrogiannopoulos <nmav@redhat.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/_hlJP0_iUyot1S8x_N59sXcaZ6E>
Cc: Daniel Migault <daniel.migault@ericsson.com>, Phillip Hallam-Baker <phill@hallambaker.com>, "Salz, Rich" <rsalz@akamai.com>, Jim Schaad <ietf@augustcellars.com>, Curdle <curdle@ietf.org>, "Dang,  Quynh \(Fed\)" <quynh.dang@nist.gov>
Subject: Re: [Curdle] Some work for the group
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 05:13:46 -0000

Nikos Mavrogiannopoulos <nmav@redhat.com> wrote:
> Brian Smith wrote:
>> Besides the security issue, my understanding is that using the
>> prehash
>> variant would result in lots of interop failures as, AFAICT, there
>> isn't going to be much support for it in verification libraries.
>
> Isn't that orthogonal to the question? If the prehash version is going
> to cause interop issues is not affected by the text quoted above. Your
> comment is on whether including the prehashed version at all.

No, it's not orthogonal. If we don't include the prehash version at
all, there won't be interop failures. Again, I don't see any
significant support for the prehash variant on the verification side.
It's a bad idea to let or encourage CAs sign things using an algorithm
that most verifiers are unlikely to implement.

Cheers,
Brian
-- 
https://briansmith.org/


From nobody Tue Feb 14 17:40:30 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7E6B127ABE; Tue, 14 Feb 2017 17:40:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qbS7MmV-njpz; Tue, 14 Feb 2017 17:40:21 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96F42129996; Tue, 14 Feb 2017 17:40:00 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 7E732B814D7; Tue, 14 Feb 2017 17:40:00 -0800 (PST)
To: ietf-announce@ietf.org, rfc-dist@rfc-editor.org
X-PHP-Originating-Script: 1005:ams_util_lib.php
From: rfc-editor@rfc-editor.org
Message-Id: <20170215014000.7E732B814D7@rfc-editor.org>
Date: Tue, 14 Feb 2017 17:40:00 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/GlOIYXkc3E3ZLWAuDGOStw_jKr0>
Cc: drafts-update-ref@iana.org, curdle@ietf.org, rfc-editor@rfc-editor.org
Subject: [Curdle] RFC 8080 on Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Feb 2017 01:40:28 -0000

A new Request for Comments is now available in online RFC libraries.

        
        RFC 8080

        Title:      Edwards-Curve Digital Security Algorithm (EdDSA) 
                    for DNSSEC 
        Author:     O. Sury, 
                    R. Edmonds
        Status:     Standards Track
        Stream:     IETF
        Date:       February 2017
        Mailbox:    ondrej.sury@nic.cz, 
                    edmonds@mycre.ws
        Pages:      7
        Characters: 13513
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-ietf-curdle-dnskey-eddsa-03.txt

        URL:        https://www.rfc-editor.org/info/rfc8080

        DOI:        10.17487/RFC8080

This document describes how to specify Edwards-curve Digital Security
Algorithm (EdDSA) keys and signatures in DNS Security (DNSSEC).  It
uses EdDSA with the choice of two curves: Ed25519 and Ed448.

This document is a product of the CURves, Deprecating and a Little more Encryption Working Group of the IETF.

This is now a Proposed Standard.

STANDARDS TRACK: This document specifies an Internet Standards Track
protocol for the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the Official
Internet Protocol Standards (https://www.rfc-editor.org/standards) for the 
standardization state and status of this protocol.  Distribution of this 
memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  https://www.ietf.org/mailman/listinfo/ietf-announce
  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see https://www.rfc-editor.org/search
For downloading RFCs, see https://www.rfc-editor.org/retrieve/bulk

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team
Association Management Solutions, LLC



From nobody Wed Feb 15 22:54:24 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 895C31299CD for <curdle@ietfa.amsl.com>; Wed, 15 Feb 2017 22:54:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.203
X-Spam-Level: 
X-Spam-Status: No, score=-4.203 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id du236j_4t4jS for <curdle@ietfa.amsl.com>; Wed, 15 Feb 2017 22:54:20 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B83D41295E5 for <curdle@ietf.org>; Wed, 15 Feb 2017 22:54:20 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 9E5FEB820E1; Wed, 15 Feb 2017 22:54:20 -0800 (PST)
To: ondrej.sury@nic.cz, edmonds@mycre.ws, stephen.farrell@cs.tcd.ie, Kathleen.Moriarty.ietf@gmail.com, daniel.migault@ericsson.com, rsalz@akamai.com
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20170216065420.9E5FEB820E1@rfc-editor.org>
Date: Wed, 15 Feb 2017 22:54:20 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/fyxBmGA315ss3IjcZDyVOymwwys>
Cc: curdle@ietf.org, rfc-editor@rfc-editor.orgContent-Type, text/plain@rfc-editor.org, me+ietf@tomthorogood.co.uk, charset=UTF-8@rfc-editor.org
Subject: [Curdle] [Technical Errata Reported] RFC8080 (4935)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 06:54:22 -0000

The following errata report has been submitted for RFC8080,
"Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=8080&eid=4935

--------------------------------------
Type: Technical
Reported by: Tom Thorogood <me+ietf@tomthorogood.co.uk>

Section: 6

Original Text
-------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4= )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 3613 example.com. (
             Edk+IB9KNNWg0HAjm7FazXyrd5m3Rk8zNZbvNpAcM+eysqcUOMIjWoevFkj
             H5GaMWeG96GUVZu6ECKOQmemHDg== )



Sury & Edmonds               Standards Track                    [Page 3]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs= )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 35217 example.com. (
             5LL2obmzdqjWI+Xto5eP5adXt/T5tMhasWvwcyW4L3SzfcRawOle9bodhC+
             oip9ayUGjY9T/rL4rN3bOuESGDA== )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 9713 example.com. (
             Nmc0rgGKpr3GKYXcB1JmqqS4NYwhmechvJTqVzt3jR+Qy/lSLFoIk1L+9e3
             9GPL+5tVzDPN3f9kAwiu8KCuPPjtl227ayaCZtRKZuJax7n9NuYlZJIusX0
             SOIOKBGzG+yWYtz1/jjbzl5GGkWvREUCUA )











Sury & Edmonds               Standards Track                    [Page 4]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 38353 example.com. (
             +JjANio/LIzp7osmMYE5XD3H/YES8kXs5Vb9H8MjPS8OAGZMD37+LsCIcjg
             5ivt0d4Om/UaqETEAsJjaYe56CEQP5lhRWuD2ivBqE0zfwJTyp4WqvpULbp
             vaukswvv/WNEFxzEYQEIm9+xDlXj4pMAMA )

Corrected Text
--------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4= )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 3613 example.com. (
             oL9krJun7xfBOIWcGHi7mag5/hdZrKWw15jPGrHpjQeRAvTdszaPD+QLs3f
             x8A4M3e23mRZ9VrbpMngwcrqNAg== )



Sury & Edmonds               Standards Track                    [Page 3]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs= )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 35217 example.com. (
             zXQ0bkYgQTEFyfLyi9QoiY6D8ZdYo4wyUhVioYZXFdT410QPRITQSqJSnzQ
             oSm5poJ7gD7AQR0O7KuI5k2pcBg== )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 9713 example.com. (
             3cPAHkmlnxcDHMyg7vFC34l0blBhuG1qpwLmjInI8w1CMB29FkEAIJUA0am
             xWndkmnBZ6SKiwZSAxGILn/NBtOXft0+Gj7FSvOKxE/07+4RQvE581N3Aj/
             JtIyaiYVdnYtyMWbSNyGEY2213WKsJlwEA )











Sury & Edmonds               Standards Track                    [Page 4]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 38353 example.com. (
             E1/oLjSGIbmLny/4fcgM1z4oL6aqo+izT3urCyHyvEp4Sp8Syg1eI+lJ57C
             SnZqjJP41O/9l4m0AsQ4f7qI1gVnML8vWWiyW2KXhT9kuAICUSxv5OWbf81
             Rq7Yu60npabODB0QFPb/rkW3kUZmQ0YQUA )

Notes
-----
The script used to generate the examples (see https://gitlab.labs.nic.cz/labs/ietf/blob/master/dnskey.py) contains two errors that make the RRSIG records in the example section invalid.
1. The script fails to print the algorithm identifier (15 & 16, TBD1 & TBD2 in earlier drafts) for RRSIGs, and
2. the implementation of label counting includes the root zone as a label, giving an incorrect count of 3 rather than 2.

The first bug is more cosmetic but does result in unparsable RRSIG records, while the second bug causes invalid signatures to be produced.

With these two bugs corrected (and no other changes) the script produces valid examples which are included in the correction above. They have been successfully tested with an independent implementation of RFC 8080 based on https://github.com/miekg/dns & https://godoc.org/golang.org/x/crypto/ed25519 .

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC8080 (draft-ietf-curdle-dnskey-eddsa-03)
--------------------------------------
Title               : Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC
Publication Date    : February 2017
Author(s)           : O. Sury, R. Edmonds
Category            : PROPOSED STANDARD
Source              : CURves, Deprecating and a Little more Encryption
Area                : Security
Stream              : IETF
Verifying Party     : IESG


From nobody Thu Feb 16 02:52:36 2017
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2459B1299FB for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 02:52:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.302
X-Spam-Level: 
X-Spam-Status: No, score=-4.302 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hRIM7y2m2B3b for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 02:52:32 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7A5D41299FA for <curdle@ietf.org>; Thu, 16 Feb 2017 02:52:32 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 23A7DBE56 for <curdle@ietf.org>; Thu, 16 Feb 2017 10:52:30 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z4xWTl8Xidvj for <curdle@ietf.org>; Thu, 16 Feb 2017 10:52:18 +0000 (GMT)
Received: from [10.87.48.210] (95-45-153-252-dynamic.agg2.phb.bdt-fng.eircom.net [95.45.153.252]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id BA94DBE2D for <curdle@ietf.org>; Thu, 16 Feb 2017 10:52:17 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1487242338; bh=o7Z86p9s6lN91j7xUSYZ0xUpXW6ccpalChwTmG7Qf8Q=; h=Subject:References:To:From:Date:In-Reply-To:From; b=UMlY8rWWqjmCwRwOc9h8YSDBtQQ9LXuDrsu2Lq01X7ua4fRVa29LlChFU3b9AFfVk PwsIRNQ7JFygCFW+JC2BVwr/+5w4kWq5QYllir+V7jVTYcquQD+2j+mw9U4JByyCil og7Pj40hm5OkuKG51bu9aoEb87tZ68O2U8/JsB/Q=
References: <20170216065420.9E5FEB820E1@rfc-editor.org>
To: "curdle@ietf.org" <curdle@ietf.org>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
X-Forwarded-Message-Id: <20170216065420.9E5FEB820E1@rfc-editor.org>
Message-ID: <52fec725-f123-4dcc-b1ac-466570bd21d1@cs.tcd.ie>
Date: Thu, 16 Feb 2017 10:52:16 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <20170216065420.9E5FEB820E1@rfc-editor.org>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="EVe0doqg19WuwgGrfXrxBRCJbc5FQg2lm"
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/soqNCyuqb1qYeoQwEY4buaVW6CI>
Subject: [Curdle] Fwd: [Technical Errata Reported] RFC8080 (4935)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 10:52:35 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--EVe0doqg19WuwgGrfXrxBRCJbc5FQg2lm
Content-Type: multipart/mixed; boundary="NcXMo64BTqj6CwibR8qmorBifVcm5LGaI";
 protected-headers="v1"
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: "curdle@ietf.org" <curdle@ietf.org>
Message-ID: <52fec725-f123-4dcc-b1ac-466570bd21d1@cs.tcd.ie>
Subject: Fwd: [Technical Errata Reported] RFC8080 (4935)
References: <20170216065420.9E5FEB820E1@rfc-editor.org>
In-Reply-To: <20170216065420.9E5FEB820E1@rfc-editor.org>

--NcXMo64BTqj6CwibR8qmorBifVcm5LGaI
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Folks,

Assuming this erratum is correct, it looks like one that'd
be good to have verified soon. Can someone confirm the
correctness or otherwise of this erratum?

Thanks,
S.


-------- Forwarded Message --------
Subject: [Technical Errata Reported] RFC8080 (4935)
Date: Wed, 15 Feb 2017 22:54:20 -0800 (PST)
From: RFC Errata System <rfc-editor@rfc-editor.org>
To: ondrej.sury@nic.cz, edmonds@mycre.ws, stephen.farrell@cs.tcd.ie,
Kathleen.Moriarty.ietf@gmail.com, daniel.migault@ericsson.com,
rsalz@akamai.com
CC: me+ietf@tomthorogood.co.uk, curdle@ietf.org,
"rfc-editor@rfc-editor.org Content-Typetext/plain"@rfc-editor.org,
charset=3DUTF-8@rfc-editor.org

The following errata report has been submitted for RFC8080,
"Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=3D8080&eid=3D4935

--------------------------------------
Type: Technical
Reported by: Tom Thorogood <me+ietf@tomthorogood.co.uk>

Section: 6

Original Text
-------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 3613 example.com. (
             Edk+IB9KNNWg0HAjm7FazXyrd5m3Rk8zNZbvNpAcM+eysqcUOMIjWoevFkj
             H5GaMWeG96GUVZu6ECKOQmemHDg=3D=3D )



Sury & Edmonds               Standards Track                    [Page 3]
=0C
RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 35217 example.com. (
             5LL2obmzdqjWI+Xto5eP5adXt/T5tMhasWvwcyW4L3SzfcRawOle9bodhC+
             oip9ayUGjY9T/rL4rN3bOuESGDA=3D=3D )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 9713 example.com. (
             Nmc0rgGKpr3GKYXcB1JmqqS4NYwhmechvJTqVzt3jR+Qy/lSLFoIk1L+9e3
             9GPL+5tVzDPN3f9kAwiu8KCuPPjtl227ayaCZtRKZuJax7n9NuYlZJIusX0
             SOIOKBGzG+yWYtz1/jjbzl5GGkWvREUCUA )











Sury & Edmonds               Standards Track                    [Page 4]
=0C
RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 38353 example.com. (
             +JjANio/LIzp7osmMYE5XD3H/YES8kXs5Vb9H8MjPS8OAGZMD37+LsCIcjg
             5ivt0d4Om/UaqETEAsJjaYe56CEQP5lhRWuD2ivBqE0zfwJTyp4WqvpULbp
             vaukswvv/WNEFxzEYQEIm9+xDlXj4pMAMA )

Corrected Text
--------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 3613 example.com. (
             oL9krJun7xfBOIWcGHi7mag5/hdZrKWw15jPGrHpjQeRAvTdszaPD+QLs3f
             x8A4M3e23mRZ9VrbpMngwcrqNAg=3D=3D )



Sury & Edmonds               Standards Track                    [Page 3]
=0C
RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 35217 example.com. (
             zXQ0bkYgQTEFyfLyi9QoiY6D8ZdYo4wyUhVioYZXFdT410QPRITQSqJSnzQ
             oSm5poJ7gD7AQR0O7KuI5k2pcBg=3D=3D )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 9713 example.com. (
             3cPAHkmlnxcDHMyg7vFC34l0blBhuG1qpwLmjInI8w1CMB29FkEAIJUA0am
             xWndkmnBZ6SKiwZSAxGILn/NBtOXft0+Gj7FSvOKxE/07+4RQvE581N3Aj/
             JtIyaiYVdnYtyMWbSNyGEY2213WKsJlwEA )











Sury & Edmonds               Standards Track                    [Page 4]
=0C
RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 38353 example.com. (
             E1/oLjSGIbmLny/4fcgM1z4oL6aqo+izT3urCyHyvEp4Sp8Syg1eI+lJ57C
             SnZqjJP41O/9l4m0AsQ4f7qI1gVnML8vWWiyW2KXhT9kuAICUSxv5OWbf81
             Rq7Yu60npabODB0QFPb/rkW3kUZmQ0YQUA )

Notes
-----
The script used to generate the examples (see
https://gitlab.labs.nic.cz/labs/ietf/blob/master/dnskey.py) contains two
errors that make the RRSIG records in the example section invalid.
1. The script fails to print the algorithm identifier (15 & 16, TBD1 &
TBD2 in earlier drafts) for RRSIGs, and
2. the implementation of label counting includes the root zone as a
label, giving an incorrect count of 3 rather than 2.

The first bug is more cosmetic but does result in unparsable RRSIG
records, while the second bug causes invalid signatures to be produced.

With these two bugs corrected (and no other changes) the script produces
valid examples which are included in the correction above. They have
been successfully tested with an independent implementation of RFC 8080
based on https://github.com/miekg/dns &
https://godoc.org/golang.org/x/crypto/ed25519 .

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  can log in to
change the status and edit the report, if necessary.
--------------------------------------
RFC8080 (draft-ietf-curdle-dnskey-eddsa-03)
--------------------------------------
Title               : Edwards-Curve Digital Security Algorithm (EdDSA)
for DNSSEC
Publication Date    : February 2017
Author(s)           : O. Sury, R. Edmonds
Category            : PROPOSED STANDARD
Source              : CURves, Deprecating and a Little more Encryption
Area                : Security
Stream              : IETF
Verifying Party     : IESG



--NcXMo64BTqj6CwibR8qmorBifVcm5LGaI--

--EVe0doqg19WuwgGrfXrxBRCJbc5FQg2lm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEcBAEBCAAGBQJYpYRhAAoJEC88hzaAX42iQDgIALe4M+Goi0M3+mC1zTlXGblS
J58lBAdRr8rkiScN0wVLjKc/bCAfKibgLeuChKRCa/0XHIfxZkCKo5D1tCDAl+NU
PEDvf5O7WzGJysNFS5Pf7J/YfEQb8aJZFW8bqggBdwwCrS1Wjk8nufcWn2neKaVJ
0y7y5bAuNML8XACZOTzbA2f4A4iRGD7r4ll9KJF6mAsK+UnFjYB4UVV1d4IHhIyZ
3JjEo+rR9QMCtdvqUajl7UWvI8wikrNDUL98IM4qRM6Qw7AG+iFWyvtqRvCBKE58
VWaNs+ZWPKPcNo0Fvq0UNHgqn46b5BLdZRQ9kaBDQ2i/F1zlvY6V9coIHMZFOQw=
=ivNU
-----END PGP SIGNATURE-----

--EVe0doqg19WuwgGrfXrxBRCJbc5FQg2lm--


From nobody Thu Feb 16 03:11:15 2017
Return-Path: <ondrej.sury@nic.cz>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7410129A05 for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 03:11:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.001
X-Spam-Level: 
X-Spam-Status: No, score=-7.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nic.cz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OxmGiPDhjEdF for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 03:11:10 -0800 (PST)
Received: from mail.nic.cz (mail.nic.cz [IPv6:2001:1488:800:400::400]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0000C1299DA for <curdle@ietf.org>; Thu, 16 Feb 2017 03:11:09 -0800 (PST)
Received: from zimbra.rfc1925.org (calcifer.labs.nic.cz [217.31.192.138]) by mail.nic.cz (Postfix) with ESMTP id 0E10860118; Thu, 16 Feb 2017 12:11:08 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nic.cz; s=default; t=1487243468; bh=5plLBL6Q5EzaFSVDeeuaOVLQd3T/cJiOXEQGcVQCY4M=; h=Date:From:To; b=lwygN9/KLbrtzkSExEbYMiqlYm+ykTVEKOpe34FpUtMpM29hzOLuLB+INdjXxiD4D 5MM/hTR8cfs2XfUXfz8ZK84O5/mDwAkw7ifP+jSlso6CXWbN6RxHObJI2hss1xRCM/ R9HkgzgZZbKtUFKNz2liw+dDQsT+qbnAq4gFcZkY=
Date: Thu, 16 Feb 2017 12:11:07 +0100 (CET)
From: =?utf-8?Q?Ond=C5=99ej_Sur=C3=BD?= <ondrej.sury@nic.cz>
To: rfc-editor <rfc-editor@rfc-editor.org>
Message-ID: <1365098723.22519.1487243467864.JavaMail.zimbra@nic.cz>
In-Reply-To: <20170216065420.9E5FEB820E1@rfc-editor.org>
References: <20170216065420.9E5FEB820E1@rfc-editor.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Originating-IP: [217.31.192.138]
X-Mailer: Zimbra 8.7.0_GA_1659 (ZimbraWebClient - SAF10 (Linux)/8.7.0_GA_1659)
Thread-Topic: RFC8080 (4935)
Thread-Index: KWWEkZrGFZjs0ORxNx7XO7UOAIb6Aw==
X-Virus-Scanned: clamav-milter 0.99.2 at mail
X-Virus-Status: Clean
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/pstMJ3EI6YcvSoY-s4J2k6cs1cs>
Cc: Daniel Migault <daniel.migault@ericsson.com>, Rich Salz <rsalz@akamai.com>, text/plain@rfc-editor.org, curdle <curdle@ietf.org>, charset=UTF-8@rfc-editor.org, Kathleen Moriarty ietf <Kathleen.Moriarty.ietf@gmail.com>, me+ietf@tomthorogood.co.uk, edmonds <edmonds@mycre.ws>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Subject: Re: [Curdle] [Technical Errata Reported] RFC8080 (4935)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 11:11:13 -0000

I have fixed the mentioned bugs in my dnskey.py and I can confirm the errat=
um is correct.

Cheers,
Ondrej

--
 Ond=C5=99ej Sur=C3=BD -- Technical Fellow
 --------------------------------------------
 CZ.NIC, z.s.p.o.    --     Laborato=C5=99e CZ.NIC
 Milesovska 5, 130 00 Praha 3, Czech Republic
 mailto:ondrej.sury@nic.cz    https://nic.cz/
 --------------------------------------------

----- Original Message -----
> From: "rfc-editor" <rfc-editor@rfc-editor.org>
> To: "Ond=C5=99ej Sur=C3=BD" <ondrej.sury@nic.cz>, "edmonds" <edmonds@mycr=
e.ws>, "Stephen Farrell" <stephen.farrell@cs.tcd.ie>,
> "Kathleen Moriarty ietf" <Kathleen.Moriarty.ietf@gmail.com>, "Daniel Miga=
ult" <daniel.migault@ericsson.com>, "Rich
> Salz" <rsalz@akamai.com>
> Cc: me+ietf@tomthorogood.co.uk, "curdle" <curdle@ietf.org>, text/plain@rf=
c-editor.org, charset=3DUTF-8@rfc-editor.org
> Sent: Thursday, 16 February, 2017 07:54:20
> Subject: [Technical Errata Reported] RFC8080 (4935)

> The following errata report has been submitted for RFC8080,
> "Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC".
>=20
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=3D8080&eid=3D4935
>=20
> --------------------------------------
> Type: Technical
> Reported by: Tom Thorogood <me+ietf@tomthorogood.co.uk>
>=20
> Section: 6
>=20
> Original Text
> -------------
> 6.  Examples
>=20
> 6.1.  Ed25519 Examples
>=20
> Private-key-format: v1.2
> Algorithm: 15 (ED25519)
> PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D
>=20
> example.com. 3600 IN DNSKEY 257 3 15 (
>             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )
>=20
> example.com. 3600 IN DS 3613 15 2 (
>             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
>             a304b )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 3 3600 (
>             1440021600 1438207200 3613 example.com. (
>             Edk+IB9KNNWg0HAjm7FazXyrd5m3Rk8zNZbvNpAcM+eysqcUOMIjWoevFkj
>             H5GaMWeG96GUVZu6ECKOQmemHDg=3D=3D )
>=20
>=20
>=20
> Sury & Edmonds               Standards Track                    [Page 3]
>=20
> RFC 8080                    EdDSA for DNSSEC               February 2017
>=20
>=20
> Private-key-format: v1.2
> Algorithm: 15 (ED25519)
> PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D
>=20
> example.com. 3600 IN DNSKEY 257 3 15 (
>             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )
>=20
> example.com. 3600 IN DS 35217 15 2 (
>             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
>             6614c )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 3 3600 (
>             1440021600 1438207200 35217 example.com. (
>             5LL2obmzdqjWI+Xto5eP5adXt/T5tMhasWvwcyW4L3SzfcRawOle9bodhC+
>             oip9ayUGjY9T/rL4rN3bOuESGDA=3D=3D )
>=20
> 6.2.  Ed448 Examples
>=20
> Private-key-format: v1.2
> Algorithm: 16 (ED448)
> PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
>            8wWbDDct/U3FhYWA
>=20
> example.com. 3600 IN DNSKEY 257 3 16 (
>             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
>             1FYYUcJKm1MDpJtIA )
>=20
> example.com. 3600 IN DS 9713 16 2 (
>             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
>             b19c7 )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 3 3600 (
>             1440021600 1438207200 9713 example.com. (
>             Nmc0rgGKpr3GKYXcB1JmqqS4NYwhmechvJTqVzt3jR+Qy/lSLFoIk1L+9e3
>             9GPL+5tVzDPN3f9kAwiu8KCuPPjtl227ayaCZtRKZuJax7n9NuYlZJIusX0
>             SOIOKBGzG+yWYtz1/jjbzl5GGkWvREUCUA )
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
> Sury & Edmonds               Standards Track                    [Page 4]
>=20
> RFC 8080                    EdDSA for DNSSEC               February 2017
>=20
>=20
> Private-key-format: v1.2
> Algorithm: 16 (ED448)
> PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
>            2BlZdz4hdSTkOdOA
>=20
> example.com. 3600 IN DNSKEY 257 3 16 (
>             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
>             Lp5HlHAMy12VoISsA )
>=20
> example.com. 3600 IN DS 38353 16 2 (
>             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
>             28af4 )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 3 3600 (
>             1440021600 1438207200 38353 example.com. (
>             +JjANio/LIzp7osmMYE5XD3H/YES8kXs5Vb9H8MjPS8OAGZMD37+LsCIcjg
>             5ivt0d4Om/UaqETEAsJjaYe56CEQP5lhRWuD2ivBqE0zfwJTyp4WqvpULbp
>             vaukswvv/WNEFxzEYQEIm9+xDlXj4pMAMA )
>=20
> Corrected Text
> --------------
> 6.  Examples
>=20
> 6.1.  Ed25519 Examples
>=20
> Private-key-format: v1.2
> Algorithm: 15 (ED25519)
> PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D
>=20
> example.com. 3600 IN DNSKEY 257 3 15 (
>             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )
>=20
> example.com. 3600 IN DS 3613 15 2 (
>             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
>             a304b )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 15 2 3600 (
>             1440021600 1438207200 3613 example.com. (
>             oL9krJun7xfBOIWcGHi7mag5/hdZrKWw15jPGrHpjQeRAvTdszaPD+QLs3f
>             x8A4M3e23mRZ9VrbpMngwcrqNAg=3D=3D )
>=20
>=20
>=20
> Sury & Edmonds               Standards Track                    [Page 3]
>=20
> RFC 8080                    EdDSA for DNSSEC               February 2017
>=20
>=20
> Private-key-format: v1.2
> Algorithm: 15 (ED25519)
> PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D
>=20
> example.com. 3600 IN DNSKEY 257 3 15 (
>             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )
>=20
> example.com. 3600 IN DS 35217 15 2 (
>             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
>             6614c )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 15 2 3600 (
>             1440021600 1438207200 35217 example.com. (
>             zXQ0bkYgQTEFyfLyi9QoiY6D8ZdYo4wyUhVioYZXFdT410QPRITQSqJSnzQ
>             oSm5poJ7gD7AQR0O7KuI5k2pcBg=3D=3D )
>=20
> 6.2.  Ed448 Examples
>=20
> Private-key-format: v1.2
> Algorithm: 16 (ED448)
> PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
>            8wWbDDct/U3FhYWA
>=20
> example.com. 3600 IN DNSKEY 257 3 16 (
>             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
>             1FYYUcJKm1MDpJtIA )
>=20
> example.com. 3600 IN DS 9713 16 2 (
>             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
>             b19c7 )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 16 2 3600 (
>             1440021600 1438207200 9713 example.com. (
>             3cPAHkmlnxcDHMyg7vFC34l0blBhuG1qpwLmjInI8w1CMB29FkEAIJUA0am
>             xWndkmnBZ6SKiwZSAxGILn/NBtOXft0+Gj7FSvOKxE/07+4RQvE581N3Aj/
>             JtIyaiYVdnYtyMWbSNyGEY2213WKsJlwEA )
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
> Sury & Edmonds               Standards Track                    [Page 4]
>=20
> RFC 8080                    EdDSA for DNSSEC               February 2017
>=20
>=20
> Private-key-format: v1.2
> Algorithm: 16 (ED448)
> PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
>            2BlZdz4hdSTkOdOA
>=20
> example.com. 3600 IN DNSKEY 257 3 16 (
>             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
>             Lp5HlHAMy12VoISsA )
>=20
> example.com. 3600 IN DS 38353 16 2 (
>             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
>             28af4 )
>=20
> example.com. 3600 IN MX 10 mail.example.com.
>=20
> example.com. 3600 IN RRSIG MX 16 2 3600 (
>             1440021600 1438207200 38353 example.com. (
>             E1/oLjSGIbmLny/4fcgM1z4oL6aqo+izT3urCyHyvEp4Sp8Syg1eI+lJ57C
>             SnZqjJP41O/9l4m0AsQ4f7qI1gVnML8vWWiyW2KXhT9kuAICUSxv5OWbf81
>             Rq7Yu60npabODB0QFPb/rkW3kUZmQ0YQUA )
>=20
> Notes
> -----
> The script used to generate the examples (see
> https://gitlab.labs.nic.cz/labs/ietf/blob/master/dnskey.py) contains two =
errors
> that make the RRSIG records in the example section invalid.
> 1. The script fails to print the algorithm identifier (15 & 16, TBD1 & TB=
D2 in
> earlier drafts) for RRSIGs, and
> 2. the implementation of label counting includes the root zone as a label=
,
> giving an incorrect count of 3 rather than 2.
>=20
> The first bug is more cosmetic but does result in unparsable RRSIG record=
s,
> while the second bug causes invalid signatures to be produced.
>=20
> With these two bugs corrected (and no other changes) the script produces =
valid
> examples which are included in the correction above. They have been
> successfully tested with an independent implementation of RFC 8080 based =
on
> https://github.com/miekg/dns & https://godoc.org/golang.org/x/crypto/ed25=
519 .
>=20
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> can log in to change the status and edit the report, if necessary.
>=20
> --------------------------------------
> RFC8080 (draft-ietf-curdle-dnskey-eddsa-03)
> --------------------------------------
> Title               : Edwards-Curve Digital Security Algorithm (EdDSA) fo=
r
> DNSSEC
> Publication Date    : February 2017
> Author(s)           : O. Sury, R. Edmonds
> Category            : PROPOSED STANDARD
> Source              : CURves, Deprecating and a Little more Encryption
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG


From nobody Thu Feb 16 03:13:25 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B2D8B129A15; Thu, 16 Feb 2017 03:13:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.203
X-Spam-Level: 
X-Spam-Status: No, score=-4.203 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kClcPDQ_NLVY; Thu, 16 Feb 2017 03:13:10 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 37286129A0E; Thu, 16 Feb 2017 03:13:10 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 26FA8B82109; Thu, 16 Feb 2017 03:13:10 -0800 (PST)
To: me+ietf@tomthorogood.co.uk, ondrej.sury@nic.cz, edmonds@mycre.ws
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20170216111310.26FA8B82109@rfc-editor.org>
Date: Thu, 16 Feb 2017 03:13:10 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/xkrzo-K-nhdAXWHce9I-pbfIsX4>
Cc: curdle@ietf.org, text/plain@rfc-editor.org, charset=UTF-8@rfc-editor.org, rfc-editor@rfc-editor.orgContent-Type, iesg@ietf.org, stephen.farrell@cs.tcd.ie
Subject: [Curdle] [Errata Verified] RFC8080 (4935)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 11:13:20 -0000

The following errata report has been verified for RFC8080,
"Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=8080&eid=4935

--------------------------------------
Status: Verified
Type: Technical

Reported by: Tom Thorogood <me+ietf@tomthorogood.co.uk>
Date Reported: 2017-02-16
Verified by: Stephen Farrell (IESG)

Section: 6

Original Text
-------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4= )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 3613 example.com. (
             Edk+IB9KNNWg0HAjm7FazXyrd5m3Rk8zNZbvNpAcM+eysqcUOMIjWoevFkj
             H5GaMWeG96GUVZu6ECKOQmemHDg== )



Sury & Edmonds               Standards Track                    [Page 3]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs= )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 35217 example.com. (
             5LL2obmzdqjWI+Xto5eP5adXt/T5tMhasWvwcyW4L3SzfcRawOle9bodhC+
             oip9ayUGjY9T/rL4rN3bOuESGDA== )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 9713 example.com. (
             Nmc0rgGKpr3GKYXcB1JmqqS4NYwhmechvJTqVzt3jR+Qy/lSLFoIk1L+9e3
             9GPL+5tVzDPN3f9kAwiu8KCuPPjtl227ayaCZtRKZuJax7n9NuYlZJIusX0
             SOIOKBGzG+yWYtz1/jjbzl5GGkWvREUCUA )











Sury & Edmonds               Standards Track                    [Page 4]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 3 3600 (
             1440021600 1438207200 38353 example.com. (
             +JjANio/LIzp7osmMYE5XD3H/YES8kXs5Vb9H8MjPS8OAGZMD37+LsCIcjg
             5ivt0d4Om/UaqETEAsJjaYe56CEQP5lhRWuD2ivBqE0zfwJTyp4WqvpULbp
             vaukswvv/WNEFxzEYQEIm9+xDlXj4pMAMA )

Corrected Text
--------------
6.  Examples

6.1.  Ed25519 Examples

Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=

example.com. 3600 IN DNSKEY 257 3 15 (
             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4= )

example.com. 3600 IN DS 3613 15 2 (
             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e79
             a304b )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 3613 example.com. (
             oL9krJun7xfBOIWcGHi7mag5/hdZrKWw15jPGrHpjQeRAvTdszaPD+QLs3f
             x8A4M3e23mRZ9VrbpMngwcrqNAg== )



Sury & Edmonds               Standards Track                    [Page 3]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=

example.com. 3600 IN DNSKEY 257 3 15 (
             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs= )

example.com. 3600 IN DS 35217 15 2 (
             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80c
             6614c )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 15 2 3600 (
             1440021600 1438207200 35217 example.com. (
             zXQ0bkYgQTEFyfLyi9QoiY6D8ZdYo4wyUhVioYZXFdT410QPRITQSqJSnzQ
             oSm5poJ7gD7AQR0O7KuI5k2pcBg== )

6.2.  Ed448 Examples

Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA9x
            8wWbDDct/U3FhYWA

example.com. 3600 IN DNSKEY 257 3 16 (
             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPodx
             1FYYUcJKm1MDpJtIA )

example.com. 3600 IN DS 9713 16 2 (
             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb2
             b19c7 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 9713 example.com. (
             3cPAHkmlnxcDHMyg7vFC34l0blBhuG1qpwLmjInI8w1CMB29FkEAIJUA0am
             xWndkmnBZ6SKiwZSAxGILn/NBtOXft0+Gj7FSvOKxE/07+4RQvE581N3Aj/
             JtIyaiYVdnYtyMWbSNyGEY2213WKsJlwEA )











Sury & Edmonds               Standards Track                    [Page 4]

RFC 8080                    EdDSA for DNSSEC               February 2017


Private-key-format: v1.2
Algorithm: 16 (ED448)
PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6NnPO
            2BlZdz4hdSTkOdOA

example.com. 3600 IN DNSKEY 257 3 16 (
             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgcN
             Lp5HlHAMy12VoISsA )

example.com. 3600 IN DS 38353 16 2 (
             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1ba
             28af4 )

example.com. 3600 IN MX 10 mail.example.com.

example.com. 3600 IN RRSIG MX 16 2 3600 (
             1440021600 1438207200 38353 example.com. (
             E1/oLjSGIbmLny/4fcgM1z4oL6aqo+izT3urCyHyvEp4Sp8Syg1eI+lJ57C
             SnZqjJP41O/9l4m0AsQ4f7qI1gVnML8vWWiyW2KXhT9kuAICUSxv5OWbf81
             Rq7Yu60npabODB0QFPb/rkW3kUZmQ0YQUA )

Notes
-----
The script used to generate the examples (see https://gitlab.labs.nic.cz/labs/ietf/blob/master/dnskey.py) contains two errors that make the RRSIG records in the example section invalid.
1. The script fails to print the algorithm identifier (15 & 16, TBD1 & TBD2 in earlier drafts) for RRSIGs, and
2. the implementation of label counting includes the root zone as a label, giving an incorrect count of 3 rather than 2.

The first bug is more cosmetic but does result in unparsable RRSIG records, while the second bug causes invalid signatures to be produced.

With these two bugs corrected (and no other changes) the script produces valid examples which are included in the correction above. They have been successfully tested with an independent implementation of RFC 8080 based on https://github.com/miekg/dns & https://godoc.org/golang.org/x/crypto/ed25519 .

--------------------------------------
RFC8080 (draft-ietf-curdle-dnskey-eddsa-03)
--------------------------------------
Title               : Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC
Publication Date    : February 2017
Author(s)           : O. Sury, R. Edmonds
Category            : PROPOSED STANDARD
Source              : CURves, Deprecating and a Little more Encryption
Area                : Security
Stream              : IETF
Verifying Party     : IESG


From nobody Thu Feb 16 03:14:04 2017
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80935129A95 for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 03:14:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.302
X-Spam-Level: 
X-Spam-Status: No, score=-4.302 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eWg9KCfIlcJq for <curdle@ietfa.amsl.com>; Thu, 16 Feb 2017 03:13:51 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B7ADE129A18 for <curdle@ietf.org>; Thu, 16 Feb 2017 03:13:50 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id B20BDBE56; Thu, 16 Feb 2017 11:13:48 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uoX7C0Llidf8; Thu, 16 Feb 2017 11:13:38 +0000 (GMT)
Received: from [10.87.48.210] (95-45-153-252-dynamic.agg2.phb.bdt-fng.eircom.net [95.45.153.252]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 1B223BE2F; Thu, 16 Feb 2017 11:13:38 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1487243618; bh=QTV9Gl2RWUuGp5H1yUq+3M5dfvpfOaBtwS9wJEyHbuw=; h=Subject:To:References:Cc:From:Date:In-Reply-To:From; b=2lQXcvhFIqioumlt6mqne7OboI7akEOkzhHdBBhZQOlOqMQWNBStigvDBqKolCPK0 op54Hkn19lp5PrQSFfWcc3tRhOB6JUBIl/T2wlax0HqaP/BlHMGqae7WvhvPuWG5eV XzcyjrdBCYg/+8ZD+JvUb7wiriLOmhO68ox4kuxs=
To: =?UTF-8?B?T25kxZllaiBTdXLDvQ==?= <ondrej.sury@nic.cz>, rfc-editor <rfc-editor@rfc-editor.org>
References: <20170216065420.9E5FEB820E1@rfc-editor.org> <1365098723.22519.1487243467864.JavaMail.zimbra@nic.cz>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <4c46aaa7-bc47-f444-d641-175a4e1cc817@cs.tcd.ie>
Date: Thu, 16 Feb 2017 11:13:35 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <1365098723.22519.1487243467864.JavaMail.zimbra@nic.cz>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="UiAk0KfUL3QfVCccKooCTnQw9Vj0u1pJe"
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/_IT8_PHR8zq2MA7vO898Svxwh3Y>
Cc: Daniel Migault <daniel.migault@ericsson.com>, Rich Salz <rsalz@akamai.com>, text/plain@rfc-editor.org, curdle <curdle@ietf.org>, charset=UTF-8@rfc-editor.org, Kathleen Moriarty ietf <Kathleen.Moriarty.ietf@gmail.com>, me+ietf@tomthorogood.co.uk, edmonds <edmonds@mycre.ws>
Subject: Re: [Curdle] [Technical Errata Reported] RFC8080 (4935)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 11:14:02 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--UiAk0KfUL3QfVCccKooCTnQw9Vj0u1pJe
Content-Type: multipart/mixed; boundary="eW5cTXeKEB4efJIhfQs5PA0qLKLdlEC5e";
 protected-headers="v1"
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: =?UTF-8?B?T25kxZllaiBTdXLDvQ==?= <ondrej.sury@nic.cz>,
 rfc-editor <rfc-editor@rfc-editor.org>
Cc: Daniel Migault <daniel.migault@ericsson.com>, Rich Salz
 <rsalz@akamai.com>, text/plain@rfc-editor.org, curdle <curdle@ietf.org>,
 charset=UTF-8@rfc-editor.org,
 Kathleen Moriarty ietf <Kathleen.Moriarty.ietf@gmail.com>,
 me+ietf@tomthorogood.co.uk, edmonds <edmonds@mycre.ws>
Message-ID: <4c46aaa7-bc47-f444-d641-175a4e1cc817@cs.tcd.ie>
Subject: Re: [Curdle] [Technical Errata Reported] RFC8080 (4935)
References: <20170216065420.9E5FEB820E1@rfc-editor.org>
 <1365098723.22519.1487243467864.JavaMail.zimbra@nic.cz>
In-Reply-To: <1365098723.22519.1487243467864.JavaMail.zimbra@nic.cz>

--eW5cTXeKEB4efJIhfQs5PA0qLKLdlEC5e
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Thanks Ond=C5=99ej.

I hit the "verify" button for that one.

S.

On 16/02/17 11:11, Ond=C5=99ej Sur=C3=BD wrote:
> I have fixed the mentioned bugs in my dnskey.py and I can confirm the e=
rratum is correct.
>=20
> Cheers,
> Ondrej
>=20
> --
>  Ond=C5=99ej Sur=C3=BD -- Technical Fellow
>  --------------------------------------------
>  CZ.NIC, z.s.p.o.    --     Laborato=C5=99e CZ.NIC
>  Milesovska 5, 130 00 Praha 3, Czech Republic
>  mailto:ondrej.sury@nic.cz    https://nic.cz/
>  --------------------------------------------
>=20
> ----- Original Message -----
>> From: "rfc-editor" <rfc-editor@rfc-editor.org>
>> To: "Ond=C5=99ej Sur=C3=BD" <ondrej.sury@nic.cz>, "edmonds" <edmonds@m=
ycre.ws>, "Stephen Farrell" <stephen.farrell@cs.tcd.ie>,
>> "Kathleen Moriarty ietf" <Kathleen.Moriarty.ietf@gmail.com>, "Daniel M=
igault" <daniel.migault@ericsson.com>, "Rich
>> Salz" <rsalz@akamai.com>
>> Cc: me+ietf@tomthorogood.co.uk, "curdle" <curdle@ietf.org>, text/plain=
@rfc-editor.org, charset=3DUTF-8@rfc-editor.org
>> Sent: Thursday, 16 February, 2017 07:54:20
>> Subject: [Technical Errata Reported] RFC8080 (4935)
>=20
>> The following errata report has been submitted for RFC8080,
>> "Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC".
>>
>> --------------------------------------
>> You may review the report below and at:
>> http://www.rfc-editor.org/errata_search.php?rfc=3D8080&eid=3D4935
>>
>> --------------------------------------
>> Type: Technical
>> Reported by: Tom Thorogood <me+ietf@tomthorogood.co.uk>
>>
>> Section: 6
>>
>> Original Text
>> -------------
>> 6.  Examples
>>
>> 6.1.  Ed25519 Examples
>>
>> Private-key-format: v1.2
>> Algorithm: 15 (ED25519)
>> PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D
>>
>> example.com. 3600 IN DNSKEY 257 3 15 (
>>             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )
>>
>> example.com. 3600 IN DS 3613 15 2 (
>>             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e7=
9
>>             a304b )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 3 3600 (
>>             1440021600 1438207200 3613 example.com. (
>>             Edk+IB9KNNWg0HAjm7FazXyrd5m3Rk8zNZbvNpAcM+eysqcUOMIjWoevFk=
j
>>             H5GaMWeG96GUVZu6ECKOQmemHDg=3D=3D )
>>
>>
>>
>> Sury & Edmonds               Standards Track                    [Page =
3]
>>
>> RFC 8080                    EdDSA for DNSSEC               February 20=
17
>>
>>
>> Private-key-format: v1.2
>> Algorithm: 15 (ED25519)
>> PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D
>>
>> example.com. 3600 IN DNSKEY 257 3 15 (
>>             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )
>>
>> example.com. 3600 IN DS 35217 15 2 (
>>             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80=
c
>>             6614c )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 3 3600 (
>>             1440021600 1438207200 35217 example.com. (
>>             5LL2obmzdqjWI+Xto5eP5adXt/T5tMhasWvwcyW4L3SzfcRawOle9bodhC=
+
>>             oip9ayUGjY9T/rL4rN3bOuESGDA=3D=3D )
>>
>> 6.2.  Ed448 Examples
>>
>> Private-key-format: v1.2
>> Algorithm: 16 (ED448)
>> PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA=
9x
>>            8wWbDDct/U3FhYWA
>>
>> example.com. 3600 IN DNSKEY 257 3 16 (
>>             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPod=
x
>>             1FYYUcJKm1MDpJtIA )
>>
>> example.com. 3600 IN DS 9713 16 2 (
>>             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb=
2
>>             b19c7 )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 3 3600 (
>>             1440021600 1438207200 9713 example.com. (
>>             Nmc0rgGKpr3GKYXcB1JmqqS4NYwhmechvJTqVzt3jR+Qy/lSLFoIk1L+9e=
3
>>             9GPL+5tVzDPN3f9kAwiu8KCuPPjtl227ayaCZtRKZuJax7n9NuYlZJIusX=
0
>>             SOIOKBGzG+yWYtz1/jjbzl5GGkWvREUCUA )
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>> Sury & Edmonds               Standards Track                    [Page =
4]
>>
>> RFC 8080                    EdDSA for DNSSEC               February 20=
17
>>
>>
>> Private-key-format: v1.2
>> Algorithm: 16 (ED448)
>> PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6Nn=
PO
>>            2BlZdz4hdSTkOdOA
>>
>> example.com. 3600 IN DNSKEY 257 3 16 (
>>             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgc=
N
>>             Lp5HlHAMy12VoISsA )
>>
>> example.com. 3600 IN DS 38353 16 2 (
>>             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1b=
a
>>             28af4 )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 3 3600 (
>>             1440021600 1438207200 38353 example.com. (
>>             +JjANio/LIzp7osmMYE5XD3H/YES8kXs5Vb9H8MjPS8OAGZMD37+LsCIcj=
g
>>             5ivt0d4Om/UaqETEAsJjaYe56CEQP5lhRWuD2ivBqE0zfwJTyp4WqvpULb=
p
>>             vaukswvv/WNEFxzEYQEIm9+xDlXj4pMAMA )
>>
>> Corrected Text
>> --------------
>> 6.  Examples
>>
>> 6.1.  Ed25519 Examples
>>
>> Private-key-format: v1.2
>> Algorithm: 15 (ED25519)
>> PrivateKey: ODIyNjAzODQ2MjgwODAxMjI2NDUxOTAyMDQxNDIyNjI=3D
>>
>> example.com. 3600 IN DNSKEY 257 3 15 (
>>             l02Woi0iS8Aa25FQkUd9RMzZHJpBoRQwAQEX1SxZJA4=3D )
>>
>> example.com. 3600 IN DS 3613 15 2 (
>>             3aa5ab37efce57f737fc1627013fee07bdf241bd10f3b1964ab55c78e7=
9
>>             a304b )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 15 2 3600 (
>>             1440021600 1438207200 3613 example.com. (
>>             oL9krJun7xfBOIWcGHi7mag5/hdZrKWw15jPGrHpjQeRAvTdszaPD+QLs3=
f
>>             x8A4M3e23mRZ9VrbpMngwcrqNAg=3D=3D )
>>
>>
>>
>> Sury & Edmonds               Standards Track                    [Page =
3]
>>
>> RFC 8080                    EdDSA for DNSSEC               February 20=
17
>>
>>
>> Private-key-format: v1.2
>> Algorithm: 15 (ED25519)
>> PrivateKey: DSSF3o0s0f+ElWzj9E/Osxw8hLpk55chkmx0LYN5WiY=3D
>>
>> example.com. 3600 IN DNSKEY 257 3 15 (
>>             zPnZ/QwEe7S8C5SPz2OfS5RR40ATk2/rYnE9xHIEijs=3D )
>>
>> example.com. 3600 IN DS 35217 15 2 (
>>             401781b934e392de492ec77ae2e15d70f6575a1c0bc59c5275c04ebe80=
c
>>             6614c )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 15 2 3600 (
>>             1440021600 1438207200 35217 example.com. (
>>             zXQ0bkYgQTEFyfLyi9QoiY6D8ZdYo4wyUhVioYZXFdT410QPRITQSqJSnz=
Q
>>             oSm5poJ7gD7AQR0O7KuI5k2pcBg=3D=3D )
>>
>> 6.2.  Ed448 Examples
>>
>> Private-key-format: v1.2
>> Algorithm: 16 (ED448)
>> PrivateKey: xZ+5Cgm463xugtkY5B0Jx6erFTXp13rYegst0qRtNsOYnaVpMx0Z/c5EiA=
9x
>>            8wWbDDct/U3FhYWA
>>
>> example.com. 3600 IN DNSKEY 257 3 16 (
>>             3kgROaDjrh0H2iuixWBrc8g2EpBBLCdGzHmn+G2MpTPhpj/OiBVHHSfPod=
x
>>             1FYYUcJKm1MDpJtIA )
>>
>> example.com. 3600 IN DS 9713 16 2 (
>>             6ccf18d5bc5d7fc2fceb1d59d17321402f2aa8d368048db93dd811f5cb=
2
>>             b19c7 )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 16 2 3600 (
>>             1440021600 1438207200 9713 example.com. (
>>             3cPAHkmlnxcDHMyg7vFC34l0blBhuG1qpwLmjInI8w1CMB29FkEAIJUA0a=
m
>>             xWndkmnBZ6SKiwZSAxGILn/NBtOXft0+Gj7FSvOKxE/07+4RQvE581N3Aj=
/
>>             JtIyaiYVdnYtyMWbSNyGEY2213WKsJlwEA )
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>
>> Sury & Edmonds               Standards Track                    [Page =
4]
>>
>> RFC 8080                    EdDSA for DNSSEC               February 20=
17
>>
>>
>> Private-key-format: v1.2
>> Algorithm: 16 (ED448)
>> PrivateKey: WEykD3ht3MHkU8iH4uVOLz8JLwtRBSqiBoM6fF72+Mrp/u5gjxuB1DV6Nn=
PO
>>            2BlZdz4hdSTkOdOA
>>
>> example.com. 3600 IN DNSKEY 257 3 16 (
>>             kkreGWoccSDmUBGAe7+zsbG6ZAFQp+syPmYUurBRQc3tDjeMCJcVMRDmgc=
N
>>             Lp5HlHAMy12VoISsA )
>>
>> example.com. 3600 IN DS 38353 16 2 (
>>             645ff078b3568f5852b70cb60e8e696cc77b75bfaaffc118cf79cbda1b=
a
>>             28af4 )
>>
>> example.com. 3600 IN MX 10 mail.example.com.
>>
>> example.com. 3600 IN RRSIG MX 16 2 3600 (
>>             1440021600 1438207200 38353 example.com. (
>>             E1/oLjSGIbmLny/4fcgM1z4oL6aqo+izT3urCyHyvEp4Sp8Syg1eI+lJ57=
C
>>             SnZqjJP41O/9l4m0AsQ4f7qI1gVnML8vWWiyW2KXhT9kuAICUSxv5OWbf8=
1
>>             Rq7Yu60npabODB0QFPb/rkW3kUZmQ0YQUA )
>>
>> Notes
>> -----
>> The script used to generate the examples (see
>> https://gitlab.labs.nic.cz/labs/ietf/blob/master/dnskey.py) contains t=
wo errors
>> that make the RRSIG records in the example section invalid.
>> 1. The script fails to print the algorithm identifier (15 & 16, TBD1 &=
 TBD2 in
>> earlier drafts) for RRSIGs, and
>> 2. the implementation of label counting includes the root zone as a la=
bel,
>> giving an incorrect count of 3 rather than 2.
>>
>> The first bug is more cosmetic but does result in unparsable RRSIG rec=
ords,
>> while the second bug causes invalid signatures to be produced.
>>
>> With these two bugs corrected (and no other changes) the script produc=
es valid
>> examples which are included in the correction above. They have been
>> successfully tested with an independent implementation of RFC 8080 bas=
ed on
>> https://github.com/miekg/dns & https://godoc.org/golang.org/x/crypto/e=
d25519 .
>>
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". If necessary, please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party
>> can log in to change the status and edit the report, if necessary.
>>
>> --------------------------------------
>> RFC8080 (draft-ietf-curdle-dnskey-eddsa-03)
>> --------------------------------------
>> Title               : Edwards-Curve Digital Security Algorithm (EdDSA)=
 for
>> DNSSEC
>> Publication Date    : February 2017
>> Author(s)           : O. Sury, R. Edmonds
>> Category            : PROPOSED STANDARD
>> Source              : CURves, Deprecating and a Little more Encryption=

>> Area                : Security
>> Stream              : IETF
>> Verifying Party     : IESG
>=20
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle
>=20


--eW5cTXeKEB4efJIhfQs5PA0qLKLdlEC5e--

--UiAk0KfUL3QfVCccKooCTnQw9Vj0u1pJe
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEcBAEBCAAGBQJYpYlfAAoJEC88hzaAX42iJO0H/00qt8qVUdCwPf495b+2okqh
oCV9WCQ7FWDZVrcD+Q1941prVIWXS/+2b9M0py+ZikQ8DwVqDN+FtG4CmAQSgA5n
cAFmxqLdIuEVKSxwr9uYyCpThSBE7da/z3uMTaWhhtr4voXnuz7EcaTQP7/PrVqh
YrlrFhAe+xvnnkWC1E68IxF3wwl08xjl2kAMMSEqysz3K9nHFF8hMk8IpI8fYVkh
Qu35pEe4Cf2r2PJUU0w/pn4nXwgl0w2ZQ1gcVUgQvsixJHec5jo/f2cbdKK4YCyQ
AHgm7akEIkNqhyh7/YBSe9FrrRTRynHT/BiJpGCNr6Cqp5vv8LgVFRpgIctwNAs=
=INVd
-----END PGP SIGNATURE-----

--UiAk0KfUL3QfVCccKooCTnQw9Vj0u1pJe--


From nobody Sat Feb 18 14:26:58 2017
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F72C129654 for <curdle@ietfa.amsl.com>; Sat, 18 Feb 2017 14:26:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xspBcOoKdsws for <curdle@ietfa.amsl.com>; Sat, 18 Feb 2017 14:26:54 -0800 (PST)
Received: from welho-filter4.welho.com (welho-filter4.welho.com [83.102.41.26]) by ietfa.amsl.com (Postfix) with ESMTP id C2801129659 for <curdle@ietf.org>; Sat, 18 Feb 2017 14:26:51 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by welho-filter4.welho.com (Postfix) with ESMTP id 381C11B94C; Sun, 19 Feb 2017 00:26:50 +0200 (EET)
X-Virus-Scanned: Debian amavisd-new at pp.htv.fi
Received: from welho-smtp1.welho.com ([IPv6:::ffff:83.102.41.84]) by localhost (welho-filter4.welho.com [::ffff:83.102.41.26]) (amavisd-new, port 10024) with ESMTP id E9cCVLh97nH5; Sun, 19 Feb 2017 00:26:50 +0200 (EET)
Received: from LK-Perkele-V2 (87-92-51-204.bb.dnainternet.fi [87.92.51.204]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by welho-smtp1.welho.com (Postfix) with ESMTPSA id ED20B28A; Sun, 19 Feb 2017 00:26:49 +0200 (EET)
Date: Sun, 19 Feb 2017 00:26:46 +0200
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: str4d <str4d@i2pmail.org>
Message-ID: <20170218222646.GA12192@LK-Perkele-V2.elisa-laajakaista.fi>
References: <20170218131518.D515DADF18@smtp.postman.i2p>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
In-Reply-To: <20170218131518.D515DADF18@smtp.postman.i2p>
User-Agent: Mutt/1.5.23 (2014-03-12)
Sender: ilariliusvaara@welho.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/QjVcST9CJzZAiJSU2fCXB4fSWGA>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in draft-ietf-curdle-pkix-03
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Feb 2017 22:26:57 -0000

On Sat, Feb 18, 2017 at 01:15:18PM +0000, str4d wrote:
> Hi all,
> 
> The problem is that the Sun AlgorithmId class always adds a NULL when
> encoding if there are no parameters, for compatibility with Solaris [4].
> So AFAICT it is presently impossible for me to write an implementation
> that simultaneously:
> 
> - follows draft-ietf-curdle-pkix-03 correctly
> - can retrieve EdDSA keys from a default Java keystore
> 
> Is anyone in the WG aware of a workaround for this, or have links to
> past WG discussion on this point? I would think that Oracle should at
> least be made aware of this issue, but even if they changes this in Java
> 10, that doesn't help my implementation run on earlier Java versions.
> The only alternatives I see at this point are:

AlgorithmId.encodeAbsentParametersAsNull(boolean)?

(The first javadoc for AlgorithmId I found has that method).


-Ilari


From nobody Sun Feb 19 12:14:28 2017
Return-Path: <str4d@i2pmail.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 32A0412950B for <curdle@ietfa.amsl.com>; Sun, 19 Feb 2017 12:14:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.451
X-Spam-Level: 
X-Spam-Status: No, score=-0.451 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_BRBL_LASTEXT=1.449, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yaXCCqsqctnI for <curdle@ietfa.amsl.com>; Sun, 19 Feb 2017 12:14:23 -0800 (PST)
Received: from mail01.sigterm.no (mail01.sigterm.no [193.150.121.27]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20609129459 for <curdle@ietf.org>; Sun, 19 Feb 2017 12:14:22 -0800 (PST)
Received: from smtp.postman.i2p (unknown [193.150.121.26]) by postman.meeh.i2p (Postfix) with ESMTP id B72972E06FB for <curdle@ietf.org>; Sun, 19 Feb 2017 21:14:19 +0100 (CET)
X-Virus-Scanned: clamav-milter 0.97 on milter.postman.i2p
To: Ilari Liusvaara <ilariliusvaara@welho.com>
References: <20170218131518.D515DADF18@smtp.postman.i2p> <20170218222709.493F3ADF01@smtp.postman.i2p>
X-Mailer: smtp.postman.i2p - Official I2P Mailer
From: str4d <str4d@i2pmail.org>
MIME-Version: 1.0
In-Reply-To: <20170218222709.493F3ADF01@smtp.postman.i2p>
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="mpoCoLa5p65qSjENbe00BqBeFBa5eMTb1"
Message-Id: <20170219172559.1E86EADF00@smtp.postman.i2p>
Date: Sun, 19 Feb 2017 17:25:59 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/VniynaR9U0huhOTuMbOvoLumggw>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in draft-ietf-curdle-pkix-03
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 19 Feb 2017 20:14:25 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--mpoCoLa5p65qSjENbe00BqBeFBa5eMTb1
Content-Type: multipart/mixed; boundary="clnnJstfdmqWp1W8UenSH8eTsbBLgnpsS";
 protected-headers="v1"
X-Mailer: smtp.postman.i2p - Official I2P Mailer
From: str4d <str4d@mail.i2p>
To: Ilari Liusvaara <ilariliusvaara@welho.com>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in
 draft-ietf-curdle-pkix-03
References: <20170218131518.D515DADF18@smtp.postman.i2p>
 <20170218222709.493F3ADF01@smtp.postman.i2p>
In-Reply-To: <20170218222709.493F3ADF01@smtp.postman.i2p>

--clnnJstfdmqWp1W8UenSH8eTsbBLgnpsS
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 02/19/2017 11:27 AM, Ilari Liusvaara wrote:
> On Sat, Feb 18, 2017 at 01:15:18PM +0000, str4d wrote:
>> Hi all,
>>
>> The problem is that the Sun AlgorithmId class always adds a NULL when
>> encoding if there are no parameters, for compatibility with Solaris [4=
].
>> So AFAICT it is presently impossible for me to write an implementation=

>> that simultaneously:
>>
>> - follows draft-ietf-curdle-pkix-03 correctly
>> - can retrieve EdDSA keys from a default Java keystore
>>
>> Is anyone in the WG aware of a workaround for this, or have links to
>> past WG discussion on this point? I would think that Oracle should at
>> least be made aware of this issue, but even if they changes this in Ja=
va
>> 10, that doesn't help my implementation run on earlier Java versions.
>> The only alternatives I see at this point are:
>=20
> AlgorithmId.encodeAbsentParametersAsNull(boolean)?
>=20
> (The first javadoc for AlgorithmId I found has that method).
>=20
>=20
> -Ilari
>=20

If I'm looking at the same JavaDoc as you [0], that method is for
iaik.asn1.structures.AlgorithmID, which is part of the proprietary
IAIK-JCE Provider. I am referring to sun.security.x509.AlgorithmId from
the Sun Provider bundled with Oracle Java, which does not have this metho=
d.

Having investigated further, it does not look possible to swap out the
Sun Provider's PKCS#8 implementation with another one, because the
default Java keystore directly calls its own classes:

sun.security.provider.JavaKeyStore.engineGetKey() [1]
  \
sun.security.provider.KeyProtector.recover() [2]
    \
sun.security.pkcs.PKCS8Key.parseKey() [3]

However, what *does* look possible is using the JceKeyStore ("jceks"),
which doesn't appear to have the PKCS8Key encode/decode cycle that the
default keystore has (instead it passes the plain key data straight into
the looked-up KeyFactory) [4]. The "jceks" keystore can additionally
read from the default "jks" keystore, so it has a workable migration
strategy. I will test this and see if it is a sufficient workaround. My
concern is that it still uses the same AlgorithmId class that doesn't
support absent parameters, which makes me suspect that while it may read
correctly-formatted keys properly, it might still write them out with
NULL parameters, subverting this entire discussion.

Either way, if the draft is not amended, then Java implementations of
draft-ietf-curdle-pkix-03 will only work with compatible non-default
keystores. The "jceks" is fortunately bundled with Oracle Java, but
still requires configuration. At first glance, it looks like
BouncyCastle might have also a workable alternative keystore (its
AlgorithmId appears to correctly support absent parameters), but that's
not a desirable dependency for at least one of my users.

I'm also still at a loss as to how I can enforce usage of non-default
keystores from inside my library or at a JCA level, in a way that
doesn't result in obscure runtime error messages. The keystore type can
be set or overridden in several places, so I doubt there is a global
value I can reliably check.

- str4d

[0]
http://javadoc.iaik.tugraz.at/iaik_jce/current/iaik/asn1/structures/Algor=
ithmID.html#encodeAbsentParametersAsNull(boolean)

[1]
http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-=
b14/sun/security/provider/JavaKeyStore.java#115

[2]
http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-=
b14/sun/security/provider/KeyProtector.java#252

[3]
http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-=
b14/sun/security/pkcs/PKCS8Key.java#115

[4]
http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-=
b14/com/sun/crypto/provider/KeyProtector.java#148


--clnnJstfdmqWp1W8UenSH8eTsbBLgnpsS--

--mpoCoLa5p65qSjENbe00BqBeFBa5eMTb1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYqdTeAAoJEGppFNr76gDaK/AP/jLoZZ9lISuNlU4roNPfAG1B
Ydpi8ixkTTUta0DNTSpl1r26UCSjO3zZnoCOl7nqT5R6svUwOfBVuSKvb/r9ac85
O4/yhReAal3vmOjPNnnVzDakKvBH5IbrKZ8BkPjq5aVUOvmA6pmyY1H6WKTdYfsn
LVkWlpv1xs+U8xBH33jdiZKjVpFMzM8mRFcEM2xHVqMPZ2dS/Zv18QYQB7Wb1ppo
IoM8rtrAPSdo3Bn93yhzYi8SnQ7ljsQ+pCibFagZVcjMB414/oEuy0VfYfWrMHpA
quCKITJdzEajUPj+SbNJ6ctErfrVgBE2WLhn/0RxyoMhBa874B2izitzRrObd20y
DBP/otJJiq7GAXxzwcF208bWGPanTV5/WtV5Z8Fsb3ni0B3+yAhptMbnbfZMGo4S
zXHUj4N0lrrildZi6USgF6upjoHeS3peCwJ7joP1JWr6QX3UhOkMLY5n1/598zCo
hLgt4143KlanuymLmv/5ppyfSdVO/A7eiSPQ6+PhetKUXhs3ctE25xDaAIjacDDK
VxRkxrjDogHq6D3cROBMBgvCO+qKLgYNHKdUywKhRJ+lMY7wKPIxQEylxBUwmMwG
FmklzetdENy5N9ms09vPRyTnyc1IshleIo9Pq4t1MS8dZHsAYMHka/xC0ZAnmVoT
kdLi31nGCQwpKdQmqQ5C
=VkQT
-----END PGP SIGNATURE-----

--mpoCoLa5p65qSjENbe00BqBeFBa5eMTb1--


From nobody Sun Feb 19 14:14:10 2017
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C180E1295BE for <curdle@ietfa.amsl.com>; Sun, 19 Feb 2017 14:14:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id woo_spYqi_Gh for <curdle@ietfa.amsl.com>; Sun, 19 Feb 2017 14:14:07 -0800 (PST)
Received: from welho-filter4.welho.com (welho-filter4.welho.com [83.102.41.26]) by ietfa.amsl.com (Postfix) with ESMTP id DDCCA1295BD for <curdle@ietf.org>; Sun, 19 Feb 2017 14:14:06 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by welho-filter4.welho.com (Postfix) with ESMTP id DAFEF1FD73; Mon, 20 Feb 2017 00:14:04 +0200 (EET)
X-Virus-Scanned: Debian amavisd-new at pp.htv.fi
Received: from welho-smtp2.welho.com ([IPv6:::ffff:83.102.41.85]) by localhost (welho-filter4.welho.com [::ffff:83.102.41.26]) (amavisd-new, port 10024) with ESMTP id n6KS_hbXyUPl; Mon, 20 Feb 2017 00:14:04 +0200 (EET)
Received: from LK-Perkele-V2 (87-92-51-204.bb.dnainternet.fi [87.92.51.204]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by welho-smtp2.welho.com (Postfix) with ESMTPSA id 941CF21C; Mon, 20 Feb 2017 00:14:04 +0200 (EET)
Date: Mon, 20 Feb 2017 00:14:00 +0200
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: str4d <str4d@i2pmail.org>
Message-ID: <20170219221400.GA13539@LK-Perkele-V2.elisa-laajakaista.fi>
References: <20170218131518.D515DADF18@smtp.postman.i2p> <20170218222709.493F3ADF01@smtp.postman.i2p> <20170219172559.1E86EADF00@smtp.postman.i2p>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
In-Reply-To: <20170219172559.1E86EADF00@smtp.postman.i2p>
User-Agent: Mutt/1.5.23 (2014-03-12)
Sender: ilariliusvaara@welho.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/qMZ2aKawzEaPomYCH2ydOZuBnso>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in draft-ietf-curdle-pkix-03
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 19 Feb 2017 22:14:08 -0000

On Sun, Feb 19, 2017 at 05:25:59PM +0000, str4d wrote:
> On 02/19/2017 11:27 AM, Ilari Liusvaara wrote:
> > On Sat, Feb 18, 2017 at 01:15:18PM +0000, str4d wrote:
> >> Hi all,
> >>
> >> The problem is that the Sun AlgorithmId class always adds a NULL when
> >> encoding if there are no parameters, for compatibility with Solaris [4].
> >> So AFAICT it is presently impossible for me to write an implementation
> >> that simultaneously:
> >>
> >> - follows draft-ietf-curdle-pkix-03 correctly
> >> - can retrieve EdDSA keys from a default Java keystore
> >>
> >> Is anyone in the WG aware of a workaround for this, or have links to
> >> past WG discussion on this point? I would think that Oracle should at
> >> least be made aware of this issue, but even if they changes this in Java
> >> 10, that doesn't help my implementation run on earlier Java versions.
> >> The only alternatives I see at this point are:
> > 
> > AlgorithmId.encodeAbsentParametersAsNull(boolean)?
> > 
> > (The first javadoc for AlgorithmId I found has that method).
> > 
> > 
> > -Ilari
> > 
> 
> If I'm looking at the same JavaDoc as you [0], that method is for
> iaik.asn1.structures.AlgorithmID, which is part of the proprietary
> IAIK-JCE Provider. I am referring to sun.security.x509.AlgorithmId from
> the Sun Provider bundled with Oracle Java, which does not have this method.

Ah, I found what I presume is code for the correct class.

The problematic method (derEncode) looks like it can take an override
from subclass.

 

-Ilari


From nobody Mon Feb 20 01:39:33 2017
Return-Path: <nmav@redhat.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F374129958 for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 01:39:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.923
X-Spam-Level: 
X-Spam-Status: No, score=-6.923 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sFjj-PpeayVa for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 01:39:31 -0800 (PST)
Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 39766128AB0 for <curdle@ietf.org>; Mon, 20 Feb 2017 01:39:31 -0800 (PST)
Received: from int-mx09.intmail.prod.int.phx2.redhat.com (int-mx09.intmail.prod.int.phx2.redhat.com [10.5.11.22]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 49AF542BA4; Mon, 20 Feb 2017 09:39:31 +0000 (UTC)
Received: from dhcp-10-40-1-102.brq.redhat.com ([10.40.2.136]) by int-mx09.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id v1K9dR9V019519 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 20 Feb 2017 04:39:29 -0500
Message-ID: <1487583567.3038.8.camel@redhat.com>
From: Nikos Mavrogiannopoulos <nmav@redhat.com>
To: Brian Smith <brian@briansmith.org>
Date: Mon, 20 Feb 2017 10:39:27 +0100
In-Reply-To: <CAFewVt6StNUUF-31nboMcs-5Gmyxhb9666wUr9+HQR_n9zS-aQ@mail.gmail.com>
References: <D4701965.2CFAB%qdang@nist.gov> <1481295892.20432.16.camel@redhat.com> <0e1701d254c6$46509670$d2f1c350$@augustcellars.com> <1481788992.2779.15.camel@redhat.com> <CAMm+LwjaTJp3JeJCTqj2Fag9mMKCUk+jE6aJMsBy=b++miu9jQ@mail.gmail.com> <CADZyTknQYmOXi+zG4f4GyC4Opquc7SkLOMads9vLbQrhg-2hdg@mail.gmail.com> <CAFewVt77331=DU2hdZtK1x8qreHp-31Cahmhea75KsU3uCkgbw@mail.gmail.com> <1485685950.1687.1.camel@redhat.com> <CAFewVt6StNUUF-31nboMcs-5Gmyxhb9666wUr9+HQR_n9zS-aQ@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Scanned-By: MIMEDefang 2.68 on 10.5.11.22
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.30]); Mon, 20 Feb 2017 09:39:31 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/9WPQsJvx4QNnmdL3x3RLlNWiIhg>
Cc: Daniel Migault <daniel.migault@ericsson.com>, Phillip Hallam-Baker <phill@hallambaker.com>, "Salz, Rich" <rsalz@akamai.com>, Jim Schaad <ietf@augustcellars.com>, Curdle <curdle@ietf.org>, "Dang, Quynh \(Fed\)" <quynh.dang@nist.gov>
Subject: Re: [Curdle] Some work for the group
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Feb 2017 09:39:32 -0000

On Thu, 2017-02-02 at 19:13 -1000, Brian Smith wrote:
> Nikos Mavrogiannopoulos <nmav@redhat.com> wrote:
> > Brian Smith wrote:
> > > Besides the security issue, my understanding is that using the
> > > prehash
> > > variant would result in lots of interop failures as, AFAICT,
> > > there
> > > isn't going to be much support for it in verification libraries.
> > 
> > Isn't that orthogonal to the question? If the prehash version is
> > going
> > to cause interop issues is not affected by the text quoted above.
> > Your
> > comment is on whether including the prehashed version at all.
> 
> No, it's not orthogonal. If we don't include the prehash version at
> all, there won't be interop failures. Again, I don't see any
> significant support for the prehash variant on the verification side.

As I said your argument is about adding this variant, and not about the
actual question which is whether it should be treated specially with
regards to CA usage.

> It's a bad idea to let or encourage CAs sign things using an
> algorithm that most verifiers are unlikely to implement.

Could you please clarify what do you mean by most? (I personally
intended to implement only the prehashed variant not the other because
it is the only variant that be used with HSMs). However, if there is a
consensus that the prehashed variant shouldn't be used, we shouldn't
drag it in the proposal.

regards,
Nikos


From nobody Mon Feb 20 04:17:14 2017
Return-Path: <str4d@i2pmail.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BDC19129462 for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 04:17:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.452
X-Spam-Level: 
X-Spam-Status: No, score=-0.452 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_BRBL_LASTEXT=1.449, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RumqtsDpY_b9 for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 04:17:11 -0800 (PST)
Received: from mail01.sigterm.no (mail01.sigterm.no [193.150.121.27]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 29E791293E4 for <curdle@ietf.org>; Mon, 20 Feb 2017 04:17:10 -0800 (PST)
Received: from smtp.postman.i2p (unknown [193.150.121.26]) by postman.meeh.i2p (Postfix) with ESMTP id 30EA32E010D for <curdle@ietf.org>; Mon, 20 Feb 2017 13:17:05 +0100 (CET)
X-Virus-Scanned: clamav-milter 0.97 on milter.postman.i2p
To: Ilari Liusvaara <ilariliusvaara@welho.com>
References: <20170218131518.D515DADF18@smtp.postman.i2p> <20170218222709.493F3ADF01@smtp.postman.i2p> <20170219172559.1E86EADF00@smtp.postman.i2p> <20170219221416.84597ADEFF@smtp.postman.i2p>
X-Mailer: smtp.postman.i2p - Official I2P Mailer
From: str4d <str4d@i2pmail.org>
MIME-Version: 1.0
In-Reply-To: <20170219221416.84597ADEFF@smtp.postman.i2p>
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="WAw2WUo9Cupa3d1Nm3XTXSOer97pAfqRL"
Message-Id: <20170220094630.B49F2ADEFE@smtp.postman.i2p>
Date: Mon, 20 Feb 2017 09:46:30 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/h8WYkluEc58u5KWvtrQbQtQvFxA>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in draft-ietf-curdle-pkix-03
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Feb 2017 12:17:13 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--WAw2WUo9Cupa3d1Nm3XTXSOer97pAfqRL
Content-Type: multipart/mixed; boundary="0v9PiuWugUCA572LoFDDuLmdV6cdETEa7";
 protected-headers="v1"
X-Mailer: smtp.postman.i2p - Official I2P Mailer
From: str4d <str4d@mail.i2p>
To: Ilari Liusvaara <ilariliusvaara@welho.com>
Cc: curdle@ietf.org
Subject: Re: [Curdle] AlgorithmIdentifier parameters in
 draft-ietf-curdle-pkix-03
References: <20170218131518.D515DADF18@smtp.postman.i2p>
 <20170218222709.493F3ADF01@smtp.postman.i2p>
 <20170219172559.1E86EADF00@smtp.postman.i2p>
 <20170219221416.84597ADEFF@smtp.postman.i2p>
In-Reply-To: <20170219221416.84597ADEFF@smtp.postman.i2p>

--0v9PiuWugUCA572LoFDDuLmdV6cdETEa7
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 02/20/2017 11:14 AM, Ilari Liusvaara wrote:
> On Sun, Feb 19, 2017 at 05:25:59PM +0000, str4d wrote:
>>
>> If I'm looking at the same JavaDoc as you [0], that method is for
>> iaik.asn1.structures.AlgorithmID, which is part of the proprietary
>> IAIK-JCE Provider. I am referring to sun.security.x509.AlgorithmId fro=
m
>> the Sun Provider bundled with Oracle Java, which does not have this me=
thod.
>=20
> Ah, I found what I presume is code for the correct class.
>=20
> The problematic method (derEncode) looks like it can take an override
> from subclass.

While that may help for implementing custom keystores outside my
library, it does not solve the incompatibility problem with the default
keystore: PKCS8Key's static methods instantiate the AlgorithmId class
directly, rather than taking an AlgorithmId parameter that could be
subclassed.


--0v9PiuWugUCA572LoFDDuLmdV6cdETEa7--

--WAw2WUo9Cupa3d1Nm3XTXSOer97pAfqRL
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYqrrjAAoJEGppFNr76gDagpUP/1HAJN4btPRlNhPoM+SbO5Wt
HhjykZNxgsqHk8HDw+OmZNb/TtljkBGDoFZnHcL1Z76dmiJFUIF8XrDVxrSCkA++
6UDIvc2J3m8KoO6HFTJ3skbNlVoeockzQ/FtZK0d4s8OAIOe2fkZHzrxZfP7ai6z
YhHb1liJLJSxhS9EQT5lnwghxxslnfXYf/Ifa3ArcGwZmBSlNw6FTHFgUHi2hd73
bbt5URE6td2yl0lIBQaSdO8z4RMi/ZN3d5Cu0kbSmvpkXnIHAhNLljIZJqzbwKIF
zK/j2idbFRJWVD5NOtyiNqj3EyOOVWNhJmANL74KQp6BibAb6HyU3OXa1Xjww1we
BGeNSsJ1NyXp3a5aolsqn2BNWf2xcjqg3Hoi+5ID1laIV0P3EzcZEmowBSBXouWu
Yq+WA+74w9GTaBTfS03gUtDeBOxGvIehZi8szbGKh3H98pK/zK1xRiiKJm5xn8Wr
XFKzKMS6zI0WMsW1q553Xk2czKygtTBUHVVw5Ogf9qxPqF5kyXaJAXKAFGQ78G1e
QSrUG3CpTnwNSpQyd7WMNuR3ZAwedxtNrBm1RDg4U/3kMn26oUZCctlnGeS8g+w/
hbLTMFlXZMTawSqF8zEbIWI/3Ae2dHwFFYuX1ii6p8sFVQRCASmhzNdBUyYvf3Oh
1C7lMxmRH1zsZJMHk8lz
=1f/+
-----END PGP SIGNATURE-----

--WAw2WUo9Cupa3d1Nm3XTXSOer97pAfqRL--


From nobody Mon Feb 20 06:32:27 2017
Return-Path: <daniel.migault@ericsson.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E42A21294E5 for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 06:32:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VppMxZi82P3p for <curdle@ietfa.amsl.com>; Mon, 20 Feb 2017 06:32:24 -0800 (PST)
Received: from usplmg20.ericsson.net (usplmg20.ericsson.net [198.24.6.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67CDA1294DD for <curdle@ietf.org>; Mon, 20 Feb 2017 06:32:24 -0800 (PST)
X-AuditID: c618062d-d73ff700000009d8-21-58ab0e2621d9
Received: from EUSAAHC004.ericsson.se (Unknown_Domain [147.117.188.84]) by  (Symantec Mail Security) with SMTP id 6F.CE.02520.72E0BA85; Mon, 20 Feb 2017 16:41:30 +0100 (CET)
Received: from EUSAAMB107.ericsson.se ([147.117.188.124]) by EUSAAHC004.ericsson.se ([147.117.188.84]) with mapi id 14.03.0319.002; Mon, 20 Feb 2017 09:32:19 -0500
From: Daniel Migault <daniel.migault@ericsson.com>
To: Nikos Mavrogiannopoulos <nmav@redhat.com>, Brian Smith <brian@briansmith.org>
Thread-Topic: [Curdle] Some work for the group
Thread-Index: AQHSUiKs3PWVL7wFScuPYdGzcgHHmKEACrsAgAUxWYCAA8bUAIAAjpqAgDQrVACAEdcRAIAAUaEAgAeCl4CAGwHhgP///UHg
Date: Mon, 20 Feb 2017 14:32:18 +0000
Message-ID: <2DD56D786E600F45AC6BDE7DA4E8A8C11801A623@eusaamb107.ericsson.se>
References: <D4701965.2CFAB%qdang@nist.gov> <1481295892.20432.16.camel@redhat.com> <0e1701d254c6$46509670$d2f1c350$@augustcellars.com> <1481788992.2779.15.camel@redhat.com> <CAMm+LwjaTJp3JeJCTqj2Fag9mMKCUk+jE6aJMsBy=b++miu9jQ@mail.gmail.com> <CADZyTknQYmOXi+zG4f4GyC4Opquc7SkLOMads9vLbQrhg-2hdg@mail.gmail.com> <CAFewVt77331=DU2hdZtK1x8qreHp-31Cahmhea75KsU3uCkgbw@mail.gmail.com> <1485685950.1687.1.camel@redhat.com> <CAFewVt6StNUUF-31nboMcs-5Gmyxhb9666wUr9+HQR_n9zS-aQ@mail.gmail.com> <1487583567.3038.8.camel@redhat.com>
In-Reply-To: <1487583567.3038.8.camel@redhat.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [147.117.188.12]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprLIsWRmVeSWpSXmKPExsUyuXRPiK4W3+oIg56NYhZXph5itti6cBaz xerp39ksfhzdymIx8cNsRouzz9azWfzf0sniwO4x+cgCZo+Nc6azeexrOMzqcWH1VyaPJUt+ MnlcO/mX1eP9vqtsAexRXDYpqTmZZalF+nYJXBkLfkoU/BCreHHzAXsD4xqxLkYODgkBE4nH 96O6GLk4hATWM0q09ixngXCWM0o8OXiNsYuRk4NNwEii7VA/O0iDiECwxP+ttiA1zAL7GSWm fF/CAlIjLKArcXXPUjYQW0RAT+JG31JGiPo8idW/eUDCLAKqEn0Pv4ON5BXwlTi8YzMjxK4l LBKH9uxhBqnnFDCU+HZKEqSGUUBM4vupNUwgNrOAuMStJ/PBbAkBAYkle84zQ9iiEi8f/2OF sJUk5ry+BjaGWUBTYv0ufYhWRYkp3Q/ZIdYKSpyc+YRlAqPoLCRTZyF0zELSMQtJxwJGllWM HKXFBTm56UYGmxiBkXZMgk13B+P96Z6HGAU4GJV4eD9sWhkhxJpYVlyZe4hRgoNZSYT35Y9V EUK8KYmVValF+fFFpTmpxYcYpTlYlMR541bfDxcSSE8sSc1OTS1ILYLJMnFwSjUw2u26vnJ1 rdHVpZbTVwu5zy9Uqri2YNb/g2uunlkokGhVeWW5XmZ7yo/y2+pM3emlrk+MN0QyrWs4Fcbb 8unJ7Ln3JXnmh9599015k+JdHu535h87NjPmMnGz5GqcEwgVrxZWl07LelZ+5ciBvc8ytPrf 7/qxaEP2kliPJgGhR9GlEneOs+p2KLEUZyQaajEXFScCAEwKLmGwAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/9DmOdXPraIC_4GXfCOdFDzwgHiw>
Cc: "Dang, Quynh \(Fed\)" <quynh.dang@nist.gov>, "Salz, Rich" <rsalz@akamai.com>, Jim Schaad <ietf@augustcellars.com>, Phillip Hallam-Baker <phill@hallambaker.com>, Curdle <curdle@ietf.org>
Subject: Re: [Curdle] Some work for the group
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Feb 2017 14:32:26 -0000

VGhhbmtzIGZvciB0aGUgaW5mb3JtYXRpb24gTmlrb3MuDQoNCkkgYWdyZWUgdGhhdCB3ZSBzaG91
bGQgZmluZCBhIGNvbmNlbnN1cyBvbiB3aGV0aGVyIHRoZSBwcmUtaGFzaGVkIHZlcnNpb24gc2hv
dWxkIGNvbnNpZGVyZWQgb3Igbm90LiAgDQoNCk9uZSByZWFzb24gZm9yIG5vdCBjb25zaWRlcmlu
ZyBpdCBpcyBpbnRlcm9wZXJhYmlsaXR5IGlzc3VlLiBDb3VsZCB3ZSBkZXNjcmliZSB0aGVtIGEg
Yml0IGRlZXBlciA/DQoNCllvdXJzLCANCg0KRGFuaWVsDQoNCi0tLS0tT3JpZ2luYWwgTWVzc2Fn
ZS0tLS0tDQpGcm9tOiBOaWtvcyBNYXZyb2dpYW5ub3BvdWxvcyBbbWFpbHRvOm5tYXZAcmVkaGF0
LmNvbV0gDQpTZW50OiBNb25kYXksIEZlYnJ1YXJ5IDIwLCAyMDE3IDQ6MzkgQU0NClRvOiBCcmlh
biBTbWl0aCA8YnJpYW5AYnJpYW5zbWl0aC5vcmc+DQpDYzogRGFuaWVsIE1pZ2F1bHQgPGRhbmll
bC5taWdhdWx0QGVyaWNzc29uLmNvbT47IFBoaWxsaXAgSGFsbGFtLUJha2VyIDxwaGlsbEBoYWxs
YW1iYWtlci5jb20+OyBEYW5nLCBRdXluaCAoRmVkKSA8cXV5bmguZGFuZ0BuaXN0Lmdvdj47IEpp
bSBTY2hhYWQgPGlldGZAYXVndXN0Y2VsbGFycy5jb20+OyBDdXJkbGUgPGN1cmRsZUBpZXRmLm9y
Zz47IFNhbHosIFJpY2ggPHJzYWx6QGFrYW1haS5jb20+DQpTdWJqZWN0OiBSZTogW0N1cmRsZV0g
U29tZSB3b3JrIGZvciB0aGUgZ3JvdXANCg0KT24gVGh1LCAyMDE3LTAyLTAyIGF0IDE5OjEzIC0x
MDAwLCBCcmlhbiBTbWl0aCB3cm90ZToNCj4gTmlrb3MgTWF2cm9naWFubm9wb3Vsb3MgPG5tYXZA
cmVkaGF0LmNvbT4gd3JvdGU6DQo+ID4gQnJpYW4gU21pdGggd3JvdGU6DQo+ID4gPiBCZXNpZGVz
IHRoZSBzZWN1cml0eSBpc3N1ZSwgbXkgdW5kZXJzdGFuZGluZyBpcyB0aGF0IHVzaW5nIHRoZSAN
Cj4gPiA+IHByZWhhc2ggdmFyaWFudCB3b3VsZCByZXN1bHQgaW4gbG90cyBvZiBpbnRlcm9wIGZh
aWx1cmVzIGFzLCANCj4gPiA+IEFGQUlDVCwgdGhlcmUgaXNuJ3QgZ29pbmcgdG8gYmUgbXVjaCBz
dXBwb3J0IGZvciBpdCBpbiANCj4gPiA+IHZlcmlmaWNhdGlvbiBsaWJyYXJpZXMuDQo+ID4gDQo+
ID4gSXNuJ3QgdGhhdCBvcnRob2dvbmFsIHRvIHRoZSBxdWVzdGlvbj8gSWYgdGhlIHByZWhhc2gg
dmVyc2lvbiBpcyANCj4gPiBnb2luZyB0byBjYXVzZSBpbnRlcm9wIGlzc3VlcyBpcyBub3QgYWZm
ZWN0ZWQgYnkgdGhlIHRleHQgcXVvdGVkIA0KPiA+IGFib3ZlLg0KPiA+IFlvdXINCj4gPiBjb21t
ZW50IGlzIG9uIHdoZXRoZXIgaW5jbHVkaW5nIHRoZSBwcmVoYXNoZWQgdmVyc2lvbiBhdCBhbGwu
DQo+IA0KPiBObywgaXQncyBub3Qgb3J0aG9nb25hbC4gSWYgd2UgZG9uJ3QgaW5jbHVkZSB0aGUg
cHJlaGFzaCB2ZXJzaW9uIGF0IA0KPiBhbGwsIHRoZXJlIHdvbid0IGJlIGludGVyb3AgZmFpbHVy
ZXMuIEFnYWluLCBJIGRvbid0IHNlZSBhbnkgDQo+IHNpZ25pZmljYW50IHN1cHBvcnQgZm9yIHRo
ZSBwcmVoYXNoIHZhcmlhbnQgb24gdGhlIHZlcmlmaWNhdGlvbiBzaWRlLg0KDQpBcyBJIHNhaWQg
eW91ciBhcmd1bWVudCBpcyBhYm91dCBhZGRpbmcgdGhpcyB2YXJpYW50LCBhbmQgbm90IGFib3V0
IHRoZSBhY3R1YWwgcXVlc3Rpb24gd2hpY2ggaXMgd2hldGhlciBpdCBzaG91bGQgYmUgdHJlYXRl
ZCBzcGVjaWFsbHkgd2l0aCByZWdhcmRzIHRvIENBIHVzYWdlLg0KDQo+IEl0J3MgYSBiYWQgaWRl
YSB0byBsZXQgb3IgZW5jb3VyYWdlIENBcyBzaWduIHRoaW5ncyB1c2luZyBhbiBhbGdvcml0aG0g
DQo+IHRoYXQgbW9zdCB2ZXJpZmllcnMgYXJlIHVubGlrZWx5IHRvIGltcGxlbWVudC4NCg0KQ291
bGQgeW91IHBsZWFzZSBjbGFyaWZ5IHdoYXQgZG8geW91IG1lYW4gYnkgbW9zdD8gKEkgcGVyc29u
YWxseSBpbnRlbmRlZCB0byBpbXBsZW1lbnQgb25seSB0aGUgcHJlaGFzaGVkIHZhcmlhbnQgbm90
IHRoZSBvdGhlciBiZWNhdXNlIGl0IGlzIHRoZSBvbmx5IHZhcmlhbnQgdGhhdCBiZSB1c2VkIHdp
dGggSFNNcykuIEhvd2V2ZXIsIGlmIHRoZXJlIGlzIGEgY29uc2Vuc3VzIHRoYXQgdGhlIHByZWhh
c2hlZCB2YXJpYW50IHNob3VsZG4ndCBiZSB1c2VkLCB3ZSBzaG91bGRuJ3QgZHJhZyBpdCBpbiB0
aGUgcHJvcG9zYWwuDQoNCnJlZ2FyZHMsDQpOaWtvcw0KDQo=


From nobody Mon Feb 27 14:07:30 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: curdle@ietf.org
Delivered-To: curdle@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D66C129430; Mon, 27 Feb 2017 14:07:29 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.46.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148823324937.13723.304737691826247105.idtracker@ietfa.amsl.com>
Date: Mon, 27 Feb 2017 14:07:29 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/GOt9vPw7irBa4QUbxMOaXjc_ylo>
Cc: curdle@ietf.org
Subject: [Curdle] I-D Action: draft-ietf-curdle-rsa-sha2-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Feb 2017 22:07:29 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the CURves, Deprecating and a Little more Encryption of the IETF.

        Title           : Use of RSA Keys with SHA-2 256 and 512 in Secure Shell (SSH)
        Author          : Denis Bider
	Filename        : draft-ietf-curdle-rsa-sha2-03.txt
	Pages           : 6
	Date            : 2017-02-27

Abstract:
  This memo defines an algorithm name, public key format, and signature
  format for use of RSA keys with SHA-2 512 for server and client
  authentication in SSH connections.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-curdle-rsa-sha2/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-curdle-rsa-sha2-03

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-rsa-sha2-03


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Mon Feb 27 14:07:46 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: curdle@ietf.org
Delivered-To: curdle@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 711F5129438; Mon, 27 Feb 2017 14:07:37 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.46.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148823325745.13859.1818801191554779419.idtracker@ietfa.amsl.com>
Date: Mon, 27 Feb 2017 14:07:37 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/wNmxHY5ePUYOQxQxH_-YXrIlIH8>
Cc: curdle@ietf.org
Subject: [Curdle] I-D Action: draft-ietf-curdle-ssh-ext-info-02.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Feb 2017 22:07:37 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the CURves, Deprecating and a Little more Encryption of the IETF.

        Title           : Extension Negotiation in Secure Shell (SSH)
        Author          : Denis Bider
	Filename        : draft-ietf-curdle-ssh-ext-info-02.txt
	Pages           : 8
	Date            : 2017-02-27

Abstract:
  This memo defines a mechanism for SSH clients and servers to exchange
  information about supported protocol extensions confidentially after
  completed key exchange.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-ext-info/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-curdle-ssh-ext-info-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-ssh-ext-info-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Feb 28 11:36:29 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 044FD12969D; Tue, 28 Feb 2017 11:36:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.203
X-Spam-Level: 
X-Spam-Status: No, score=-4.203 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JSYmfMQP8i76; Tue, 28 Feb 2017 11:36:18 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7945E1296AF; Tue, 28 Feb 2017 11:36:09 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 5DEF0B80347; Tue, 28 Feb 2017 11:36:09 -0800 (PST)
To: ietf-announce@ietf.org, rfc-dist@rfc-editor.org
X-PHP-Originating-Script: 1005:ams_util_lib.php
From: rfc-editor@rfc-editor.org
Message-Id: <20170228193609.5DEF0B80347@rfc-editor.org>
Date: Tue, 28 Feb 2017 11:36:09 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/RwUe_Et3rk4q8PzL4oVGTdcwrOQ>
Cc: drafts-update-ref@iana.org, curdle@ietf.org, rfc-editor@rfc-editor.org
Subject: [Curdle] RFC 8103 on Using ChaCha20-Poly1305 Authenticated Encryption in the Cryptographic Message Syntax (CMS)
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Feb 2017 19:36:26 -0000

A new Request for Comments is now available in online RFC libraries.

        
        RFC 8103

        Title:      Using ChaCha20-Poly1305 Authenticated Encryption in 
                    the Cryptographic Message Syntax (CMS) 
        Author:     R. Housley
        Status:     Standards Track
        Stream:     IETF
        Date:       February 2017
        Mailbox:    housley@vigilsec.com
        Pages:      9
        Characters: 18866
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-ietf-curdle-cms-chacha20-poly1305-06.txt

        URL:        https://www.rfc-editor.org/info/rfc8103

        DOI:        10.17487/RFC8103

This document describes the conventions for using ChaCha20-Poly1305
Authenticated Encryption in the Cryptographic Message Syntax (CMS).
ChaCha20-Poly1305 is an authenticated encryption algorithm
constructed of the ChaCha stream cipher and Poly1305 authenticator.

This document is a product of the CURves, Deprecating and a Little more Encryption Working Group of the IETF.

This is now a Proposed Standard.

STANDARDS TRACK: This document specifies an Internet Standards Track
protocol for the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the Official
Internet Protocol Standards (https://www.rfc-editor.org/standards) for the 
standardization state and status of this protocol.  Distribution of this 
memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  https://www.ietf.org/mailman/listinfo/ietf-announce
  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see https://www.rfc-editor.org/search
For downloading RFCs, see https://www.rfc-editor.org/retrieve/bulk

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team
Association Management Solutions, LLC


