From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 01 12:12:55 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DoO8M-00048y-W2
	for secsh-archive@megatron.ietf.org; Fri, 01 Jul 2005 12:12:55 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11021
	for <secsh-archive@odin.ietf.org>; Fri, 1 Jul 2005 12:12:51 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 665183A409; Fri,  1 Jul 2005 16:12:48 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from vandyke.com (mail.vandyke.com [204.134.9.1])
	by mail.netbsd.org (Postfix) with ESMTP id E0F1C3A406
	for <ietf-ssh@netbsd.org>; Fri,  1 Jul 2005 16:12:45 +0000 (UTC)
Received: from [127.0.0.1] (HELO [0.0.0.0])
  by vandyke.com (CommuniGate Pro SMTP 3.4.7)
  with ESMTP id 7623514; Fri, 01 Jul 2005 10:12:44 -0600
Message-ID: <42C56CAF.2070204@vandyke.com>
Date: Fri, 01 Jul 2005 10:17:51 -0600
From: Joseph Galbraith <galb-list@vandyke.com>
User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Sara Golemon <ietf-secsh@libssh2.org>
Cc: ietf-ssh@NetBSD.org
Subject: Re: draft-ietf-secsh-filexfer  Change to rename op in version 5
References: <00a501c5736d$623ecec0$5c8be5a9@ohr.berkeley.edu>
In-Reply-To: <00a501c5736d$623ecec0$5c8be5a9@ohr.berkeley.edu>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

Sara Golemon wrote:
> I got tripped up by some vague wording in the changelog covering differences
> between version 4 and version 5, specifically:
> 
>  o  Add support for better control of the rename operation.
> 
> 
> After looking through implementation sources, I found that this refers to
> the addition of the flags parameter to FXP_RENAME.
> 
>        byte   SSH_FXP_RENAME
>        uint32 request-id
>        string oldpath [UTF-8]
>        string newpath [UTF-8]
>        uint32 flags
> 
> To avoid others being confused by this I'd like to propose a change to the
> changelog entry's wording:
> 
>  o  Add flags parameter to the rename operation to control rename behavior.

I'll make this change...

Thanks,

Joseph



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 01 12:15:41 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DoOB3-0004mW-JQ
	for secsh-archive@megatron.ietf.org; Fri, 01 Jul 2005 12:15:41 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11420
	for <secsh-archive@odin.ietf.org>; Fri, 1 Jul 2005 12:15:38 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 181433A44F; Fri,  1 Jul 2005 16:15:38 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from vandyke.com (mail.vandyke.com [204.134.9.1])
	by mail.netbsd.org (Postfix) with ESMTP id 739823A3B4
	for <ietf-ssh@netbsd.org>; Fri,  1 Jul 2005 16:15:36 +0000 (UTC)
Received: from [127.0.0.1] (HELO [0.0.0.0])
  by vandyke.com (CommuniGate Pro SMTP 3.4.7)
  with ESMTP id 7623525 for ietf-ssh@netbsd.org; Fri, 01 Jul 2005 10:15:35 -0600
Message-ID: <42C56D5A.8000602@vandyke.com>
Date: Fri, 01 Jul 2005 10:20:42 -0600
From: Joseph Galbraith <galb-list@vandyke.com>
User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "ietf-ssh@netbsd.org" <ietf-ssh@NetBSD.org>
Subject: SFTP status...
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

I believe I have all outstanding issues taken care of in the
sftp draft ...

(I have to refind the issue tracker info so I can check that,
and close resolved issues.)

There probably remains a lot of 'syntatical' work that needs
to be done... I know it needs to be run through a spell checker
(I am the world's worst speller.)

So if anyone knows of some thing that needs to be done, now
is the time to pipe up and say "here!"

Thanks,

Joseph



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sat Jul 02 05:43:19 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DoeWs-0001qL-N0
	for secsh-archive@megatron.ietf.org; Sat, 02 Jul 2005 05:43:18 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA26511
	for <secsh-archive@odin.ietf.org>; Sat, 2 Jul 2005 05:43:15 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 0386D3A3C7; Sat,  2 Jul 2005 09:43:11 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from blaster.systems.pipex.net (blaster.systems.pipex.net [62.241.163.7])
	by mail.netbsd.org (Postfix) with ESMTP id 350643A3A9
	for <ietf-ssh@netbsd.org>; Sat,  2 Jul 2005 09:43:09 +0000 (UTC)
Received: from pc6 (1Cust235.tnt105.lnd4.gbr.da.uu.net [213.116.58.235])
	by blaster.systems.pipex.net (Postfix) with SMTP id D6B72E0000C5
	for <ietf-ssh@netbsd.org>; Sat,  2 Jul 2005 10:13:29 +0100 (BST)
Message-ID: <00f601c57edd$df4d8980$0601a8c0@pc6>
Reply-To: "Tom Petch" <nwnetworks@dial.pipex.com>
From: "Tom Petch" <nwnetworks@dial.pipex.com>
To: <ietf-ssh@NetBSD.org>
References: <tsloea8hlip.fsf@cz.mit.edu>
Subject: 'DSSH'
Date: Sat, 2 Jul 2005 10:12:07 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

Has anyone ever looked at the possibility of a DSSH comparable to a DTLS, ie
adding a shim layer to enable SSH to work over an unreliable transport, such as
UDP?

Tom Petch

ps If you are familiar with the isms list, you will know where this query comes
from:-)




From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 07 07:33:15 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DqUd1-0000lo-Ow
	for secsh-archive@megatron.ietf.org; Thu, 07 Jul 2005 07:33:15 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA26004
	for <secsh-archive@odin.ietf.org>; Thu, 7 Jul 2005 07:33:13 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 2326A3A3DB; Thu,  7 Jul 2005 11:33:06 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from ppsw-9.csi.cam.ac.uk (ppsw-9.csi.cam.ac.uk [131.111.8.139])
	by mail.netbsd.org (Postfix) with ESMTP id EA2A73A3A9
	for <ietf-ssh@netbsd.org>; Thu,  7 Jul 2005 11:33:03 +0000 (UTC)
X-Cam-SpamDetails: Not scanned
X-Cam-AntiVirus: No virus found
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from draco.cus.cam.ac.uk ([131.111.8.18]:47127)
	by ppsw-9.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.139]:25)
	with esmtp id 1DqUcn-0004e8-V9 (Exim 4.51) for ietf-ssh@netbsd.org
	(return-path <bjh21@cus.cam.ac.uk>); Thu, 07 Jul 2005 12:33:01 +0100
Received: from bjh21 (helo=localhost)
	by draco.cus.cam.ac.uk with local-esmtp (Exim 4.52)
	id 1DqUcn-0000u5-Gz
	for ietf-ssh@netbsd.org; Thu, 07 Jul 2005 12:33:01 +0100
Date: Thu, 7 Jul 2005 12:33:01 +0100 (BST)
From: Ben Harris <bjh21@bjh21.me.uk>
To: ietf-ssh@NetBSD.org
Subject: draft-harris-ssh-rsa-kex-02 and a possible future change
Message-ID: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

I've uploaded a new version of my RSA KEX draft. 
<http://www.ietf.org/internet-drafts/draft-harris-ssh-rsa-kex-02.txt>

Notable changes are:

1: Using SHA-512 in place of SHA-256.  This is largely because I've got
    the impression that -dh-group-exchange is heading in the direction of
    using SHA-512, and it seems silly to require implementations to support
    both SHA-256 and SHA-512.  Plus of course it gives us headroom in case
    decent collision attacks are found against the higher SHAs.

2: Including the encrypted secret in the data hashed to generate the
    exchange hash.  This should make it much harder for a client to
    generate hash collisions, since they'd need to generate K such that K
    and its RSA encryption between them generate a collision.  I conjecture
    that for reasonable RSA key sizes this is infeasible.

I don't imagine that either of these will be controversial.

I'd like to make another change, to move the transmission of K_S, the 
server's host key, from SSH_MSG_KEXRSA_DONE to SSH_MSG_KEXRSA_PUBKEY.  The 
reason for this would be to ensure that even if the server can change its 
key (which I can imagine being possible for some kinds of certificate), it 
can't use this to mount a collision attack on the exchange hash because it 
doesn't know what secret the client is going to send.  While this is 
rather different from the way the current KEX methods work, I can't 
imagine it being any more difficult for server implementations.  Would any 
client imeplementors find it a problem?

-- 
Ben Harris



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 07 10:57:51 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DqXoz-0007PO-HW
	for secsh-archive@megatron.ietf.org; Thu, 07 Jul 2005 10:57:51 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA14963
	for <secsh-archive@odin.ietf.org>; Thu, 7 Jul 2005 10:57:46 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 8B79E3A660; Thu,  7 Jul 2005 14:57:42 +0000 (UTC)
X-Original-To: ietf-ssh@NetBSD.org
Delivered-To: ietf-ssh@NetBSD.org
Received: from Sparkle.Rodents.Montreal.QC.CA (Sparkle.Rodents.Montreal.QC.CA [216.46.5.7])
	by mail.netbsd.org (Postfix) with ESMTP id C38603A39D
	for <ietf-ssh@NetBSD.org>; Thu,  7 Jul 2005 14:57:39 +0000 (UTC)
Received: (from mouse@localhost)
	by Sparkle.Rodents.Montreal.QC.CA (8.8.8/8.8.8) id KAA01707;
	Thu, 7 Jul 2005 10:57:33 -0400 (EDT)
From: der Mouse <mouse@Rodents.Montreal.QC.CA>
Message-Id: <200507071457.KAA01707@Sparkle.Rodents.Montreal.QC.CA>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the zombie armies.
Date: Thu, 7 Jul 2005 10:45:45 -0400 (EDT)
To: ietf-ssh@NetBSD.org
Subject: Re: draft-harris-ssh-rsa-kex-02 and a possible future change
In-Reply-To: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk>
References: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk>
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 8bit

> I've uploaded a new version of my RSA KEX draft. 
> <http://www.ietf.org/internet-drafts/draft-harris-ssh-rsa-kex-02.txt>

> 1: Using SHA-512 in place of SHA-256.

I'm not sure I like this.  SHA-256 is reasonably good for 32-bit
machines; SHA-512 (and SHA-384) are basically 64-bit algorithms,
calling for eight 64-bit temporaries in their core loops.

I think this change will disproportionately hurt exactly those machines
where your kex is most beneficial - old, slow, half-lung machines,
which are usually 32-bit.

>    Plus of course it gives us headroom in case decent collision
>    attacks are found against the higher SHAs.

True, though I'd prefer to address this by defining variants using
block-cipher-based hash functions.

> 2: Including the encrypted secret in the data hashed to generate the
>    exchange hash.

My reaction here is basically "shrug".  I don't really see the hazard
in the client managing to generate two sessions with the same exchange
hash in the first place.

> I'd like to make another change, to move the transmission of K_S, the
> server's host key, from SSH_MSG_KEXRSA_DONE to SSH_MSG_KEXRSA_PUBKEY.
> [...].  Would any client imeplementors find it a problem?

Tentatively, I wouldn't.  I'll have to look at my code, though, and
make sure I do indeed have (or can easily arrange to have) the host key
at hand at that point.

/~\ The ASCII				der Mouse
\ / Ribbon Campaign
 X  Against HTML	       mouse@rodents.montreal.qc.ca
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 07 14:34:47 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DqbCx-0005Wv-0a
	for secsh-archive@megatron.ietf.org; Thu, 07 Jul 2005 14:34:47 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA05102
	for <secsh-archive@odin.ietf.org>; Thu, 7 Jul 2005 14:34:44 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 0CBC83A3B5; Thu,  7 Jul 2005 18:34:36 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from chiark.greenend.org.uk (chiark.greenend.org.uk [193.201.200.170])
	by mail.netbsd.org (Postfix) with ESMTP id E90CB3A394
	for <ietf-ssh@netbsd.org>; Thu,  7 Jul 2005 18:34:33 +0000 (UTC)
Received: by chiark.greenend.org.uk (Debian Exim 3.35 #1) with local
	(return-path bjharris@chiark.greenend.org.uk)
	id 1DqbCi-0002Mi-00; Thu, 07 Jul 2005 19:34:32 +0100
From: Ben Harris <bjh21@bjh21.me.uk>
To: mouse@Rodents.Montreal.QC.CA, ietf-ssh@NetBSD.org
Subject: Re: draft-harris-ssh-rsa-kex-02 and a possible future change
In-Reply-To: <200507071457.KAA01707@Sparkle.Rodents.Montreal.QC.CA>
References: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk> <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk> <200507071457.KAA01707@Sparkle.Rodents.Montreal.QC.CA>
Organization: Linux Unlimited
Message-Id: <E1DqbCi-0002Mi-00@chiark.greenend.org.uk>
Date: Thu, 07 Jul 2005 19:34:32 +0100
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

In article <200507071457.KAA01707@Sparkle.Rodents.Montreal.QC.CA> you write:
>> I've uploaded a new version of my RSA KEX draft. 
>> <http://www.ietf.org/internet-drafts/draft-harris-ssh-rsa-kex-02.txt>
>
>> 1: Using SHA-512 in place of SHA-256.
>
>I'm not sure I like this.  SHA-256 is reasonably good for 32-bit
>machines; SHA-512 (and SHA-384) are basically 64-bit algorithms,
>calling for eight 64-bit temporaries in their core loops.
>
>I think this change will disproportionately hurt exactly those machines
>where your kex is most beneficial - old, slow, half-lung machines,
>which are usually 32-bit.

You're right.  On a convenient slow machine (50MHzish ARM7500FE), a 2048-bit
RSA public operation takes about 1/3s and a 1024-byte SHA-512 takes about
1/2s.  I haven't got a convenient SHA-256 implementation, but looking at the
spec it's a lot friendlier to small systems.  I'll reverse that change.

>> 2: Including the encrypted secret in the data hashed to generate the
>>    exchange hash.
>
>My reaction here is basically "shrug".  I don't really see the hazard
>in the client managing to generate two sessions with the same exchange
>hash in the first place.

I don't think there's a hazard there, but there is one if the client gets to
co-operate with (or be) a server using a KEX method that lets the server
choose the last input to the hash.  Such a KEX method would be approximately
as sane as rsa1024-sha1-draft-01, so I can't safely assume that no-one will
ever deploy one.  Indeed, I suspect that the currently-defined KEX methods
might qualify depending on the host key formats in use.

-- 
Ben Harris



From ietf-bounces@ietf.org Thu Jul 07 16:16:48 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dqcng-0007Jt-54; Thu, 07 Jul 2005 16:16:48 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1Dqcnd-0007JO-FE
	for ietf@megatron.ietf.org; Thu, 07 Jul 2005 16:16:45 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA21245
	for <ietf@ietf.org>; Thu, 7 Jul 2005 16:16:42 -0400 (EDT)
Received: from ppsw-0.csi.cam.ac.uk ([131.111.8.130])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1DqdEr-00010i-Hu
	for ietf@ietf.org; Thu, 07 Jul 2005 16:44:54 -0400
X-Cam-SpamDetails: Not scanned
X-Cam-AntiVirus: No virus found
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from virgo.cus.cam.ac.uk ([131.111.8.20]:36693)
	by ppsw-0.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.130]:25)
	with esmtp id 1DqcnU-0007OU-2n (Exim 4.51) for ietf@ietf.org
	(return-path <bjh21@cus.cam.ac.uk>); Thu, 07 Jul 2005 21:16:36 +0100
Received: from bjh21 (helo=localhost)
	by virgo.cus.cam.ac.uk with local-esmtp (Exim 4.52)
	id 1DqcnT-000510-Uq; Thu, 07 Jul 2005 21:16:35 +0100
Date: Thu, 7 Jul 2005 21:16:35 +0100 (BST)
From: Ben Harris <bjh21@bjh21.me.uk>
To: Sam Hartman <hartmans-ietf@mit.edu>
In-Reply-To: <tslmzp9b4uk.fsf@cz.mit.edu>
Message-ID: <Pine.SOC.4.61.0507072110000.14642@virgo.cus.cam.ac.uk>
References: <tslmzp9b4uk.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
X-Spam-Score: 0.9 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab
Cc: ietf-ssh@netbsd.org, ietf@ietf.org
Subject: Re: Resolution of last call comments for
	draft-harris-ssh-arcfour-fixes-02.txt
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>,
	<mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>,
	<mailto:ietf-request@ietf.org?subject=subscribe>
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org

On Wed, 29 Jun 2005, Sam Hartman wrote:

> Please add an applicability statement discussing the performance
> advantages of RC4 against the known security weaknesses.  You may end
> up reusing text from your security considerations text.  Your
> applicability statement needs to suggest to the reader that they
> consider the ssh newmodes draft as an alternative to your rc4 ciphers.
> This alternative should be chosen in environments where the advantages
> of RC4 do not make it attractive.

I've done this and sent draft-harris-ssh-arcfour-fixes-03.txt to be 
posted.

> In addition, I'm still waiting to hear back from you on the questions
> raised in the security directorate review.  While these points are
> minor, they should be addressed.

I've replied to them, removed my dodgy information theory and referenced 
the relevant recent papers.

-- 
Ben Harris

_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf

From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 07 16:16:53 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dqcnl-0007LY-0W
	for secsh-archive@megatron.ietf.org; Thu, 07 Jul 2005 16:16:53 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA21325
	for <secsh-archive@odin.ietf.org>; Thu, 7 Jul 2005 16:16:50 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id EC97A3A6F4; Thu,  7 Jul 2005 20:16:43 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from ppsw-0.csi.cam.ac.uk (ppsw-0.csi.cam.ac.uk [131.111.8.130])
	by mail.netbsd.org (Postfix) with ESMTP id C96093A394
	for <ietf-ssh@netbsd.org>; Thu,  7 Jul 2005 20:16:41 +0000 (UTC)
X-Cam-SpamDetails: Not scanned
X-Cam-AntiVirus: No virus found
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from virgo.cus.cam.ac.uk ([131.111.8.20]:36694)
	by ppsw-0.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.130]:25)
	with esmtp id 1DqcnU-0007OX-2o (Exim 4.51) for ietf-ssh@netbsd.org
	(return-path <bjh21@cus.cam.ac.uk>); Thu, 07 Jul 2005 21:16:36 +0100
Received: from bjh21 (helo=localhost)
	by virgo.cus.cam.ac.uk with local-esmtp (Exim 4.52)
	id 1DqcnT-000510-Uq; Thu, 07 Jul 2005 21:16:35 +0100
Date: Thu, 7 Jul 2005 21:16:35 +0100 (BST)
From: Ben Harris <bjh21@bjh21.me.uk>
To: Sam Hartman <hartmans-ietf@mit.edu>
Cc: ietf@ietf.org, ietf-ssh@NetBSD.org
Subject: Re: Resolution of last call comments  for draft-harris-ssh-arcfour-fixes-02.txt
In-Reply-To: <tslmzp9b4uk.fsf@cz.mit.edu>
Message-ID: <Pine.SOC.4.61.0507072110000.14642@virgo.cus.cam.ac.uk>
References: <tslmzp9b4uk.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

On Wed, 29 Jun 2005, Sam Hartman wrote:

> Please add an applicability statement discussing the performance
> advantages of RC4 against the known security weaknesses.  You may end
> up reusing text from your security considerations text.  Your
> applicability statement needs to suggest to the reader that they
> consider the ssh newmodes draft as an alternative to your rc4 ciphers.
> This alternative should be chosen in environments where the advantages
> of RC4 do not make it attractive.

I've done this and sent draft-harris-ssh-arcfour-fixes-03.txt to be 
posted.

> In addition, I'm still waiting to hear back from you on the questions
> raised in the security directorate review.  While these points are
> minor, they should be addressed.

I've replied to them, removed my dodgy information theory and referenced 
the relevant recent papers.

-- 
Ben Harris





From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 07 21:52:46 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dqi2l-0004aY-GG
	for secsh-archive@megatron.ietf.org; Thu, 07 Jul 2005 21:52:46 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA25121
	for <secsh-archive@odin.ietf.org>; Thu, 7 Jul 2005 21:52:40 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 1B2003A3C4; Fri,  8 Jul 2005 01:52:34 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from smtpa.itss.auckland.ac.nz (mailhost.auckland.ac.nz [130.216.190.11])
	by mail.netbsd.org (Postfix) with ESMTP id 0B5403A3BC
	for <ietf-ssh@netbsd.org>; Fri,  8 Jul 2005 01:52:32 +0000 (UTC)
Received: from localhost (smtpa.itss.auckland.ac.nz [127.0.0.1])
	by smtpa.itss.auckland.ac.nz (Postfix) with ESMTP id 2985634CE8;
	Fri,  8 Jul 2005 13:32:09 +1200 (NZST)
Received: from smtpa.itss.auckland.ac.nz ([127.0.0.1])
 by localhost (smtpa.itss.auckland.ac.nz [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 27047-20; Fri,  8 Jul 2005 13:32:09 +1200 (NZST)
Received: from iris.cs.auckland.ac.nz (iris.cs.auckland.ac.nz [130.216.33.152])
	by smtpa.itss.auckland.ac.nz (Postfix) with ESMTP id 148F833F1C;
	Fri,  8 Jul 2005 13:32:08 +1200 (NZST)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33])
	by iris.cs.auckland.ac.nz (Postfix) with ESMTP
	id 7CF6137743; Fri,  8 Jul 2005 13:32:08 +1200 (NZST)
Received: from pgut001 by medusa01.cs.auckland.ac.nz with local (Exim 3.36 #1 (Debian))
	id 1Dqhit-0005Jk-00; Fri, 08 Jul 2005 13:32:11 +1200
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: bjh21@bjh21.me.uk, ietf-ssh@NetBSD.org
Subject: Re: draft-harris-ssh-rsa-kex-02 and a possible future change
In-Reply-To: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk>
Message-Id: <E1Dqhit-0005Jk-00@medusa01.cs.auckland.ac.nz>
Date: Fri, 08 Jul 2005 13:32:11 +1200
X-Virus-Scanned: by amavisd-new at mailhost.auckland.ac.nz
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

Ben Harris <bjh21@bjh21.me.uk> writes:

>I don't imagine that either of these will be controversial.

They are :-).  An SHA-2 discussion has just finished on the S/MIME list, where
the choice was MUST SHA-256, MAY the others.  The reason for this is that
SHA-512, being targeted at register-rich 64-bit CPUs, is horrible to implement
on the majority of current CPUs, which are neither register-rich (x86), nor
64-bit (any low-power embedded system).  In fact the hardware with 95% or
whatever of the market share (AMD/Intel x86) fails to meet both of these
requirements.

The other point is that there's no strong argument for -512 instead of -256.
The only reason for having it at all is to match large ECC and DLP field sizes
for DSA/ECC signatures, which is hardly a consideration in this case.

Peter.



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 08 07:30:47 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dqr49-00011Q-2h
	for secsh-archive@megatron.ietf.org; Fri, 08 Jul 2005 07:30:47 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA22478
	for <secsh-archive@odin.ietf.org>; Fri, 8 Jul 2005 07:30:43 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 9A8903A416; Fri,  8 Jul 2005 11:30:38 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from chiark.greenend.org.uk (chiark.greenend.org.uk [193.201.200.170])
	by mail.netbsd.org (Postfix) with ESMTP id D697D3A3AA
	for <ietf-ssh@netbsd.org>; Fri,  8 Jul 2005 11:30:36 +0000 (UTC)
Received: by chiark.greenend.org.uk (Debian Exim 3.35 #1) with local
	(return-path bjharris@chiark.greenend.org.uk)
	id 1Dqr3z-0000J5-00; Fri, 08 Jul 2005 12:30:35 +0100
From: Ben Harris <bjh21@bjh21.me.uk>
To: pgut001@cs.auckland.ac.nz, ietf-ssh@NetBSD.org
Subject: Re: draft-harris-ssh-rsa-kex-02 and a possible future change
In-Reply-To: <E1Dqhit-0005Jk-00@medusa01.cs.auckland.ac.nz>
References: <Pine.SOC.4.61.0507071206430.701@draco.cus.cam.ac.uk> <E1Dqhit-0005Jk-00@medusa01.cs.auckland.ac.nz>
Organization: Linux Unlimited
Message-Id: <E1Dqr3z-0000J5-00@chiark.greenend.org.uk>
Date: Fri, 08 Jul 2005 12:30:35 +0100
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

In article <E1Dqhit-0005Jk-00@medusa01.cs.auckland.ac.nz> you write:
>Ben Harris <bjh21@bjh21.me.uk> writes:
>
>>I don't imagine that either of these will be controversial.
>
>They are :-).

So I see.  Expect -03 on Monday.

-- 
Ben Harris



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sat Jul 09 08:05:36 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DrE5Q-0004CY-8y
	for secsh-archive@megatron.ietf.org; Sat, 09 Jul 2005 08:05:36 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA25792
	for <secsh-archive@odin.ietf.org>; Sat, 9 Jul 2005 08:05:34 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id D16AE3A486; Sat,  9 Jul 2005 12:05:25 +0000 (UTC)
X-Original-To: IETF-SSH@netbsd.org
Delivered-To: IETF-SSH@netbsd.org
Received: from atlrel8.hp.com (atlrel8.hp.com [156.153.255.206])
	by mail.netbsd.org (Postfix) with ESMTP id 4623E3A39F
	for <IETF-SSH@netbsd.org>; Sat,  9 Jul 2005 12:05:24 +0000 (UTC)
Received: from taynzmail03.nz-tay.cpqcorp.net (relay.wipro.tcpn.com [16.47.4.103])
	by atlrel8.hp.com (Postfix) with ESMTP id 70FA41954
	for <IETF-SSH@netbsd.org>; Sat,  9 Jul 2005 08:05:18 -0400 (EDT)
Received: from lassie.tcpip.zko.hp.com (unknown [16.116.92.100])
	by taynzmail03.nz-tay.cpqcorp.net (Postfix) with SMTP id 19D251FF0
	for <IETF-SSH@netbsd.org>; Sat,  9 Jul 2005 08:05:18 -0400 (EDT)
Date: Sat, 9 Jul 2005 07:56:10 -0400 (EDT)
Message-Id: <05070907561045_46E06578@vms.zko.hp.com>
From: Karol.Zielonko@hp.com (Karol Zielonko)
To: IETF-SSH@NetBSD.org
Subject: SSH Kerberos packet exchange
X-VMS-To: IETF-SSH@NETBSD.ORG
X-VMS-True-From: zielonko@vms.zko.hp.com (Karol Zielonko)
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

I am trying to get the Kerberos authentication code working in our VMS port of
SSH. (It is based on SSH Comm. Inc's version 3.2.0). I know next to nothing
about Kerberos (and only slightly more about ssh ;^). I'm looking for a draft
or RFC that specifies the packet exchange over SSH that implements Kerberos
authentication. Can anyone point me in the right direction?

Thanks in advance,

Karol Zielonko



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sat Jul 09 14:01:10 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DrJdW-00068H-3G
	for secsh-archive@megatron.ietf.org; Sat, 09 Jul 2005 14:01:10 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15084
	for <secsh-archive@odin.ietf.org>; Sat, 9 Jul 2005 14:01:08 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 9F9D63A4E9; Sat,  9 Jul 2005 18:01:01 +0000 (UTC)
X-Original-To: IETF-SSH@NetBSD.org
Delivered-To: IETF-SSH@NetBSD.org
Received: from nutty.inf.ed.ac.uk (nutty.inf.ed.ac.uk [129.215.216.3])
	by mail.netbsd.org (Postfix) with ESMTP id 847993A3D5
	for <IETF-SSH@NetBSD.org>; Sat,  9 Jul 2005 18:00:59 +0000 (UTC)
Received: from hadrian.inf.ed.ac.uk (hadrian.inf.ed.ac.uk [129.215.155.148])
	by nutty.inf.ed.ac.uk (8.12.8/8.12.8) with ESMTP id j69HNYkW030104;
	Sat, 9 Jul 2005 18:23:34 +0100
Received: from hadrian.inf.ed.ac.uk (localhost [127.0.0.1])
	by hadrian.inf.ed.ac.uk (8.12.8/8.12.8) with ESMTP id j69HNXg6030969;
	Sat, 9 Jul 2005 18:23:33 +0100
Received: from localhost (sxw@localhost)
	by hadrian.inf.ed.ac.uk (8.12.8/8.12.8/Submit) with ESMTP id j69HNXVB030965;
	Sat, 9 Jul 2005 18:23:33 +0100
X-Authentication-Warning: hadrian.inf.ed.ac.uk: sxw owned process doing -bs
Date: Sat, 9 Jul 2005 18:23:33 +0100 (BST)
From: sxw@inf.ed.ac.uk
To: Karol Zielonko <Karol.Zielonko@hp.com>
Cc: IETF-SSH@NetBSD.org
Subject: Re: SSH Kerberos packet exchange
In-Reply-To: <05070907561045_46E06578@vms.zko.hp.com>
Message-ID: <Pine.LNX.4.44.0507091821150.30790-100000@hadrian.inf.ed.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

On Sat, 9 Jul 2005, Karol Zielonko wrote:

> I am trying to get the Kerberos authentication code working in our VMS port of
> SSH. (It is based on SSH Comm. Inc's version 3.2.0). I know next to nothing
> about Kerberos (and only slightly more about ssh ;^). I'm looking for a draft
> or RFC that specifies the packet exchange over SSH that implements Kerberos
> authentication. Can anyone point me in the right direction?

http://www.ietf.org/internet-drafts/draft-ietf-secsh-gsskeyex-09.txt

Although, at one point, ssh.com did have their own Kerberos mechanism, 
named kerberos-2@ssh.com. I'm not sure whether they still use this, or 
now use the GSSAPI mechansism described above. kerberos-2 was never 
standardised, and I'm not sure if its documented anywhere.

Cheers,

Simon.





From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sun Jul 10 15:49:15 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Drhnd-0000kM-6R
	for secsh-archive@megatron.ietf.org; Sun, 10 Jul 2005 15:49:15 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA21154
	for <secsh-archive@odin.ietf.org>; Sun, 10 Jul 2005 15:49:10 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id C0A103A5F6; Sun, 10 Jul 2005 19:49:03 +0000 (UTC)
X-Original-To: IETF-SSH@netbsd.org
Delivered-To: IETF-SSH@netbsd.org
Received: from atlrel8.hp.com (atlrel8.hp.com [156.153.255.206])
	by mail.netbsd.org (Postfix) with ESMTP id 055013A482
	for <IETF-SSH@netbsd.org>; Sun, 10 Jul 2005 19:49:01 +0000 (UTC)
Received: from taynzmail03.nz-tay.cpqcorp.net (taynzmail03.nz-tay.cpqcorp.net [16.47.4.103])
	by atlrel8.hp.com (Postfix) with ESMTP id 954C5197C
	for <IETF-SSH@netbsd.org>; Sun, 10 Jul 2005 15:48:56 -0400 (EDT)
Received: from tcpi64.tcpip.zko.hp.com (unknown [16.116.92.210])
	by taynzmail03.nz-tay.cpqcorp.net (Postfix) with SMTP id 5E844202D
	for <IETF-SSH@netbsd.org>; Sun, 10 Jul 2005 15:48:56 -0400 (EDT)
Received: from unknown.hostname (16.115.197.112)
	 by tcpi64.tcpip.zko.hp.com (V5.5-11);
	Sun, 10 Jul 2005 15:48:55 -0400 (EDT)
Message-ID: <001901c58588$67ca8820$6401a8c0@americas.hpqcorp.net>
From: "Karol Zielonko" <Karol.Zielonko@hp.com>
To: <sxw@inf.ed.ac.uk>
Cc: <IETF-SSH@NetBSD.org>
References: <Pine.LNX.4.44.0507091821150.30790-100000@hadrian.inf.ed.ac.uk>
Subject: Re: SSH Kerberos packet exchange
Date: Sun, 10 Jul 2005 15:48:54 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	format=flowed;
	charset="iso-8859-1";
	reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

Thank you.

> Although, at one point, ssh.com did have their own Kerberos mechanism, 
> named kerberos-2@ssh.com

Unfortunately the version of SSH that I'm working on, 3.2.0, uses
the  kerberos-2@ssh.com variant. Anybody know if this one's packet
exchange is documented anywhere?

Karol




From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Mon Jul 11 12:46:18 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Ds1Q6-0007zM-0a
	for secsh-archive@megatron.ietf.org; Mon, 11 Jul 2005 12:46:18 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA27920
	for <secsh-archive@odin.ietf.org>; Mon, 11 Jul 2005 12:46:10 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 2FB703A4DF; Mon, 11 Jul 2005 16:46:04 +0000 (UTC)
X-Original-To: IETF-SSH@NetBSD.org
Delivered-To: IETF-SSH@NetBSD.org
Received: from mail-in-01.arcor-online.net (mail-in-06.arcor-online.net [151.189.21.46])
	by mail.netbsd.org (Postfix) with ESMTP id 0897F3A439
	for <IETF-SSH@NetBSD.org>; Mon, 11 Jul 2005 16:46:02 +0000 (UTC)
Received: from mail-in-03-z2.arcor-online.net (mail-in-03-z2.arcor-online.net [151.189.8.15])
	by mail-in-01.arcor-online.net (Postfix) with ESMTP id 836702A75F;
	Mon, 11 Jul 2005 11:11:57 +0200 (CEST)
Received: from mail-in-07.arcor-online.net (mail-in-07.arcor-online.net [151.189.21.47])
	by mail-in-03-z2.arcor-online.net (Postfix) with ESMTP id 778BA178C6D;
	Mon, 11 Jul 2005 11:11:57 +0200 (CEST)
Received: from folly.informatik.uni-erlangen.de (dsl-084-057-006-214.arcor-ip.net [84.57.6.214])
	by mail-in-07.arcor-online.net (Postfix) with ESMTP id 547542829D;
	Mon, 11 Jul 2005 11:11:57 +0200 (CEST)
Received: by folly.informatik.uni-erlangen.de (Postfix, from userid 31451)
	id A9B251427D; Mon, 11 Jul 2005 11:11:56 +0200 (CEST)
Date: Mon, 11 Jul 2005 11:11:56 +0200
From: Markus Friedl <markus@openbsd.org>
To: Karol Zielonko <Karol.Zielonko@hp.com>
Cc: sxw@inf.ed.ac.uk, IETF-SSH@NetBSD.org
Subject: Re: SSH Kerberos packet exchange
Message-ID: <20050711091156.GA11305@folly>
References: <Pine.LNX.4.44.0507091821150.30790-100000@hadrian.inf.ed.ac.uk> <001901c58588$67ca8820$6401a8c0@americas.hpqcorp.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <001901c58588$67ca8820$6401a8c0@americas.hpqcorp.net>
User-Agent: Mutt/1.4.2i
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

On Sun, Jul 10, 2005 at 03:48:54PM -0400, Karol Zielonko wrote:
> Thank you.
> 
> >Although, at one point, ssh.com did have their own Kerberos mechanism, 
> >named kerberos-2@ssh.com
> 
> Unfortunately the version of SSH that I'm working on, 3.2.0, uses
> the  kerberos-2@ssh.com variant. Anybody know if this one's packet
> exchange is documented anywhere?

http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/Attic/auth2-krb5.c?rev=1.2&content-type=text/x-cvsweb-markup

contains the old openssh code for this.  it got removed
because it's not really secure and is now replaced by
the GSSAPI variant.



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Tue Jul 12 23:27:42 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DsXuQ-0004ym-Gf
	for secsh-archive@megatron.ietf.org; Tue, 12 Jul 2005 23:27:42 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA21414
	for <secsh-archive@odin.ietf.org>; Tue, 12 Jul 2005 23:27:39 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id E77353A5EB; Wed, 13 Jul 2005 03:27:30 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from host334.ipowerweb.com (host334.ipowerweb.com [72.22.69.19])
	by mail.netbsd.org (Postfix) with SMTP id CD1973A4C6
	for <ietf-ssh@netbsd.org>; Wed, 13 Jul 2005 03:27:28 +0000 (UTC)
Received: (qmail 38619 invoked from network); 13 Jul 2005 03:20:36 -0000
Received: from unknown (HELO info3@servicepaypai.com) (80.97.190.156)
  by host334.ipowerweb.com with SMTP; 13 Jul 2005 03:20:36 -0000
Reply-To: "eBay" <aw-confirm@ebay.com>
From: "eBay" <aw-confirm@ebay.com>
To: <ietf-ssh@NetBSD.org>
Subject: Important Notice: Verification Required To Avoid Account Suspension
Date: Tue, 12 Jul 2005 21:24:07 -0600
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Message-Id: <20050713032728.CD1973A4C6@mail.netbsd.org>
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit


eBay Case ID number: PP 261-449-806

Recently, our Account Review Team identified some unusual activity in
your account.
In accordance with eBay's User Agreement and to ensure that your
account has not been
compromised, access to your account was limited.
Your account access will remain limited until this issue has been
resolved.
Protecting the security of your eBay account is our primary concern,
and we apologize for any inconvenience this may cause.

In order to secure your account and quickly restore full access,
we may require some specific information from you. To restore your
account to its regular status,
you must complete the following steps:

1. Verify your primary e-mail address by clicking the verification link
2. Confirm your identity by completing the account verification process

Once you have updated your account records, your eBay session will not
be interrupted and will continue as normal.

To verify your eBay records ,click on the following link:


http://privacy-ebay.com/.signin.ebay.com/ws/eBayISAPI.dll/?SignIn&UsingSSL=1&pUserId=&ru


We encourage you to log in and restore full access as soon as possible.
Should access to your account remain limited for an extended period of
time, it may result in further limitations on the use of your account
or may result in eventual account closure.

Thank you for your prompt attention to this matter. Please understand
that this is a security measure meant to help protect you and your
account.
We apologize for any inconvenience.

Sincerely,
eBay Account Review Department



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 14 21:54:08 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtFOy-0008UM-1K
	for secsh-archive@megatron.ietf.org; Thu, 14 Jul 2005 21:54:08 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA28950
	for <secsh-archive@odin.ietf.org>; Thu, 14 Jul 2005 21:54:05 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 177AC3A54E; Fri, 15 Jul 2005 01:53:56 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-2.sun.com (nwkea-mail-2.sun.com [192.18.42.14])
	by mail.netbsd.org (Postfix) with ESMTP id 06D8F3A415
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 01:53:52 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j6F1rqcn023721
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 18:53:52 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6F1rpFx013226
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 21:53:52 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6F1rpSW210128;
	Thu, 14 Jul 2005 21:53:51 -0400 (EDT)
Subject: draft-ietf-secsh-newmodes-04.txt is ready for AD Review
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Sam Hartman <hartmans-ietf@mit.edu>, Russ Housley <housley@vigilsec.com>
Cc: iesg-secretary@ietf.org, ietf-ssh@NetBSD.org
Content-Type: text/plain; charset=ISO-8859-1
Message-Id: <1121392430.207125.451.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Thu, 14 Jul 2005 21:53:51 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

I believe that the consensus of the Secure Shell working group is that
draft-ietf-secsh-newmodes-04.txt should be published as a Proposed
Standard.
Please start Area Director review.

						- Bill

[This is a writeup checklist following the provisional WG Chair
document shepherd process described in:

	draft-ietf-proto-wgchair-doc-shepherding-05.txt]

   1.a) Have the chairs personally reviewed this version of the Internet
        Draft (ID), and in particular, do they believe this ID is ready
        to forward to the IESG for publication?

Yes.  

There is a known nit in the -04 version:

The CAST-128 cipher takes a variable-length key of up to 128 bits;
the document does not specify a key size.  

Given the 128-bit-and-up requirement on key length included in section
6.1 of draft-ietf-secsh-transport, the resolution is obvious and
non-controversial: implementations should only use 128 bit keys with
cast-128 in counter mode.

This nit is expected to be fixed prior to IETF-wide last call.

   1.b) Has the document had adequate review from both key WG members
        and key non-WG members?  Do you have any concerns about the
        depth or breadth of the reviews that have been performed?

There appears to have been adequate review.  

   1.c) Do you have concerns that the document needs more review from a
        particular (broader) perspective (e.g., security, operational
        complexity, someone familiar with AAA, etc.)?

No.

   1.d) Do you have any specific concerns/issues with this document that
        you believe the ADs and/or IESG should be aware of?  For
        example, perhaps you are uncomfortable with certain parts of the
        document, or have concerns whether there really is a need for
        it.  In any event, if your issues have been discussed in the WG
        and the WG has indicated it that it still wishes to advance the
        document, detail those concerns in the write-up.

In the security area there have been recurring philosophical debates on
the relative merits of algorithm diversity in protocols and
implementations.  While there appears to be general consensus that
protocols should be algorithm-agile, there is also a view that excessive
algorithm proliferation should be avoided.  But exactly where to draw
the line seems to be a matter of personal preference.

The Secure Shell WG on the whole does not appear to have particularly
strong opinions on the topic but has historically pursued a
high-diversity approach.  As a specific example,
draft-ietf-secsh-transport-24.txt defined thirteen codepoints for
CBC-mode algorithms.  This document defines an additional thirteen
codepoints for counter-mode variants of the same set of algorithms,
providing more-secure alternatives to all of the ciphers exhibiting the
CBC-mode problem in -transport.

   1.e) How solid is the WG consensus behind this document? Does it
        represent the strong concurrence of a few individuals, with
        others being silent, or does the WG as a whole understand and
        agree with it?

Discussion of this draft has been focussed and smooth.  Consensus
appears to be solid.  

   1.f) Has anyone threatened an appeal or otherwise indicated extreme
        discontent?  If so, please summarise the areas of conflict in
        separate email to the Responsible Area Director.

No.

   1.g) Have the chairs verified that the document adheres to all of the
        ID nits? (see http://www.ietf.org/ID-Checklist.html).

The draft, submitted on April 8, 2005, still has RFC3667/8 boilerplate,
which is now flagged by idnits.

There is one manual checklist nit:

	3.1.B: one citation appears:

   Bellare, Kohno, and Namprempre [ACM CCS 2002] prove that if an SSH
   application implements the modifications described in this document,
   then the symmetric cryptographic portion of that application will
   provably resist chosen-plaintext, chosen-ciphertext, reaction-based
   privacy and integrity/authenticity attacks.

I've sent a suggested reword to the document editor (out of band)

   1.h) Is the document split into normative and informative references?

Yes.

        Are there normative references to IDs, where the IDs are not
        also ready for advancement or are otherwise in an unclear state?
No.

   1.ijk) Writeup:

        *    Technical Summary

Researchers have discovered that the authenticated encryption portion of
the current SSH Transport Protocol is vulnerable to several attacks.

This document describes new counter-mode based symmetric encryption
methods for the SSH Transport Protocol and gives specific
recommendations on how frequently SSH implementations should rekey.

        *    Working Group Summary

This document was non-controversial and well-received by the WG.

        *    Protocol Quality

The spec is relatively simple, and the working group is aware of
multiple implementations, has received informal reports of successful
interoperability, and has not received reports of any implementation
difficulties.





From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Thu Jul 14 22:06:52 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtFbI-0006zv-CH
	for secsh-archive@megatron.ietf.org; Thu, 14 Jul 2005 22:06:52 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA29632
	for <secsh-archive@odin.ietf.org>; Thu, 14 Jul 2005 22:06:49 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 261DA3A537; Fri, 15 Jul 2005 02:06:45 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-2.sun.com (nwkea-mail-2.sun.com [192.18.42.14])
	by mail.netbsd.org (Postfix) with ESMTP id C2E993A415
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 02:06:42 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j6F26gcn001454
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 19:06:42 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6F26gFt015238
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 22:06:42 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6F26fR7210160;
	Thu, 14 Jul 2005 22:06:41 -0400 (EDT)
Subject: [Fwd: do your WG's documents use language tags?]
From: Bill Sommerfeld <sommerfeld@sun.com>
To: ietf-ssh@NetBSD.org
Content-Type: text/plain; charset=ISO-8859-1
Message-Id: <1121393201.207125.463.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Thu, 14 Jul 2005 22:06:41 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

As my eyes glaze over when it comes to fine points of I18N, I'm
forwarding this query to the WG as a whole....

						- Bill

-----Forwarded Message-----
From: Randy Presuhn <randy_presuhn@mindspring.com>
To: Working Group Chairs <wgchairs@ietf.org>
Subject: do your WG's documents use language tags?
Date: Thu, 14 Jul 2005 16:42:54 -0700

Hi -

Language tags are used in many applications and protocols,  so
we'd like to get as broad a review as practical of these:
http://www.ietf.org/internet-drafts/draft-ietf-ltru-registry-09.txt
http://www.ietf.org/internet-drafts/draft-ietf-ltru-initial-02.txt
The former would replace RFC 3066 (a BCP), the later would become
an informational RFC.

The ltru working group last call on these concludes July 28.  If you or
people in your WG read either of these, we'd like to hear from you.
Post to ltru@ietf.org, even if all you have to say is "I've read it and
don't have any specific comments on it."

Randy








From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 00:00:10 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtHMw-00047N-NY
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 00:00:10 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA05589
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 00:00:07 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 8BB053A3E7; Fri, 15 Jul 2005 04:00:03 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-2.sun.com (nwkea-mail-2.sun.com [192.18.42.14])
	by mail.netbsd.org (Postfix) with ESMTP id 5FA073A550
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 03:59:59 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j6F3xwcn009216
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 20:59:59 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6F3xwFt001731
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 23:59:58 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6F3xwea210682;
	Thu, 14 Jul 2005 23:59:58 -0400 (EDT)
Subject: Re: WG Last Call: draft-ietf-secsh-break-03.txt
From: Bill Sommerfeld <sommerfeld@sun.com>
To: ietf-ssh@NetBSD.org
In-Reply-To: <1117057237.32717.415.camel@unknown.hamachi.org>
References: <1117057237.32717.415.camel@unknown.hamachi.org>
Content-Type: text/plain; charset=iso-8859-1
Message-Id: <1121399997.207125.512.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Thu, 14 Jul 2005 23:59:58 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

The working group last call on draft-ietf-secsh-break-03.txt has
concluded.

We have clear WG consensus to advance this as a standards-track
document.

Note: A small number of typographical errors were found during the last
call period.  A new revision of the draft with these typos fixed should
be released before the document is sent for IETF-wide last call.

						- Bill





From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 01:01:03 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtIJq-0005Km-Td
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 01:01:03 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA09374
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 01:01:01 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id B9E8F3AA1D; Fri, 15 Jul 2005 05:00:52 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-1.sun.com (nwkea-mail-1.sun.com [192.18.42.13])
	by mail.netbsd.org (Postfix) with ESMTP id 565DD3A9E6
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 05:00:45 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-1.sun.com (8.12.10/8.12.9) with ESMTP id j6F4Rd3t027996
	for <ietf-ssh@netbsd.org>; Thu, 14 Jul 2005 21:27:39 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6F4RcFx007449
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 00:27:39 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6F4Rb5w210756;
	Fri, 15 Jul 2005 00:27:38 -0400 (EDT)
Subject: draft-ietf-secsh-break-03 ready for AD review.
From: Bill Sommerfeld <sommerfeld@Sun.COM>
To: Sam Hartman <hartmans-ietf@mit.edu>, Russ Housley <housley@vigilsec.com>
Cc: iesg-secretary@ietf.org, ietf-ssh@NetBSD.org
Content-Type: text/plain; charset=ISO-8859-1
Message-Id: <1121401657.207125.518.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Fri, 15 Jul 2005 00:27:37 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

Having passed a WG Last Call, draft-ietf-secsh-break-03 is ready for AD
review.

The WG last call turned up only typographical errors in the -03
revision; fixes to these typos should appear in a forthcoming -04
version.

   1.a) Have the chairs personally reviewed this version of the Internet
        Draft (ID), and in particular, do they believe this ID is ready
        to forward to the IESG for publication?

Yes.  

   1.b) Has the document had adequate review from both key WG members
        and key non-WG members?  Do you have any concerns about the
        depth or breadth of the reviews that have been performed?

Adequate review has occurred from WG members, and it has been reviewed
by people with subject-matter expertise in terminal/console servers and
similar devices.

   1.c) Do you have concerns that the document needs more review from a
        particular (broader) perspective (e.g., security, operational
        complexity, someone familiar with AAA, etc.)?

No.

   1.d) Do you have any specific concerns/issues with this document that
        you believe the ADs and/or IESG should be aware of?  For
        example, perhaps you are uncomfortable with certain parts of the
        document, or have concerns whether there really is a need for
        it.  In any event, if your issues have been discussed in the WG
        and the WG has indicated it that it still wishes to advance the
        document, detail those concerns in the write-up.

No.

   1.e) How solid is the WG consensus behind this document? Does it
        represent the strong concurrence of a few individuals, with
        others being silent, or does the WG as a whole understand and
        agree with it?

There is strong consensus to publish this document.

   1.f) Has anyone threatened an appeal or otherwise indicated extreme
        discontent?  If so, please summarise the areas of conflict in
        separate email to the Responsible Area Director.

No.

   1.g) Have the chairs verified that the document adheres to all of the
        ID nits? (see http://www.ietf.org/ID-Checklist.html).

Yes.

   1.h) Is the document split into normative and informative references?
        Are there normative references to IDs, where the IDs are not
        also ready for advancement or are otherwise in an unclear state?
        (note here that the RFC editor will not publish an RFC with
        normative references to IDs, it will delay publication until all
        such IDs are also ready for publication as RFCs.)

Yes.

   1.ijk) Write-up section:

        *    Technical Summary
	
The Session Channel Break Extension provides a means to send a BREAK
signal over a Secure Shell (SSH) terminal session.  

        *    Working Group Summary

The consensus of the working group was to publish this as a
standards-track document.

        *    Protocol Quality

This extension is a replacement for vendor-specific hacks which
provide the same functionality.  There are known to be multiple
interoperable implementations of this extension and substantial vendor
interest.






From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 15:50:17 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtWCO-0005vp-VT
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 15:50:17 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA11007
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 15:50:13 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id D98723A909; Fri, 15 Jul 2005 19:50:05 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from newodin.ietf.org (unknown [132.151.6.50])
	by mail.netbsd.org (Postfix) with ESMTP id 768CB3A5DD
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 19:50:03 +0000 (UTC)
Received: from mlee by newodin.ietf.org with local (Exim 4.43)
	id 1DtWCA-0001tG-5z; Fri, 15 Jul 2005 15:50:02 -0400
Content-Type: Multipart/Mixed; Boundary="NextPart"
Mime-Version: 1.0
To: i-d-announce@ietf.org
Cc: ietf-ssh@NetBSD.org
From: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-secsh-x509-02.txt 
Message-Id: <E1DtWCA-0001tG-5z@newodin.ietf.org>
Date: Fri, 15 Jul 2005 15:50:02 -0400
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Secure Shell Working Group of the IETF.

	Title		: X.509 authentication in SSH2
	Author(s)	: O. Saarenmaa, J. Galbraith
	Filename	: draft-ietf-secsh-x509-02.txt
	Pages		: 8
	Date		: 2005-7-15
	
The X.509 extension specifies how X.509 keys and signatures are used
   within the SSH2 protocol.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-secsh-x509-02.txt

To remove yourself from the I-D Announcement list, send a message to 
i-d-announce-request@ietf.org with the word unsubscribe in the body of the message.  
You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce 
to change your subscription settings.


Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-secsh-x509-02.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-secsh-x509-02.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2005-7-15131039.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-secsh-x509-02.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-secsh-x509-02.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2005-7-15131039.I-D@ietf.org>

--OtherAccess--

--NextPart--




From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 18:06:11 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtYJv-00019V-1n
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 18:06:11 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA28950
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 18:06:07 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 108B73A55C; Fri, 15 Jul 2005 22:06:03 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-2.sun.com (nwkea-mail-2.sun.com [192.18.42.14])
	by mail.netbsd.org (Postfix) with ESMTP id 47DB73A3DD
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 22:06:01 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j6FM60cn024284
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 15:06:00 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6FM5xFv022132
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 18:06:00 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6FM5wHD214026;
	Fri, 15 Jul 2005 18:05:59 -0400 (EDT)
Subject: WG Chair Nits on draft-ietf-secsh-gsskeyex-09.txt
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Jeffrey Hutzelman <jhutz@cmu.edu>
Cc: ietf-ssh@NetBSD.org
Content-Type: text/plain; charset=ISO-8859-1
Message-Id: <1121465158.212935.447.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Fri, 15 Jul 2005 18:05:58 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

Going through the manual part of http://www.ietf.org/ID-Checklist.html I
found a few nits:

Abstract:
	There are multiple references in the abstract.  These need to be
	removed so the abstract can be stand-alone.

	Also, the reference-to-2119 text should not appear in the Abstract. 
	(Usually it goes in immediately after the Introduction)

Security Considerations section: 
	"SSH_MSG_KEXGEE_CONTINUE" looks like a typo.

You don't need to rev the draft right now as I'm about to start a Last
Call.
 
						- Bill











From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 18:14:41 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtYS9-00031O-Px
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 18:14:41 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA29936
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 18:14:38 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id BFDA13A5F8; Fri, 15 Jul 2005 22:14:37 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from nwkea-mail-1.sun.com (nwkea-mail-1.sun.com [192.18.42.13])
	by mail.netbsd.org (Postfix) with ESMTP id 090393A5EF
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 22:14:36 +0000 (UTC)
Received: from eastmail1bur.East.Sun.COM ([129.148.9.49])
	by nwkea-mail-1.sun.com (8.12.10/8.12.9) with ESMTP id j6FMEZ3t008511
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 15:14:35 -0700 (PDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail1bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6FMEZFt023601
	for <ietf-ssh@netbsd.org>; Fri, 15 Jul 2005 18:14:35 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6FMEYTO214074;
	Fri, 15 Jul 2005 18:14:34 -0400 (EDT)
Subject: Start of WG Last Call on draft-ietf-secsh-gsskeyex-09.txt
From: Bill Sommerfeld <sommerfeld@sun.com>
To: ietf-ssh@NetBSD.org
Content-Type: text/plain; charset=ISO-8859-1
Message-Id: <1121465673.212935.485.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Fri, 15 Jul 2005 18:14:34 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

This message marks the start of a Working Group Last Call on
draft-ietf-secsh-gsskeyex-09.txt, for publication
as an Proposed Standard.  This last call period expires on August 5th,
2005 (extended to the end of the IETF meeting week).

During this Last Call period, comments supporting publication are
encouraged as are comments pointing out problems or suggesting changes
to the spec.  

Reports of successful implementation of this draft are encouraged.  As a
reminder, tests of interoperability are *not* a prerequisite for
publication as Proposed Standard but any obstacles to implementation or
spec ambiguities should be corrected before publication.

Please send comments to the WG list as a whole.  Reports of minor
problems (typos) will not delay advancement of this document.

						- Bill








From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 15 19:06:11 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtZFz-0003Bz-J3
	for secsh-archive@megatron.ietf.org; Fri, 15 Jul 2005 19:06:11 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA05614
	for <secsh-archive@odin.ietf.org>; Fri, 15 Jul 2005 19:06:07 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id E68BE3A3D0; Fri, 15 Jul 2005 23:06:04 +0000 (UTC)
X-Original-To: ietf-ssh@NetBSD.org
Delivered-To: ietf-ssh@NetBSD.org
Received: from brmea-mail-4.sun.com (brmea-mail-4.Sun.COM [192.18.98.36])
	by mail.netbsd.org (Postfix) with ESMTP id 1D4203A3A2
	for <ietf-ssh@NetBSD.org>; Fri, 15 Jul 2005 23:06:03 +0000 (UTC)
Received: from eastmail2bur.East.Sun.COM ([129.148.13.40])
	by brmea-mail-4.sun.com (8.12.10/8.12.9) with ESMTP id j6FN62r3016341
	for <ietf-ssh@NetBSD.org>; Fri, 15 Jul 2005 17:06:02 -0600 (MDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail2bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j6FN61C2003438
	for <ietf-ssh@NetBSD.org>; Fri, 15 Jul 2005 19:06:02 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1])
	by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j6FN61jp214195;
	Fri, 15 Jul 2005 19:06:01 -0400 (EDT)
Subject: Re: 'DSSH'
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Tom Petch <nwnetworks@dial.pipex.com>
Cc: ietf-ssh@NetBSD.org
In-Reply-To: <00f601c57edd$df4d8980$0601a8c0@pc6>
References: <tsloea8hlip.fsf@cz.mit.edu>
	 <00f601c57edd$df4d8980$0601a8c0@pc6>
Content-Type: text/plain; charset=iso-8859-1
Message-Id: <1121468759.212935.595.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.316 
Date: Fri, 15 Jul 2005 19:06:01 -0400
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list
Content-Transfer-Encoding: 7bit

On Sat, 2005-07-02 at 04:12, Tom Petch wrote:
> Has anyone ever looked at the possibility of a DSSH comparable to a DTLS, ie
> adding a shim layer to enable SSH to work over an unreliable transport, such as
> UDP?

I'm not personally aware of any such thing.

There has been a small amount of discussion of something of an inverse
of this, which is forwarding of UDP traffic via SSH, but this is one of
those "ideas in search of a document author" which has never turned into
an actual draft.

					- Bill









From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sat Jul 16 13:23:13 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtqNc-00060e-TO
	for secsh-archive@megatron.ietf.org; Sat, 16 Jul 2005 13:23:13 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA15488
	for <secsh-archive@odin.ietf.org>; Sat, 16 Jul 2005 13:23:09 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id B1E373A464; Sat, 16 Jul 2005 16:27:07 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from ppsw-0.csi.cam.ac.uk (ppsw-0.csi.cam.ac.uk [131.111.8.130])
	by mail.netbsd.org (Postfix) with ESMTP id E126B3A3A1
	for <ietf-ssh@netbsd.org>; Sat, 16 Jul 2005 16:27:05 +0000 (UTC)
X-Cam-SpamDetails: Not scanned
X-Cam-AntiVirus: No virus found
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from libra.cus.cam.ac.uk ([131.111.8.19]:41177)
	by ppsw-0.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.130]:25)
	with esmtp id 1DtpV4-0000kf-09 (Exim 4.51) for ietf-ssh@netbsd.org
	(return-path <bjh21@cus.cam.ac.uk>); Sat, 16 Jul 2005 17:26:50 +0100
Received: from bjh21 (helo=localhost)
	by libra.cus.cam.ac.uk with local-esmtp (Exim 4.52)
	id 1DtpV3-0006MY-N1
	for ietf-ssh@netbsd.org; Sat, 16 Jul 2005 17:26:49 +0100
Date: Sat, 16 Jul 2005 17:26:49 +0100 (BST)
From: Ben Harris <bjh21@bjh21.me.uk>
To: ietf-ssh@NetBSD.org
Subject: draft-harris-ssh-rsa-kex-03
Message-ID: <Pine.SOC.4.61.0507161620210.5824@libra.cus.cam.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

Yet another RSA KEX draft has made it into the repository.  I hope this 
represents the final version of the protocol (apart from moving its name 
into the IETF namespace if it becomes an RFC), though probably not of the 
document.  This version:

1: goes back to using SHA-256 with 2048-bit RSA keys, since SHA-512 is
    ludicrously slow.

2: has the server send its host key to the client in SSH_MSG_KEXRSA_PUBKEY
    rather than in SSH_MSG_KEXRSA_DONE.  This prevents the server
    manipulating the exchange hash input by changing its public key.

I hope you like it.

<http://www.ietf.org/internet-drafts/draft-harris-ssh-rsa-kex-03.txt>

-- 
Ben Harris



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Sat Jul 16 15:20:43 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DtsDJ-0006uH-K1
	for secsh-archive@megatron.ietf.org; Sat, 16 Jul 2005 15:20:43 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA26525
	for <secsh-archive@odin.ietf.org>; Sat, 16 Jul 2005 15:20:39 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 347A53A49A; Sat, 16 Jul 2005 19:20:34 +0000 (UTC)
X-Original-To: ietf-ssh@NetBSD.org
Delivered-To: ietf-ssh@NetBSD.org
Received: from nutcracker.it.su.se (unknown [213.80.60.227])
	by mail.netbsd.org (Postfix) with ESMTP id C26163A47F
	for <ietf-ssh@NetBSD.org>; Sat, 16 Jul 2005 19:20:31 +0000 (UTC)
Received: by nutcracker.it.su.se (Postfix, from userid 913)
	id 184B834C17B; Sat, 16 Jul 2005 18:34:06 +0200 (CEST)
To: ietf-ssh@NetBSD.org
Subject: Re: I-D ACTION:draft-ietf-secsh-x509-02.txt
References: <E1DtWCA-0001tG-5z@newodin.ietf.org>
From: =?iso-8859-1?q?Love_H=F6rnquist_=C5strand?= <lha@stacken.kth.se>
Date: Sat, 16 Jul 2005 18:34:00 +0200
In-Reply-To: <E1DtWCA-0001tG-5z@newodin.ietf.org> (Internet-Drafts@ietf.org's
 message of "Fri, 15 Jul 2005 15:50:02 -0400")
Message-ID: <ammzom677r.fsf@nutcracker.it.su.se>
User-Agent: Gnus/5.1006 (Gnus v5.10.6) Emacs/21.3 (berkeley-unix)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-=";
	micalg=pgp-sha1; protocol="application/pgp-signature"
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

--=-=-=


Internet-Drafts@ietf.org writes:

> The X.509 extension specifies how X.509 keys and signatures are used
>    within the SSH2 protocol.

*** EKU

RFC3280 claims serverAuth and clientAuth EKU is for
  -- TLS WWW server authentication
and
  -- TLS WWW client authentication

Sure you want to overload that meaning TLS and SSH server/client
authentication ?

Should my http possibly run with the same certificate as my ssh server? So
if my http server is compromised, it will expose my users to that stolen
certificate when they try to contant that server.

I think you should make up your own object identifiers.

*** PKCS.7

[PKCS.7.1993] is kind of oldish, RFC3852 defines CMS now.

*** Certificates

in "4.  Use in SSH2 Protocol" there is certificate data defined:

       string    DER encoded x.509v3 certificate data

How may certificates is this, one, or a chain ? If the pki is deeper then
grass, one level, (a real tree), it might good to send the whole chain
(excluding the trust anchor)

*** x509v3-sign

"4.3 x509v3-sign" talkes about "DER encoded PKCS7 data", I assume that is
DER encocded SignedData from CMS. I think that should be more explicit.


I read over the document again when get back from the movie.

Love


--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (NetBSD)

iQEVAwUAQtk2/do1gLFKFEjAAQLoCgf/TIsta4wjjwpBzvZJjMyZentZIa/RnZDe
j5Qr4L8gmcXgnXbqZxj2SzQ2SR4htxm2O/10Fx23G+T0I7YgNK6h5UDzz+lOhikp
XALMroptVOo++n4rKygNdsOKGUJiidn9QsarGLZqnVbK6CD0tS6YTg4m1ybHWEI0
iKlzQ0MUjRC87p9mL3dz/XnuZA0Snr6LSQcxDi1x1yTBOHI8ngOJRZK/eHAcYjBx
u5/lDyyojm4z4ryMOePbyQnL8DwUKC6E8K3k87e2v/ZDVFJsDtNz/ac7NqtzBOCr
BrGvZPP+kkcha01WU83k1JN7dQgAdTHHIZGAMV4aUgdJOXSTpBOLXw==
=+EBA
-----END PGP SIGNATURE-----
--=-=-=--



From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Tue Jul 19 16:28:00 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Duyh5-0006jF-To
	for secsh-archive@megatron.ietf.org; Tue, 19 Jul 2005 16:28:00 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA12895
	for <secsh-archive@odin.ietf.org>; Tue, 19 Jul 2005 16:27:56 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id CC08C3A3A8; Tue, 19 Jul 2005 20:27:49 +0000 (UTC)
X-Original-To: ietf-ssh@netbsd.org
Delivered-To: ietf-ssh@netbsd.org
Received: from chiark.greenend.org.uk (chiark.greenend.org.uk [193.201.200.170])
	by mail.netbsd.org (Postfix) with ESMTP id F32B33A39C
	for <ietf-ssh@netbsd.org>; Tue, 19 Jul 2005 20:27:47 +0000 (UTC)
Received: by chiark.greenend.org.uk (Debian Exim 3.35 #1) with local
	(return-path bjharris@chiark.greenend.org.uk)
	id 1Duygt-00029P-00
	for ietf-ssh@netbsd.org; Tue, 19 Jul 2005 21:27:47 +0100
From: Ben Harris <bjh21@bjh21.me.uk>
To: ietf-ssh@NetBSD.org
Subject: Re: draft-harris-ssh-rsa-kex-03
In-Reply-To: <Pine.SOC.4.61.0507161620210.5824@libra.cus.cam.ac.uk>
References: <Pine.SOC.4.61.0507161620210.5824@libra.cus.cam.ac.uk>
Organization: Linux Unlimited
Message-Id: <E1Duygt-00029P-00@chiark.greenend.org.uk>
Date: Tue, 19 Jul 2005 21:27:47 +0100
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

In article <Pine.SOC.4.61.0507161620210.5824@libra.cus.cam.ac.uk> you write:
>Yet another RSA KEX draft has made it into the repository.  I hope this 
>represents the final version of the protocol

Of course, saying that was a good way to expose silly mistakes like, for
instance, having SSH_MSG_RSAKEX_PUBKEY containing K_T||K_S and the exchange
hash including K_S||K_T.  This isn't a security hole, but it's going to
confuse implementors, so there'll be a -04 in August that changes the order
of SSH_MSG_RSAKEX_PUBKEY.  Sorry about that.

-- 
Ben Harris

 (apart from moving its name 
>into the IETF namespace if it becomes an RFC), though probably not of the 
>document.  This version:
>
>1: goes back to using SHA-256 with 2048-bit RSA keys, since SHA-512 is
>    ludicrously slow.
>
>2: has the server send its host key to the client in SSH_MSG_KEXRSA_PUBKEY
>    rather than in SSH_MSG_KEXRSA_DONE.  This prevents the server
>    manipulating the exchange hash input by changing its public key.
>
>I hope you like it.
>
><http://www.ietf.org/internet-drafts/draft-harris-ssh-rsa-kex-03.txt>
>
>-- 
>Ben Harris





From bounces-ietf-ssh-owner-secsh-archive=odin.ietf.org@NetBSD.org Fri Jul 22 06:09:11 2005
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DvuSr-0002xd-Fg
	for secsh-archive@megatron.ietf.org; Fri, 22 Jul 2005 06:09:11 -0400
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA27806
	for <secsh-archive@odin.ietf.org>; Fri, 22 Jul 2005 06:09:06 -0400 (EDT)
Received: by mail.netbsd.org (Postfix, from userid 0)
	id 10C863A44D; Fri, 22 Jul 2005 10:09:00 +0000 (UTC)
X-Original-To: ietf-ssh@NetBSD.org
Delivered-To: ietf-ssh@NetBSD.org
Received: from nutty.inf.ed.ac.uk (nutty.inf.ed.ac.uk [129.215.216.3])
	by mail.netbsd.org (Postfix) with ESMTP id B1DB53A3F2
	for <ietf-ssh@NetBSD.org>; Fri, 22 Jul 2005 10:08:57 +0000 (UTC)
Received: from boogaloo.inf.ed.ac.uk (boogaloo.inf.ed.ac.uk [129.215.165.25])
	by nutty.inf.ed.ac.uk (8.12.8/8.12.8) with ESMTP id j6MA8rkW021438;
	Fri, 22 Jul 2005 11:08:53 +0100
Received: from boogaloo.inf.ed.ac.uk (localhost [127.0.0.1])
	by boogaloo.inf.ed.ac.uk (8.13.1/8.13.1) with ESMTP id j6MA8r5q030393;
	Fri, 22 Jul 2005 11:08:53 +0100
Received: from localhost (sxw@localhost)
	by boogaloo.inf.ed.ac.uk (8.13.1/8.13.1/Submit) with ESMTP id j6MA8qZF030387;
	Fri, 22 Jul 2005 11:08:52 +0100
X-Authentication-Warning: boogaloo.inf.ed.ac.uk: sxw owned process doing -bs
Date: Fri, 22 Jul 2005 11:08:52 +0100 (BST)
From: sxw@inf.ed.ac.uk
To: Bill Sommerfeld <sommerfeld@sun.com>
Cc: ietf-ssh@NetBSD.org
Subject: Re: Start of WG Last Call on draft-ietf-secsh-gsskeyex-09.txt
In-Reply-To: <1121465673.212935.485.camel@thunk>
Message-ID: <Pine.LNX.4.62.0507221106550.27310@boogaloo.inf.ed.ac.uk>
References: <1121465673.212935.485.camel@thunk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Sender: ietf-ssh-owner@NetBSD.org
Precedence: list

On Fri, 15 Jul 2005, Bill Sommerfeld wrote:

> During this Last Call period, comments supporting publication are
> encouraged as are comments pointing out problems or suggesting changes
> to the spec.

I have implemented this draft in many of its incarnations, including the 
most recent. I support its publication.

Cheers,

Simon.



