
From nobody Tue Dec  5 16:28:22 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4EE9C128B90; Tue,  5 Dec 2017 16:28:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gZbWLh_1IZcg; Tue,  5 Dec 2017 16:28:18 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8F39D128B8F; Tue,  5 Dec 2017 16:28:18 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id BD3C2B81EAE; Tue,  5 Dec 2017 16:28:00 -0800 (PST)
To: ietf-announce@ietf.org, rfc-dist@rfc-editor.org
X-PHP-Originating-Script: 1005:ams_util_lib.php
From: rfc-editor@rfc-editor.org
Cc: rfc-editor@rfc-editor.org, drafts-update-ref@iana.org, curdle@ietf.org
Content-type: text/plain; charset=UTF-8
Message-Id: <20171206002800.BD3C2B81EAE@rfc-editor.org>
Date: Tue,  5 Dec 2017 16:28:00 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/cW1KnrUW89Y3VleZAUosD14s6aA>
Subject: [Curdle] =?utf-8?q?RFC_8270_on_Increase_the_Secure_Shell_Minimum_?= =?utf-8?q?Recommended_Diffie-Hellman_Modulus_Size_to_2048_Bits?=
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Dec 2017 00:28:20 -0000

A new Request for Comments is now available in online RFC libraries.

        
        RFC 8270

        Title:      Increase the Secure Shell Minimum 
                    Recommended Diffie-Hellman Modulus 
                    Size to 2048 Bits 
        Author:     L. Velvindron, 
                    M. Baushke
        Status:     Standards Track
        Stream:     IETF
        Date:       December 2017
        Mailbox:    logan@hackers.mu, 
                    mdb@juniper.net
        Pages:      5
        Characters: 9440
        Updates:    RFC 4419

        I-D Tag:    draft-ietf-curdle-ssh-dh-group-exchange-06.txt

        URL:        https://www.rfc-editor.org/info/rfc8270

        DOI:        10.17487/RFC8270

The Diffie-Hellman (DH) Group Exchange for the Secure Shell (SSH)
transport-layer protocol specifies that servers and clients should
support groups with a minimum modulus group size of 1024 bits.
Recent security research has shown that the minimum value of 1024
bits is insufficient to protect against state-sponsored actors and
any organization with enough computing resources.  This RFC updates
RFC 4419, which allowed for DH moduli less than 2048 bits; now, 2048
bits is the minimum acceptable group size.


This document is a product of the CURves, Deprecating and a Little more Encryption Working Group of the IETF.

This is now a Proposed Standard.

STANDARDS TRACK: This document specifies an Internet Standards Track
protocol for the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the Official
Internet Protocol Standards (https://www.rfc-editor.org/standards) for the 
standardization state and status of this protocol.  Distribution of this 
memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  https://www.ietf.org/mailman/listinfo/ietf-announce
  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see https://www.rfc-editor.org/search
For downloading RFCs, see https://www.rfc-editor.org/retrieve/bulk

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team
Association Management Solutions, LLC



From nobody Sat Dec  9 12:22:43 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: curdle@ietf.org
Delivered-To: curdle@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 116FA124F57; Sat,  9 Dec 2017 12:22:41 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: curdle@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151285096101.24658.6833692177897273472@ietfa.amsl.com>
Date: Sat, 09 Dec 2017 12:22:41 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/PSOvF9nDFnhruewB66tccXjG1uA>
Subject: [Curdle] I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Dec 2017 20:22:41 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the CURves, Deprecating and a Little more Encryption WG of the IETF.

        Title           : Depreciating RC4 in all IETF Protocols
        Author          : Luis Camara
	Filename        : draft-ietf-curdle-rc4-die-die-die-03.txt
	Pages           : 8
	Date            : 2017-12-09

Abstract:
   RC4 is extremely weak as shown by RFC 6649 and RFC 7457, is
   prohibited in TLS by RFC 7465, is prohibited in Kerberos by RFC xxxx
   and it needs to be prohibited in all IETF protocols. This document
   obsoletes RFC 4345 "Improved Arcfour Modes for the Secure Shell (SSH)
   Transport Layer Protocol" (note Arcfour and RC4 are synonymous).
   RFC 3501, RFC 4253, RFC 6649 and RFC 6733 are updated to note the
   deprecation of RC4 in all IETF protocols.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-curdle-rc4-die-die-die/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-03
https://datatracker.ietf.org/doc/html/draft-ietf-curdle-rc4-die-die-die-03

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-rc4-die-die-die-03


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Sun Dec 10 12:42:58 2017
Return-Path: <rsalz@akamai.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 22E39127522 for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 12:42:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OixZ1zr9Zfkl for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 12:42:55 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 41788127137 for <curdle@ietf.org>; Sun, 10 Dec 2017 12:42:55 -0800 (PST)
Received: from pps.filterd (m0122331.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.0.21/8.16.0.21) with SMTP id vBAKg0Qq018851 for <curdle@ietf.org>; Sun, 10 Dec 2017 20:42:54 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=rwxKQ/fY2wXVVmNojajgj0OGMuZMAViZLOEHK4Xf7oc=; b=TKttEPSIS/0wCf9y2aCBWTna4ecwv+DsN+apGcU5vKmzAzhqEXBQlaJ/WJlSY948bNoa DnyV37zi4pGNN77/Hzdcw8SJZXnedMejAG7RNYCuIyQ86wNVvohUt0uP8f30l78CTkBV 33ywgu0Jx4U9ab+3SoIzDllNeMAhPq/44wpMwnOFr1ND69Rwj390bX+byXaZhkIk7Rom CR253zaZEYzyWa/bvcVGq5OQTOpdVR0yQEMvpg5u3BuxfSYYZoBjeGmpdQvP5CqbOk4Y nrgxIxYZjj05vlGo4bUf1Wrfte616y8t//Ndas37mvk66O/sydtNSNaLw78XB1wUDEWJ KQ== 
Received: from prod-mail-ppoint2 (prod-mail-ppoint2.akamai.com [184.51.33.19]) by mx0b-00190b01.pphosted.com with ESMTP id 2er5juv3dk-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <curdle@ietf.org>; Sun, 10 Dec 2017 20:42:54 +0000
Received: from pps.filterd (prod-mail-ppoint2.akamai.com [127.0.0.1]) by prod-mail-ppoint2.akamai.com (8.16.0.21/8.16.0.21) with SMTP id vBAKeQAY011601 for <curdle@ietf.org>; Sun, 10 Dec 2017 15:42:53 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.31]) by prod-mail-ppoint2.akamai.com with ESMTP id 2erc1xmucc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT) for <curdle@ietf.org>; Sun, 10 Dec 2017 15:42:53 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com (172.27.123.101) by usma1ex-dag1mb1.msg.corp.akamai.com (172.27.123.101) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Sun, 10 Dec 2017 15:42:52 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com ([172.27.123.101]) by usma1ex-dag1mb1.msg.corp.akamai.com ([172.27.123.101]) with mapi id 15.00.1263.000; Sun, 10 Dec 2017 15:42:52 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "curdle@ietf.org" <curdle@ietf.org>
Thread-Topic: [Curdle] I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
Thread-Index: AQHTcSt6tgJDsvuT6UuQeDInxp1PbqM9YF+A
Date: Sun, 10 Dec 2017 20:42:51 +0000
Message-ID: <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com>
References: <151285096101.24658.6833692177897273472@ietfa.amsl.com>
In-Reply-To: <151285096101.24658.6833692177897273472@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/f.27.0.171010
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.43.46]
Content-Type: text/plain; charset="utf-8"
Content-ID: <854CBC714A51EC42AD24B4CCF717B428@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-12-10_06:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1712100310
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-12-10_06:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1712100310
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/UwHbh1it-4wg9AykskMXZcQqcZY>
Subject: [Curdle] FW: I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Dec 2017 20:42:57 -0000

VGhlIHNlY3VyaXR5IEFE4oCZcyBqdXN0IGdvdCBiYWNrIHRvIHVzLiAgQXBvbG9naWVzIGZyb20g
dGhlIEFE4oCZcyBhbmQgQ2hhaXJzIGZvciBsZXR0aW5nIHRoaXMgZmFsbCB0aHJvdWdoIHRoZSBj
cmFja3MuDQoNCkEgZ2VuZXJhbCDigJxkZXByZWNhdGUgaW4gYWxsIHByb3RvY29sc+KAnSBkb2N1
bWVudCBpcyBub3QgYXBwcm9wcmlhdGUgZm9yIENVUkRMRS4gIFRoaXMgbWVhbnMgdGhhdCBTZWN0
aW9uIDQgKElNQVAtPkVYVFJBKSwgU2VjdGlvbiA2IChESUFNRVRFUi0+RElNRSkgYW5kIFNlY3Rp
b24gNyBhcmUgb3V0IG9mIHNjb3BlIGZvciB0aGlzIFdHLiBUaGlzIGlzIHF1b3RpbmcgRXJpYywg
b25lIG9mIHRoZSBjby1EaXJlY3RvcnMuDQoNCk9uIGEgcGVyc29uYWwgbGV2ZWwsIEkgdGhpbmsg
U2VjdGlvbiAzIHNob3VsZCBiZSBoYW5kbGVkIGJ5IFVUQS4gQW5kIFNlY3Rpb24gNSBoYXMgS0lU
VEVODQoNCkV2ZW4gaWYgdGhlIFdHIGRpc2FncmVlcyB3aXRoIG1lIGFib3V0IDMgYW5kIDUsIHRo
ZXJlIGlzIGEgcXVlc3Rpb24gYWJvdXQgaWYgaXTigJlzIHdvcnRoIHN0aWxsIGhhdmluZyB0aGlz
IGFzIGEgV0cgZG9jdW1lbnQuICBQbGVhc2UgcG9zdCB5b3VyIHJlcGx5IHRvIHRoZSBsaXN0OyB3
ZSB3aWxsIGNhbGwgZm9yIGNvbnNlbnN1cyB0byBtb3ZlIHRoaXMgZm9yd2FyZCBvciBhYmFuZG9u
IGl0IGVhcmx5IGluIEphbnVhcnkuDQoNCk9uIDEyLzkvMTcsIDM6MjIgUE0sICJpbnRlcm5ldC1k
cmFmdHNAaWV0Zi5vcmciIDxpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmc+IHdyb3RlOg0KDQogICAg
IA0KICAgIEEgTmV3IEludGVybmV0LURyYWZ0IGlzIGF2YWlsYWJsZSBmcm9tIHRoZSBvbi1saW5l
IEludGVybmV0LURyYWZ0cyBkaXJlY3Rvcmllcy4NCiAgICBUaGlzIGRyYWZ0IGlzIGEgd29yayBp
dGVtIG9mIHRoZSBDVVJ2ZXMsIERlcHJlY2F0aW5nIGFuZCBhIExpdHRsZSBtb3JlIEVuY3J5cHRp
b24gV0cgb2YgdGhlIElFVEYuDQogICAgDQogICAgICAgICAgICBUaXRsZSAgICAgICAgICAgOiBE
ZXByZWNpYXRpbmcgUkM0IGluIGFsbCBJRVRGIFByb3RvY29scw0KICAgICAgICAgICAgQXV0aG9y
ICAgICAgICAgIDogTHVpcyBDYW1hcmENCiAgICAJRmlsZW5hbWUgICAgICAgIDogZHJhZnQtaWV0
Zi1jdXJkbGUtcmM0LWRpZS1kaWUtZGllLTAzLnR4dA0KICAgIAlQYWdlcyAgICAgICAgICAgOiA4
DQogICAgCURhdGUgICAgICAgICAgICA6IDIwMTctMTItMDkNCiAgICANCiAgICBBYnN0cmFjdDoN
CiAgICAgICBSQzQgaXMgZXh0cmVtZWx5IHdlYWsgYXMgc2hvd24gYnkgUkZDIDY2NDkgYW5kIFJG
QyA3NDU3LCBpcw0KICAgICAgIHByb2hpYml0ZWQgaW4gVExTIGJ5IFJGQyA3NDY1LCBpcyBwcm9o
aWJpdGVkIGluIEtlcmJlcm9zIGJ5IFJGQyB4eHh4DQogICAgICAgYW5kIGl0IG5lZWRzIHRvIGJl
IHByb2hpYml0ZWQgaW4gYWxsIElFVEYgcHJvdG9jb2xzLiBUaGlzIGRvY3VtZW50DQogICAgICAg
b2Jzb2xldGVzIFJGQyA0MzQ1ICJJbXByb3ZlZCBBcmNmb3VyIE1vZGVzIGZvciB0aGUgU2VjdXJl
IFNoZWxsIChTU0gpDQogICAgICAgVHJhbnNwb3J0IExheWVyIFByb3RvY29sIiAobm90ZSBBcmNm
b3VyIGFuZCBSQzQgYXJlIHN5bm9ueW1vdXMpLg0KICAgICAgIFJGQyAzNTAxLCBSRkMgNDI1Mywg
UkZDIDY2NDkgYW5kIFJGQyA2NzMzIGFyZSB1cGRhdGVkIHRvIG5vdGUgdGhlDQogICAgICAgZGVw
cmVjYXRpb24gb2YgUkM0IGluIGFsbCBJRVRGIHByb3RvY29scy4NCiAgICANCiAgICANCiAgICBU
aGUgSUVURiBkYXRhdHJhY2tlciBzdGF0dXMgcGFnZSBmb3IgdGhpcyBkcmFmdCBpczoNCiAgICBo
dHRwczovL2RhdGF0cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1pZXRmLWN1cmRsZS1yYzQtZGll
LWRpZS1kaWUvDQogICAgDQogICAgVGhlcmUgYXJlIGFsc28gaHRtbGl6ZWQgdmVyc2lvbnMgYXZh
aWxhYmxlIGF0Og0KICAgIGh0dHBzOi8vdG9vbHMuaWV0Zi5vcmcvaHRtbC9kcmFmdC1pZXRmLWN1
cmRsZS1yYzQtZGllLWRpZS1kaWUtMDMNCiAgICBodHRwczovL2RhdGF0cmFja2VyLmlldGYub3Jn
L2RvYy9odG1sL2RyYWZ0LWlldGYtY3VyZGxlLXJjNC1kaWUtZGllLWRpZS0wMw0KICAgIA0KICAg
IEEgZGlmZiBmcm9tIHRoZSBwcmV2aW91cyB2ZXJzaW9uIGlzIGF2YWlsYWJsZSBhdDoNCiAgICBo
dHRwczovL3d3dy5pZXRmLm9yZy9yZmNkaWZmP3VybDI9ZHJhZnQtaWV0Zi1jdXJkbGUtcmM0LWRp
ZS1kaWUtZGllLTAzDQogICAgDQogICAgDQogICAgUGxlYXNlIG5vdGUgdGhhdCBpdCBtYXkgdGFr
ZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZyb20gdGhlIHRpbWUgb2Ygc3VibWlzc2lvbg0KICAgIHVu
dGlsIHRoZSBodG1saXplZCB2ZXJzaW9uIGFuZCBkaWZmIGFyZSBhdmFpbGFibGUgYXQgdG9vbHMu
aWV0Zi5vcmcuDQogICAgDQogICAgSW50ZXJuZXQtRHJhZnRzIGFyZSBhbHNvIGF2YWlsYWJsZSBi
eSBhbm9ueW1vdXMgRlRQIGF0Og0KICAgIGZ0cDovL2Z0cC5pZXRmLm9yZy9pbnRlcm5ldC1kcmFm
dHMvDQogICAgDQogICAgX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX18NCiAgICBDdXJkbGUgbWFpbGluZyBsaXN0DQogICAgQ3VyZGxlQGlldGYub3JnDQogICAg
aHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9jdXJkbGUNCiAgICANCg0K


From nobody Sun Dec 10 13:37:33 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80FEB127866 for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 13:37:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m_k9u6X93ajy for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 13:37:29 -0800 (PST)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1C7B91241F5 for <curdle@ietf.org>; Sun, 10 Dec 2017 13:37:26 -0800 (PST)
X-AuditID: 1209190c-cbdff70000003839-72-5a2da914ed70
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-1.mit.edu (Symantec Messaging Gateway) with SMTP id 4D.80.14393.519AD2A5; Sun, 10 Dec 2017 16:37:25 -0500 (EST)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id vBALbNNa017168; Sun, 10 Dec 2017 16:37:24 -0500
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id vBALbK8c000534 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Sun, 10 Dec 2017 16:37:22 -0500
Date: Sun, 10 Dec 2017 15:37:20 -0600
From: Benjamin Kaduk <kaduk@mit.edu>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: "curdle@ietf.org" <curdle@ietf.org>
Message-ID: <20171210213720.GO39477@kduck.kaduk.org>
References: <151285096101.24658.6833692177897273472@ietfa.amsl.com> <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupjleLIzCtJLcpLzFFi42IR4hTV1hVdqRtl0LGUy2LrwlnMFv+3dLI4 MHlMPrKA2WPJkp9MAUxRXDYpqTmZZalF+nYJXBlHDyxmLdgvU7F++yS2Bsazol2MnBwSAiYS n7c1s3UxcnEICSxmkvhx9DErhLORUeJDawdU5iqTxJKNW1lAWlgEVCV+TGhnBbHZBFQkGrov M4PYIgLKEsdnPmAEsZkF1CV+HTsGZgsL+EmcvPgZaBAHBy/QutsXLEDCQgLlEqcP/AZr5RUQ lDg58wkLTOufeZeYQcqZBaQllv/jgAjLSzRvnQ1WzilgJ9F4ahLYdFGgrXv7DrFPYBSchWTS LCSTZiFMmoVk0gJGllWMsim5Vbq5iZk5xanJusXJiXl5qUW6hnq5mSV6qSmlmxjBQS3Js4Px zBuvQ4wCHIxKPLwLZutGCbEmlhVX5h5ilORgUhLlTVTRjhLiS8pPqcxILM6ILyrNSS0+xCjB wawkwmvqB1TOm5JYWZValA+TkuZgURLndTcBahNITyxJzU5NLUgtgsnKcHAoSfDyrwBqFCxK TU+tSMvMKUFIM3FwggznARpuC1LDW1yQmFucmQ6RP8Woy/Fs5usGZiGWvPy8VClx3lfLgYoE QIoySvPg5oCSkUT2/ppXjOJAbwnzpoCM4gEmMrhJr4CWMAEtYZqsDbKkJBEhJdXAOLvQs/1Q XtSKmzva/3D92te7R++Zs4bZ/4eOKfKpR7k+eMleurLVM8hBLHPutUvH/c1fCZ1Q2rjD46xo oPSfXzn7d2/bevneyv1LbvxeUfeeYcK5FXe5Nqz2qrx31P5e1rnTfWWrXBeJXmn+rXvl6Ifv 6pOMXklJJZ6xC4vQ29H2/qXPafUJjiuUWIozEg21mIuKEwGPHTseIQMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/DmCJcm_dzcYTdRJGzNUJ-jVmrRo>
Subject: Re: [Curdle] FW: I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Dec 2017 21:37:31 -0000

On Sun, Dec 10, 2017 at 08:42:51PM +0000, Salz, Rich wrote:
> The security AD’s just got back to us.  Apologies from the AD’s and Chairs for letting this fall through the cracks.
> 
> A general “deprecate in all protocols” document is not appropriate for CURDLE.  This means that Section 4 (IMAP->EXTRA), Section 6 (DIAMETER->DIME) and Section 7 are out of scope for this WG. This is quoting Eric, one of the co-Directors.
> 
> On a personal level, I think Section 3 should be handled by UTA. And Section 5 has KITTEN

I think section 5 is roughly equivalent to
draft-ietf-curdle-des-des-des-die-die-die (of which I am coauthor),
which is currently waiting for the IESG to decide whether it is more
appropriate to move RFC 4757 to Historic or make it Obsolete.
So I'm surpirsed that this draft did not refer to "RFC xxxx" in
section 5 but did refer to it in other places :)

> Even if the WG disagrees with me about 3 and 5, there is a question about if it’s worth still having this as a WG document.  Please post your reply to the list; we will call for consensus to move this forward or abandon it early in January.

I think it is worth having this WG do the work it can do in this
space within its charter (which is probably the bits in this
document minus sections 3 and 5).  It feels a little strange to me
to do it all in a single document, as this does, but I wouldn't let
that stop us from doing it.

-Ben

> On 12/9/17, 3:22 PM, "internet-drafts@ietf.org" <internet-drafts@ietf.org> wrote:
> 
>      
>     A New Internet-Draft is available from the on-line Internet-Drafts directories.
>     This draft is a work item of the CURves, Deprecating and a Little more Encryption WG of the IETF.
>     
>             Title           : Depreciating RC4 in all IETF Protocols
>             Author          : Luis Camara
>     	Filename        : draft-ietf-curdle-rc4-die-die-die-03.txt
>     	Pages           : 8
>     	Date            : 2017-12-09
>     
>     Abstract:
>        RC4 is extremely weak as shown by RFC 6649 and RFC 7457, is
>        prohibited in TLS by RFC 7465, is prohibited in Kerberos by RFC xxxx
>        and it needs to be prohibited in all IETF protocols. This document
>        obsoletes RFC 4345 "Improved Arcfour Modes for the Secure Shell (SSH)
>        Transport Layer Protocol" (note Arcfour and RC4 are synonymous).
>        RFC 3501, RFC 4253, RFC 6649 and RFC 6733 are updated to note the
>        deprecation of RC4 in all IETF protocols.
>     
>     
>     The IETF datatracker status page for this draft is:
>     https://datatracker.ietf.org/doc/draft-ietf-curdle-rc4-die-die-die/
>     
>     There are also htmlized versions available at:
>     https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-03
>     https://datatracker.ietf.org/doc/html/draft-ietf-curdle-rc4-die-die-die-03
>     
>     A diff from the previous version is available at:
>     https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-rc4-die-die-die-03
>     
>     
>     Please note that it may take a couple of minutes from the time of submission
>     until the htmlized version and diff are available at tools.ietf.org.
>     
>     Internet-Drafts are also available by anonymous FTP at:
>     ftp://ftp.ietf.org/internet-drafts/
>     
>     _______________________________________________
>     Curdle mailing list
>     Curdle@ietf.org
>     https://www.ietf.org/mailman/listinfo/curdle
>     
> 
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle


From nobody Sun Dec 10 13:58:44 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A40B9124239 for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 13:58:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b007J3RF_C_G for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 13:58:42 -0800 (PST)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D59581241F5 for <curdle@ietf.org>; Sun, 10 Dec 2017 13:58:41 -0800 (PST)
X-AuditID: 1209190d-1edff70000003876-17-5a2dae0fd45e
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-2.mit.edu (Symantec Messaging Gateway) with SMTP id 11.C1.14454.01EAD2A5; Sun, 10 Dec 2017 16:58:40 -0500 (EST)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id vBALwa66010672; Sun, 10 Dec 2017 16:58:37 -0500
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id vBALwXhN005166 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Sun, 10 Dec 2017 16:58:35 -0500
Date: Sun, 10 Dec 2017 15:58:32 -0600
From: Benjamin Kaduk <kaduk@mit.edu>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: "curdle@ietf.org" <curdle@ietf.org>
Message-ID: <20171210215832.GQ39477@kduck.kaduk.org>
References: <151285096101.24658.6833692177897273472@ietfa.amsl.com> <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com> <20171210213720.GO39477@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <20171210213720.GO39477@kduck.kaduk.org>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupjleLIzCtJLcpLzFFi42IRYrdT0RVYpxtl8Klf22LrwlnMFv+3dLI4 MHlMPrKA2WPJkp9MAUxRXDYpqTmZZalF+nYJXBm7TtsVPFSqOPN5HUsD43qpLkYODgkBE4kD XxW7GLk4hAQWM0l8X/CbFcLZyCjRdb2RBcK5yiTR82cLUxcjJweLgKpEy7EPrCA2m4CKREP3 ZWYQW0RAWeL4zAeMIDazgLrEr2PHwGxhAT+Jkxc/s4HYvEDb3t98CjV0EaPExxMn2CESghIn Zz5hgWn+M+8SM8h5zALSEsv/cUCE5SWat84G28UpYCrR37sQrFwUaO/evkPsExgFZyGZNAvJ pFkIk2YhmbSAkWUVo2xKbpVubmJmTnFqsm5xcmJeXmqRrpFebmaJXmpK6SZGUFBzSvLuYPx3 1+sQowAHoxIP74LZulFCrIllxZW5hxglOZiURHkTVbSjhPiS8lMqMxKLM+KLSnNSiw8xSnAw K4nwmvoBlfOmJFZWpRblw6SkOViUxHndTYDaBNITS1KzU1MLUotgsjIcHEoSvOfWADUKFqWm p1akZeaUIKSZODhBhvMADddYCzK8uCAxtzgzHSJ/ilGX49nM1w3MQix5+XmpUuK8eSCDBECK Mkrz4OaAkpFE9v6aV4ziQG8J8wqCjOIBJjK4Sa+AljABLWGarA2ypCQRISXVwOjzySz+Vtz8 JfN+tRe6nRYwMP9zb2c5z7s0t1PGIo6mGiq+5cZ2PBqXihXMDCUjpDV/TzonqfczjEWO587P D+YruVUFeN8zcTF4hR89eG3a4pceuTOn5p6bfTHhvkL07usnzt7+FCyTtVHMr6n30RmeutOu CxZXGRhMzo5s+nvaTV607f28K0osxRmJhlrMRcWJALuEe5YhAwAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/kqrT0TRWZsKSAyx3izRbbtGy79w>
Subject: Re: [Curdle] FW: I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Dec 2017 21:58:43 -0000

On Sun, Dec 10, 2017 at 03:37:20PM -0600, Benjamin Kaduk wrote:
> On Sun, Dec 10, 2017 at 08:42:51PM +0000, Salz, Rich wrote:
> > The security AD’s just got back to us.  Apologies from the AD’s and Chairs for letting this fall through the cracks.
> > 
> > A general “deprecate in all protocols” document is not appropriate for CURDLE.  This means that Section 4 (IMAP->EXTRA), Section 6 (DIAMETER->DIME) and Section 7 are out of scope for this WG. This is quoting Eric, one of the co-Directors.
> > 
> > On a personal level, I think Section 3 should be handled by UTA. And Section 5 has KITTEN
> 
> I think section 5 is roughly equivalent to
> draft-ietf-curdle-des-des-des-die-die-die (of which I am coauthor),
> which is currently waiting for the IESG to decide whether it is more
> appropriate to move RFC 4757 to Historic or make it Obsolete.
> So I'm surpirsed that this draft did not refer to "RFC xxxx" in
> section 5 but did refer to it in other places :)
> 
> > Even if the WG disagrees with me about 3 and 5, there is a question about if it’s worth still having this as a WG document.  Please post your reply to the list; we will call for consensus to move this forward or abandon it early in January.
> 
> I think it is worth having this WG do the work it can do in this
> space within its charter (which is probably the bits in this
> document minus sections 3 and 5).  It feels a little strange to me

A little bird points out that sections 3 and 5 are what Rich was
uncertain of, but it is sections 4, 6, and 7 that Ekr did not think
were appropriate, which is perhaps more authoritative.

> to do it all in a single document, as this does, but I wouldn't let
> that stop us from doing it.

And all in all, the mentioned sections are basically the entire
document.  So, I have to revise my opinion to "this document as-is
doesn't make much sense, but we might consider separate
document(s) for the one or two sections that may still remain".

-Ben

> > On 12/9/17, 3:22 PM, "internet-drafts@ietf.org" <internet-drafts@ietf.org> wrote:
> > 
> >      
> >     A New Internet-Draft is available from the on-line Internet-Drafts directories.
> >     This draft is a work item of the CURves, Deprecating and a Little more Encryption WG of the IETF.
> >     
> >             Title           : Depreciating RC4 in all IETF Protocols
> >             Author          : Luis Camara
> >     	Filename        : draft-ietf-curdle-rc4-die-die-die-03.txt
> >     	Pages           : 8
> >     	Date            : 2017-12-09
> >     
> >     Abstract:
> >        RC4 is extremely weak as shown by RFC 6649 and RFC 7457, is
> >        prohibited in TLS by RFC 7465, is prohibited in Kerberos by RFC xxxx
> >        and it needs to be prohibited in all IETF protocols. This document
> >        obsoletes RFC 4345 "Improved Arcfour Modes for the Secure Shell (SSH)
> >        Transport Layer Protocol" (note Arcfour and RC4 are synonymous).
> >        RFC 3501, RFC 4253, RFC 6649 and RFC 6733 are updated to note the
> >        deprecation of RC4 in all IETF protocols.
> >     
> >     
> >     The IETF datatracker status page for this draft is:
> >     https://datatracker.ietf.org/doc/draft-ietf-curdle-rc4-die-die-die/
> >     
> >     There are also htmlized versions available at:
> >     https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-03
> >     https://datatracker.ietf.org/doc/html/draft-ietf-curdle-rc4-die-die-die-03
> >     
> >     A diff from the previous version is available at:
> >     https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-rc4-die-die-die-03
> >     
> >     
> >     Please note that it may take a couple of minutes from the time of submission
> >     until the htmlized version and diff are available at tools.ietf.org.
> >     
> >     Internet-Drafts are also available by anonymous FTP at:
> >     ftp://ftp.ietf.org/internet-drafts/
> >     
> >     _______________________________________________
> >     Curdle mailing list
> >     Curdle@ietf.org
> >     https://www.ietf.org/mailman/listinfo/curdle
> >     
> > 
> > _______________________________________________
> > Curdle mailing list
> > Curdle@ietf.org
> > https://www.ietf.org/mailman/listinfo/curdle
> 
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle


From nobody Sun Dec 10 23:36:39 2017
Return-Path: <mdb@juniper.net>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4993C127ABE for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 23:36:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kN3Z9ulESl6R for <curdle@ietfa.amsl.com>; Sun, 10 Dec 2017 23:36:35 -0800 (PST)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A18D3127978 for <curdle@ietf.org>; Sun, 10 Dec 2017 23:36:35 -0800 (PST)
Received: from pps.filterd (m0108161.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.21/8.16.0.21) with SMTP id vBB7Y9CE023195; Sun, 10 Dec 2017 23:36:34 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=to : cc : subject : in-reply-to : references : from : date : message-id : sender : mime-version : content-type; s=PPS1017; bh=IRTgFkf9TUJu4WfxVs8Kc/Df90qqnjegGR+Nlt6Xzbw=; b=hNtXWzgWFzDz7sRi8e8TjOJiVV3etgVsIFb1gwv/IBFPYitFT3fPLueo1SG0SALq6LHz YXloW2oDUBZBDHCjc4DQKjhJXtU/yS3PcPnFGJ2u3qgwtbxt1LmmU4Vs3U4wKC/77w1R uCG3DDp/s9LNfTRvxEk8u6la0REdJMHkskrflZXtzCcd82pr9/RerGIKPkDLGwgmu02Z /fw9sprs73Eau9uzMbndTQR1TW+5PZ9KwnT5RWs8Vr/7a+DksG6i5PefQlLum5onPjQ1 aTSllNpTH/XFoUZBP6tOi0MJzLXcp0+HkJFDwsAjyr3WuSZnn7EcTV0nFx1Vaqfrsa67 hw== 
Received: from nam01-by2-obe.outbound.protection.outlook.com (mail-by2nam01lp0176.outbound.protection.outlook.com [216.32.181.176]) by mx0b-00273201.pphosted.com with ESMTP id 2esmd3r4r4-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Sun, 10 Dec 2017 23:36:33 -0800
Received: from CO2PR05CA0106.namprd05.prod.outlook.com (10.165.92.32) by SN1PR0501MB2080.namprd05.prod.outlook.com (10.163.227.29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.4; Mon, 11 Dec 2017 07:36:31 +0000
Received: from BY2NAM05FT004.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e52::206) by CO2PR05CA0106.outlook.office365.com (2603:10b6:104:1::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.323.4 via Frontend Transport; Mon, 11 Dec 2017 07:36:31 +0000
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by BY2NAM05FT004.mail.protection.outlook.com (10.152.100.141) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P256) id 15.20.302.6 via Frontend Transport; Mon, 11 Dec 2017 07:36:30 +0000
Received: from p-mailhub01.juniper.net (10.47.226.20) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Sun, 10 Dec 2017 23:36:24 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id vBB7aNBQ028796; Sun, 10 Dec 2017 23:36:23 -0800	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 909AC1141B;	Sun, 10 Dec 2017 23:36:22 -0800 (PST)
To: "Salz, Rich" <rsalz@akamai.com>
CC: "curdle@ietf.org" <curdle@ietf.org>
In-Reply-To: <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com> 
References: <151285096101.24658.6833692177897273472@ietfa.amsl.com> <15C5FA9C-DCC9-4C39-B102-47B4618259E4@akamai.com>
Comments: In-reply-to: "Salz, Rich" <rsalz@akamai.com> message dated "Sun, 10 Dec 2017 20:42:51 +0000."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Sun, 10 Dec 2017 23:36:22 -0800
Message-ID: <93673.1512977782@eng-mail01.juniper.net>
Sender: <mdb@juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(376002)(39860400002)(346002)(2980300002)(189003)(199004)(5660300001)(53936002)(105596002)(478600001)(69596002)(6392003)(7846003)(4326008)(97876018)(106466001)(6266002)(6246003)(8936002)(81166006)(81156014)(8676002)(558084003)(86362001)(2810700001)(7126002)(356003)(305945005)(48376002)(316002)(2906002)(47776003)(230783001)(53416004)(97736004)(117636001)(16586007)(229853002)(68736007)(77096006)(55016002)(7696005)(51416003)(76506005)(50466002)(6916009)(2950100002)(76176011)(4743002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR0501MB2080; H:p-emfe01a-sac.jnpr.net; FPR:; SPF:SoftFail; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en; 
X-Microsoft-Exchange-Diagnostics: 1; BY2NAM05FT004; 1:663Nmtp+9dxrLTdqgMpf92DRxiZOlUBqNtiZg/SNFcdjlKpEaFAd4ifPcNXd//HvtEkoMI1dIL1+eFq1Bure7VFKruyYaxR00dRy3V3W7IUhQBNXOK0cAOtfCLo1zw74
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: db30bbe8-a40d-4b5f-ea81-08d54069e57d
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4627115)(201703031133081)(201702281549075)(2017052603307); SRVR:SN1PR0501MB2080; 
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2080; 3:5c3PLCp+oee+xyX4I8VMZA2LuNremJCeI8q9efqzTUU/nzGBppmiu1ttGTTfg9p8uVu4tk7qhhEsOHJ2N3mtBjBzIyZ34CjdG9ziw47HH9tQlkkhDspxzc1YpE3ACjWXCUlLX/5XLxvi3XXr9DvBUTeItMAdpygnfBYLNZeDHfcvE/v0DiFhc4EvOifCw3NWuUzICnv/LoG8pZRHHDLbBOrCMYD4mxtxnUezwU4LDKctDiGswRQBjuo5+pj4XDQoffd+GLoHXNkG9+xQwR62uX8wZpAwQJ46z9TMRoKnKfpDm446dkKqOeTHvIT9fELVmA141pUuB8ulF5wJl9/PsWfoLlIkm8D3g1X5nYyfyvU=; 25:A8Ye2fyqPCDinX7HJic94BVNvaz1eXLrsxU55F+3eSvoPYduqvbqN9AopYO+xxL7xDaVlu20Q+4ZxLlrj3kgDiTFXeuL3WaHKD0LV9kuzmcxZ4zEfnPF1Ej1E8uzauTBjcy4W0Sh/TIMfJ+N45FWQ2W2HU+FesPUkaA3sWHIZZh66jIV35tm7pF+KEwhNBZaKc/i9epuv20GH7zX/NpvqKPKYWL73ISVJm7yTQEc9iVDIFFvn4emL5rpH/N3jw+fgfkIjGHi7F7yzZ1htSX0B6IgFQGtxC42SQc/mTY8o3u69Oyiba7tF2Khuk3dFh81zkF1hK9coX6wC+zSVFdBiA==
X-MS-TrafficTypeDiagnostic: SN1PR0501MB2080:
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2080; 31:b1VEJoreXjE1jnnTZY0yCVrt4iTnkPl+PdfieCzm9jaDObFy5krY3FAYM4biM4oHWfpQ5aHUfwpaNwMGx69kebSyatTy4YJXQj4/BRYrhXuea/83LTRkmYc1gaekXj00yMkidaILODKtpQVHFaqvtLLja8/nqaKH2BO9WgOgaEwgDKVmhpGhqizHm7HLf80ixqnnqVs9CDK6Z/MzB/Zv6Em7eJ1HNKge9N/iS/olQhk=; 20:un0+taXalnePk7/C4NDfKAjLyZoTbABJILV8zHOIwMizmQ2b36ftcn1AOXQhwOS3VNzY2V+yqO9jJHT8oKqNaX3DY6sNaOBvR55uaIalYXN+9fnQF3+vdP7tJV1aemXHznLZQLayrwDUuV6E9YX1iGHNBK/8CVDU8ERIMIeRf0EFODDtNXnQc6f30BfqOnBt0Hcx0HGBDvnFxg7htoGZkLrbqqK/cjFQfGoJuIhqu6OKsdUSLMdFoacUZIhtAV4i2OQeXp5qPac2BDyUFlEZIOHt8wn9M/h04gu/1sQ6Vi6zUOKZMMiDhFQO83zfy6p3B/AyllToiHQDPhR/X8llbkEGXd4v9q2bgLGxnubBB4J/HhAGf2igbQrqyVjQyyQVy/qC6pNt8agHb1NJz1+BzNaiUp5VWa2eihZ5FHA21/TbvgNyfbzQ5QlDRlStG7E9eqPoWriz5R3BvCHtbEcbED++9s8bI9VvkgKndb5E/Cqec8BWoA2Kcf57rak0v076
X-Microsoft-Antispam-PRVS: <SN1PR0501MB20802A416C2F19E82F352083BF370@SN1PR0501MB2080.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(2401047)(8121501046)(5005006)(93006095)(93003095)(3002001)(10201501046)(3231022)(6055026)(6041248)(20161123562025)(20161123564025)(20161123560025)(20161123555025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(201708071742011); SRVR:SN1PR0501MB2080; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:SN1PR0501MB2080; 
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2080; 4:phnV8xjQwG1vmlqe8k8V3J8nG4fOxJBydPl7KXdwVQtz8SU1j6FYgn4xHmJwcuU+9k/c+POeffir7UMX/TM3JYfXaRYgdOORZ2fZo/mu1r1wyrEiMTip3dL+Fl2Ib0gFWRcPULyx1ipZRqs6Ri1o/IWLWbAnQxLoBff30lcusr620uXylwOb4f0iRTNoeMc+2IYqpEMQu9LJ528dlL4AuocRpUG8f99Iq2LD5REZKsWvHnCwp5IWPH/1YAhj5dzu9hpO/8w+lUfYPfMGa71+dw==
X-Forefront-PRVS: 0518EEFB48
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1; SN1PR0501MB2080; 23:P3gmnO7tA6eMiDor0NWiLZkHh2W77gcp+WYJ/mF?= =?us-ascii?Q?UQct4XGGuHXDukVkYXt8SxK7oB87hNJ0HN1CQKvxrVg0fpeORWV7cUKERjMv?= =?us-ascii?Q?wIc+0pDVrMnQPMI3j5r5wJBLH+bbK1OzaA0oF9LxWUVLJB5O7xbeRNhiI8iq?= =?us-ascii?Q?ofs7wrkMfGy21a9ZLf517E6J4ORZ1DZeZBcTscmwEV6WSZOUObBbiTShUSSc?= =?us-ascii?Q?6SLPlwGfBdW+R2N/fexfYg8I/P931vSROeILDa4D+s1IeGaX5VnfGftsLCA9?= =?us-ascii?Q?9Vjkf3x7Qp7hqZUjWEqdgBczyZMdVMZ8bwPWdAKu+7E7a8981FkhtLZTCTor?= =?us-ascii?Q?iGoxRrbgZByN/KD5RPrSxF/n/ZuJsAhgbBx4imN+30k/0Dw7M12LTrn2yKIO?= =?us-ascii?Q?PDK6fuwY/H5Znun9H7aphbzo6z7F3z6XoMhVOVBMq96lfzUM1qSFGwbTUUDT?= =?us-ascii?Q?8eZmmqPTT/oA2tDhSaVVdVDVkUsTl3Megv8IPaB5jZhVp6dsaD1IhBQe7L2F?= =?us-ascii?Q?eczgGB3MHDhUmWaJInCJ4dApHfzTKNfwSE3/dvpcyBnBswYvbRvRIgbfvK85?= =?us-ascii?Q?5ih6slsf4xx/RfxNpgjoPc90Vj/cdj8NJMTzPFrrK3uD3kguI+Pva49Pe8gH?= =?us-ascii?Q?+5fbLzZlLAqvUewWYhQWwto6s1D00eGCFd8CmxX453RWAYIDYBzbYPnmXrnT?= =?us-ascii?Q?c4EUryWpzpvq8jkccLO8x5v0Z0ndyk4ZwLrCzArFw+Mdss4GA7lw4Kbb+KL7?= =?us-ascii?Q?xohoYfB5j2/19zLSU10B/uCxjNu+QJSet1vgAXLl90DgK4vICIEfyOEBI/T4?= =?us-ascii?Q?ET6VeXLWuih7oe6Vv+5b5MPyi9Ch59YClNORZTtZdQaCcu9YiKsGSP/YvTKf?= =?us-ascii?Q?HXSLUN3LN2545UcXBN+IosCONty9n9+DtvT9zKp9tVWCYPupeDFIxB9N1sPV?= =?us-ascii?Q?sMx2J4KxgX+O18N9tAVc8hEDLbzNi/vLRc2MntOphsmZK/+DgzevbtkT69MC?= =?us-ascii?Q?8QdlCiyWt5LX1j51dO7k0/PNlUbxUrtxXXw7mhlwNfV5oJYQrXbDhL5VKsbH?= =?us-ascii?Q?MAAyHvfgJP1I+XifMfutXgXA4piYNZ7m++2LBngLxhtGJYOuBk4LdBH/cpCr?= =?us-ascii?Q?B24g9LaO5jPUFEXuFZ3Y7+koDcYSOGiTqd2KPIadtjxe4bd5Ff+aY0A=3D?= =?us-ascii?Q?=3D?=
X-Microsoft-Exchange-Diagnostics: 1; SN1PR0501MB2080; 6:UjVwcXzuzAndvdBVlNGrXRKAn+O9JdcXgACtMVAm6vAjoU3cZ3tiL/+UUdzH2q1sw1vXnkdXsF3svIOLqMvQviwMuIcntcljANkpu2avEwYA6J4VVdddplbe9avuAlvjlmimvWm+zIJQkID/6P3PKXE2b1pmLxgU7ZPOlRxiufpvSjpfWkPUHohmyRwaYkgzTSs2zfqK0zJmgmR67tE0ZFwiH+oX2Omk/ktdgh7zTWUMQK+VJeopEPadTjcHKKvvhgkadWLxwa81DpSD49EXYlOwUZ0KVQkRelvwsbCCKawkCuSElCj9UQjqHWpJNpnoTO7qM9xXFfbgC45cFfR8jRZf8IN0zB0wF/0GmlPZR6k=; 5:9P4cqSDlAlLaxYZk8skdE/UbX+Rr8r3x5SuvWGX59U7wOl0fB2mdfSSZbExjLTnW9xHjYCUUiv+Lt1SLpBkw0CzCsQPt0eV1w254EvNJhbnSy9Ex9wxQBDleXSK+s1ui6sMgzXz4/hIpfIoWWBVc8wTKgJ1RtihudnoaofdY90I=; 24:vwGYS5BJ8QsiW91arRDJyasoSjwrIpx/Vop650aKogGYIhoXAJCQHqWAOVvA6udv80/FJMdDDC15eNIesiqQovzI+Oz1fCxWd4lTnwLOyXk=; 7:H5S0bD6b2XDeYL0iVEGWCYoChifPpIbJTEigtZ9mNNHhqWXVH0VNXgeUyUIAOl2o58DoL9qodM9EkWOMNws1CNV1JJlDnVL7X5jwMzzFFW4zJdfDmY2wM0ePl2qKBbwxiNSAEcsJ7JzYg79zwA49P+Hl5Hxo2ISvJGSHyoEeB88YlAWjHf5RIyINI6LKukbYxT6MPheSFNzBYmU8nMDwxczVD1bw0x2CFo9YLKL3yxnZwni+F9T1GRB0xpEn6TVT
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Dec 2017 07:36:30.1583 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: db30bbe8-a40d-4b5f-ea81-08d54069e57d
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4; Ip=[66.129.239.12];  Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR0501MB2080
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-12-11_03:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=1 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=768 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1712110117
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/v40-Y0R20F6DrDBWbRfZnNGQHWE>
Subject: Re: [Curdle] FW: I-D Action: draft-ietf-curdle-rc4-die-die-die-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Dec 2017 07:36:37 -0000

For what it is worth, I would like to see SSH use of arcfour in RFC4253
and arcfour128 and arcfour256 in rfc4345 deprecated.

I do not know if this needs to be a separate document or not, but I
think the CURdle WG changes to SSH are in scope.

	-- Mark


From nobody Tue Dec 12 13:37:04 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: curdle@ietf.org
Delivered-To: curdle@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 265D9127444; Tue, 12 Dec 2017 13:37:03 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: curdle@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151311462310.14148.2268946523220929471@ietfa.amsl.com>
Date: Tue, 12 Dec 2017 13:37:03 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/3KjUgqhIbbJr-YqRJpSNUwdioD0>
Subject: [Curdle] I-D Action: draft-ietf-curdle-rc4-die-die-die-04.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Dec 2017 21:37:03 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the CURves, Deprecating and a Little more Encryption WG of the IETF.

        Title           : Depreciating RC4 in all IETF Protocols
        Author          : Luis Camara
	Filename        : draft-ietf-curdle-rc4-die-die-die-04.txt
	Pages           : 7
	Date            : 2017-12-12

Abstract:
   RC4 is extremely weak as shown by RFC 6649 and RFC 7457, is
   prohibited in TLS by RFC 7465, is prohibited in Kerberos by RFC xxxx
   and it needs to be prohibited in all IETF protocols. This document
   obsoletes RFC 4345 "Improved Arcfour Modes for the Secure Shell (SSH)
   Transport Layer Protocol" (note Arcfour and RC4 are synonymous).
   RFC 3501, RFC 4253, RFC 6649 and RFC 6733 are updated to note the
   depreciation of RC4 in all IETF protocols.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-curdle-rc4-die-die-die/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-04
https://datatracker.ietf.org/doc/html/draft-ietf-curdle-rc4-die-die-die-04

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-rc4-die-die-die-04


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed Dec 13 12:09:03 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DFA191241FC; Wed, 13 Dec 2017 12:08:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HQh84rcUc87l; Wed, 13 Dec 2017 12:08:54 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3196E1242F5; Wed, 13 Dec 2017 12:08:54 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 4923BB81649; Wed, 13 Dec 2017 12:08:28 -0800 (PST)
To: ietf-announce@ietf.org, rfc-dist@rfc-editor.org
X-PHP-Originating-Script: 1005:ams_util_lib.php
From: rfc-editor@rfc-editor.org
Cc: rfc-editor@rfc-editor.org, drafts-update-ref@iana.org, curdle@ietf.org
Content-type: text/plain; charset=UTF-8
Message-Id: <20171213200828.4923BB81649@rfc-editor.org>
Date: Wed, 13 Dec 2017 12:08:28 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/wOpQoEJNfavRPF5wRj2BiCp9izg>
Subject: [Curdle] =?utf-8?q?RFC_8268_on_More_Modular_Exponentiation_=28MOD?= =?utf-8?q?P=29_Diffie-Hellman_=28DH=29_Key_Exchange_=28KEX=29_Groups_for_?= =?utf-8?q?Secure_Shell_=28SSH=29?=
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 20:08:56 -0000

A new Request for Comments is now available in online RFC libraries.

        
        RFC 8268

        Title:      More Modular Exponentiation (MODP) Diffie-Hellman 
                    (DH) Key Exchange (KEX) Groups for 
                    Secure Shell (SSH) 
        Author:     M. Baushke
        Status:     Standards Track
        Stream:     IETF
        Date:       December 2017
        Mailbox:    mdb@juniper.net
        Pages:      8
        Characters: 16318
        Updates:    RFC 4250, RFC 4253

        I-D Tag:    draft-ietf-curdle-ssh-modp-dh-sha2-09.txt

        URL:        https://www.rfc-editor.org/info/rfc8268

        DOI:        10.17487/RFC8268

This document defines added Modular Exponentiation (MODP) groups for
the Secure Shell (SSH) protocol using SHA-2 hashes.  This document
updates RFC 4250.  This document updates RFC 4253 by correcting an
error regarding checking the Peer's DH Public Key.

This document is a product of the CURves, Deprecating and a Little more Encryption Working Group of the IETF.

This is now a Proposed Standard.

STANDARDS TRACK: This document specifies an Internet Standards Track
protocol for the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the Official
Internet Protocol Standards (https://www.rfc-editor.org/standards) for the 
standardization state and status of this protocol.  Distribution of this 
memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  https://www.ietf.org/mailman/listinfo/ietf-announce
  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see https://www.rfc-editor.org/search
For downloading RFCs, see https://www.rfc-editor.org/retrieve/bulk

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team
Association Management Solutions, LLC



From nobody Wed Dec 13 12:24:52 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: curdle@ietf.org
Delivered-To: curdle@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B2DDC128792; Wed, 13 Dec 2017 12:24:50 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: curdle@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151319669069.29995.13704301511342942978@ietfa.amsl.com>
Date: Wed, 13 Dec 2017 12:24:50 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/Xo1H0hsIxLP73sHpmBt0pgKxdhw>
Subject: [Curdle] I-D Action: draft-ietf-curdle-gss-keyex-sha2-03.txt
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 20:24:50 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the CURves, Deprecating and a Little more Encryption WG of the IETF.

        Title           : GSS-API Key Exchange with SHA2
        Authors         : Simo Sorce
                          Hubert Kario
	Filename        : draft-ietf-curdle-gss-keyex-sha2-03.txt
	Pages           : 16
	Date            : 2017-12-13

Abstract:
   This document specifies additions and amendments to SSH GSS-API
   Methods [RFC4462].  It defines a new key exchange method that uses
   SHA-2 for integrity and deprecates weak DH groups.  The purpose of
   this specification is to modernize the cryptographic primitives used
   by GSS Key Exchanges.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-curdle-gss-keyex-sha2/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-curdle-gss-keyex-sha2-03
https://datatracker.ietf.org/doc/html/draft-ietf-curdle-gss-keyex-sha2-03

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-curdle-gss-keyex-sha2-03


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Dec 19 13:11:02 2017
Return-Path: <mglt.ietf@gmail.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 784BC124239; Tue, 19 Dec 2017 13:11:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level: 
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wqyTFDdC-RTH; Tue, 19 Dec 2017 13:10:59 -0800 (PST)
Received: from mail-lf0-x232.google.com (mail-lf0-x232.google.com [IPv6:2a00:1450:4010:c07::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 875781200FC; Tue, 19 Dec 2017 13:10:58 -0800 (PST)
Received: by mail-lf0-x232.google.com with SMTP id x204so21679133lfa.11; Tue, 19 Dec 2017 13:10:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:sender:from:date:message-id:subject:to:cc; bh=q/1LVIyjRLzotL4uM94ki1buEoAut2+qhWwjL7Gxipk=; b=b5QONCadhMoQ+AoxRXkfnfJsr3JnCtb+6Egj93Pt0o48pGESn3R1jdhWT0rprRhMCy xFUiHg1anSQ6nv7S/UWk8mk+NW8qeXqTxlxOBzOGfz4lB805X+1dJj6qqP0fu5yZJ7ZI BeWpw1mYOzT5bjvjlolcHgfgaOgCZNujyMXOuqSTUBLpttUE7uYLvO+Pf6dgPm5Q3GeW m9NAP3+n50m2yDAL/8lrdeJqCWhN+KrhQexP2SLeX9i3Skwzzb1iifNLNHb5dWnJLR3D 2RN1JDJlTknrQB2SZ8RD+1YkR6LvakrKRDoSqtB+I+qhfU1+rrCElQbQeaqCjBgEV/V2 5C1w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:from:date:message-id:subject :to:cc; bh=q/1LVIyjRLzotL4uM94ki1buEoAut2+qhWwjL7Gxipk=; b=I8HfJ1sGXK8AMzucF96+kgnI8jjzJRaWDEZ7iCRLVpqP5Mc6JJoqPRKFXN4CeP9hrw Wx6W8NWUwSKDlSACdTvF0rlWKQFC4HYSIFxK2ZYKdp7oKn+LYmk6AYBPcHGROa3okbSt 76Pd1YF/X+2V7bBG7N/iDGx7VrluQn0jAA3AaomvGapqyJT5ZQsWt598p3H6hqG3dL/R LvtseP5kTPZJLQL+/mF0XF5mPtlThGZQreo6hBupZ7mNiUwf45LxxYL9ZG7kiiaUVhYo 6/Jg7nbjof0KJ8qn5fIn3AF1J13VyV0A5kS7LxFA9vU5DeAyZb0MFSxlJh14gJrn6toG ug8g==
X-Gm-Message-State: AKGB3mI3I4JMgydgOZAVFHjXUo07kGiVgSqArnED6vj7xBSe33fLDCtC 8U463+VBBm+BH333CAalGNcOB35TzPg1+sQ02ct5lw==
X-Google-Smtp-Source: ACJfBov5lpONkJ/pm/TFHEKVxb3gl6qROueIrh9SWcFfwW8EQ0ddxm64QKbREOHsxySEUV1HD/7h5vu8yohqlZ4PvJc=
X-Received: by 10.46.15.25 with SMTP id 25mr3048268ljp.119.1513717856537; Tue, 19 Dec 2017 13:10:56 -0800 (PST)
MIME-Version: 1.0
Sender: mglt.ietf@gmail.com
Received: by 10.46.80.17 with HTTP; Tue, 19 Dec 2017 13:10:55 -0800 (PST)
From: Daniel Migault <daniel.migault@ericsson.com>
Date: Tue, 19 Dec 2017 16:10:55 -0500
X-Google-Sender-Auth: qdKoPPY6tB2qTKpMJeAcF56rWp0
Message-ID: <CADZyTkksHDXEDX4rq8oW9Koi2TXc5yYxhwE3UJo3tGx_E27J7A@mail.gmail.com>
To: curdle <curdle@ietf.org>
Cc: curdle-chairs <curdle-chairs@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c1ce7a02119b70560b7e786"
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/f34VdBIO-w1VVVkk1_m6kJSBMIc>
Subject: [Curdle] comments on draft-ietf-curdle-ssh-kex-sha2-09
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 21:11:01 -0000

--94eb2c1ce7a02119b70560b7e786
Content-Type: text/plain; charset="UTF-8"

Hi,

Please find the shepherd write-up [1] for draft-ietf-curdle-ssh-kex-sha2
[2]  as well as my comments regarding the current version below:

Unless some raises any concerns, the draft will be sent to the IESG as soon
as the current version is updated.

Yours,

Daniel

[1]
https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-kex-sha2/shepherdwriteup/
[2] https://tools.ietf.org/html/draft-ietf-curdle-ssh-kex-sha2-09

section 1

maybe the sentence below should be removed.

   [TO BE REMOVED: Please send comments on this draft to
   curdle@ietf.org.]

reference I-D.ietf-curdle-ssh-modp-dh-sha2 is now rfc8268, so references
should be updated and moved from informational to normative.

section 3.1

Curve25519 and SHA-256 may point to references such as RFC8031 RFC6234.

It might be also good to have a reference to the code point
curves25519-sha256 with draft-ietf-curdle-ssh-curves.

section 3.2

Curve448 and curve448-256 may also point to references RFC8031 and
draft-ietf-curdle-ssh-curves

section 3.3


I think the sentence below repeats itself and should be changed:
""
It is recommended that these key exchange groups NOT
be used. This key exchange SHOULD NOT be used.
"""

section 3.5

diffiehellman-group1-sha1 should be referenced by RFC4253

section 3.6 - 3.11

The code points should refer to rfc8268.

section 3.7

It is surprising DH is defined so deep in the document ;-)

section 3.12 -3.14

The code points should should refer rfc5656

section 3.15 - 3.17

The code points should refer rfc4462

section 3.18 - 3.27

The code points should refer draft-ietf-curdle-gss-keyex-sha2


section 3.28 - 3.29

The code points should  mention rfc 4432

In section 3.29 I think that more text should be added to justify the MAY.
rsa2048-sha256 matches all reasons rsa1024-sha1 's status is MUST NOT.

section 4

""Of course, use of SHA384""" may be """Of course, the use of SHA384"""
I might be wrong as well.

section 5

new-modp should be replaced by rfc8268



section 8

rsa1024-sha1 is the only code point to be updated by
IANA in that case, it may be easier to mention it rather than
referring to the table.

The nits provides the following output.

idnits 2.15.00

tmp/draft-ietf-curdle-ssh-kex-sha2-09.txt:

  Checking boilerplate required by RFC 5378 and the IETF Trust (see
  https://trustee.ietf.org/license-info):
  ----------------------------------------------------------------------------

     No issues found here.

  Checking nits according to https://www.ietf.org/id-info/1id-guidelines.txt:
  ----------------------------------------------------------------------------

     No issues found here.

  Checking nits according to https://www.ietf.org/id-info/checklist :
  ----------------------------------------------------------------------------

     No issues found here.

  Miscellaneous warnings:
  ----------------------------------------------------------------------------

     (Using the creation date from RFC4250, updated by this document, for
     RFC5378 checks: 2005-03-16)

  -- The document seems to lack a disclaimer for pre-RFC5378 work, but may
     have content which was first submitted before 10 November 2008.  If you
     have contacted all the original authors and they are all willing to grant
     the BCP78 rights to the IETF Trust, then this is fine, and you can ignore
     this comment.  If not, you may need to add the pre-RFC5378 disclaimer.
     (See the Legal Provisions document at
     https://trustee.ietf.org/license-info for more information.)

  -- The document date (July 30, 2017) is 142 days in the past.  Is this
     intentional?


  Checking references for intended status: Proposed Standard
  ----------------------------------------------------------------------------

     (See RFCs 3967 and 4897 for information about using normative references
     to lower-maturity documents in RFCs)

  == Outdated reference: A later version (-03) exists of
     draft-ietf-curdle-gss-keyex-sha2-02

  == Outdated reference: A later version (-06) exists of
     draft-ietf-curdle-ssh-curves-05

  == Outdated reference: draft-ietf-curdle-ssh-dh-group-exchange has been
     published as RFC 8270

  == Outdated reference: draft-ietf-curdle-ssh-modp-dh-sha2 has been
     published as RFC 8268


     Summary: 0 errors (**), 0 flaws (~~), 4 warnings (==), 2 comments (--).

     Run idnits with the --verbose option for more detailed information about
     the items above.

--94eb2c1ce7a02119b70560b7e786
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div><div><div>Hi, <br><br></div>Please fin=
d the shepherd write-up [1] for draft-ietf-curdle-ssh-kex-sha2 [2]=C2=A0 as=
 well as my comments regarding the current version below:<br><br></div>Unle=
ss some raises any concerns, the draft will be sent to the IESG as soon as =
the current version is updated. <br><br></div>Yours, <br><br></div>Daniel<b=
r><br>[1] <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh=
-kex-sha2/shepherdwriteup/">https://datatracker.ietf.org/doc/draft-ietf-cur=
dle-ssh-kex-sha2/shepherdwriteup/</a><br>[2] <a href=3D"https://tools.ietf.=
org/html/draft-ietf-curdle-ssh-kex-sha2-09">https://tools.ietf.org/html/dra=
ft-ietf-curdle-ssh-kex-sha2-09</a><br><br></div>section 1<br><br></div>mayb=
e the sentence below should be removed. <br><div><div><pre class=3D"gmail-n=
ewpage">   [TO BE REMOVED: Please send comments on this draft to
   <a href=3D"mailto:curdle@ietf.org">curdle@ietf.org</a>.]
</pre><div>reference I-D.ietf-curdle-ssh-modp-dh-sha2 is now rfc8268, so re=
ferences should be updated and moved from informational to normative. <br><=
/div><div> <br></div><div>section 3.1</div><div><br></div><div>Curve25519 a=
nd SHA-256 may point to references such as RFC8031 RFC6234.<br></div><div><=
br></div><div>It might be also good to have a reference to the code point c=
urves25519-sha256 with draft-ietf-curdle-ssh-curves. <br></div><div><br></d=
iv><div>section 3.2</div><div><br></div><div>Curve448 and curve448-256 may =
also point to references RFC8031 and draft-ietf-curdle-ssh-curves</div><div=
>=C2=A0</div><div>section 3.3 <br></div><br><div><br></div><div>I think the=
 sentence below repeats itself and should be changed:</div><div>&quot;&quot=
;<br></div><div>It is recommended that these key exchange groups NOT<br></d=
iv><div>  be used.  This key exchange SHOULD NOT be used.</div><div>&quot;&=
quot;&quot;<br></div><div><br></div><div>section 3.5 <br></div><div><br></d=
iv><div>diffiehellman-group1-sha1 should be referenced by RFC4253<br></div>=
<div><br></div><div>section 3.6 - 3.11<br></div><div><br></div><div>The cod=
e points should refer to rfc8268.</div><div><br></div><div>section 3.7 <br>=
</div><div><br></div><div>It is surprising DH is defined so deep in the doc=
ument ;-)</div><div><br></div><div>section 3.12 -3.14<br></div><div><br></d=
iv><div>The code points should should refer rfc5656</div><div><br></div><di=
v>section 3.15 - 3.17</div><div><br></div><div>The code points should refer=
 rfc4462</div><div><br></div><div>section 3.18 - 3.27 <br></div><div><br></=
div><div>The code points should refer draft-ietf-curdle-gss-keyex-sha2<br><=
/div><div><br></div><div><br></div><div>section 3.28 - 3.29<br></div><div><=
br></div><div> The code points should=C2=A0 mention rfc 4432<br></div><div>=
<br></div><div>In section 3.29 I think that more text should be added to ju=
stify the MAY. rsa2048-sha256 matches all reasons rsa1024-sha1 &#39;s statu=
s is MUST NOT. <br></div><div><br></div><div>section 4</div><div><span styl=
e=3D"font-family:arial,helvetica,sans-serif"><br></span></div><div><pre cla=
ss=3D"gmail-newpage"><span style=3D"font-family:arial,helvetica,sans-serif"=
>&quot;&quot;Of course, use of SHA384&quot;&quot;&quot; may be &quot;&quot;=
&quot;Of course, the use of SHA384&quot;&quot;&quot; <br>I might be wrong a=
s well. <br><br></span></pre><pre class=3D"gmail-newpage"><span style=3D"fo=
nt-family:arial,helvetica,sans-serif">section 5 <br><br></span></pre><pre c=
lass=3D"gmail-newpage"><span style=3D"font-family:arial,helvetica,sans-seri=
f">new-modp should be replaced by rfc8268<br></span></pre></div><div><br></=
div><div><br></div><div>section 8<br></div><div><br></div><div><pre class=
=3D"gmail-newpage">rsa1024-sha1 is the only code point to be updated by <br=
>IANA in that case, it may be easier to mention it rather than referring to=
 the table. <br><br></pre><pre class=3D"gmail-newpage">The nits provides th=
e following output. <br><br>idnits 2.15.00=20

tmp/draft-ietf-curdle-ssh-kex-sha2-09.txt:

  Checking boilerplate required by RFC 5378 and the IETF Trust (see
  <a href=3D"https://trustee.ietf.org/license-info">https://trustee.ietf.or=
g/license-info</a>):
  -------------------------------------------------------------------------=
---

     No issues found here.

  Checking nits according to <a href=3D"https://www.ietf.org/id-info/1id-gu=
idelines.txt">https://www.ietf.org/id-info/1id-guidelines.txt</a>:
  -------------------------------------------------------------------------=
---

     No issues found here.

  Checking nits according to <a href=3D"https://www.ietf.org/id-info/checkl=
ist">https://www.ietf.org/id-info/checklist</a> :
  -------------------------------------------------------------------------=
---

     No issues found here.

  Miscellaneous warnings:
  -------------------------------------------------------------------------=
---

     (Using the creation date from RFC4250, updated by this document, for
     RFC5378 checks: 2005-03-16)

  -- The document seems to lack a disclaimer for pre-RFC5378 work, but may
     have content which was first submitted before 10 November 2008.  If yo=
u
     have contacted all the original authors and they are all willing to gr=
ant
     the BCP78 rights to the IETF Trust, then this is fine, and you can ign=
ore
     this comment.  If not, you may need to add the pre-RFC5378 disclaimer.=
=20
     (See the Legal Provisions document at
     <a href=3D"https://trustee.ietf.org/license-info">https://trustee.ietf=
.org/license-info</a> for more information.)

  -- The document date (July 30, 2017) is 142 days in the past.  Is this
     intentional?


  Checking references for intended status: Proposed Standard
  -------------------------------------------------------------------------=
---

     (See RFCs 3967 and 4897 for information about using normative referenc=
es
     to lower-maturity documents in RFCs)

  =3D=3D Outdated reference: A later version (-03) exists of
     draft-ietf-curdle-gss-keyex-sha2-02

  =3D=3D Outdated reference: A later version (-06) exists of
     draft-ietf-curdle-ssh-curves-05

  =3D=3D Outdated reference: draft-ietf-curdle-ssh-dh-group-exchange has be=
en
     published as RFC 8270

  =3D=3D Outdated reference: draft-ietf-curdle-ssh-modp-dh-sha2 has been
     published as RFC 8268


     Summary: 0 errors (**), 0 flaws (~~), 4 warnings (=3D=3D), 2 comments =
(--).

     Run idnits with the --verbose option for more detailed information abo=
ut
     the items above.</pre></div><div><br></div></div></div></div>

--94eb2c1ce7a02119b70560b7e786--


From nobody Tue Dec 19 16:16:45 2017
Return-Path: <mglt.ietf@gmail.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16E8912D953 for <curdle@ietfa.amsl.com>; Tue, 19 Dec 2017 16:16:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level: 
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lsu5QlR6-DWw for <curdle@ietfa.amsl.com>; Tue, 19 Dec 2017 16:16:38 -0800 (PST)
Received: from mail-lf0-x22f.google.com (mail-lf0-x22f.google.com [IPv6:2a00:1450:4010:c07::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C6B62126B7F for <curdle@ietf.org>; Tue, 19 Dec 2017 16:16:37 -0800 (PST)
Received: by mail-lf0-x22f.google.com with SMTP id y78so16431370lfd.1 for <curdle@ietf.org>; Tue, 19 Dec 2017 16:16:37 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:sender:from:date:message-id:subject:to; bh=n5Far1u9ebN+Q3GShi2vqDfqBsRk1KKSFwpkcEvhjis=; b=n35Nxf6Vu82VKqrT0kb/vB2kxi/q8f3GUxxYxIBaiUtANQeeSXfQ9s9Uyh2KfGA9H3 hxXvttGEFWCVlylHCKTQeZXZhaM+ilz7WlAd2h7WJ0jI1xyNSZJQFFWCYX+Bp9t9UqHo iRG5of2Lg8uxFoRLAtTIg3Ud3A8F5SYy034vc4EIBcD+TtaJ9jcHTrGZ0U1VurkCLKTY wyyjlqQemH4cktVYHwXKol9JxrbqeydBOAchSV3sB+yiSajLbVe3lYlvgwtLH8KkP/Tu YMQBeCEg7nhbtqsGt3Lno7Mtgoh2fAiNYOAZR0m3R8dUHxqUbkdmbSR1BNWp3WD+mY5l gcPQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:from:date:message-id:subject :to; bh=n5Far1u9ebN+Q3GShi2vqDfqBsRk1KKSFwpkcEvhjis=; b=DLcaI8H9nxCYx4M5xYQC+7bKGZiKtxH+ISaXmGvHdTW2200datBjSpwOzZH28/kmwa ED4mWw1mAxeg8dhOL402BoqGIJ5fM7xmwv2r3X8EyxEu0xd3SwGLaLTjDpyNc+I5qsUc 6cATjWSrpNN7UMyilA4Er2OkGR95m7ZiMNCN/G3SB3O5g43fiE8+LB++IVg5nUU47lOi qaLR9gQ0cNXPtZiwyNqBabAHE3HVSf/nbqfNkbX/MQua0kBTesG9ccQaD6uo7oTOoK4H L+yfa3izXGKQmy1d0NylL5lgF1+Hn2oB3uBf/tZwxacuQAYIHX2w20y0iy/NFbVbFcNs iquQ==
X-Gm-Message-State: AKGB3mKk5gIQZ/a6pFkXD7xZ8FUb21DMOsul/UPDUQtNL3+f4F/2fy3u 24zz3kq1cX6Y7mDedhOTWiPVaRFQ2+W45skwh7ktPA==
X-Google-Smtp-Source: ACJfBouhNqS7JT2xyPNY+l7CBuBbHqRNBsQd8Lq9WumyxNtPGmYxXNIekL4UU/cMk7ZMeaFEwLoVGJU6ncedPbbq+F0=
X-Received: by 10.25.80.93 with SMTP id z29mr1916008lfj.9.1513728995825; Tue, 19 Dec 2017 16:16:35 -0800 (PST)
MIME-Version: 1.0
Sender: mglt.ietf@gmail.com
Received: by 10.46.80.17 with HTTP; Tue, 19 Dec 2017 16:16:35 -0800 (PST)
From: Daniel Migault <daniel.migault@ericsson.com>
Date: Tue, 19 Dec 2017 19:16:35 -0500
X-Google-Sender-Auth: D9JnB8gAj_D4KKLYtovHT8NRUnk
Message-ID: <CADZyTkkB_QjzM=Cc_FOhugJfbRva39RZVKn5dzm7nOkZYxy-5w@mail.gmail.com>
To: curdle <curdle@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c1cd624151bbf0560ba7f4d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/NKckfz2tLf_Op0EJGQXJphDmga0>
Subject: [Curdle] comments on draft-ietf-curdle-gss-keyex-sha2-03
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 00:16:41 -0000

--94eb2c1cd624151bbf0560ba7f4d
Content-Type: text/plain; charset="UTF-8"

Hi,

Please find my review for draft-ietf-curdle-gss-keyex-sha2-03 [1].

The corresponding shepherd write-up can be found here[2]. Feel free to
comment as well.


[1] https://tools.ietf.org/html/draft-ietf-curdle-gss-keyex-sha2-03
[2]
https://datatracker.ietf.org/doc/draft-ietf-curdle-gss-keyex-sha2/shepherdwriteup/

section 4, 5.2

I believe that "RECOMMENDED" and "OPTIONAL" can be removed and are
redundant with SHOULD / MAY.

References:

[FIPS-180-4] is referenced, but not mentioned in the text.

'NIST-SP-800-131Ar1' should be moved as informative references
in my opinion. The reference is provided to justify the rational,
not to describe the protocol.

ISO-IEC-8825-1 is a reference for ASN1. It seems to me that
informational is the right place.

[I-D.ietf-curdle-ssh-modp-dh-sha2] is now an RFC, I believe it
should be an informational document rather than a normative
document as it is only cited as an example to move from SHA1 to sha2.

RFC6194]  Polk, T., Chen, L., Turner, S., and P. Hoffman, "Security
Considerations for the SHA-0 and SHA-1 Message-Digest Algorithms"
should be in my opinion an informational reference.

It would be good to add a link to the IANA in the IANA section
registry and have it as an informational reference.

The draft mentions the SSH algorithm registry, but I am not
sure that is the correct registry. instead, the Key Exchange
Method Names registry might be more appropriated.


here is the output of the nits:

idnits 2.15.00

tmp/draft-ietf-curdle-gss-keyex-sha2-03.txt:

  Checking boilerplate required by RFC 5378 and the IETF Trust (see
  https://trustee.ietf.org/license-info):
  ----------------------------------------------------------------------------

     No issues found here.

  Checking nits according to https://www.ietf.org/id-info/1id-guidelines.txt:
  ----------------------------------------------------------------------------

     No issues found here.

  Checking nits according to https://www.ietf.org/id-info/checklist :
  ----------------------------------------------------------------------------

  ** The abstract seems to contain references ([RFC4462]), which it
     shouldn't.  Please replace those with straight textual mentions of the
     documents in question.

  -- The draft header indicates that this document updates RFC4462, but the
     abstract doesn't seem to directly say this.  It does mention RFC4462
     though, so this could be OK.


  Miscellaneous warnings:
  ----------------------------------------------------------------------------

  == Line 412 has weird spacing: '... string    out...'

  == Line 418 has weird spacing: '... string    ser...'

  == Line 430 has weird spacing: '... string    out...'

  == Line 443 has weird spacing: '... string    out...'

  == Line 457 has weird spacing: '... string    mic...'

  == (2 more instances...)

     (Using the creation date from RFC4462, updated by this document, for
     RFC5378 checks: 2005-08-23)

  -- The document seems to lack a disclaimer for pre-RFC5378 work, but may
     have content which was first submitted before 10 November 2008.  If you
     have contacted all the original authors and they are all willing to grant
     the BCP78 rights to the IETF Trust, then this is fine, and you can ignore
     this comment.  If not, you may need to add the pre-RFC5378 disclaimer.
     (See the Legal Provisions document at
     https://trustee.ietf.org/license-info for more information.)

  -- The document date (December 12, 2017) is 7 days in the past.  Is this
     intentional?


  Checking references for intended status: Proposed Standard
  ----------------------------------------------------------------------------

     (See RFCs 3967 and 4897 for information about using normative references
     to lower-maturity documents in RFCs)

  == Unused Reference: 'FIPS-180-4' is defined on line 637, but no explicit
     reference was found in the text

  -- Possible downref: Non-RFC (?) normative reference: ref. 'ANSI-X9-62-2005'

  -- Possible downref: Non-RFC (?) normative reference: ref. 'FIPS-180-4'

  == Outdated reference: A later version (-06) exists of
     draft-ietf-curdle-ssh-curves-04

  == Outdated reference: draft-ietf-curdle-ssh-modp-dh-sha2 has been
     published as RFC 8268

  -- Possible downref: Non-RFC (?) normative reference: ref. 'ISO-IEC-8825-1'

  -- Possible downref: Non-RFC (?) normative reference: ref.
     'NIST-SP-800-131Ar1'

  ** Downref: Normative reference to an Informational RFC: RFC 1321

  ** Downref: Normative reference to an Informational RFC: RFC 6194

  ** Downref: Normative reference to an Informational RFC: RFC 7546

  ** Downref: Normative reference to an Informational RFC: RFC 7748

  -- Possible downref: Non-RFC (?) normative reference: ref. 'SEC2v2'


     Summary: 5 errors (**), 0 flaws (~~), 9 warnings (==), 8 comments (--).

     Run idnits with the --verbose option for more detailed information about
     the items above.

--94eb2c1cd624151bbf0560ba7f4d
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div>Hi, <br></div><div><br></div><div>Please fi=
nd my review for draft-ietf-curdle-gss-keyex-sha2-03 [1]. <br></div><div><b=
r></div><div>The corresponding shepherd write-up can be found here[2]. Feel=
 free to comment as well. <br></div><div><br></div><div><br></div><div>[1] =
<a href=3D"https://tools.ietf.org/html/draft-ietf-curdle-gss-keyex-sha2-03"=
>https://tools.ietf.org/html/draft-ietf-curdle-gss-keyex-sha2-03</a></div><=
div>[2] <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-curdle-gss-k=
eyex-sha2/shepherdwriteup/">https://datatracker.ietf.org/doc/draft-ietf-cur=
dle-gss-keyex-sha2/shepherdwriteup/</a></div><div><font size=3D"1"><span st=
yle=3D"font-family:arial,helvetica,sans-serif"><span class=3D"gmail-h1"></s=
pan></span></font><span class=3D"gmail-h1"></span><br></div><div>section 4,=
 5.2<br><br></div>I believe that &quot;RECOMMENDED&quot; and &quot;OPTIONAL=
&quot; can be removed and are redundant with SHOULD / MAY. <br></div><br></=
div>References:<br><br><div><pre class=3D"gmail-newpage">[<a name=3D"ref-FI=
PS-180-4" id=3D"gmail-ref-FIPS-180-4">FIPS-180-4</a>] is referenced, but no=
t mentioned in the text. <br><br>&#39;NIST-SP-800-131Ar1&#39; should be mov=
ed as informative references <br>in my opinion. The reference is provided t=
o justify the rational,<br>not to describe the protocol. <br></pre><pre cla=
ss=3D"gmail-newpage">ISO-IEC-8825-1 is a reference for ASN1. It seems to me=
 that <br>informational is the right place. <br><br>[I-D.ietf-curdle-ssh-mo=
dp-dh-sha2] is now an RFC, I believe it <br>should be an informational docu=
ment rather than a normative <br>document as it is only cited as an example=
 to move from SHA1 to sha2.<br><br><a name=3D"ref-RFC6194" id=3D"gmail-ref-=
RFC6194">RFC6194</a>]  Polk, T., Chen, L., Turner, S., and P. Hoffman, &quo=
t;Security
Considerations for the SHA-0 and SHA-1 Message-Digest Algorithms&quot; <br>=
should be in my opinion an informational reference. <br><br></pre><pre clas=
s=3D"gmail-newpage">It would be good to add a link to the IANA in the IANA =
section <br>registry and have it as an informational reference. <br></pre><=
pre class=3D"gmail-newpage">The draft mentions the SSH algorithm registry, =
but I am not <br>sure that is the correct registry. instead, the Key Exchan=
ge <br>Method Names registry might be more appropriated. <br></pre><pre cla=
ss=3D"gmail-newpage"><br></pre><pre class=3D"gmail-newpage">here is the out=
put of the nits:<br><br>idnits 2.15.00=20

tmp/draft-ietf-curdle-gss-keyex-sha2-03.txt:

  Checking boilerplate required by RFC 5378 and the IETF Trust (see
  <a href=3D"https://trustee.ietf.org/license-info">https://trustee.ietf.or=
g/license-info</a>):
  -------------------------------------------------------------------------=
---

     No issues found here.

  Checking nits according to <a href=3D"https://www.ietf.org/id-info/1id-gu=
idelines.txt">https://www.ietf.org/id-info/1id-guidelines.txt</a>:
  -------------------------------------------------------------------------=
---

     No issues found here.

  Checking nits according to <a href=3D"https://www.ietf.org/id-info/checkl=
ist">https://www.ietf.org/id-info/checklist</a> :
  -------------------------------------------------------------------------=
---

  ** The abstract seems to contain references ([RFC4462]), which it
     shouldn&#39;t.  Please replace those with straight textual mentions of=
 the
     documents in question.

  -- The draft header indicates that this document updates RFC4462, but the
     abstract doesn&#39;t seem to directly say this.  It does mention RFC44=
62
     though, so this could be OK.


  Miscellaneous warnings:
  -------------------------------------------------------------------------=
---

  =3D=3D Line 412 has weird spacing: &#39;... string    out...&#39;

  =3D=3D Line 418 has weird spacing: &#39;... string    ser...&#39;

  =3D=3D Line 430 has weird spacing: &#39;... string    out...&#39;

  =3D=3D Line 443 has weird spacing: &#39;... string    out...&#39;

  =3D=3D Line 457 has weird spacing: &#39;... string    mic...&#39;

  =3D=3D (2 more instances...)

     (Using the creation date from RFC4462, updated by this document, for
     RFC5378 checks: 2005-08-23)

  -- The document seems to lack a disclaimer for pre-RFC5378 work, but may
     have content which was first submitted before 10 November 2008.  If yo=
u
     have contacted all the original authors and they are all willing to gr=
ant
     the BCP78 rights to the IETF Trust, then this is fine, and you can ign=
ore
     this comment.  If not, you may need to add the pre-RFC5378 disclaimer.=
=20
     (See the Legal Provisions document at
     <a href=3D"https://trustee.ietf.org/license-info">https://trustee.ietf=
.org/license-info</a> for more information.)

  -- The document date (December 12, 2017) is 7 days in the past.  Is this
     intentional?


  Checking references for intended status: Proposed Standard
  -------------------------------------------------------------------------=
---

     (See RFCs 3967 and 4897 for information about using normative referenc=
es
     to lower-maturity documents in RFCs)

  =3D=3D Unused Reference: &#39;FIPS-180-4&#39; is defined on line 637, but=
 no explicit
     reference was found in the text

  -- Possible downref: Non-RFC (?) normative reference: ref. &#39;ANSI-X9-6=
2-2005&#39;

  -- Possible downref: Non-RFC (?) normative reference: ref. &#39;FIPS-180-=
4&#39;

  =3D=3D Outdated reference: A later version (-06) exists of
     draft-ietf-curdle-ssh-curves-04

  =3D=3D Outdated reference: draft-ietf-curdle-ssh-modp-dh-sha2 has been
     published as RFC 8268

  -- Possible downref: Non-RFC (?) normative reference: ref. &#39;ISO-IEC-8=
825-1&#39;

  -- Possible downref: Non-RFC (?) normative reference: ref.
     &#39;NIST-SP-800-131Ar1&#39;

  ** Downref: Normative reference to an Informational RFC: RFC 1321

  ** Downref: Normative reference to an Informational RFC: RFC 6194

  ** Downref: Normative reference to an Informational RFC: RFC 7546

  ** Downref: Normative reference to an Informational RFC: RFC 7748

  -- Possible downref: Non-RFC (?) normative reference: ref. &#39;SEC2v2&#3=
9;


     Summary: 5 errors (**), 0 flaws (~~), 9 warnings (=3D=3D), 8 comments =
(--).

     Run idnits with the --verbose option for more detailed information abo=
ut
     the items above.
=C2=A0<a name=3D"ref-I-D.ietf-curdle-ssh-modp-dh-sha2" id=3D"gmail-ref-I-D.=
ietf-curdle-ssh-modp-dh-sha2"></a></pre></div></div>

--94eb2c1cd624151bbf0560ba7f4d--

