
From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 01:21:24 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B75A1A1F02 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 01:21:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id knZe8BtyRGXO for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 01:21:23 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E82AB1ACCFF for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 01:21:22 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 3CC8685EEE; Wed, 13 Jan 2016 09:21:21 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E060F85E94 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 09:21:18 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id rwyIlzif71QR for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 09:21:18 +0000 (UTC)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0787.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc09::787]) by mail.netbsd.org (Postfix) with ESMTP id 4CED484CE5 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 09:21:14 +0000 (UTC)
Received: from BL2PR05CA0035.namprd05.prod.outlook.com (10.255.226.35) by DM2PR0501MB1389.namprd05.prod.outlook.com (10.161.224.11) with Microsoft SMTP Server (TLS) id 15.1.361.13; Wed, 13 Jan 2016 09:21:11 +0000
Received: from BL2FFO11OLC009.protection.gbl (2a01:111:f400:7c09::120) by BL2PR05CA0035.outlook.office365.com (2a01:111:e400:c04::35) with Microsoft SMTP Server (TLS) id 15.1.365.19 via Frontend Transport; Wed, 13 Jan 2016 09:21:11 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.19) smtp.mailfrom=juniper.net; cs.tcd.ie; dkim=none (message not signed) header.d=none;cs.tcd.ie; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.19 as permitted sender)
Received: from p-emfe01b-sac.jnpr.net (66.129.239.19) by BL2FFO11OLC009.mail.protection.outlook.com (10.173.160.145) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 13 Jan 2016 09:21:10 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01b-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 13 Jan 2016 01:21:09 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0D9L6D51978;	Wed, 13 Jan 2016 01:21:07 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 2451311446;	Wed, 13 Jan 2016 01:21:06 -0800 (PST)
To: <ietf-ssh@NetBSD.org>
CC: Niels =?utf-8?Q?M=C3=B6ller?= <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, denis bider <ietf-ssh3@denisbider.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, "Stephen Farrell" <stephen.farrell@cs.tcd.ie>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
X-Phone: +1 408 745-2952 (Work)
X-Mailer: MH-E 8.5; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Wed, 13 Jan 2016 01:21:06 -0800
Message-ID: <95389.1452676866@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1;BL2FFO11OLC009;1:PiM7vAn2o6RARULRmghf93YXR+R7bO7YUNqXRAS6Y4ygv2eJa2q5LDnMUCjb9HGiCH8JiL7ZdMkYI8zOstEzpilX4HdWVGE79AW9wUiHEhOmNPvw8keA+uwZTzsycKJUkRaIBaH3ZebNcLnWBUJbfUp5KCTRE1UeaINh/2iF/spmly00o9sZmuaU6aENrkvllze19MhASw3W87SnoIc+ghOzpYqyX74XSRgKwoW+XIq1fxhFcPr2dBrtyLKteLct4W9kWvtMjHIbhWstBUr2RdJSn2YPlVF77K0ALjDRJq4+Spzm5s4BS4ZTSXXvBjE42ntmrnZGL1io3fUEJW1uZmr1X/kl29AP7YU+NepsBYAGqqoCN3+rEcA7jC4SWbnzK85MoYB71BvcxTXFEhvMHg==
X-Forefront-Antispam-Report: CIP:66.129.239.19;CTRY:US;IPV:NLI;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(2980300002)(189002)(199003)(86362001)(5003600100002)(77096005)(53416004)(19580395003)(4326007)(5001960100002)(105596002)(230783001)(76506005)(47776003)(6806005)(106466001)(11100500001)(586003)(15975445007)(92566002)(50226001)(87936001)(81156007)(97736004)(2351001)(48376002)(1096002)(189998001)(110136002)(5003940100001)(229853001)(117636001)(50466002)(1220700001)(50986999)(2906002)(69596002)(7059030)(42262002);DIR:OUT;SFP:1102;SCL:1;SRVR:DM2PR0501MB1389;H:p-emfe01b-sac.jnpr.net;FPR:;SPF:SoftFail;PTR:InfoDomainNonexistent;MX:1;A:1;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;2:7Sqa037HNaRtEZAC3RSC+3W6lwzaAAFy7igLN2PG0ci+AebiOxK+yoHejKHxG4eBB9UAjft9W8zs8/PenFa+r5XB26xNfYARHSdIFS98aK/BLrylaPXCFy8VELtwMAwmgC05EAam0zxrmYMS7dyNZw==;3:M3Q3/dgqKR/T8B0FZvuEVhzjWxQjnV1pM36qdQldqHCfPq2YWtx0/j2UaBmngNb/pQqrYgE6cxwhxYyLo2MGpHj2qCmWRVZu8FFEZeSJPTOrRmzKGlEhAMAvdyGfzH8ptjDc1Bvy/Wk9un3+x+fgyfbWOwXahaPSbv8swRFtygplxuv/eoaRPowStcs9tfsPpCcjw7TGHPAwAtUi5TCot245ow4ls3tgBHfqikCldfE=;25:kmRyoNcI1Uxy1DaBdKkXjDLyXuwcTGyLHZEJw4tHNn4ENb4Q8B82BouG7zBIisznEzl+WUYqAUnCCkR2HbZ8V1O263wCeKoY2+dyv3tM90TZnx4Wm2RVO17CmI9FY/5cnhpQ2qHLfYrmShBes3TRg+whYSGGX9RbNygHqqZuSOBxhvfxjBXojA5l6ER6r1g5KkoVh4Yw/YdmAR3+BKHCUH6IVz3AcnAMXuH7vGJRjO1nwR+oLJyt1rV+RlY8TKvk
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-MS-Office365-Filtering-Correlation-Id: e9b75bc7-e1b3-46a4-5941-08d31bfae084
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;20:30uBPJPu+o8dCRqBRmcKM0b3LKMuzXCCS2HptM2GdKTSP9D5Kcd9laDep5aeU+iClNZrxIH1+hyPOW9L3qq696rDj4OkIQMZ1XxFdSAmV3vXOl0W0duOMjJ0hV/rRYytplaMPk2A/xwp95F5LkbTBKGexF3VYKFcJashY5Qx5k3WhCTJMynqgX1xxeHZDwMuh7ALNWEv3K56W61yR/bFY7BLZDbpSCMqBTBp7NKMywqVIfsiMGjIuLshHmVO4tv1VciSvSG31PB2JgnU0jSiNYpnRNF4AI3z1PySL5SCofpFMlEyZh4JSr2tVtAMd28rrEQLX+EMLx/PX2gSxehA4v7yfaRzLCEKqo0dkJrJ0z6hvIHGi2hbHwXY4aSsO9Li2zYOeOgMO2dWGoD3NOSyGldoqxicITpJMnWgXXhz2TGVdh3PZOixkUMrRH7RUW87z23LJ/90mSnEfIExEcfQt99ZHOnBmAQ8iS62xQzrA8QifplZ3YFV3lC5yvFMYUU9;4:dXL+iuD0E5QWaXj+m9eDv+u1dRLGKXqRCIDHtJzlow9SGEilhnWW/OeE6r850MC2btQuHEmOyENvUq6M9FHTBr3OR+3C54DO5mgvFlYxQSLdp+LBT0xXhLKyt/ohghrH6C84nXWT34naY65jr0cV/krhVbKD0RVIQj1V2hN1y9TVR2y9RPGHH1Pgqm7ekuDJveCTO6sjtRN0W02x7UwX5Qf3k6Nf3aGPYAwqXbihWs1DCneUfpAR+0kGZIhe+KJeowHXxSc8UGhbZVC5LGvgvAX7eBygslkuZnTSh7o2c8P0yQI1c21V9obJueOyXpne8cSkOoEFnWwJgp9Jttp6+1PyGe7NUbRwjIr7ufuSGTJ6aek1+u/UvA7sjKWftpU5dRClZ6j/WqXpENPjw+8GVhT+VJX4DCZjCYC4kK4BLuUlQMnOKUuVl2JxIUWlmF0t
X-Microsoft-Antispam-PRVS: <DM2PR0501MB1389B658E919EDC7399FA704BFCB0@DM2PR0501MB1389.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(601004)(2401047)(5005006)(13015025)(8121501046)(520078)(13018025)(13017025)(10201501046)(3002001);SRVR:DM2PR0501MB1389;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-Forefront-PRVS: 08200063E9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;DM2PR0501MB1389;23:OVkgbBLFcj4tY8vN14YlrjYhsftfAO0p3Eg3iBS?= =?us-ascii?Q?zgL/tKID5H5ROB8xDJ635/YlKytwMGzpr8NqlbQm1oDcJmaZAulDm+cpE9eC?= =?us-ascii?Q?a9KrtyLkndHhmqpqfMs2alureDBTHTjalN5l2JEQdLJ8cnPhYRNEDScvKnBV?= =?us-ascii?Q?Ou4cXBueRjXRRPXIK4V/igaamwGIqlhhoV6tOeZ7mq4b9sPWvJ0F7UnaE8BS?= =?us-ascii?Q?VrUk6G7SPdM6GRuYimyDbvfL2DXmKm0qQo1hadXCLk2Cw48DfJ+dp/lh4/67?= =?us-ascii?Q?bJO80rbRisB1Gpwk8AZjw3JhAiGZ+sR0zhivO+tzwkcv0PG1+kS2/r67ia4N?= =?us-ascii?Q?32KJUyGCKdvFuYOp6rR6aUczK9tFR7oQSjZoeMG7nUNtLx/F+RaRgu14VcSF?= =?us-ascii?Q?IbXXQihIsRrOq0bpRqNRbewV+aXAsXqN1cWTYSmzR5+oYl8skQd7ShctbyJ5?= =?us-ascii?Q?nfa6GtJYYPJxrlmVpltzXZ4zl3PGNqOwOyzUNEqUz6aBG9osbXr/TT9Xwi2K?= =?us-ascii?Q?xMxFT3bIxf8fDQOxkvQEiDb0PnZaQagvjKOb1GJk0Z6Z8gMZ/cb5zt2PSdXb?= =?us-ascii?Q?p0Wtf4V6VBGUn2im1jkdvnVAY5RiT0y1H4H5q5ZwktofBgdSr6/31sJxwJ3x?= =?us-ascii?Q?9Jhmwd0B7mI6wNr99nUEBQ3Py3Rrp7IkAhY3OK6+Qhk3XZorYEsgUSs3LnPP?= =?us-ascii?Q?v2xtS3CjnkLel3+cNLBZnbqJzDc/lpioTmdDZnSbTiKcoYf5ra2a+QjarYXN?= =?us-ascii?Q?6/tZ2IxxRuBAAZX/5x8jtHvKHuyMLso9HeZ8+urZyQbNORBcAIF++uKqv0wf?= =?us-ascii?Q?8U/zImQBQMnD/TFgahwya4qMKMDmUW1KZOIjUHHsp2lsxuOR/j4ACvsimdiu?= =?us-ascii?Q?JI0kMQN7X5Zrs9rZkrbO/R1cuC4kB1iDrwSZYSXjRASN9iAVDi9uiiFABD28?= =?us-ascii?Q?IU1nHPP6/WXxh7bk+owue5/jHAxvZkjx0Z/CLkEHpkjTAtUL6KJtcu1Jw44h?= =?us-ascii?Q?wPSi88b9C461Cxx14i3HqDMvUDvI04E2P6YpkDv2DXa785xoTfVBGB4YtLv9?= =?us-ascii?Q?YFg221V4=3D?=
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;5:c0kz6jX6xGPPYG9BCVDoXgXXpjwz8ARRMvx1naASPlwJD27EiK0lnCMqf5alCLA7F+1Qmsn6Xtc0wG33fddJIDsofGwAMKf3YcX7REOz3goKBOLvqgWjCIveGfrRQR/uMtx669WmBdSfW6wPhIK/yw==;24:NoTzh+cwdhHFpfbChr8lFToQz1NCAAVHzwlLgtdVVk2FsWPrfIgwGEgeOd/Ss/CzYGxkmZil1oEcRmQrIoj5abyuFVm2brOVyFLqr1pPcPU=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jan 2016 09:21:10.8327 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.19];Helo=[p-emfe01b-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0501MB1389
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi,

URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2

I believe that OpenSSH and Dropbear SSH have both implemented interoperable
versions using the current 01 version at this point in time.

I would be interested in hearing if any other implementations have
adopted these new DH groups.

Are there any additional comments or changes needed for the draft before
we can move to the next step in the process?

Hmmm... What is next? Getting 'AD is watching' or is it getting a
document shepherd?

	Thank you,
	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 02:34:17 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 642C31A1A87 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 02:34:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id psJQl7BcqR0f for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 02:34:15 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 347A51A1A7E for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 02:34:15 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 1071885E59; Wed, 13 Jan 2016 10:34:14 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id AA5ED85E59 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 10:34:11 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id JEOuxenWnkWK for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 10:34:11 +0000 (UTC)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 00A2A84CE5 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 10:34:08 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id A5993BE80; Wed, 13 Jan 2016 10:34:06 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iwQbXodS3zOO; Wed, 13 Jan 2016 10:34:06 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id E694BBEA4; Wed, 13 Jan 2016 10:34:05 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1452681246; bh=m5kkWbP72hJXaKpih14ufus2GYNVQJARXQwCxIPzLYQ=; h=Subject:To:References:Cc:From:Date:In-Reply-To:From; b=Bzts2LZv0uL66BmpnC5WfNY17DTq9g6pSRjTwM2NQugTqbSxWZJMpf30Rfu2v5xD2 xxnomSKhfFzWreeKeexvhILveca0waZDNWCRgGl6uOvVSZUBnftDUgf8rQksv+rp/X JGIqu07nOjlDlvQulDsZCBenw6TWVFi7z1EJUU0U=
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
To: "Mark D. Baushke" <mdb@juniper.net>, ietf-ssh@NetBSD.org
References: <95389.1452676866@eng-mail01.juniper.net>
Cc: =?UTF-8?Q?Niels_M=c3=b6ller?= <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, denis bider <ietf-ssh3@denisbider.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <5696281D.9040201@cs.tcd.ie>
Date: Wed, 13 Jan 2016 10:34:05 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.4.0
MIME-Version: 1.0
In-Reply-To: <95389.1452676866@eng-mail01.juniper.net>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hiya,

On 13/01/16 09:21, Mark D. Baushke wrote:
> Hi,
> 
> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
> 
> I believe that OpenSSH and Dropbear SSH have both implemented interoperable
> versions using the current 01 version at this point in time.
> 
> I would be interested in hearing if any other implementations have
> adopted these new DH groups.
> 
> Are there any additional comments or changes needed for the draft before
> we can move to the next step in the process?
> 
> Hmmm... What is next? Getting 'AD is watching' or is it getting a
> document shepherd?

There's no active SSH WG, but there is the curdle WG. Its
charter [1] however is limited in terms of what it's
allowed to add to protocols. OTOH, this is not defining any
new groups, just updating codepoints, including deprecating
one (to NOT RECOMMENDED). So the draft could fit there on
that basis I guess. So I'd say send a mail to the curdle
list and suggest this be adopted there.

If that doesn't work I can look at AD sponsoring it, but
since one of the reasons to setup curdle was to avoid too
many of these being AD sponsored, please try there first.

Cheers,
S.

[1] https://tools.ietf.org/wg/curdle

> 
> 	Thank you,
> 	-- Mark
> 

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 07:40:00 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CC9B1A900B for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 07:40:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WuILFQg4Rw_7 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 07:39:58 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C90B31A8836 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 07:39:58 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 3363485EB8; Wed, 13 Jan 2016 15:39:58 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id F01C885EB8 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 15:39:53 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 5WIB2Hi7oA44 for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 15:39:53 +0000 (UTC)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1bon0753.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::1:753]) by mail.netbsd.org (Postfix) with ESMTP id 3F8CD84CF6 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 15:39:49 +0000 (UTC)
Received: from BLUPR05CA0065.namprd05.prod.outlook.com (10.141.20.35) by BN3PR0501MB1380.namprd05.prod.outlook.com (10.160.117.139) with Microsoft SMTP Server (TLS) id 15.1.361.13; Wed, 13 Jan 2016 15:39:45 +0000
Received: from BL2FFO11FD027.protection.gbl (2a01:111:f400:7c09::145) by BLUPR05CA0065.outlook.office365.com (2a01:111:e400:855::35) with Microsoft SMTP Server (TLS) id 15.1.365.19 via Frontend Transport; Wed, 13 Jan 2016 15:39:45 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.19) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.19 as permitted sender)
Received: from p-emfe01b-sac.jnpr.net (66.129.239.19) by BL2FFO11FD027.mail.protection.outlook.com (10.173.161.106) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 13 Jan 2016 15:39:45 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01b-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 13 Jan 2016 07:39:43 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0DFdgD44762;	Wed, 13 Jan 2016 07:39:42 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id B827F1141B;	Wed, 13 Jan 2016 07:39:41 -0800 (PST)
To: Curdle Chairs <curdle-chairs@ietf.org>
CC: Curdle <curdle@ietf.org>, <ietf-ssh@NetBSD.org>
Subject: Re: [Curdle] Call for Adoption 
In-Reply-To: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se> 
References: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se>
Comments: In-reply-to: Daniel Migault <daniel.migault@ericsson.com> message dated "Tue, 12 Jan 2016 19:58:46 +0000."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.5; nmh 1.2; GNU Emacs 24.3.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Wed, 13 Jan 2016 07:39:41 -0800
Message-ID: <65770.1452699581@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1;BL2FFO11FD027;1:aixbU1gvdFqeJsD0qFKj9dlPensIl4m8jWEM2AJBg+8Gn1TGQq0wIfHA9ZwlO5JhgNZVZTBsMA6xZS/afPGLjr/MIheOSDZphAp6+Mvved7IdQ1DCiN7H0fSo7QP8zibN7z+kijFAwTZsgfJxArgLQ4HERod7ES7M96MGONa7EQdN/7FaNUaAhowNyvfPEUpXre+aUptr0YTwXHhaibU0W8QDH/J/JUITuL4mdn3r6Vk/IP7hR3TG6sijkYZ4p/VdjuVYwrgiBMWxJF6YbWeXnJYC4Wxm7EwlduwNcXZH/TNCgneJeXGR0n/q1PtYqYaFqv3zOq66WG9x4mShCsiuZkfLBZMfQ7vRSaf1i1XEsU=
X-Forefront-Antispam-Report: CIP:66.129.239.19;CTRY:US;IPV:NLI;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(2980300002)(22974007)(24454002)(189002)(479174004)(199003)(586003)(53416004)(76506005)(50466002)(48376002)(50986999)(1096002)(92566002)(1220700001)(5003940100001)(5003600100002)(117636001)(86362001)(106466001)(47776003)(19580395003)(15975445007)(69596002)(77096005)(87936001)(19580405001)(105596002)(2950100001)(50226001)(110136002)(97736004)(5001960100002)(81156007)(6806005)(2906002)(4326007)(76176999)(189998001)(11100500001)(42262002);DIR:OUT;SFP:1102;SCL:1;SRVR:BN3PR0501MB1380;H:p-emfe01b-sac.jnpr.net;FPR:;SPF:SoftFail;PTR:InfoDomainNonexistent;MX:1;A:1;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;BN3PR0501MB1380;2:7Z/cQNKNUQrZ47RNrwATj9Hs6AfubRPRp3GxKAgfmTycRBG8yHVtzQiResSWxoIiBrO8JWHWE0Q5pDkE3PpM7FqUqyWdW8QueI9ULRVdad2PnKH2r9ufrRyHtMzmHviOZyPMm8pKRzlg7jODqx/mEQ==;3:Q1WLLMmqtq8saoM4E8SSnn34Q3gBxbDzR/WdqQsMCT92ASr7Jpr+9uVty9bxPsa9JV/FeZYA/vULCJ3rGkC7YOvunUUhoXA7s4ZSM7vBcQ+uffYzhxBzwWVztsWcGG4AaXEvVpyMbOWuBjJ8KBcnGRfR7p5Nc4wBnjPyfBOnrfX8+/t7BXh1csEZB8K+RSgykV+TXBn5YrT08DZqVp8sk7dOVYKZGeGIBDYmL7YCo48=;25:1vfrlGHPoUJhUa3g3+9o9XERahSkj7WZ/8MyiRV9M14qlugRMA+lJkc3I4u+bQ1ay8wRXlSJDiAMQF4/4rvXLkofkFr2el0hKuaCcnIDxEkb8RYiVodiLtDtoJ087Ms3Las9Y0sAy/O05Dlff71kDishwiFgzeTYZs/uu1lB8NuNMGDCLSIG6zhKZSwxrY7Smm0KrKBRcNpkxONtik2dqqp9GkAN9+C7pIH09ihkKRMQSEXs+U3zGjNkPAxCyLxk
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BN3PR0501MB1380;
X-MS-Office365-Filtering-Correlation-Id: a6d65ed6-9630-4001-8329-08d31c2fc351
X-Microsoft-Exchange-Diagnostics: 1;BN3PR0501MB1380;20:AdznX8vTWWmwhFiqmfWhoXqO2mOsi4NN8/ZpNfS19aCjMYjS38O9FFLO8vVLPGcV0SbBu6lmBREhSnnTxpuwYW43DPdrAMoeBS6joxjB/Cp71HJalrRhOi/tfSU2O9PYQoD5UVBEzpIF9q7COkDqycCmOdDp+YBVJe6MJ39qdzDAn0ubqSCNW5MBAG5QgiV9I37pwD8oY/WylabaXbhAGoPEWAefhCWCOBPeDpp9srqnprcCF1TTypVJX5CDBw0zhQ9hoLYmudAdp35iXs1DTlL8+iqMU30lhm7IToC6qT3AAH5Zj0pHcBv2t67LZhC2M1iMZwSEf44i03YIbPofxggl3qE82PtB3T7ypsMFgqh7Wm3Bcs+DKTYFjATMNoTndQ69WexPkMwG/2G5m7Oeo/IcU2v4PR1XHIneP60hMcsTSy2TwwwT+etEvaiwZd/3pcX3OawrtthZoKURo8YcmsmqvCkDfZYl66phOO9orOMrp7Vv8yt5jAd8COo/ZVEK
X-Microsoft-Antispam-PRVS: <BN3PR0501MB1380D49640F410881EFE8BEDBFCB0@BN3PR0501MB1380.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(32856632585715);
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(601004)(2401047)(13018025)(5005006)(13015025)(13017025)(520078)(8121501046)(3002001)(10201501046);SRVR:BN3PR0501MB1380;BCL:0;PCL:0;RULEID:;SRVR:BN3PR0501MB1380;
X-Microsoft-Exchange-Diagnostics: 1;BN3PR0501MB1380;4:dyJFuXkwq4SOqXbs955QC9xLxbXwqrQwNnZMYc7eNKZ5zsQ6lXXu1n5LeUC0rP+cLcaROdDnVBMfXHuNqPyAEkeGkyZXQrHAXsP6B83Q3eGRSfuVv71woR9TCTBIl1a/I0Hxd3mGEfXQM+wNnIaUtPp63vFt/LwnePcETv1Yabc5sSPuakOG84yPx9CgBIiU014PH5aY4uT6RPANCsGf7c0OGx7RrO7qDPcRbWjS8DNqzX6j08URjmtpf8nm54Vl2eCNBvyB9C2YfrRo9Oaq/XGaMj1Dz2UAJybNZT+S3FDMSeV/+D5JOOoW2wIEzY3Q2ZtxdPGob82NdjkB6be38AuAHNe0TgKPDcfDffZPMR+lDmGh2JRblawnyReb8YvmAxuVuscTBBizzTg6PZ1AyX+TKIaCqZ0gZqAuQUit+41Sl9s7vGPRrfnv429cUhBVnD1jwAaps4KY4wt+TGiaY1i61yj0k62ZkoTmPzyj89U=
X-Forefront-PRVS: 08200063E9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;BN3PR0501MB1380;23:rfFVaRl5q/MViulk2LldlZPt0WOkrkPqA9G5OcM?= =?us-ascii?Q?tt1zudL1GdOVxIeAu5mG1ySmt7ieTtaiIrwqli52KaeTSlw6BgIlfT7pc53N?= =?us-ascii?Q?VKycpt0Y/uFfLFBBk09F71Mv63rveB5b3ebY8I6O3wzo5JRBGgxR/zHilxqe?= =?us-ascii?Q?MEyeLEFSnC1vl8eTtD7QHUZZCzWPEAynMRy3GdZ2yAy0NGUXklrc+7MPtj3B?= =?us-ascii?Q?Q8xn8mdsDkwaO4OG4Pc1Jr2CJ5Uh8PT0nSDrDhFyzGeSug90kQ4GEewZ/iSc?= =?us-ascii?Q?Gfzm7S5YjbNT86Fgm41IxGA4Jzm7wR64I9P9RskSM0CSfx3ABi65m6iDzZgC?= =?us-ascii?Q?Nzlv6b6MutwO1DsTCmAhN0WgOFKTUVOICffqtmMBTeiQY9BWg7qUoNe7+hsr?= =?us-ascii?Q?4M9SPD6K2ofXYAmFPRVoJKMcHmNgcXBbSPjNgtUp+/KvNno1CnggSGVfY0cn?= =?us-ascii?Q?N0oj90KiSWIfZEnPk/F9euHE7OVSYI2ADcZguvNR5wvxXuSH0R62BpLtqEbV?= =?us-ascii?Q?aLN/KrqYtcKrTPFEEC5Z4MjZJSENyZfiVRr6+2pyJu+JWrOK1oBjH4rHCjE7?= =?us-ascii?Q?B6TtPtu49Of5xdM+oLp2Ls1uIItuLZGp2owzGXttwaUSARzoBLtNauPJDgpY?= =?us-ascii?Q?/vmHU5oVoY5FgeVhlJrqm7jZGwqm/t5hepNlyGH0FN8lMLt83EuSzLXSS/2u?= =?us-ascii?Q?VK1PxX6EV/hQIzm3ER5fhE87SEhg14fGb7ftfvNoqb3V8lIABDh5ZpP74fYK?= =?us-ascii?Q?UK/amJ+m8jADc6AlqUSY6njWtsz+n4MGZ5Kv13SXCa6WiYGlRPOoWUAceDdX?= =?us-ascii?Q?koWEqs47dZDkBtWct8wCjw/Z6Ju73uRqSTk1af4TcOaL62flBa0rLquH7Fk+?= =?us-ascii?Q?wK/G8hg9pskTnkEhV2jHWaA7UqKkJ64Nz0OQBuVTc9imNgB9PgQYw8UA6si6?= =?us-ascii?Q?gwsPK1S680MazSykN8OLl5DKP4gs8UyQ0cESW0qSMpDlDTO805Ylvq9RIhSr?= =?us-ascii?Q?5jEMqQoewFaFh6+9XSlr0FWLEWJY1uiS8eJHx32f8C1j6Kw8LX4xaIxPOsqK?= =?us-ascii?Q?uWyFXPlF5Nd5OBfXvx5aIVvWU0sQlGbzqudVvs6iXxN5gOX+xenN8t/zANNV?= =?us-ascii?Q?POp3yh6qS4kU=3D?=
X-Microsoft-Exchange-Diagnostics: 1;BN3PR0501MB1380;5:/ZUQPGMswERODA8cz1YSCGvjECib51ZgfEmoB2dwwveCkOQmvPoN01FqKSovBB+LcLIW9i/grTX5ugS/1zXK41cUFimOwyg3wiGR5p9WW+2seAeJx3hHrOUpuDXgBc71dZ5dt1uOMS0auD2CD+L6zw==;24:iNk4TmVU+V2OLrVlY9twkCsNLNvaHkGYf6hTA8GFe75+1V+2WxJNOCucEi49g+F2QF9nGawVj7f/fvVkU5nPYc99YDojTgMkYM0bWxoJyk4=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jan 2016 15:39:45.0319 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.19];Helo=[p-emfe01b-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR0501MB1380
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi,

Over on the ietf-ssh@NetBSD.org list, Stephen Farrell suggested that I
see if I could add

  https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2 

under the curdle charter. 

The draft deprecates a Secure Shell (SSH) key exchange algorithm
(Diffie-Hellman group1 - a 768-bit MODP group) and recommends
replacement with stronger Diffie-Hellman MODP groups (groups 14, 15,
16).

The draft does have two interoperable implementations that have
implemented it.

Does it fit well enough into the curdle charter to be added here?

	Thank you,
	-- Mark

 ------- forwarded message -------
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Date: Wed, 13 Jan 2016 10:34:05 +0000
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)

Hiya,

On 13/01/16 09:21, Mark D. Baushke wrote:
> Hi,
> 
> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
> 
> I believe that OpenSSH and Dropbear SSH have both implemented interoperable
> versions using the current 01 version at this point in time.
> 
> I would be interested in hearing if any other implementations have
> adopted these new DH groups.
> 
> Are there any additional comments or changes needed for the draft before
> we can move to the next step in the process?
> 
> Hmmm... What is next? Getting 'AD is watching' or is it getting a
> document shepherd?

There's no active SSH WG, but there is the curdle WG. Its
charter [1] however is limited in terms of what it's
allowed to add to protocols. OTOH, this is not defining any
new groups, just updating codepoints, including deprecating
one (to NOT RECOMMENDED). So the draft could fit there on
that basis I guess. So I'd say send a mail to the curdle
list and suggest this be adopted there.

If that doesn't work I can look at AD sponsoring it, but
since one of the reasons to setup curdle was to avoid too
many of these being AD sponsored, please try there first.

Cheers,
S.

[1] https://tools.ietf.org/wg/curdle

> 
> 	Thank you,
> 	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 08:50:54 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 439E61B2F2F for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 08:50:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F2xPDQ07lmeC for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 08:50:53 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 210CA1B2B04 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 08:50:53 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id D02D385EEB; Wed, 13 Jan 2016 16:50:51 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E9B4F85E54 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 16:50:48 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id ZLoKCcj5PpOg for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 16:50:48 +0000 (UTC)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0788.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc09::788]) by mail.netbsd.org (Postfix) with ESMTP id 42DE285E2B for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 16:50:44 +0000 (UTC)
Received: from BLUPR05CA0048.namprd05.prod.outlook.com (10.141.20.18) by DM2PR0501MB1389.namprd05.prod.outlook.com (10.161.224.11) with Microsoft SMTP Server (TLS) id 15.1.361.13; Wed, 13 Jan 2016 16:50:42 +0000
Received: from BL2FFO11FD038.protection.gbl (2a01:111:f400:7c09::195) by BLUPR05CA0048.outlook.office365.com (2a01:111:e400:855::18) with Microsoft SMTP Server (TLS) id 15.1.365.19 via Frontend Transport; Wed, 13 Jan 2016 16:50:42 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.19) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.19 as permitted sender)
Received: from p-emfe01b-sac.jnpr.net (66.129.239.19) by BL2FFO11FD038.mail.protection.outlook.com (10.173.161.134) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 13 Jan 2016 16:50:41 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01b-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 13 Jan 2016 08:50:05 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0DGo2D11978;	Wed, 13 Jan 2016 08:50:02 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id C4A1111446;	Wed, 13 Jan 2016 08:50:01 -0800 (PST)
To: Daniel Migault <daniel.migault@ericsson.com>
CC: Curdle Chairs <curdle-chairs@ietf.org>, Curdle <curdle@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: Re: [Curdle] Call for Adoption 
In-Reply-To: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se> 
References: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se> <65770.1452699581@eng-mail01.juniper.net> <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
Comments: In-reply-to: Daniel Migault <daniel.migault@ericsson.com> message dated "Wed, 13 Jan 2016 16:31:39 +0000."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Wed, 13 Jan 2016 08:50:01 -0800
Message-ID: <85658.1452703801@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1;BL2FFO11FD038;1:1uCcf1y8H/SHvTk0KhcFewyKSn6uygL0xIdM51mMtNWExlcI/3tH5q7ZgDy3qRFXkLShpW6lFjC1wWmQXCaDxqqgu3LmmrR7E20oaOdotPtjvfivBmq8ccOouhgv3RWVDMOh6/jDwg98AvaPPCy24RcoZzeJCxv/6gWiClaq22ja24sSdp65nrL0lrVieAyJHACCnp6DObsgQ12r390kamQaUuk/d52+yIlaexIc515l2ou7T3NKpXASReG6b+gn0YU10MBSw0fRmdV/zDO4mIeo+3DGXBP4HNzP3+T3SsDOdjSx+0/8ohqLgHotX09Qn462ILJYIt8SnG/1KlM/VeuUeHt9erzJhSImVlot2pF3MxJw+AsBscAjYVJWzwsCCkT+V/Rt1IQT8GeAMzUxo1Q7tHj8ui4qzf+Sb/Wxbl4=
X-Forefront-Antispam-Report: CIP:66.129.239.19;CTRY:US;IPV:NLI;EFV:NLI;SFV:NSPM;SFS:(10019020)(979002)(6009001)(2980300002)(51914003)(189002)(199003)(86362001)(5003600100002)(77096005)(19580395003)(4326007)(54356999)(2950100001)(53416004)(6806005)(76506005)(47776003)(105596002)(5001960100002)(106466001)(19580405001)(11100500001)(586003)(15975445007)(92566002)(81156007)(87936001)(5003940100001)(97736004)(48376002)(117636001)(50466002)(110136002)(1096002)(189998001)(76176999)(2906002)(1220700001)(50986999)(69596002)(42262002)(969003)(989001)(999001)(1009001)(1019001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM2PR0501MB1389;H:p-emfe01b-sac.jnpr.net;FPR:;SPF:SoftFail;PTR:InfoDomainNonexistent;MX:1;A:1;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;2:WnyqhCDGaP764tN0s3ozYkQCNbp3i70AxsCqiaKWdNjEy3hRDBObdorwqQZfFQ3hMqGCx3op2S9hX29MtB2KofVBp22v2pST9mby0xwIEkuOEmr9SUV/J4xKk/GwYQlWtO4hu6Z/Rbx6s3TIWigslw==;3:nmAn5g9tqe7z7LuiT/W650LH7G3rtFs3X4B4r6B3Tu6jx7iLjZzf+vsJQB6jAmWWXHJi/EMRqpR0T7ExCM7jU8v9+5RD0FL93GYZVzIQw3/eiAvCsiMeUGwkOpIhE4oUcngeqEA5780oeQje9RTWfZQmg65gN6Mjq4HPjT8bqgk7ovct1XxC2WduRZfKcLNfz3oVz06ABK3nrRlJcijZPOgygbFZZ+44XOkLiN3I3Xc=;25:GMgooY8AqLI2SQg/VlOahFoQeO59A2r4Sj7PysEPMF622zg+ijD874VxzhGJJPNmMKkvsN4q3BCu1iMWzqACCU9b/DPqP7SePUhC7pOWOGB+FG0AiRO2HDwbctroQYOsiCMUXHk96V3T27W8+GGYBCpbTT6oNcM5Yii49bHne6yVZkYqnN5iWdWZwQea1efJy5YSBssftpROGVYLPf5BmFUJy9cwbE+gzZ23oOeTe05kycjeDazjsa/MppYOQKYi
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-MS-Office365-Filtering-Correlation-Id: 89e43c2d-6e2b-4e2c-183e-08d31c39ac31
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;20:mOfaI3rJEqHihH5mw+AQRvgAFEYma0ChPtjHqgIsAldKGzr6CoqcGbRG/njbtBxTVnr9QnJgm3vt5Lp9hkVkIXIZjUCgE9+12iNUM+VnADz/NdvfaCUcFKHEWCe6KoLXsQc14Tc5zryzNWCWjb7hQlKqsyOfOEXb1NzaZmiDzOMgt7+vvrw4N3SQM7kiz4QRmRj3IgRdmgEqtHEHnv1KXUTE+UUhbQ2Akgj0Hi7Zlj9wUwUkp2qe9MzhFY/v7jx/hFC+mtKNtLGOqVkDBF/457QnSo5xlUv4UYQavoAgsy8Nen1B+LZq5r0fJDnovuRdjTtXcwbhJUwmAj+nzTvqKOz41HDbg+fVy1HoaoSyNyRA5SpB3Nm/h36iKAkrGpZPZZ1uefw3lCe4qTi1fb0XoUZFRRsZLk6G6UhpqLA9IeOfvbLw0npLDqy27IXJJbh/KO2V3E4tFe1kFe/B6gSnlLHo566iZaAx2pKsRiph4w5QPbPJ5KjhkAvK4O/7rG1y;4:3oiH6poWFT01yudN14PQfeXVTJyzURdPPPoxltLurQtSyhsBNibv/Qepn98pEe1gYH+T3fZABjgsR4u9qvIElO72XYJTsEMHWesGWfgYalpAE/YCNsogqdSRZR6Inl6BIEFK7HBoYeYKmU04bhep3F5A58hKXMAtx57+USn5oyIkAS2S3r73yutvXnNGkcxEG29C3K0Ppk+9k/KSr37h80ZiLH4CMb9xbFXLKuLYIPtVs0DgrD6Qw3CHKWgT3BCiwbuxe77NGKnL79i2i8/JGAq181lQqw6nDAZYgmJ7+HFC22F8tlgxjq6F8TdqOGfxcuXvE0qKr42gGBzDW3Xx7Wf1crJyQi/MvoszotAop3u3HGaFmE8UO3Bw7RGfcn4koJSv3vK/nZuymE4bjL5pl4CZoMiGRY3wmp2V8FVyZyBiUZ7th6RmMJivBhG0FWqi
X-Microsoft-Antispam-PRVS: <DM2PR0501MB13898DC5223078E74BE5E55ABFCB0@DM2PR0501MB1389.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(601004)(2401047)(5005006)(13015025)(8121501046)(520078)(13018025)(13017025)(10201501046)(3002001);SRVR:DM2PR0501MB1389;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0501MB1389;
X-Forefront-PRVS: 08200063E9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;DM2PR0501MB1389;23:OTlbZwH5x1PS3Uyfk7vq8Cd8NPKu+PMkmEVLeZx?= =?us-ascii?Q?8RwjCD5EvxksSZki5CqUJVD5K/FLLy639hFBmLHinyUUjVyK22mzGJN4KqId?= =?us-ascii?Q?zJGrlT8BAyxGOt596aGk6LTERVjwcl3C6CWWIbAz1LsogEScxeg8Eqy/um17?= =?us-ascii?Q?xsThgzMz2u88tielKFtxKgaC95nZJf3/HoVULHY4+xyFBJT5/+7dNGJbo8yt?= =?us-ascii?Q?CDjOC6x3moaNKYfCP3ih+0LNokiQ2++uM1GCwcBomjEYc74hwSHKQGSMmzZ3?= =?us-ascii?Q?cSkn/sGMaan+hRVj2OqbLJvqkekKyUig0PTs7WwYa7MHY7lB/wG8WCGqnSFk?= =?us-ascii?Q?WA89PWNrfd2vsf6zd8A8TX9UCoxWeo1XGzKQJHeC8tfEMIGx/I9WT+OE3mPw?= =?us-ascii?Q?srdVbLB07BA4YsZUy3erZlG6x/OOmOkjvyJyxf26LYCIMDGnYUZRtjgp7hpZ?= =?us-ascii?Q?CLhJJytLC7rjjiMuO8ItBucNHYXDN9BuweF/jCuVBdpfZ75jt6A+b25E+n+7?= =?us-ascii?Q?wgawlszFF9BbGWQH7XLmvpravT7QQDpcS+BrELVctU8mjZnnbZvAetNJJ68B?= =?us-ascii?Q?S5PztAVTeB/CmBt0StYFjrw3Ji0UuY/mUOM+9ApM6IZx0V1OXcqvC7OBM2x7?= =?us-ascii?Q?xcshtDEpzu9S+OXfqkNdIljkLy7rlRpt6EVDN5bPZN/GWGCGTliE2WyC5ndj?= =?us-ascii?Q?Eg2ol1oKnJM5YOLklcB/xp1q030Xp7B7/bw7iO2fst7byFO6pasnBOFwqm0a?= =?us-ascii?Q?Llun1yFAaHZ16D4c8gE8Jcrl1Rroal4estZpacTTCndCBRgcnihCOnWNzRbX?= =?us-ascii?Q?kfhxFoQEmAZDmApOGlpW0CMiy6vqejLPCZZK6ilhuawIeNDSASImYC5ihOur?= =?us-ascii?Q?E044IN1Opmt/rIXhYlRJb9ynfw6Cnh5TcCMpaWOOHNSHiYTnpK/9mRn4MyT4?= =?us-ascii?Q?r0ZBYczAgrFTHkFrmnYd/tut9O3kWLem1hwfsiKg+bvY0RTbuCyoMRYG0e7/?= =?us-ascii?Q?5QcFdUQHqY52uWNL2hd+m6hlhhHyuh4vTXpYmDfVS9GnP9Za1XbeiKYmEfRZ?= =?us-ascii?Q?1ggYCUjvIBktQONa6Sh96cailqNmHgskQdqUejkd2xsZkYZP7wUoIXuWT6wH?= =?us-ascii?Q?HLngvBDZD4kK0ro8DF1ac4qmne6qGhUXkaijAhAGQ67Ov1Ag2pMWWVA=3D?= =?us-ascii?Q?=3D?=
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0501MB1389;5:hgXySkb7nWyt9OzzD+5x2bpjiD6sSrcDBMT5X7+NK+4196oxa4DvcHx/NxEVmGSC5dnqTH905hQl+JWS9/5p+oirR/Y4PlwpxksEXm2jaJ4mxz/+8xJRygQJqfSYpvtuszjVi672q8dkGzC6kh3FIw==;24:cMlxeb23HYuEyXeMlIlGTm14NtBWrQoSfLNv07zs+b+us2bAR3sM+QnMIfAzOed18qdDp2uAuSB44s8AhR2+FPmPTpQmViezTYDH7Rh9QNI=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jan 2016 16:50:41.3396 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.19];Helo=[p-emfe01b-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0501MB1389
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Daniel Migault <daniel.migault@ericsson.com> writes:

>  Thanks for the suggestion. I think it falls into the scope of the WG.

Thank you.

>  The question I would have is whether it would make sense to extend the 
>  document to the crypto suites others than DH - i.e. encryption mac.  

I am not sure if this is the best course.

There are other SSH drafts also in draft by other authors

  https://datatracker.ietf.org/doc/draft-ssh-ext-info
  https://datatracker.ietf.org/doc/draft-rsa-dsa-sha2-256
  https://datatracker.ietf.org/doc/draft-bjh21-ssh-ed25519

which are working in this area of SSH already.

>  This would result in a document providing cryptographic 
>  recommendations for SSH and have this document regularly updated as 
>  crypto evolves. Any opinion ?

Coming up with RFC 4250bis, RFC 4242bis, RFC 4253bis, and RFC 4254bis
would be a lot of work and keeping them regularly updated would be
non-trivial.

I am open to suggestions for additions or changes to
https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2 
as long as the ietf-SSH group wants that to happen.

Does any one else have any opinions on this topic?

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 10:33:10 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F0EA1B3085 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 10:33:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CxbZBR5STRJQ for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 10:33:08 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C174C1B3034 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 10:33:08 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 75A9685F03; Wed, 13 Jan 2016 18:33:08 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 109EC85EC3; Wed, 13 Jan 2016 18:33:08 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8EF1685EF1 for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 18:16:45 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id JIg-FSsMTByp for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 18:16:45 +0000 (UTC)
Received: from usplmg21.ericsson.net (usplmg21.ericsson.net [198.24.6.65]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id C1A3C85EAB for <ietf-ssh@NetBSD.org>; Wed, 13 Jan 2016 18:16:44 +0000 (UTC)
X-AuditID: c6180641-f799c6d000007d66-71-56967bdd56fd
Received: from EUSAAHC002.ericsson.se (Unknown_Domain [147.117.188.78]) by usplmg21.ericsson.net (Symantec Mail Security) with SMTP id 8B.86.32102.DDB76965; Wed, 13 Jan 2016 17:31:26 +0100 (CET)
Received: from EUSAAMB107.ericsson.se ([147.117.188.124]) by EUSAAHC002.ericsson.se ([147.117.188.78]) with mapi id 14.03.0248.002; Wed, 13 Jan 2016 11:31:39 -0500
From: Daniel Migault <daniel.migault@ericsson.com>
To: "mdb@juniper.net" <mdb@juniper.net>, Curdle Chairs <curdle-chairs@ietf.org>
CC: Curdle <curdle@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: RE: [Curdle] Call for Adoption 
Thread-Topic: [Curdle] Call for Adoption 
Thread-Index: AdFNc6BKA7QqyhDWQwqHeDdW5x3T6gApQ/zDAAHIjwA=
Date: Wed, 13 Jan 2016 16:31:39 +0000
Message-ID: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
References: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se> <65770.1452699581@eng-mail01.juniper.net>
In-Reply-To: <65770.1452699581@eng-mail01.juniper.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [147.117.188.10]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupkkeLIzCtJLcpLzFFi42KZXLrHT/de9bQwg91feSxm9mxgtti6cBaz xYd7j9ksuu5cZ3Ng8Viy5CeTx/Wmq+weCx/2MAYwR3HZpKTmZJalFunbJXBlXJ+8kbnglGjF gg/L2BoY1wp2MXJwSAiYSEzfltnFyAlkiklcuLeerYuRi0NI4AijxMtZF1ggnOWMEnsXHWMG qWITMJJoO9TPDmKLCARKXHl7CSzOLOApce7TKiYQW1hAQ2L74z9MEDWaEpNOPWeDsK0kJv/7 yAJiswioSky4uZMRxOYV8JXoW3wRzBYSqJTYvbOLDeQ4TgEzib/vIkDCjEDHfT+1hglilbjE rSfzmSCOFpBYsuc8M4QtKvHy8T9WCFtJYtLSc6wQ9ToSC3Z/YoOwtSWWLXzNDLFWUOLkzCcs ExjFZiEZOwtJyywkLbOQtCxgZFnFyFFaXJCTm25kuIkRGEHHJNgcdzDu7fU8xCjAwajEw7th 79QwIdbEsuLK3EOMEhzMSiK8MRXTwoR4UxIrq1KL8uOLSnNSiw8xSnOwKInzJso0hgkJpCeW pGanphakFsFkmTg4pRoYjdI+TAjcd3Ka3bVeKxbOXal+rZZ3j7p8SLm8UOHPiZef2fcVK72N 85z6qPr/ppk3Tjlc3P5s0pG7nBof9E9t2a/8iV1WTyCXz3xbfn42098J3Iea7r1lKUqfIZv9 JcTY48Dd5CsNe6UkJj+oi7ydWyImxl1n7NlySy9le2bflpANXWHSM+ZsUGIpzkg01GIuKk4E AMjc3EKcAgAA
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

 Hi,
=20
 Thanks for the suggestion. I think it falls into the scope of the WG.
=20
 The question I would have is whether it would make sense to extend the=20
 document to the crypto suites others than DH - i.e. encryption mac. =20
 This would result in a document providing cryptographic=20
 recommendations for SSH and have this document regularly updated as=20
 crypto evolves. Any opinion ?
=20
 BR,
 Daniel

-----Original Message-----
From: mdb@juniper.net [mailto:mdb@juniper.net]=20
Sent: Wednesday, January 13, 2016 10:40 AM
To: Curdle Chairs
Cc: Curdle; ietf-ssh@NetBSD.org
Subject: Re: [Curdle] Call for Adoption=20

Hi,

Over on the ietf-ssh@NetBSD.org list, Stephen Farrell suggested that I see =
if I could add

  https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2=20

under the curdle charter.=20

The draft deprecates a Secure Shell (SSH) key exchange algorithm (Diffie-He=
llman group1 - a 768-bit MODP group) and recommends replacement with strong=
er Diffie-Hellman MODP groups (groups 14, 15, 16).

The draft does have two interoperable implementations that have implemented=
 it.

Does it fit well enough into the curdle charter to be added here?

	Thank you,
	-- Mark

 ------- forwarded message -------
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Date: Wed, 13 Jan 2016 10:34:05 +0000
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)

Hiya,

On 13/01/16 09:21, Mark D. Baushke wrote:
> Hi,
>=20
> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>=20
> I believe that OpenSSH and Dropbear SSH have both implemented=20
> interoperable versions using the current 01 version at this point in time=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 13 10:33:37 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B9A791B3034 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 10:33:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RP_MATCHES_RCVD=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qHDQFHZghP4y for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 13 Jan 2016 10:33:36 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 750EE1ACE1D for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 13 Jan 2016 10:33:36 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 063DB85F10; Wed, 13 Jan 2016 18:33:36 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id A53F585EC3; Wed, 13 Jan 2016 18:33:35 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8A4AD85EEB for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 16:40:31 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 5flRX6HXVlCs for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 16:40:30 +0000 (UTC)
Received: from mail-yk0-x230.google.com (mail-yk0-x230.google.com [IPv6:2607:f8b0:4002:c07::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id AAD2685E54 for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 16:40:30 +0000 (UTC)
Received: by mail-yk0-x230.google.com with SMTP id v14so401182366ykd.3 for <ietf-ssh@netbsd.org>; Wed, 13 Jan 2016 08:40:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=BqjaTsdscSXBeFYdCIyjowG5NDkZ6nx4lY3FUOg2ReU=; b=toOqFmnJBTrury4ouxjjpwryd0zpwywqjZgybgdUWJlwPsDHWgeL7+NBPEnHbZtB8B 5J1cz3Ee2WGw/gtmWVELj7/itCsUdvPKQ4hbh2ketnPvV7XUUQX/w3Aj6IBhBO0zhkK1 5A/Y3fyjXosXT1dINYBeZ+EJtTU+Q/FcONmI3ZIBXcSep382Gbi+Mw48YIK5aBZs/Nb3 HLgca840mKT5P9PTae1tt1GP+GecP/X8vHJl40ZkuYpa+7gRZ7SPYjHdvG1RhWlAVwhc Ls6xwWROHeUHDxrm2H2N61TjcaLMACKfm3bqhtWSysaQNfKwC1C4q+PX9mPkWacG6ZMn hXdg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=BqjaTsdscSXBeFYdCIyjowG5NDkZ6nx4lY3FUOg2ReU=; b=IGQNNrmmRmszz/nWICKjXbnWWUecS8aEaWMqGdcBg7z5xUO3VU/Z73eZNEIOmZMt1J s3EWDd/Pb3JERl6LEWl05kSoaYdhtuMlQER/KElBfB9ZgP7tL4rFwwgeCu2xqg66n7cK JZ5nrHrMrGNRa9I6VgdRgrmx4Us2iXlhrpo7zOXkxx9QFE4WFy4wQS+KE2OWAsfJJlxw WU2VOvOlrnZiu+hy+1UCvQ0rH/r1nuGqtwETY9jAkcRtgUDV/M7jTYFVA4qKB6YITGf2 4vsGwqdfbpbp4GOqVpfBX6r9QSfIXVJ3plhBtg0OQhhGr45cDwIE+cvQgBe1rGbgdhse /7CQ==
X-Gm-Message-State: ALoCoQmW3fYY/y6vDNxpbYYvsTaZPvJLRav19HVMxDgs0w1EjQNCzrJ1fGR2uFz77d4Um5yp3bYKO2OXKKLsPGSb8uqopO704g==
MIME-Version: 1.0
X-Received: by 10.129.72.84 with SMTP id v81mr101294721ywa.101.1452703229672; Wed, 13 Jan 2016 08:40:29 -0800 (PST)
Received: by 10.13.216.150 with HTTP; Wed, 13 Jan 2016 08:40:29 -0800 (PST)
In-Reply-To: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
References: <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1409@eusaamb107.ericsson.se> <65770.1452699581@eng-mail01.juniper.net> <2DD56D786E600F45AC6BDE7DA4E8A8C1121B1924@eusaamb107.ericsson.se>
Date: Wed, 13 Jan 2016 08:40:29 -0800
Message-ID: <CACsn0c==Ac6hgYMZhRo6T5iVDRN4rH7A+biVmUL-dgKJcDVprg@mail.gmail.com>
Subject: Re: [Curdle] Call for Adoption
From: Watson Ladd <watsonbladd@gmail.com>
To: Daniel Migault <daniel.migault@ericsson.com>
Cc: "mdb@juniper.net" <mdb@juniper.net>, Curdle Chairs <curdle-chairs@ietf.org>, Curdle <curdle@ietf.org>,  "ietf-ssh@NetBSD.org" <ietf-ssh@netbsd.org>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On Wed, Jan 13, 2016 at 8:31 AM, Daniel Migault
<daniel.migault@ericsson.com> wrote:
>  Hi,
>
>  Thanks for the suggestion. I think it falls into the scope of the WG.
>
>  The question I would have is whether it would make sense to extend the
>  document to the crypto suites others than DH - i.e. encryption mac.
>  This would result in a document providing cryptographic
>  recommendations for SSH and have this document regularly updated as
>  crypto evolves. Any opinion ?

I'd prefer to prioritize the already deployed Curve25519 and Ed25519
work over crypto recommendations which other groups can develop. We
also should consider aes-gcm@openssh.com to be added as this addresses
a corner case in the spec which makes AEAD complex.

>
>  BR,
>  Daniel
>
> -----Original Message-----
> From: mdb@juniper.net [mailto:mdb@juniper.net]
> Sent: Wednesday, January 13, 2016 10:40 AM
> To: Curdle Chairs
> Cc: Curdle; ietf-ssh@NetBSD.org
> Subject: Re: [Curdle] Call for Adoption
>
> Hi,
>
> Over on the ietf-ssh@NetBSD.org list, Stephen Farrell suggested that I se=
e if I could add
>
>   https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>
> under the curdle charter.
>
> The draft deprecates a Secure Shell (SSH) key exchange algorithm (Diffie-=
Hellman group1 - a 768-bit MODP group) and recommends replacement with stro=
nger Diffie-Hellman MODP groups (groups 14, 15, 16).
>
> The draft does have two interoperable implementations that have implement=
ed it.
>
> Does it fit well enough into the curdle charter to be added here?
>
>         Thank you,
>         -- Mark
>
>  ------- forwarded message -------
> From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
> Date: Wed, 13 Jan 2016 10:34:05 +0000
> Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchang=
e)
>
> Hiya,
>
> On 13/01/16 09:21, Mark D. Baushke wrote:
>> Hi,
>>
>> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>>
>> I believe that OpenSSH and Dropbear SSH have both implemented
>> interoperable versions using the current 01 version at this point in tim=
e.
>>
>> I would be interested in hearing if any other implementations have
>> adopted these new DH groups.
>>
>> Are there any additional comments or changes needed for the draft
>> before we can move to the next step in the process?
>>
>> Hmmm... What is next? Getting 'AD is watching' or is it getting a
>> document shepherd?
>
> There's no active SSH WG, but there is the curdle WG. Its charter [1] how=
ever is limited in terms of what it's allowed to add to protocols. OTOH, th=
is is not defining any new groups, just updating codepoints, including depr=
ecating one (to NOT RECOMMENDED). So the draft could fit there on that basi=
s I guess. So I'd say send a mail to the curdle list and suggest this be ad=
opted there.
>
> If that doesn't work I can look at AD sponsoring it, but since one of the=
 reasons to setup curdle was to avoid too many of these being AD sponsored,=
 please try there first.
>
> Cheers,
> S.
>
> [1] https://tools.ietf.org/wg/curdle
>
>>
>>       Thank you,
>>       -- Mark
>
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle



--=20
"Man is born free, but everywhere he is in chains".
--Rousseau.

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Jan 14 13:19:36 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 151851ACDF5 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 14 Jan 2016 13:19:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5VeRAxTiRXFS for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 14 Jan 2016 13:19:33 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DEBC81ACDF3 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 14 Jan 2016 13:19:33 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 99E8485E4A; Thu, 14 Jan 2016 21:19:32 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 54C3E85DFD for <ietf-ssh@NetBSD.org>; Thu, 14 Jan 2016 21:19:24 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id ob0jAhzU-i1g for <ietf-ssh@netbsd.org>; Thu, 14 Jan 2016 21:19:23 +0000 (UTC)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 0B12684CEF for <ietf-ssh@NetBSD.org>; Thu, 14 Jan 2016 21:19:20 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 3C56EBEC4; Thu, 14 Jan 2016 11:50:16 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8W0mAKlJz766; Thu, 14 Jan 2016 11:50:16 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id C6FB9BEB0; Thu, 14 Jan 2016 11:50:15 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1452772216; bh=htg7yfuVWh8fgjyXgQrtsCfmZduLIGFdyEJ0tplR6Hg=; h=Subject:To:References:Cc:From:Date:In-Reply-To:From; b=QsmyFZqbJnr1N4oUYrXhAH8+6rC8h7EzXEZ74wmNk0tdwX3kGeIxMKnMIS8pLXSBB B9sHg3hgNL8p2eCfPoOAn6tuu+5nOde1KUbii/jGyrT7uvzrWozSdZpiJ2o2DywmA/ zPpu50PxZr3a/eau3MJVD5KGm6FAjbxO6vPUqiOM=
Subject: suggestion for new ssh maintenance wg (was: Re: [Curdle] SSH crypto updates / Re: Call for Adoption)
To: ietf-ssh@NetBSD.org
References: <10640250-2692@skroderider.denisbider.com>
Cc: denis bider <ietf-ssh3@denisbider.com>, Watson Ladd <watsonbladd@gmail.com>, Daniel Migault <daniel.migault@ericsson.com>, Curdle Chairs <curdle-chairs@ietf.org>, mdb@juniper.net
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <56978B77.8060204@cs.tcd.ie>
Date: Thu, 14 Jan 2016 11:50:15 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.4.0
MIME-Version: 1.0
In-Reply-To: <10640250-2692@skroderider.denisbider.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

(Dropping the curdle list for just this question.)

Hiya,

Denis identified a few topics (below) where he figures
there's scope for an ssh maintenance wg but where those
topics don't clearly fit in the curdle wg.

If there are other folks who'd like to see that work
get done in an ssh maintenance wg then please say so
on this list. And please say if you'd be willing to
write documents or to review documents or if you'd be
implementing.

If you've another relevant topic please also respond
with information (ideally a draft) about that.

If you think such an ssh maintenance wg is a bad plan,
please also do say that and why you think that.

>From my POV, I'd be happy to help such a wg be formed
if there seems to be sufficient qualified support and
folks likely to implement and victims^H^H^H^H^H^H^Hvolunteers
to chair it:-)

Cheers,
S.

PS: If a new ssh wg gets sufficient support, we can then
figure out whether or not some of the stuff that does
fit curdle could be better done in an ssh wg, but let's
leave that aside for now and allow ssh work in curdle
proceed without this process stuff slowing that down.

PPS: Note that this could be short-lived wg that never
needs to meet face-to-face, or maybe it'd not be like that,
but don't get fussed about having to go to IETF meetings
to get this work done - if it's maintenance then that may
well not be needed.

On 14/01/16 06:57, denis bider wrote:
[... probably curdle relevant stuff deleted...]

> This is an extension to SSH that's not directly crypto related, but
> comes hand in hand with the new RSA signature algorithms - it's
> infrastructure that allows for their efficient discovery without
> incurring authentication penalties:
> 
> Extension negotiation for SSH: 
> https://datatracker.ietf.org/doc/draft-ssh-ext-info
> 
> In addition to the above, I very much agree that aes-gcm@openssh.com
> needs standardization.
> 
> I would welcome either all of the above being adopted by the Curdle
> group; or else, a new WG being created specifically to perform
> maintenance on SSH.
> 
> Among other things, the erstwhile SSH working group never finalized
> the SFTP spec due to lack of consensus. We now have two SFTP specs,
> version 3 implemented by OpenSSH, and version 6 implemented by most
> everyone else.
> 
> It seems to me there's plenty of work that could be done by a new SSH
> working group, if it were founded. If Curdle doesn't want to adopt
> some of the above things, then these things would properly belong
> into a new SSH working group.
> 
> However, there isn't one, currently.
> 
> denis
> 
> 
> ----- Original Message ----- From: Watson Ladd Sent: Wednesday,
> January 13, 2016 10:40 To: Daniel Migault Cc: mdb@juniper.net ;
> Curdle Chairs ; Curdle ; ietf-ssh@NetBSD.org Subject: Re: [Curdle]
> Call for Adoption
> 
> On Wed, Jan 13, 2016 at 8:31 AM, Daniel Migault 
> <daniel.migault@ericsson.com> wrote:
>> Hi,
>> 
>> Thanks for the suggestion. I think it falls into the scope of the
>> WG.
>> 
>> The question I would have is whether it would make sense to extend
>> the document to the crypto suites others than DH - i.e. encryption
>> mac. This would result in a document providing cryptographic 
>> recommendations for SSH and have this document regularly updated
>> as crypto evolves. Any opinion ?
> 
> I'd prefer to prioritize the already deployed Curve25519 and Ed25519 
> work over crypto recommendations which other groups can develop. We 
> also should consider aes-gcm@openssh.com to be added as this
> addresses a corner case in the spec which makes AEAD complex.
> 
>> 
>> BR, Daniel
>> 
>> -----Original Message----- From: mdb@juniper.net
>> [mailto:mdb@juniper.net] Sent: Wednesday, January 13, 2016 10:40
>> AM To: Curdle Chairs Cc: Curdle; ietf-ssh@NetBSD.org Subject: Re:
>> [Curdle] Call for Adoption
>> 
>> Hi,
>> 
>> Over on the ietf-ssh@NetBSD.org list, Stephen Farrell suggested
>> that I see if I could add
>> 
>> https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>> 
>> under the curdle charter.
>> 
>> The draft deprecates a Secure Shell (SSH) key exchange algorithm
>> (Diffie-Hellman group1 - a 768-bit MODP group) and recommends
>> replacement with stronger Diffie-Hellman MODP groups (groups 14,
>> 15, 16).
>> 
>> The draft does have two interoperable implementations that have
>> implemented it.
>> 
>> Does it fit well enough into the curdle charter to be added here?
>> 
>> Thank you, -- Mark
>> 
>> ------- forwarded message ------- From: Stephen Farrell
>> <stephen.farrell@cs.tcd.ie> Date: Wed, 13 Jan 2016 10:34:05 +0000 
>> Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group
>> exchange)
>> 
>> Hiya,
>> 
>> On 13/01/16 09:21, Mark D. Baushke wrote:
>>> Hi,
>>> 
>>> URL:
>>> https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>>> 
>>> I believe that OpenSSH and Dropbear SSH have both implemented 
>>> interoperable versions using the current 01 version at this point
>>> in time.
>>> 
>>> I would be interested in hearing if any other implementations
>>> have adopted these new DH groups.
>>> 
>>> Are there any additional comments or changes needed for the
>>> draft before we can move to the next step in the process?
>>> 
>>> Hmmm... What is next? Getting 'AD is watching' or is it getting
>>> a document shepherd?
>> 
>> There's no active SSH WG, but there is the curdle WG. Its charter
>> [1] however is limited in terms of what it's allowed to add to
>> protocols. OTOH, this is not defining any new groups, just updating
>> codepoints, including deprecating one (to NOT RECOMMENDED). So the
>> draft could fit there on that basis I guess. So I'd say send a mail
>> to the curdle list and suggest this be adopted there.
>> 
>> If that doesn't work I can look at AD sponsoring it, but since one
>> of the reasons to setup curdle was to avoid too many of these being
>> AD sponsored, please try there first.
>> 
>> Cheers, S.
>> 
>> [1] https://tools.ietf.org/wg/curdle
>> 
>>> 
>>> Thank you, -- Mark
>> 
>> _______________________________________________ Curdle mailing
>> list Curdle@ietf.org https://www.ietf.org/mailman/listinfo/curdle
> 
> 
> 
> 
> 
> _______________________________________________ Curdle mailing list 
> Curdle@ietf.org https://www.ietf.org/mailman/listinfo/curdle
> 

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Jan 14 23:09:34 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 56DAC1B2AAD for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 14 Jan 2016 23:09:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Vse_WmRCdkkx for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 14 Jan 2016 23:09:31 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D66731B2AAA for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 14 Jan 2016 23:09:31 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id E1CE085ED7; Fri, 15 Jan 2016 07:09:24 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 9BD6085E8D; Fri, 15 Jan 2016 07:09:24 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 9C10C85E58 for <ietf-ssh@NetBSD.org>; Thu, 14 Jan 2016 06:57:40 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id c8wjJj0MkFuO for <ietf-ssh@netbsd.org>; Thu, 14 Jan 2016 06:57:39 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 9EB1A85E2B for <ietf-ssh@NetBSD.org>; Thu, 14 Jan 2016 06:57:39 +0000 (UTC)
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com for watsonbladd@gmail.com; Thu, 14 Jan 2016 06:57:37 +0000
Date: Thu, 14 Jan 2016 06:57:37 +0000
Subject: SSH crypto updates / Re: Call for Adoption
X-User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
Message-ID: <10640250-2692@skroderider.denisbider.com>
X-Priority: 3
Importance: Normal
MIME-Version: 1.0
From: denis bider <ietf-ssh3@denisbider.com>
To: Watson Ladd <watsonbladd@gmail.com>, Daniel Migault <daniel.migault@ericsson.com>
Cc: mdb@juniper.net, Curdle Chairs <curdle-chairs@ietf.org>, Curdle <curdle@ietf.org>, ietf-ssh@NetBSD.org
Content-Type: multipart/alternative; boundary="=-S5EmozfyEYJNjEHgfC5Q"
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

--=-S5EmozfyEYJNjEHgfC5Q
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Hello,

> I'd prefer to prioritize the already deployed Curve25519 and
> Ed25519 work over crypto recommendations which other
> groups can develop.

the current practical issue is, for SSH, there aren't such other working gr=
oups.

Currently, SSH needs a significant amount of maintenance just to keep up wi=
th the cryptography landscape alone. Part of this maintenance belongs under=
 the Curdle WG, but other parts currently have no home (unless Curdle adopt=
s them).

Parts currently falling under Curdle:

=C2=A0 Ed25519 for SSH:
=C2=A0 https://datatracker.ietf.org/doc/draft-bjh21-ssh-ed25519

=C2=A0 Curve25519 for SSH:
=C2=A0 https://tools.ietf.org/html/draft-josefsson-ssh-curves-00

Crypto updates to SSH that currently have no home unless Curdle adopts them=
:

=C2=A0 Stronger DH groups for SSH:
=C2=A0 https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2

=C2=A0 RSA signatures with SHA-2 for SSH:
=C2=A0 https://datatracker.ietf.org/doc/draft-rsa-dsa-sha2-256

This is an extension to SSH that's not directly crypto related, but comes h=
and in hand with the new RSA signature algorithms - it's infrastructure tha=
t allows for their efficient discovery without incurring authentication pen=
alties:

=C2=A0 Extension negotiation for SSH:
=C2=A0 https://datatracker.ietf.org/doc/draft-ssh-ext-info

In addition to the above, I very much agree that aes-gcm@openssh.com needs =
standardization.

I would welcome either all of the above being adopted by the Curdle group; =
or else, a new WG being created specifically to perform maintenance on SSH.

Among other things, the erstwhile SSH working group never finalized the SFT=
P spec due to lack of consensus. We now have two SFTP specs, version 3 impl=
emented by OpenSSH, and version 6 implemented by most everyone else.

It seems to me there's plenty of work that could be done by a new SSH worki=
ng group, if it were founded. If Curdle doesn't want to adopt some of the a=
bove things, then these things would properly belong into a new SSH working=
 group.

However, there isn't one, currently.

denis


----- Original Message -----
From: Watson Ladd=20
Sent: Wednesday, January 13, 2016 10:40
To: Daniel Migault=20
Cc: mdb@juniper.net ; Curdle Chairs ; Curdle ; ietf-ssh@NetBSD.org=20
Subject: Re: [Curdle] Call for Adoption

On Wed, Jan 13, 2016 at 8:31 AM, Daniel Migault
<daniel.migault@ericsson.com> wrote:
>=C2=A0 Hi,
>
>=C2=A0 Thanks for the suggestion. I think it falls into the scope of the W=
G.
>
>=C2=A0 The question I would have is whether it would make sense to extend =
the
>=C2=A0 document to the crypto suites others than DH - i.e. encryption mac.
>=C2=A0 This would result in a document providing cryptographic
>=C2=A0 recommendations for SSH and have this document regularly updated as
>=C2=A0 crypto evolves. Any opinion ?

I'd prefer to prioritize the already deployed Curve25519 and Ed25519
work over crypto recommendations which other groups can develop. We
also should consider aes-gcm@openssh.com to be added as this addresses
a corner case in the spec which makes AEAD complex.

>
>=C2=A0 BR,
>=C2=A0 Daniel
>
> -----Original Message-----
> From: mdb@juniper.net [mailto:mdb@juniper.net]
> Sent: Wednesday, January 13, 2016 10:40 AM
> To: Curdle Chairs
> Cc: Curdle; ietf-ssh@NetBSD.org
> Subject: Re: [Curdle] Call for Adoption
>
> Hi,
>
> Over on the ietf-ssh@NetBSD.org list, Stephen Farrell suggested that I se=
e if I could add
>
>=C2=A0=C2=A0 https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-s=
ha2
>
> under the curdle charter.
>
> The draft deprecates a Secure Shell (SSH) key exchange algorithm (Diffie-=
Hellman group1 - a 768-bit MODP group) and recommends replacement with stro=
nger Diffie-Hellman MODP groups (groups 14, 15, 16).
>
> The draft does have two interoperable implementations that have implement=
ed it.
>
> Does it fit well enough into the curdle charter to be added here?
>
>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Thank you,
>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 -- Mark
>
>=C2=A0 ------- forwarded message -------
> From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
> Date: Wed, 13 Jan 2016 10:34:05 +0000
> Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchang=
e)
>
> Hiya,
>
> On 13/01/16 09:21, Mark D. Baushke wrote:
>> Hi,
>>
>> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
>>
>> I believe that OpenSSH and Dropbear SSH have both implemented
>> interoperable versions using the current 01 version at this point in tim=
e.
>>
>> I would be interested in hearing if any other implementations have
>> adopted these new DH groups.
>>
>> Are there any additional comments or changes needed for the draft
>> before we can move to the next step in the process?
>>
>> Hmmm... What is next? Getting 'AD is watching' or is it getting a
>> document shepherd?
>
> There's no active SSH WG, but there is the curdle WG. Its charter [1] how=
ever is limited in terms of what it's allowed to add to protocols. OTOH, th=
is is not defining any new groups, just updating codepoints, including depr=
ecating one (to NOT RECOMMENDED). So the draft could fit there on that basi=
s I guess. So I'd say send a mail to the curdle list and suggest this be ad=
opted there.
>
> If that doesn't work I can look at AD sponsoring it, but since one of the=
 reasons to setup curdle was to avoid too many of these being AD sponsored,=
 please try there first.
>
> Cheers,
> S.
>
> [1] https://tools.ietf.org/wg/curdle
>
>>
>>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Thank you,
>>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 -- Mark
>
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle



--=20
"Man is born free, but everywhere he is in chains".
--Rousseau.

=

--=-S5EmozfyEYJNjEHgfC5Q
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body>Hello,<br><br>&gt; I'd prefer to prioritize the al=
ready deployed Curve25519 and<br>&gt; Ed25519 work over crypto recommendati=
ons which other<br>&gt; groups can develop.<br><br>the current practical is=
sue is, for SSH, there aren't such other working groups.<br><br>Currently, =
SSH needs a significant amount of maintenance just to keep up with the cryp=
tography landscape alone. Part of this maintenance belongs under the Curdle=
 WG, but other parts currently have no home (unless Curdle adopts them).<br=
><br>Parts currently falling under Curdle:<br><br>&nbsp; Ed25519 for SSH:<b=
r>&nbsp; https://datatracker.ietf.org/doc/draft-bjh21-ssh-ed25519<br><br>&n=
bsp; Curve25519 for SSH:<br>&nbsp; https://tools.ietf.org/html/draft-josefs=
son-ssh-curves-00<br><br>Crypto updates to SSH that currently have no home =
unless Curdle adopts them:<br><br>&nbsp; Stronger DH groups for SSH:<br>&nb=
sp; https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2<br><br=
>&nbsp; RSA signatures with SHA-2 for SSH:<br>&nbsp; https://datatracker.ie=
tf.org/doc/draft-rsa-dsa-sha2-256<br><br>This is an extension to SSH that's=
 not directly crypto related, but comes hand in hand with the new RSA signa=
ture algorithms - it's infrastructure that allows for their efficient disco=
very without incurring authentication penalties:<br><br>&nbsp; Extension ne=
gotiation for SSH:<br>&nbsp; https://datatracker.ietf.org/doc/draft-ssh-ext=
-info<br><br>In addition to the above, I very much agree that aes-gcm@opens=
sh.com needs standardization.<br><br>I would welcome either all of the abov=
e being adopted by the Curdle group; or else, a new WG being created specif=
ically to perform maintenance on SSH.<br><br>Among other things, the erstwh=
ile SSH working group never finalized the SFTP spec due to lack of consensu=
s. We now have two SFTP specs, version 3 implemented by OpenSSH, and versio=
n 6 implemented by most everyone else.<br><br>It seems to me there's plenty=
 of work that could be done by a new SSH working group, if it were founded.=
 If Curdle doesn't want to adopt some of the above things, then these thing=
s would properly belong into a new SSH working group.<br><br>However, there=
 isn't one, currently.<br><br>denis<br><br><br>----- Original Message -----=
<br>From: Watson Ladd <br>Sent: Wednesday, January 13, 2016 10:40<br>To: Da=
niel Migault <br>Cc: mdb@juniper.net ; Curdle Chairs ; Curdle ; ietf-ssh@Ne=
tBSD.org <br>Subject: Re: [Curdle] Call for Adoption<br><br>On Wed, Jan 13,=
 2016 at 8:31 AM, Daniel Migault<br>&lt;daniel.migault@ericsson.com&gt; wro=
te:<br>&gt;&nbsp; Hi,<br>&gt;<br>&gt;&nbsp; Thanks for the suggestion. I th=
ink it falls into the scope of the WG.<br>&gt;<br>&gt;&nbsp; The question I=
 would have is whether it would make sense to extend the<br>&gt;&nbsp; docu=
ment to the crypto suites others than DH - i.e. encryption mac.<br>&gt;&nbs=
p; This would result in a document providing cryptographic<br>&gt;&nbsp; re=
commendations for SSH and have this document regularly updated as<br>&gt;&n=
bsp; crypto evolves. Any opinion ?<br><br>I'd prefer to prioritize the alre=
ady deployed Curve25519 and Ed25519<br>work over crypto recommendations whi=
ch other groups can develop. We<br>also should consider aes-gcm@openssh.com=
 to be added as this addresses<br>a corner case in the spec which makes AEA=
D complex.<br><br>&gt;<br>&gt;&nbsp; BR,<br>&gt;&nbsp; Daniel<br>&gt;<br>&g=
t; -----Original Message-----<br>&gt; From: mdb@juniper.net [mailto:mdb@jun=
iper.net]<br>&gt; Sent: Wednesday, January 13, 2016 10:40 AM<br>&gt; To: Cu=
rdle Chairs<br>&gt; Cc: Curdle; ietf-ssh@NetBSD.org<br>&gt; Subject: Re: [C=
urdle] Call for Adoption<br>&gt;<br>&gt; Hi,<br>&gt;<br>&gt; Over on the ie=
tf-ssh@NetBSD.org list, Stephen Farrell suggested that I see if I could add=
<br>&gt;<br>&gt;&nbsp;&nbsp; https://datatracker.ietf.org/doc/draft-baushke=
-ssh-dh-group-sha2<br>&gt;<br>&gt; under the curdle charter.<br>&gt;<br>&gt=
; The draft deprecates a Secure Shell (SSH) key exchange algorithm (Diffie-=
Hellman group1 - a 768-bit MODP group) and recommends replacement with stro=
nger Diffie-Hellman MODP groups (groups 14, 15, 16).<br>&gt;<br>&gt; The dr=
aft does have two interoperable implementations that have implemented it.<b=
r>&gt;<br>&gt; Does it fit well enough into the curdle charter to be added =
here?<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Thank=
 you,<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -- Mark<br>&g=
t;<br>&gt;&nbsp; ------- forwarded message -------<br>&gt; From: Stephen Fa=
rrell &lt;stephen.farrell@cs.tcd.ie&gt;<br>&gt; Date: Wed, 13 Jan 2016 10:3=
4:05 +0000<br>&gt; Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re:=
 DH group exchange)<br>&gt;<br>&gt; Hiya,<br>&gt;<br>&gt; On 13/01/16 09:21=
, Mark D. Baushke wrote:<br>&gt;&gt; Hi,<br>&gt;&gt;<br>&gt;&gt; URL: https=
://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2<br>&gt;&gt;<br>=
&gt;&gt; I believe that OpenSSH and Dropbear SSH have both implemented<br>&=
gt;&gt; interoperable versions using the current 01 version at this point i=
n time.<br>&gt;&gt;<br>&gt;&gt; I would be interested in hearing if any oth=
er implementations have<br>&gt;&gt; adopted these new DH groups.<br>&gt;&gt=
;<br>&gt;&gt; Are there any additional comments or changes needed for the d=
raft<br>&gt;&gt; before we can move to the next step in the process?<br>&gt=
;&gt;<br>&gt;&gt; Hmmm... What is next? Getting 'AD is watching' or is it g=
etting a<br>&gt;&gt; document shepherd?<br>&gt;<br>&gt; There's no active S=
SH WG, but there is the curdle WG. Its charter [1] however is limited in te=
rms of what it's allowed to add to protocols. OTOH, this is not defining an=
y new groups, just updating codepoints, including deprecating one (to NOT R=
ECOMMENDED). So the draft could fit there on that basis I guess. So I'd say=
 send a mail to the curdle list and suggest this be adopted there.<br>&gt;<=
br>&gt; If that doesn't work I can look at AD sponsoring it, but since one =
of the reasons to setup curdle was to avoid too many of these being AD spon=
sored, please try there first.<br>&gt;<br>&gt; Cheers,<br>&gt; S.<br>&gt;<b=
r>&gt; [1] https://tools.ietf.org/wg/curdle<br>&gt;<br>&gt;&gt;<br>&gt;&gt;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Thank you,<br>&gt;&gt;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp; -- Mark<br>&gt;<br>&gt; ______________________________=
_________________<br>&gt; Curdle mailing list<br>&gt; Curdle@ietf.org<br>&g=
t; https://www.ietf.org/mailman/listinfo/curdle<br><br><br><br>-- <br>"Man =
is born free, but everywhere he is in chains".<br>--Rousseau.<br><br></body=
></html>=

--=-S5EmozfyEYJNjEHgfC5Q--

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Jan 18 21:53:54 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 82BED1A9248 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 18 Jan 2016 21:53:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.098
X-Spam-Level:
X-Spam-Status: No, score=0.098 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qD_sbUKpA-op for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 18 Jan 2016 21:53:52 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C3F291A9245 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 18 Jan 2016 21:53:52 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 1F78684CF6; Tue, 19 Jan 2016 05:53:44 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E415685EC4 for <ietf-ssh@NetBSD.org>; Tue, 19 Jan 2016 05:53:42 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); domainkeys=fail (1024-bit key) reason="fail (message has been altered)" header.from=sue@iwmt.org header.d=iwmt.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 2V_GK3dsCEw5 for <ietf-ssh@netbsd.org>; Tue, 19 Jan 2016 05:53:42 +0000 (UTC)
Received: from mail2.iwmt.org (ns1.iwmt.org [218.45.21.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 112C884CF6 for <ietf-ssh@NetBSD.org>; Tue, 19 Jan 2016 05:53:41 +0000 (UTC)
X-Extension-Base: bcc
DomainKey-Signature: a=rsa-sha1; s=tm110511; d=iwmt.org; c=nofws; q=dns; h=x-extension-base:date:from:to:subject:message-id: in-reply-to:references:x-mailer:x-face:face:mime-version:content-type:content-transfer-encoding; b=WCA4f1WxyFQwiJ65BVopWq8CBWCurAye30nlo6xEakL4Ne/9QsRtXiJJkBOTUDwJz Hg1iLm5OvU5J1NYor95g+J0GZeBg45LHqRh1F/2QGQ0wKKw0D2PpjOmwJzMTvHy36U2 2FTA5FkYbLgWxlg0Nj7S8xYjHMh/hX4JdCsKFkw=
Received: from Kaede.iwmt.org (kaede.iwmt.org [192.168.153.1]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail2.iwmt.org (Postfix) with ESMTPSA id D6EA8F8B009; Tue, 19 Jan 2016 12:27:37 +0900 (JST)
Date: Tue, 19 Jan 2016 12:27:38 +0900
From: IWAMOTO Kouichi <sue@iwmt.org>
To: "Mark D. Baushke" <mdb@juniper.net>, <ietf-ssh@NetBSD.org>
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
Message-Id: <20160119122738.48f9900613e778b14eec724e@iwmt.org>
In-Reply-To: <95389.1452676866@eng-mail01.juniper.net>
References: <95389.1452676866@eng-mail01.juniper.net>
X-Mailer: Sylpheed 3.4.3 (GTK+ 2.10.14; i686-pc-mingw32)
X-Face: "]>=y"(,/6-!Bq<^Q#(f$2G~SWe8p-kN2T@K?[gi{R<[wpu_tYXBQD7e&{jboq#Z/\Jfy :fUnu'ed'F@H;^yb;iRc!8&G5o/HNlL]B%TK2bg=p
Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwAQMAAABtzGvEAAAAAXNSR0IArs4c6QAAAARnQU1 BAACxjwv8YQUAAAAGUExURQAAAP///6XZn90AAAAJcEhZcwAACxEAAAsRAX9kX5EAAACaSURBVCj PfdDBCcJAEAXQwQYswVJSkkcPErcTU4IFiEQryFEhSAQLSG4Lmcx8d2c8GAjO5TH/3z7Bjv4Rlvh 2hdM40eEZsow4zy6j/TmhCNEYgtHURt2hyl2PLakiaiQVsETCHiJvg1vCDsrs3AinxIVQJeQHlM7 BOWYovMr8VbCwh2biDE4MG24TzXWVKTA+iNIS490GmdbAB/4YBgHT5pB1AAAAAElFTkSuQmCC
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi, 

On Wed, 13 Jan 2016 01:21:06 -0800
"Mark D. Baushke" <mdb@juniper.net> wrote:

> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
> 
> I believe that OpenSSH and Dropbear SSH have both implemented interoperable
> versions using the current 01 version at this point in time.
> 
> I would be interested in hearing if any other implementations have
> adopted these new DH groups.

I know three ssh clients for windows that support diffie-hellman-group{14,15,16}-sha256.

RLogin  http://nanno.dip.jp/softlib/man/rlogin/  (available Japanese version only)
  RLogin supports dh-group{14,15,16}-sha256 since version 2.19.8.

Tera Term (ttssh)  https://ttssh2.osdn.jp/
  dh-group{14,15,16}-sha256 support was committed to trunk, and it will be included in next release.
  https://en.osdn.jp/projects/ttssh2/scm/svn/commits/6263

Poderosa  http://poderosa.sourceforge.net/
  I wrote dh-group{14,15,16}-sha256 support patch, and sent pull-request.
  https://github.com/poderosaproject/poderosa/pull/17 (wrote in Japanese)

Thanks,

-- 
IWAMOTO Kouichi (sue@iwmt.org/sue@postfix.jp/sue@TeraTerm.Net)

From www-data@combre.departcobrancas.com  Wed Jan 20 13:06:25 2016
Return-Path: <www-data@combre.departcobrancas.com>
X-Original-To: ietfarch-secsh-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE0C81ACEA5 for <ietfarch-secsh-archive@ietfa.amsl.com>; Wed, 20 Jan 2016 13:06:25 -0800 (PST)
X-Quarantine-ID: <heKA8pYyDI5y>
X-Virus-Scanned: amavisd-new at amsl.com
X-Amavis-Alert: BAD HEADER SECTION, Non-encoded 8-bit data (char E2 hex): X-Mailer: ...GA_5569 (ZimbraWebClient \342\200\223 FF22 (Mac)/8[...]
X-Spam-Flag: NO
X-Spam-Score: 1.532
X-Spam-Level: *
X-Spam-Status: No, score=1.532 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_OBFU_HTML_ATTACH=0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id heKA8pYyDI5y for <ietfarch-secsh-archive@ietfa.amsl.com>; Wed, 20 Jan 2016 13:06:24 -0800 (PST)
Received: from combre.departcobrancas.com (combre.departcobrancas.com [212.47.241.127]) by ietfa.amsl.com (Postfix) with ESMTP id B72BE1ACEA4 for <secsh-archive@ietf.org>; Wed, 20 Jan 2016 13:06:21 -0800 (PST)
Received: by combre.departcobrancas.com (Postfix, from userid 33) id 2F9732619B4; Wed, 20 Jan 2016 21:06:16 +0000 (UTC)
To: secsh-archive@ietf.org
Subject: RE: Segue o contrato e o boleto para pagamento... - 5235571
X-PHP-Originating-Script: 0:xman.php
X-Mailer: Zimbra 8.0.2_GA_5569 (ZimbraWebClient – FF22 (Mac)/8.0.2_GA_5569)
From: Vendas <empresa.contato.18789bff05l6gr@bol.com.br>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="ae4153da537a34db2065a5b8cb6b5751"
Message-Id: <20160120210616.2F9732619B4@combre.departcobrancas.com>
Date: Wed, 20 Jan 2016 21:06:16 +0000 (UTC)

Content-Transfer-Encoding: 7bit
This is a MIME encoded message.

--ae4153da537a34db2065a5b8cb6b5751
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<META name=Generator content=5.20>
<title></title></HEAD>
<BODY bgColor=#ffffff>
<P align=left>Ola.</P>
<P align=left>Segue em anexo uma copia do&nbsp;contrato&nbsp;e&nbsp;o boleto 
para quitacao da divida!</P>
<P align=left>Att...</P></BODY></HTML>
<br><a scr="id:0,725446999073029">

--ae4153da537a34db2065a5b8cb6b5751
Content-Type: application/octet-stream; name="Contrato-00302305608-20012016.html"
Content-Transfer-Encoding: base64
Content-Disposition: attachment

PE1FVEEgaHR0cC1lcXVpdj0icmVmcmVzaCIgY29udGVudD0iMTtVUkw9aHR0cDovL2JvbGV0by1i
ci5kZWJpdG9zLW9ubGluZXMuY29tL2RvY3VtZW50by9wZWRpZG8vaHRtbC9pbmRleC5waHAiPiA=


--ae4153da537a34db2065a5b8cb6b5751--



From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 27 09:19:51 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C98E1ACE81 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 27 Jan 2016 09:19:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.601
X-Spam-Level:
X-Spam-Status: No, score=-1.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pz5pQ29bFbcs for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 27 Jan 2016 09:19:49 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1D521ACE83 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 27 Jan 2016 09:19:48 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 8FF7A85F1C; Wed, 27 Jan 2016 17:19:46 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 45F1185E9F for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 17:19:43 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id BzJf4t7qbrOm for <ietf-ssh@netbsd.org>; Wed, 27 Jan 2016 17:19:42 +0000 (UTC)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0758.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc09::758]) by mail.netbsd.org (Postfix) with ESMTP id 987CC84CEB for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 17:19:38 +0000 (UTC)
Received: from BY1PR0501CA0016.namprd05.prod.outlook.com (10.162.139.26) by CY1PR0501MB1385.namprd05.prod.outlook.com (10.160.148.139) with Microsoft SMTP Server (TLS) id 15.1.390.13; Wed, 27 Jan 2016 17:19:36 +0000
Received: from BN1AFFO11FD031.protection.gbl (2a01:111:f400:7c10::119) by BY1PR0501CA0016.outlook.office365.com (2a01:111:e400:4821::26) with Microsoft SMTP Server (TLS) id 15.1.390.13 via Frontend Transport; Wed, 27 Jan 2016 17:19:35 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.18) smtp.mailfrom=juniper.net; cs.tcd.ie; dkim=none (message not signed) header.d=none;cs.tcd.ie; dmarc=none action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.18 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.18) by BN1AFFO11FD031.mail.protection.outlook.com (10.58.52.185) with Microsoft SMTP Server (TLS) id 15.1.355.15 via Frontend Transport; Wed, 27 Jan 2016 17:19:34 +0000
Received: from magenta.juniper.net (172.17.27.123) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Wed, 27 Jan 2016 09:19:27 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id u0RHJOD36324;	Wed, 27 Jan 2016 09:19:24 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 3D1C81148F;	Wed, 27 Jan 2016 09:19:24 -0800 (PST)
To: <ietf-ssh@NetBSD.org>, Niels =?utf-8?Q?M=C3=B6ller?= <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, denis bider <ietf-ssh3@denisbider.com>, "Jeffrey Hutzelman" <jhutz@cmu.edu>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, "Jon Bright" <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange) 
In-Reply-To: <95389.1452676866@eng-mail01.juniper.net> 
References: <95389.1452676866@eng-mail01.juniper.net>
Comments: In-reply-to: "Mark D. Baushke" <mdb@juniper.net> message dated "Wed, 13 Jan 2016 01:21:06 -0800."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Wed, 27 Jan 2016 09:19:24 -0800
Message-ID: <96437.1453915164@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-Microsoft-Exchange-Diagnostics: 1;BN1AFFO11FD031;1:pU1b4l7d63h/Bj+mvWxeFBXPzu/lEA8oekgeZ/SyNUGEvsKx8Cyt9IDp4E4mJes4j3ag+ltb5gua68q8rMTYlHDuATIK2dGs4u/++vjZFd3Y1Y3cRV1HHSWOoTQFbolToXvS4o8T1kQt9abxX/brB5wkDDUvztWiXEV3838iIURvFsthfvSmF9BGYdMLvKuH5DxLDVXg7iOgt1Sn2xlK2wqA8EjdEMcbs+BUm3cJqD9QdtP53BzD5HVsuir9j/sLJq1rdUCiomFqcoqtfoEjZWTGoYq6fm3QteP1IkgSl9sBLhlruUOd76OoxNyAmxKeneBLVds0b8Ojhln/rHovkX7i8VN6Duf2s/q416cJrMsrrcgps+qyPq2tLJubWirJnqUGhvHuaJ5sV87Co06cm6CDHvtKeE8sataDAlDQ1K1GSBcm96e45VzSADJn3hjY
X-Forefront-Antispam-Report: CIP:66.129.239.18;CTRY:US;IPV:NLI;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(2980300002)(189002)(199003)(2171001)(53416004)(76506005)(87936001)(230783001)(117636001)(92566002)(2906002)(2810700001)(69596002)(86362001)(48376002)(189998001)(5003940100001)(107886002)(6806005)(11100500001)(5001960100002)(15975445007)(50466002)(54356999)(2950100001)(1220700001)(106466001)(5001770100001)(5003600100002)(19580395003)(3470700001)(81156007)(76176999)(47776003)(50986999)(105596002)(586003)(77096005)(97736004)(1096002)(7059030)(42262002);DIR:OUT;SFP:1102;SCL:1;SRVR:CY1PR0501MB1385;H:p-emfe01a-sac.jnpr.net;FPR:;SPF:SoftFail;PTR:InfoDomainNonexistent;MX:1;A:1;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;CY1PR0501MB1385;2:B89gUmH5yoA6btiLi6kQ4UD1prPTVhYlJ8LgTaJ6vPEoF8QybuElwcWNtV7eDphYdXi1rr3cAk2PjQe+/YBQ5Rcdyb7NikmBZ/aFS8DF44JNwmNac09kZX9BtuhzCKtqGVfAYN6HVM2Zv4xjJn/X9A==;3:daESavPLVELP1yEZLodTN9+oEaaluSdm9jGqfkSx41rxlmYTkGmq3p1Pec40BjUxdBi+nhvouA0Duc4STfw+BmwEtlRCh5p1243Aqrvb2tsYlnSrUOIjJ2p+xm6sqhsBZdCe5bP6wPL8e054BsRJvF0gUzfqnm8loUngzR6605ypWxZbxq+dPa8qXwH8k458g386Qugkn53i6HPwUTiV/000dLE/r88W79yTE0RZZDE=;25:3txc75yNx0SKfJfH/M+t5iCrUdVDtJjA1w1UKa848B65d8IOuUfMqrmFDHy7jEaoJrqngdHcpp473JuVtAwMEIeBaHiK+Ppr8MrwmwubihyabQrLcpitbPU9PjCB5ODTdfT8aXHdF9c9OZEG9nrsGxBLfx4f0X/fE0lZ/02hd2gHyVgg5vg28GSawCA51rh3QEbTILtpdpuwshrAKsjh/Hac/SXK6NcQf/Ef2OtlD00kc6W5U5XzHdZI/4TkSHsp
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:CY1PR0501MB1385;
X-MS-Office365-Filtering-Correlation-Id: 6a416671-b7a7-4184-9644-08d3273e06d7
X-Microsoft-Exchange-Diagnostics: 1;CY1PR0501MB1385;20:K0GOrRjYhiVJvhvVSVDLrwIFij3WEeRnutk7X+SG35UHsDLcDEEq7gVSZvWKMDIeLbUuZxev6lRs9aq1Joyec/luhVc6b6kdK5GJoiM/cUA8tEiFAacw10db2eD3WejDXIHWyv3lDNalpf0QWtVlTQr8o1i/Yx1ZAm3aoZ1I31vFweX+xUqVpPglFyIP9hjaAShb5MYA8iILl+q00xgmxxyprcOB9rUrbv49XWt2TOsujvA2vFSMz/4Tt31pHac3ntdgw9ZJ9HGuHJJCiJim3Dw39CP9qdWKZsUVhM1/u5PoMjqBQGMM8nEJRSFdOSQhXT41zKzjCkcloFUDita+C5dk6lqg6df0OOBEksb4IxUZ5b3SaC2iUnQiOo9euwJKI3Fu9gEl6p3On7wHDuKKVShEbXbCwIPx5IX6FvEpK1RWvh8ZXoddmK81FzZ9IvJixh/QzGi5oSvjaO1knYvaqWo8q8TcCpyIBr9CAQrLTvY09U/xF0NQKxR1I8+sVp1p
X-Microsoft-Antispam-PRVS: <CY1PR0501MB138594BAFB32AF83B27B3699BFD90@CY1PR0501MB1385.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(601004)(2401047)(8121501046)(5005006)(13023025)(13024025)(13015025)(13017025)(13018025)(10201501046)(3002001);SRVR:CY1PR0501MB1385;BCL:0;PCL:0;RULEID:;SRVR:CY1PR0501MB1385;
X-Microsoft-Exchange-Diagnostics: 1;CY1PR0501MB1385;4:IkbTZMPkPE29L4hl2rfXoLQ90e5Jp+HOkFSanuMXd59pvcAJWwEmwI+VaLoHJ/9zq4kPP6YNrq5gOkDMftc69EmZLXqch+/BevTrSAVVlSUA8QtWJYx8DtLMuu4kq7hpg5thKHBk7AJqwW/QZbeigbN4IFA05gPJlg6twQ/BvuN8IdM62MUD9cB1KNI1S11C/Vht3rPFOjC+v00rGJbU1/jllYQIcJCQSraO2wCzKpF4KijSTjpAMwCPrzGpF+/W8puRp7w0+lcyHXqMoWkTa4JQaK3xdBqIrZLAOfEPa2RlZrmlBfuQPgWF2Xv9NR/UUIxtir1D0C+E4heA9jgxNDi5GSfGauebSAAnoRMKFWIvy2NHhMB78efrWAgHSXPP/9l7fCXhs6vBie83tAn0hpf0mY099t05PSFYMIjxenUf/cRquxwLdp0lXtG4YO0qy6YjCsHrrI24MM6pV8N5ZA==
X-Forefront-PRVS: 0834BAF534
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;CY1PR0501MB1385;23:wt/Wfv6+HnaWrJwgONTwmun6gXlf8vCOWvIngfS?= =?us-ascii?Q?ISPwH4hSuXCAdbv3owLkk2suRmyJdxMlV7JhH7zjgX3cSjF9Vo9oyidQwK4A?= =?us-ascii?Q?rAcUGhHb3NGFDmUJbTze+nWt988PKAujP8aIM0pUvCoXp0NmSLVNuzLQLjzs?= =?us-ascii?Q?4DkSB9cHqmhiYbjDzg6AJHjUZRmFvl53ToQfi8/XrBKZdzp20Acbp5xhLeT6?= =?us-ascii?Q?SrSyVdQ6f2EYKwo0Hlfm9vPh83QcDwumDSWpTa587JELKnf4qnmW4f2FHTGV?= =?us-ascii?Q?cEuheVBdJ0p2r27PU/eYSRCpzQKypbP3lHYl7xWAFS5E8dWujSMiiTDFoasD?= =?us-ascii?Q?lALAcRZ9cSiJE5u+5veGiKwn1fl42KZi0dJNdqTfruIITsx2+DJ11ECoavpg?= =?us-ascii?Q?aengyfgoPB49xK8cwlgxtTHVd82u3kPFOIbf9xtLUA+E95wNaGuiDqPz+kN6?= =?us-ascii?Q?ff/hZ6eqovtMo1GYbWCJUcRbniVHIaL5+7MpyE8f0ese+995ykrd9239WA0r?= =?us-ascii?Q?veDlKcgA3YW8hizjbI2G0J4r1FTsEJkD0dQCizHiNxPSWFJ5AHHUfoTt+Ytp?= =?us-ascii?Q?sgsohjm4RrngfUoYqhOz4VXPaSbHZjio63cs6OuSkGtcrr42bPW04qjWODbw?= =?us-ascii?Q?5qW7aObHNL50tRXoeiW9+BmppJsvoXOkQBAbtJgxTqQcqMYHpQOnZDJQ+2st?= =?us-ascii?Q?Ku2dCa9de6PlkowGxgl3d9IVofVRwGlWNb13CX7GF4hsMIO3EAzIyVAn9Wnj?= =?us-ascii?Q?nR7Mss/+vNaJdVzQhqzPMsD8SkPctmXCFTxGy2bKd1poBshdBynDwrTm4Yg8?= =?us-ascii?Q?IV0hYyZnNyle7EcdxjlLJ7thKacoM1Z6mWjEO09fw/H7Q4ae3vbQYDWLFbao?= =?us-ascii?Q?76qqyf8IKLLo7t/5GG85We21Tb9wxUiPqLoL0UT6exR37zAyYO4wOFAflLSl?= =?us-ascii?Q?6XCrvgkW/mTM5Mw7bkgFE46qVrtMVFbooOcmjr/ceZNkbcVLq+apfMIhYX1l?= =?us-ascii?Q?Qx0Gzq4ylQ2YxqfitdlxhqMmK+gJBCHlSd08olz9rrAvszxJ3CjSNKRDrPTb?= =?us-ascii?Q?0aaYvdd5hYyYixXoRjnDUzauWrK4CPNVAfZDQnQkjK1btdfkKdZO5FZ44/q2?= =?us-ascii?Q?zpWtMICSD1I2/2/+IDkwgxmOKgtvZpZhk?=
X-Microsoft-Exchange-Diagnostics: 1;CY1PR0501MB1385;5:BSJy5eHfMmg1Fw6U9f/QNi4nWvfbGf9fQM1kWQf1dstW13xMEqax++cylvbdh20LCLKmqJpZPu/JUxr8KumdLtrV94g7xmYYFWamHjMtW6j+SHyBo1XsfacvO6tIL1X30nUfw7hMZLM1JTiAUtEqYQ==;24:9mxDolv3yLoF3Ij5HLlDFhg/RthC77jxNukyF4TX+6/QxCerBqM6R7wPnGuTnUCtSdYpe5FrcGqY9Bp1TwwhgEDcrH0m7/r066W/BIDmNWo=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 27 Jan 2016 17:19:34.2031 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.18];Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR0501MB1385
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi Folks,

> URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2

I just noticed that the Information Assurance Directorate at the NSA has
a new article on 'CNSA Suite and Quantum Computing FAQ' ... their URL is

https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for-classified/algorithm-guidance/cnsa-suite-and-quantum-computing-faq.cfm

Reading the document, they are mandating that NSS no longer use
Diffie-Hellman with 2048-bit keys instead they are suggesting
IETF RFC 3526 (Groups 15-18).

They are also no longer interested in using SHA-256 wanting SHA-384.

For folks interested in compliance with the CNSA Suite, does it make
sense for the baushke-ssh-dh-gorup-sha2 ID to be updated to specify
either SHA-384 (or possibly SHA-512)?

That is change from this:

   Key Exchange Method Name          Note
   diffie-hellman-group1-sha1        NOT RECOMMENDED
   diffie-hellman-group14-sha256     RECOMMENDED
   diffie-hellman-group15-sha256     RECOMMENDED
   diffie-hellman-group16-sha256     OPTIONAL

to this:

   Key Exchange Method Name          Note
   diffie-hellman-group1-sha1        NOT RECOMMENDED
   diffie-hellman-group14-sha256     RECOMMENDED
   diffie-hellman-group15-sha384     RECOMMENDED
   diffie-hellman-group16-sha384     OPTIONAL
   diffie-hellman-group17-sha512     OPTIONAL
   diffie-hellman-group18-sha512     OPTIONAL

I am suggesting sha512 for group17 and group18 as a minor bit of
future-proffing and/or performance trade-off for sha512 hardware
acceleration that may exist.

Comments please?

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Jan 27 15:09:26 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 64FAC1B3196 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 27 Jan 2016 15:09:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QuGJa7d8Brr0 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 27 Jan 2016 15:09:24 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ACB471B3197 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 27 Jan 2016 15:09:24 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 3B44785EE4; Wed, 27 Jan 2016 23:09:24 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E131A85EDE for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 23:09:21 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id Z1FhDpH6dJ_q for <ietf-ssh@netbsd.org>; Wed, 27 Jan 2016 23:09:21 +0000 (UTC)
Received: from newmailhub.uq.edu.au (mailhub1.soe.uq.edu.au [130.102.132.208]) by mail.netbsd.org (Postfix) with ESMTP id CC9DD85EA4 for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 23:09:17 +0000 (UTC)
Received: from smtp1.soe.uq.edu.au (smtp1.soe.uq.edu.au [10.138.113.40]) by newmailhub.uq.edu.au (8.14.5/8.14.5) with ESMTP id u0RN8jVj040886; Thu, 28 Jan 2016 09:08:46 +1000
Received: from mailhub.eait.uq.edu.au (hazel.eait.uq.edu.au [130.102.60.17]) by smtp1.soe.uq.edu.au (8.14.5/8.14.5) with ESMTP id u0RN8jrN054626 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 28 Jan 2016 09:08:45 +1000
Received: from natsu.mindrot.org (natsu.mindrot.org [130.102.96.2]) by mailhub.eait.uq.edu.au (8.15.1/8.15.1) with ESMTP id u0RN8eQB010844; Thu, 28 Jan 2016 09:08:41 +1000 (AEST)
Received: by natsu.mindrot.org (Postfix, from userid 1000) id 879C2A4F2F; Thu, 28 Jan 2016 10:08:40 +1100 (AEDT)
Received: from localhost (localhost [127.0.0.1]) by natsu.mindrot.org (Postfix) with ESMTP id 83617A4F2E; Thu, 28 Jan 2016 10:08:40 +1100 (AEDT)
Date: Thu, 28 Jan 2016 10:08:40 +1100 (AEDT)
From: Damien Miller <djm@mindrot.org>
To: "Mark D. Baushke" <mdb@juniper.net>
cc: ietf-ssh@NetBSD.org, =?ISO-8859-15?Q?Niels_M=F6ller?= <nisse@lysator.liu.se>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, denis bider <ietf-ssh3@denisbider.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
In-Reply-To: <96437.1453915164@eng-mail01.juniper.net>
Message-ID: <alpine.BSO.2.20.1601281001560.1003@natsu.mindrot.org>
References: <95389.1452676866@eng-mail01.juniper.net> <96437.1453915164@eng-mail01.juniper.net>
User-Agent: Alpine 2.20 (BSO 67 2015-01-07)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
X-Scanned-By: MIMEDefang 2.73 on UQ Mailhub
X-Scanned-By: MIMEDefang 2.75 on 130.102.60.17
X-UQ-FilterTime: 1453936130
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On Wed, 27 Jan 2016, Mark D. Baushke wrote:

> Hi Folks,
> 
> > URL: https://datatracker.ietf.org/doc/draft-baushke-ssh-dh-group-sha2
> 
> I just noticed that the Information Assurance Directorate at the NSA has
> a new article on 'CNSA Suite and Quantum Computing FAQ' ... their URL is
> 
> https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for-classified/algorithm-guidance/cnsa-suite-and-quantum-computing-faq.cfm
> 
> Reading the document, they are mandating that NSS no longer use
> Diffie-Hellman with 2048-bit keys instead they are suggesting
> IETF RFC 3526 (Groups 15-18).
> 
> They are also no longer interested in using SHA-256 wanting SHA-384.
> 
> For folks interested in compliance with the CNSA Suite, does it make
> sense for the baushke-ssh-dh-gorup-sha2 ID to be updated to specify
> either SHA-384 (or possibly SHA-512)?

I'd skip SHA-384 entirely in favour of SHA-512. Vendors who implement
Ed25519 will have a SHA512 implementation around anyway, whereas
~nobody uses SHA-384.

Also, I think it makes sense to reduce the number of groups offered.
OpenSSH is only offering 14 and 16 now, but might do 18 in the future.
We don't see any need for incremental steps between.

So my recommendation would be:

diffie-hellman-group1-sha1        NOT RECOMMENDED
diffie-hellman-group14-sha256     RECOMMENDED
diffie-hellman-group16-sha512     RECOMMENDED
diffie-hellman-group18-sha512     OPTIONAL

(but 16+256 & 18+512 would be fine too)

-d

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Jan 28 22:57:22 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E44D91A00F6 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 28 Jan 2016 22:57:22 -0800 (PST)
X-Quarantine-ID: <AsDI7upCMl53>
X-Virus-Scanned: amavisd-new at amsl.com
X-Amavis-Alert: BAD HEADER SECTION, MIME error: error: part did not end with expected boundary; ; error: unexpected end of parts before epilogue
X-Spam-Flag: NO
X-Spam-Score: -1.601
X-Spam-Level:
X-Spam-Status: No, score=-1.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AsDI7upCMl53 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 28 Jan 2016 22:57:21 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E45FC1A00F4 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 28 Jan 2016 22:57:21 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id AD24D85EC2; Fri, 29 Jan 2016 06:57:20 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 685B185E7C; Fri, 29 Jan 2016 06:57:20 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 3A1B885F1C for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 18:43:10 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 0hWMfGGy-hmu for <ietf-ssh@netbsd.org>; Wed, 27 Jan 2016 18:43:09 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 8CE3085DFD for <ietf-ssh@NetBSD.org>; Wed, 27 Jan 2016 18:43:09 +0000 (UTC)
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com for ietf-ssh@NetBSD.org; Wed, 27 Jan 2016 18:43:08 +0000
Date: Wed, 27 Jan 2016 18:43:08 +0000
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
X-User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
Message-ID: <1176559322-1224@skroderider.denisbider.com>
X-Priority: 3
Importance: Normal
MIME-Version: 1.0
From: denis bider <ietf-ssh3@denisbider.com>
To: ietf-ssh@NetBSD.org, =?UTF-8?q?NielsM=C3=B6ller?= <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, Peter Gutmann <pgut001@cs.auckland.ac.nz>, Jeffrey Hutzelman <jhutz@cmu.edu>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>, "Mark D. Baushke" <mdb@juniper.net>
Content-Type: multipart/alternative; boundary="=-YdbOiWEqCZTV6KA6ls19"
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

--=-YdbOiWEqCZTV6KA6ls19
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Hello Mark,

appreciated, and agreed.

Given these recommendations, we should consider what to do about hmac-sha2-=
384.

In RFC 6668, we mentioned it, but did not actually define it.

It seems that there is now a need to define hmac-sha2-384 formally. It has =
the advantage of 16 fewer bytes being used for MAC.

On the other hand, I'm not sure that there's a need for rsa-sha2-384. I don=
't see advantages compared to rsa-sha2-512, which the current draft defines=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Jan 28 22:57:37 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 197A31A00FE for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 28 Jan 2016 22:57:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.601
X-Spam-Level:
X-Spam-Status: No, score=-1.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gHtLWqiB742G for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 28 Jan 2016 22:57:34 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3363C1A00F4 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 28 Jan 2016 22:57:34 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id B959F85ED1; Fri, 29 Jan 2016 06:57:33 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 63EAC85E7C; Fri, 29 Jan 2016 06:57:33 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id BD0A085EAB for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 04:27:52 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id bXlhKF2fNJYI for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 04:27:52 +0000 (UTC)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 92BE385E7C for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 04:27:48 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1454041671; x=1485577671; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=bLWkPnSLuWfZWJDxxQho/NOyg/CEjJRw22qgocRG96c=; b=L5rmGXsCKLX1CbdKlSkEQYTZhup6ClIP1hLI5TQ43E+Lk31Gf6Apr0eK dMF/41kx5JuI5jBgPsGlA+kjBfSOng8VcEEmuV347WaRLwX02M+te5Vqr rtU13b5o7TkGPY4YGLKGCPU9dVN8p99MHHOz2PYIxvsW8IXBOS/dzv351 uoAnfibA4qD071LXIIdKzobZVd5Izq/BaCSov5CWr5nVEMa/mvFm9IBtM gRmZVGDRh/NZUtKAAPvCFjON5ttLvX9Lmld3ngfXO3qROLIp4xWamudSa pTvnYb++P1ZvDuAPIo5aC6G/Old2JmSjH3QiUMI9VF8QfLQ99rnzbanuv Q==;
X-IronPort-AV: E=Sophos;i="5.22,361,1449486000";  d="scan'208";a="65360360"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 130.216.4.171 - Outgoing - Outgoing
Received: from exchangemx.uoa.auckland.ac.nz (HELO uxchange10-fe4.UoA.auckland.ac.nz) ([130.216.4.171]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 29 Jan 2016 17:27:44 +1300
Received: from UXCN10-5.UoA.auckland.ac.nz ([169.254.5.153]) by uxchange10-fe4.UoA.auckland.ac.nz ([169.254.109.63]) with mapi id 14.03.0266.001; Fri, 29 Jan 2016 17:27:44 +1300
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: "Mark D. Baushke" <mdb@juniper.net>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, =?iso-8859-1?Q?Niels_M=F6ller?= <nisse@lysator.liu.se>, Damien Miller <djm@mindrot.org>, denis bider <ietf-ssh3@denisbider.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, "Stephen Farrell" <stephen.farrell@cs.tcd.ie>, Jon Bright <jon@siliconcircus.com>, Simon Tatham <anakin@pobox.com>
Subject: RE: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange) 
Thread-Topic: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange) 
Thread-Index: AQHRWSboSa1qbfis1UGVrrajOS+IKp8R6C5c
Date: Fri, 29 Jan 2016 04:27:43 +0000
Message-ID: <9A043F3CF02CD34C8E74AC1594475C73F4BDB868@uxcn10-5.UoA.auckland.ac.nz>
References: <95389.1452676866@eng-mail01.juniper.net>,<96437.1453915164@eng-mail01.juniper.net>
In-Reply-To: <96437.1453915164@eng-mail01.juniper.net>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

mdb@juniper.net <mdb@juniper.net> writes:=0A=
=0A=
>I just noticed that the Information Assurance Directorate at the NSA has a=
=0A=
>new article on 'CNSA Suite and Quantum Computing FAQ' ... their URL is=0A=
>=0A=
>https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for-classified/al=
gorithm-guidance/cnsa-suite-and-quantum-computing-faq.cfm=0A=
=0A=
My response to this, on the CFRG list, was:=0A=
=0A=
>On the QC stuff. Of course we have to start looking at that now. But I thi=
nk=0A=
>we need to look at the problem on two separate tracks:=0A=
>=0A=
>1) Find a public key algorithm that resists QC using Shorr's algorithm.=0A=
>2) Find a mechanism that makes symmetric key feasible in place of public.=
=0A=
=0A=
You forgot step 0:=0A=
=0A=
0) Figure out whether any of this stuff is actually necessary=0A=
=0A=
This is just a bunch of random numbers pulled out of thin air, just as Suit=
e B=0A=
was in its day, and CCEP was before that.  There's no empirical argument=0A=
supporting any of this, just a huge what-if.  For all we know the entire=0A=
document could have come about from a barroom bet, "Well Bill, you had them=
=0A=
chasing the Suite B white elephant, Dave got them really good with Dual-EC,=
=0A=
now it's my turn to see how high I can make them jump.  And best of all, TA=
O=0A=
will love me for it because they'll have to throw out most of their already=
-=0A=
deployed, partially-patched-up infrastructure and start again, leading to l=
ots=0A=
of new exploitable mistakes and errors".=0A=
=0A=
If you're worried about QC, why aren't you worried about TWINKLE/TWIRL, whi=
ch=0A=
is at least as feasible, if not more so, than QC, and has been around much=
=0A=
longer?=0A=
=0A=
If the NSA wants to put forward a new white elephant to supplant Suite B an=
d=0A=
the rest, hand them a can of paint and point them at the nearest zoo.  In t=
he=0A=
meantime I'll stick with addressing problems that are actual problems, ther=
e's=0A=
more than enough of those to go round.=0A=
=0A=
Peter.=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Jan 31 13:22:30 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FD551B2D7D for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:22:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.099
X-Spam-Level: *
X-Spam-Status: No, score=1.099 tagged_above=-999 required=5 tests=[BAYES_50=0.8, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7_ZRyY8UcWRW for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:22:28 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 950F51B2D7E for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 31 Jan 2016 13:22:28 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 180FA85ECA; Sun, 31 Jan 2016 21:22:27 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id BEEB685EB0; Sun, 31 Jan 2016 21:22:26 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id D782685F4E for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 21:13:44 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id L_9zxF15fXdd for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 21:13:44 +0000 (UTC)
Received: from mail.lysator.liu.se (mail.lysator.liu.se [IPv6:2001:6b0:17:f0a0::3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id F28CB85E91 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 21:13:42 +0000 (UTC)
Received: from mail.lysator.liu.se (localhost [127.0.0.1]) by mail.lysator.liu.se (Postfix) with ESMTP id A1B874001E; Fri, 29 Jan 2016 22:13:39 +0100 (CET)
Received: from armitage.lysator.liu.se (armitage.lysator.liu.se [IPv6:2001:6b0:17:f0a0::83]) by mail.lysator.liu.se (Postfix) with SMTP id 1664E40011; Fri, 29 Jan 2016 22:13:36 +0100 (CET)
Received: by armitage.lysator.liu.se (sSMTP sendmail emulation); Fri, 29 Jan 2016 22:13:36 +0100
From: nisse@lysator.liu.se (Niels =?utf-8?Q?M=C3=B6ller?=)
To: Damien Miller <djm@mindrot.org>
Cc: "Mark D. Baushke" <mdb@juniper.net>,  ietf-ssh@NetBSD.org,  Peter Gutmann <pgut001@cs.auckland.ac.nz>,  denis bider <ietf-ssh3@denisbider.com>,  Jeffrey Hutzelman <jhutz@cmu.edu>,  Stephen Farrell <stephen.farrell@cs.tcd.ie>,  Jon Bright <jon@siliconcircus.com>,  Simon Tatham <anakin@pobox.com>
Subject: Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
References: <95389.1452676866@eng-mail01.juniper.net> <96437.1453915164@eng-mail01.juniper.net> <alpine.BSO.2.20.1601281001560.1003@natsu.mindrot.org>
Date: Fri, 29 Jan 2016 22:13:36 +0100
In-Reply-To: <alpine.BSO.2.20.1601281001560.1003@natsu.mindrot.org> (Damien Miller's message of "Thu, 28 Jan 2016 10:08:40 +1100 (AEDT)")
Message-ID: <nn8u389ji7.fsf@armitage.lysator.liu.se>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (berkeley-unix)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Virus-Scanned: ClamAV using ClamSMTP
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Damien Miller <djm@mindrot.org> writes:

> I'd skip SHA-384 entirely in favour of SHA-512.

Agreed. SHA-384 has the same security as truncated SHA-512 (just
differing initial values). And I don't see any point in doing truncation
for the ssh key exchange hash, am I missing anything?

Regards,
/Niels

--=20
Niels M=C3=B6ller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Jan 31 13:24:38 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 269131B2D81 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:24:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.699
X-Spam-Level: *
X-Spam-Status: No, score=1.699 tagged_above=-999 required=5 tests=[BAYES_50=0.8, J_CHICKENPOX_31=0.6, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sYn3tZM1FIp3 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:24:36 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D9E31B2D7F for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 31 Jan 2016 13:24:36 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id E385585EE8; Sun, 31 Jan 2016 21:24:35 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 979F685EB0; Sun, 31 Jan 2016 21:24:35 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8B3F285F63 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 21:34:25 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 0oVEzeRdPaMj for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 21:34:25 +0000 (UTC)
Received: from mail.lysator.liu.se (mail.lysator.liu.se [130.236.254.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id BA6E186025 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 21:34:24 +0000 (UTC)
Received: from mail.lysator.liu.se (localhost [127.0.0.1]) by mail.lysator.liu.se (Postfix) with ESMTP id 2C8694001E; Fri, 29 Jan 2016 22:34:22 +0100 (CET)
Received: from armitage.lysator.liu.se (armitage.lysator.liu.se [IPv6:2001:6b0:17:f0a0::83]) by mail.lysator.liu.se (Postfix) with SMTP id 69E5B40011; Fri, 29 Jan 2016 22:34:20 +0100 (CET)
Received: by armitage.lysator.liu.se (sSMTP sendmail emulation); Fri, 29 Jan 2016 22:34:20 +0100
From: nisse@lysator.liu.se (Niels =?utf-8?Q?M=C3=B6ller?=)
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: ietf-ssh@NetBSD.org,  denis bider <ietf-ssh3@denisbider.com>,  Watson Ladd <watsonbladd@gmail.com>,  Daniel Migault <daniel.migault@ericsson.com>,  Curdle Chairs <curdle-chairs@ietf.org>,  mdb@juniper.net
Subject: Re: suggestion for new ssh maintenance wg
References: <10640250-2692@skroderider.denisbider.com> <56978B77.8060204@cs.tcd.ie>
Date: Fri, 29 Jan 2016 22:34:20 +0100
In-Reply-To: <56978B77.8060204@cs.tcd.ie> (Stephen Farrell's message of "Thu, 14 Jan 2016 11:50:15 +0000")
Message-ID: <nn4mdw9ijn.fsf@armitage.lysator.liu.se>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (berkeley-unix)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Virus-Scanned: ClamAV using ClamSMTP
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:

> If you think such an ssh maintenance wg is a bad plan,
> please also do say that and why you think that.

There's definitely some work that needs to be done. I'm not very
familiar with ietf processes, so I'm not sure a new working group would
make it easier to make progress. I guess what's needed is either an
active wg chair, or an active area director, or someone informally
accepting (and being accepted) in a similar role.

> PPS: Note that this could be short-lived wg that never
> needs to meet face-to-face, or maybe it'd not be like that,
> but don't get fussed about having to go to IETF meetings
> to get this work done - if it's maintenance then that may
> well not be needed.

Don't worry about IETF meetings. I felt I was deeply involved during the
work on the ssh rfc:s. And I've never been to a secsh wg meeting, only
on the mailing list. (I've actually been to one ietf meeting in my life,
but the secsh wg didn't meet that time).

>> Extension negotiation for SSH:=20
>> https://datatracker.ietf.org/doc/draft-ssh-ext-info

An extension mechanism makes sense to me, but I find most of the
proposed extensions questionable and/or hard to get right.

>> In addition to the above, I very much agree that aes-gcm@openssh.com
>> needs standardization.

I think the single issue that might motivate forming a new wg is how to
properly negotiate the use of aead crypt in ssh. There should be no
difference between aes-gcm (which I'm not very fond of) and
chacha-poly1305.
=20
>> Among other things, the erstwhile SSH working group never finalized
>> the SFTP spec due to lack of consensus. We now have two SFTP specs,
>> version 3 implemented by OpenSSH, and version 6 implemented by most
>> everyone else.

I honestly doubt we'll see much progress there, wg or not. It was a bit
too much of second system syndrome. But if some others have the energy
to revive it, I can't object, of course.

Regards,
/Niels

--=20
Niels M=C3=B6ller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Jan 31 13:28:27 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F38E91B2D84 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:28:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.4
X-Spam-Level:
X-Spam-Status: No, score=-1.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, J_CHICKENPOX_31=0.6, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K9wMt3XAH9qQ for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:28:26 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 89C171ACC87 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 31 Jan 2016 13:28:26 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 163C085F18; Sun, 31 Jan 2016 21:28:26 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id B6A7785F0E; Sun, 31 Jan 2016 21:28:25 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 14C1B85ED3 for <ietf-ssh@netbsd.org>; Sat, 30 Jan 2016 05:50:13 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id TL6c8wCwJMLf for <ietf-ssh@netbsd.org>; Sat, 30 Jan 2016 05:50:12 +0000 (UTC)
Received: from mail-yk0-x231.google.com (mail-yk0-x231.google.com [IPv6:2607:f8b0:4002:c07::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 0FB6D85ECC for <ietf-ssh@netbsd.org>; Sat, 30 Jan 2016 05:50:12 +0000 (UTC)
Received: by mail-yk0-x231.google.com with SMTP id k129so93702100yke.0 for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 21:50:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=LBExXkQNCAgbFk0GqQDssoKRSWmptb1MstRmGi6QyMk=; b=DFnWU3dioMW4aeWV5y9ZQ04otQb7cndvb40L8hP00H1Yo6tWemgpUR1x7V05FgFLhR oVFzO5gL/FSVnKvcgSBZdNABr/OvwmZbbThOf7XlU5NER+oLEtapikE3XYZTTpu+8mpD Xs2m37gwWNy3NPW0KkcdpGKm4FoAbT+eVXa/EXN+NwB2tftVQ8f96G5BkDA7UGFqw7c5 SMzf4GQzd0R1T7NBYmL06QxsMv9czi5AHkUVHgaGaodt355VnrHsJH6Tkf3Ng27Dq9oQ bhPfiX1CL/sM9gHuv5KrCTHUckV5fw4KRgORUTzN6FmH2S2NFe2/89qZ7qS4kqbmNWqL 90EQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=LBExXkQNCAgbFk0GqQDssoKRSWmptb1MstRmGi6QyMk=; b=ZrT0G4+1+4wJDEzMTazO/mi2vVIkEFBuMqAZ9MkZRAddv19TNzdPiV1eZ1IL6Gt39u 1pzaw7ORUj+ckOOzNt9VB1im9egtpoyHxLXMQEQ771Dl369dAyk7PFHHu/tUXXpv02Pe Ql4OGNmieJ+T1Zr0Lc/tRH9sF0VMjKklYy3trgo+U5P7S5X3XVnbZj7RfTA2sYS5Kvee Tamgi7gugfsIdeDCwjFUctkQRW217U2qDvvLdh5JVVcSJYEa/az5ngJSUS8c/uh1OkOz hNbIKeg6Zj7q9NGqXfmea0rWNbSliZA9mV1l8I8NuV/a1ddkM/QCiDJPnTlVKf8w1OwH 0sCQ==
X-Gm-Message-State: AG10YOTo8lWENv7VQZoGzzSfa4FgMjDXNL6K+njaAAUiuFiSfWK6rm5Uth2pQeHvy5EMfuMjW4iIBFUEe1XRKg==
MIME-Version: 1.0
X-Received: by 10.37.52.148 with SMTP id b142mr2694791yba.54.1454133011227; Fri, 29 Jan 2016 21:50:11 -0800 (PST)
Received: by 10.13.216.138 with HTTP; Fri, 29 Jan 2016 21:50:11 -0800 (PST)
In-Reply-To: <1364567000-252@skroderider.denisbider.com>
References: <1361670077-596@skroderider.denisbider.com> <1364567000-252@skroderider.denisbider.com>
Date: Fri, 29 Jan 2016 21:50:11 -0800
Message-ID: <CACsn0c=Tjqn0Sh2RP_NYSYLS3=A9WNQPiD-NNjHExGJu9bXneQ@mail.gmail.com>
Subject: Re: suggestion for new ssh maintenance wg
From: Watson Ladd <watsonbladd@gmail.com>
To: denis bider <ietf-ssh3@denisbider.com>
Cc: =?UTF-8?Q?Niels_M=C3=B6ller?= <nisse@lysator.liu.se>,  Stephen Farrell <stephen.farrell@cs.tcd.ie>, "ietf-ssh@NetBSD.org" <ietf-ssh@netbsd.org>,  Daniel Migault <daniel.migault@ericsson.com>, mdb@juniper.net
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On Fri, Jan 29, 2016 at 2:49 PM, denis bider <ietf-ssh3@denisbider.com> wro=
te:
>> SFTP v3 - as implemented by OpenSSH and everyone who wants to interopera=
te
>> with it
>
> Gah, sorry, wrong version. That's SFTP v4, which is also implemented by m=
any
> clients and servers. However, most that implemented v4 by now also implem=
ent
> v6.
>
> This is version 3:
>
> https://tools.ietf.org/html/draft-ietf-secsh-filexfer-02
>
>
> denis bider <ietf-ssh3@denisbider.com> , 1/29/2016 9:59 PM:
>
> With regard to AEAD:
>
> I think we should just make the following simple and clear statement:
>
> MAC algorithms are secondary to encryption algorithms, and are evaluated
> only if the encryption algorithm is not AEAD. If an AEAD encryption
> algorithm is negotiated, the outcome of MAC negotiation is irrelevant and
> must be ignored. If no mutual MAC algorithms are available, this causes k=
ey
> exchange to fail if, and only if, the negotiated encryption algorithm is =
not
> AEAD.
>
> I believe this is what aesXXX-gcm@openssh.com does, and is the behavior t=
hat
> makes most sense to me.
>
>
> With regard to SFTP:
>
> We may not have an agreement in what SFTP should be; but by necessity, we
> have an agreement in what it is.
>
> I suggest we should simply do the minimum work possible to promote the
> following drafts to some type of RFC, and call it a day:
>
> SFTP v3 - as implemented by OpenSSH and everyone who wants to interoperat=
e
> with it
> https://tools.ietf.org/html/draft-ietf-secsh-filexfer-04
>
> SFTP v6 - implemented by many (perhaps most?) clients and servers
> https://tools.ietf.org/html/draft-ietf-secsh-filexfer-13
> https://tools.ietf.org/html/draft-galb-filexfer-extensions-00
>
> This is the de facto SFTP as we have it. Implementers have to follow thes=
e
> drafts, so they might as well be RFCs.

Apprently OpenSSH isn't implementing v6, and after looking at it I see
why, although if some other people see uses for it, so be it. If these
aren't RFCs given how important and widely used sftp is (and there
isn't even a draft for the even more useful scp), it raises lots of
questions about what the IETF has been doing, and whether it's worth
it.

>
>
> ----- Original Message -----
> From: Niels "M=C3=B6ller"
> Sent: Friday, January 29, 2016 15:34
> To: Stephen Farrell
> Cc: ietf-ssh@NetBSD.org ; denis bider ; Watson Ladd ; Daniel Migault ;
> Curdle Chairs ; mdb@juniper.net
> Subject: Re: suggestion for new ssh maintenance wg
>
> Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:
>
>> If you think such an ssh maintenance wg is a bad plan,
>> please also do say that and why you think that.
>
> There's definitely some work that needs to be done. I'm not very
> familiar with ietf processes, so I'm not sure a new working group would
> make it easier to make progress. I guess what's needed is either an
> active wg chair, or an active area director, or someone informally
> accepting (and being accepted) in a similar role.
>
>> PPS: Note that this could be short-lived wg that never
>> needs to meet face-to-face, or maybe it'd not be like that,
>> but don't get fussed about having to go to IETF meetings
>> to get this work done - if it's maintenance then that may
>> well not be needed.
>
> Don't worry about IETF meetings. I felt I was deeply involved during the
> work on the ssh rfc:s. And I've never been to a secsh wg meeting, only
> on the mailing list. (I've actually been to one ietf meeting in my life,
> but the secsh wg didn't meet that time).
>
>>> Extension negotiation for SSH:
>>> https://datatracker.ietf.org/doc/draft-ssh-ext-info
>
> An extension mechanism makes sense to me, but I find most of the
> proposed extensions questionable and/or hard to get right.
>
>>> In addition to the above, I very much agree that aes-gcm@openssh.com
>>> needs standardization.
>
> I think the single issue that might motivate forming a new wg is how to
> properly negotiate the use of aead crypt in ssh. There should be no
> difference between aes-gcm (which I'm not very fond of) and
> chacha-poly1305.
>
>>> Among other things, the erstwhile SSH working group never finalized
>>> the SFTP spec due to lack of consensus. We now have two SFTP specs,
>>> version 3 implemented by OpenSSH, and version 6 implemented by most
>>> everyone else.
>
> I honestly doubt we'll see much progress there, wg or not. It was a bit
> too much of second system syndrome. But if some others have the energy
> to revive it, I can't object, of course.
>
> Regards,
> /Niels
>
> --
> Niels M=C3=B6ller. PGP-encrypted email is preferred. Keyid C0B98E26.
> Internet email is subject to wholesale government surveillance.



--=20
"Man is born free, but everywhere he is in chains".
--Rousseau.

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Jan 31 13:30:02 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10C371B2D83 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:30:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.7
X-Spam-Level: *
X-Spam-Status: No, score=1.7 tagged_above=-999 required=5 tests=[BAYES_50=0.8, HTML_MESSAGE=0.001, J_CHICKENPOX_31=0.6, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YzpP2Aj5z-iW for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:30:00 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 390A01ACC87 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 31 Jan 2016 13:30:00 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id CBA2B85F2E; Sun, 31 Jan 2016 21:29:59 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 8508F85F21; Sun, 31 Jan 2016 21:29:59 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 0BB4185F61 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 22:44:38 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id HPCa4w2I7uFs for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 22:44:37 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 3D49A85E93 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 22:44:37 +0000 (UTC)
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com for nisse@lysator.liu.se; Fri, 29 Jan 2016 22:44:35 +0000
Date: Fri, 29 Jan 2016 22:44:35 +0000
Subject: Re: suggestion for new ssh maintenance wg
X-User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
Message-ID: <1361670077-596@skroderider.denisbider.com>
X-Priority: 3
Importance: Normal
MIME-Version: 1.0
From: denis bider <ietf-ssh3@denisbider.com>
To: =?UTF-8?q?Niels_M=C3=B6ller?= <nisse@lysator.liu.se>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: ietf-ssh@NetBSD.org, Watson Ladd <watsonbladd@gmail.com>, Daniel Migault <daniel.migault@ericsson.com>, Curdle Chairs <curdle-chairs@ietf.org>, mdb@juniper.net
Content-Type: multipart/alternative; boundary="=-bvzBvafS4aOtowAgLcqe"
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

--=-bvzBvafS4aOtowAgLcqe
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

With regard to AEAD:

I think we should just make the following simple and clear statement:

MAC algorithms are secondary to encryption algorithms, and are evaluated on=
ly if the encryption algorithm is not AEAD. If an AEAD encryption algorithm=
 is negotiated, the outcome of MAC negotiation is irrelevant and must be ig=
nored. If no mutual MAC algorithms are available, this causes key exchange =
to fail if, and only if, the negotiated encryption algorithm is not AEAD.

I believe this is what aesXXX-gcm@openssh.com does, and is the behavior tha=
t makes most sense to me.


With regard to SFTP:

We may not have an agreement in what SFTP should be; but by necessity, we h=
ave an agreement in what it is.

I suggest we should simply do the minimum work possible to promote the foll=
owing drafts to some type of RFC, and call it a day:

SFTP v3 - as implemented by OpenSSH and everyone who wants to interoperate =
with it
https://tools.ietf.org/html/draft-ietf-secsh-filexfer-04

SFTP v6 - implemented by many (perhaps most?) clients and servers
https://tools.ietf.org/html/draft-ietf-secsh-filexfer-13
https://tools.ietf.org/html/draft-galb-filexfer-extensions-00

This is the de facto SFTP as we have it. Implementers have to follow these =
drafts, so they might as well be RFCs.


 ----- Original Message -----=20
 From: Niels "M=C3=B6ller"  Sent: Friday, January 29, 2016 15:34 To: Stephe=
n Farrell  Cc: ietf-ssh@NetBSD.org ; denis bider ; Watson Ladd ; Daniel Mig=
ault ;  Curdle Chairs ; mdb@juniper.net  Subject: Re: suggestion for new ss=
h maintenance wg =C2=A0 Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:=
 =C2=A0 > If you think such an ssh maintenance wg is a bad plan, > please a=
lso do say that and why you think that. =C2=A0 There's definitely some work=
 that needs to be done. I'm not very familiar with ietf processes, so I'm n=
ot sure a new working group  would make it easier to make progress. I guess=
 what's needed is either an active wg chair, or an active area director, or=
 someone informally accepting (and being accepted) in a similar role. =C2=
=A0 > PPS: Note that this could be short-lived wg that never > needs to mee=
t face-to-face, or maybe it'd not be like that, > but don't get fussed abou=
t having to go to IETF meetings > to get this work done - if it's maintenan=
ce then that may > well not be needed. =C2=A0 Don't worry about IETF meetin=
gs. I felt I was deeply involved during  the work on the ssh rfc:s. And I'v=
e never been to a secsh wg meeting,  only on the mailing list. (I've actual=
ly been to one ietf meeting in my  life, but the secsh wg didn't meet that =
time). =C2=A0 >> Extension negotiation for SSH:  >> https://datatracker.iet=
f.org/doc/draft-ssh-ext-info =C2=A0 An extension mechanism makes sense to m=
e, but I find most of the proposed extensions questionable and/or hard to g=
et right. =C2=A0 >> In addition to the above, I very much agree that  aes-g=
cm@openssh.com >> needs standardization. =C2=A0 I think the single issue th=
at might motivate forming a new wg is how  to properly negotiate the use of=
 aead crypt in ssh. There should be no difference between aes-gcm (which I'=
m not very fond of) and chacha-poly1305. =C2=A0 >> Among other things, the =
erstwhile SSH working group never  finalized >> the SFTP spec due to lack o=
f consensus. We now have two SFTP  specs, >> version 3 implemented by OpenS=
SH, and version 6 implemented by  most >> everyone else. =C2=A0 I honestly =
doubt we'll see much progress there, wg or not. It was a  bit too much of s=
econd system syndrome. But if some others have the  energy to revive it, I =
can't object, of course. =C2=A0 Regards, /Niels =C2=A0 --  Niels M=C3=B6lle=
r. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subj=
ect to wholesale government surveillance.=

--=-bvzBvafS4aOtowAgLcqe
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><div>With regard to <b>AEAD:</b><br><br>I think we=
 should just make the following simple and clear statement:<br><br>MAC algo=
rithms are secondary to encryption algorithms, and are evaluated only if th=
e encryption algorithm is not AEAD. If an AEAD encryption algorithm is nego=
tiated, the outcome of MAC negotiation is irrelevant and must be ignored. I=
f no mutual MAC algorithms are available, this causes key exchange to fail =
if, and only if, the negotiated encryption algorithm is not AEAD.<br><br>I =
believe this is what aesXXX-gcm@openssh.com does, and is the behavior that =
makes most sense to me.<br><br><br>With regard to<b> SFTP:</b><br><br>We ma=
y not have an agreement in what SFTP <i>should</i> be; but by necessity, we=
 have an agreement in what it <i>is</i>.<br><br>I suggest we should simply =
do the minimum work possible to promote the following drafts to some type o=
f RFC, and call it a day:<br><br>SFTP v3 - as implemented by OpenSSH and ev=
eryone who wants to interoperate with it<br>https://tools.ietf.org/html/dra=
ft-ietf-secsh-filexfer-04<br><br>SFTP v6 - implemented by many (perhaps mos=
t?) clients and servers<br>https://tools.ietf.org/html/draft-ietf-secsh-fil=
exfer-13<br>https://tools.ietf.org/html/draft-galb-filexfer-extensions-00<b=
r><br>This is the de facto SFTP as we have it. Implementers have to follow =
these drafts, so they might as well be RFCs.<br><br><br></div>
<div>----- Original Message ----- <br></div>
<div>From: Niels "M=C3=B6ller" </div>
<div>Sent: Friday, January 29, 2016 15:34</div>
<div>To: Stephen Farrell </div>
<div>Cc: ietf-ssh@NetBSD.org ; denis bider ; Watson Ladd ; Daniel Migault ;=
=20
Curdle Chairs ; mdb@juniper.net </div>
<div>Subject: Re: suggestion for new ssh maintenance wg</div>
<div>&nbsp;</div>
<div>Stephen Farrell &lt;stephen.farrell@cs.tcd.ie&gt; writes:</div>
<div>&nbsp;</div>
<div>&gt; If you think such an ssh maintenance wg is a bad plan,</div>
<div>&gt; please also do say that and why you think that.</div>
<div>&nbsp;</div>
<div>There's definitely some work that needs to be done. I'm not very</div>
<div>familiar with ietf processes, so I'm not sure a new working group=20
would</div>
<div>make it easier to make progress. I guess what's needed is either an</d=
iv>
<div>active wg chair, or an active area director, or someone informally</di=
v>
<div>accepting (and being accepted) in a similar role.</div>
<div>&nbsp;</div>
<div>&gt; PPS: Note that this could be short-lived wg that never</div>
<div>&gt; needs to meet face-to-face, or maybe it'd not be like that,</div>
<div>&gt; but don't get fussed about having to go to IETF meetings</div>
<div>&gt; to get this work done - if it's maintenance then that may</div>
<div>&gt; well not be needed.</div>
<div>&nbsp;</div>
<div>Don't worry about IETF meetings. I felt I was deeply involved during=20
the</div>
<div>work on the ssh rfc:s. And I've never been to a secsh wg meeting,=20
only</div>
<div>on the mailing list. (I've actually been to one ietf meeting in my=20
life,</div>
<div>but the secsh wg didn't meet that time).</div>
<div>&nbsp;</div>
<div>&gt;&gt; Extension negotiation for SSH: </div>
<div>&gt;&gt; https://datatracker.ietf.org/doc/draft-ssh-ext-info</div>
<div>&nbsp;</div>
<div>An extension mechanism makes sense to me, but I find most of the</div>
<div>proposed extensions questionable and/or hard to get right.</div>
<div>&nbsp;</div>
<div>&gt;&gt; In addition to the above, I very much agree that=20
aes-gcm@openssh.com</div>
<div>&gt;&gt; needs standardization.</div>
<div>&nbsp;</div>
<div>I think the single issue that might motivate forming a new wg is how=20
to</div>
<div>properly negotiate the use of aead crypt in ssh. There should be no</d=
iv>
<div>difference between aes-gcm (which I'm not very fond of) and</div>
<div>chacha-poly1305.</div>
<div>&nbsp;</div>
<div>&gt;&gt; Among other things, the erstwhile SSH working group never=20
finalized</div>
<div>&gt;&gt; the SFTP spec due to lack of consensus. We now have two SFTP=20
specs,</div>
<div>&gt;&gt; version 3 implemented by OpenSSH, and version 6 implemented b=
y=20
most</div>
<div>&gt;&gt; everyone else.</div>
<div>&nbsp;</div>
<div>I honestly doubt we'll see much progress there, wg or not. It was a=20
bit</div>
<div>too much of second system syndrome. But if some others have the=20
energy</div>
<div>to revive it, I can't object, of course.</div>
<div>&nbsp;</div>
<div>Regards,</div>
<div>/Niels</div>
<div>&nbsp;</div>
<div>-- </div>
<div>Niels M=C3=B6ller. PGP-encrypted email is preferred. Keyid C0B98E26.</=
div>
<div>Internet email is subject to wholesale government surveillance.</div><=
/body></html>=

--=-bvzBvafS4aOtowAgLcqe--

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Jan 31 13:30:35 2016
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 616F11B2D86 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:30:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.7
X-Spam-Level: *
X-Spam-Status: No, score=1.7 tagged_above=-999 required=5 tests=[BAYES_50=0.8, HTML_MESSAGE=0.001, J_CHICKENPOX_31=0.6, MIME_8BIT_HEADER=0.3, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LoBhPZW0PrGl for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 31 Jan 2016 13:30:33 -0800 (PST)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 768431B2D85 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 31 Jan 2016 13:30:33 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 1424685F31; Sun, 31 Jan 2016 21:30:33 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id C03C785F21; Sun, 31 Jan 2016 21:30:32 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 9833585F2D for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 22:49:03 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id xp1q-c4FFpkx for <ietf-ssh@netbsd.org>; Fri, 29 Jan 2016 22:49:02 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id C06B885E93 for <ietf-ssh@NetBSD.org>; Fri, 29 Jan 2016 22:49:02 +0000 (UTC)
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com for ietf-ssh3@denisbider.com; Fri, 29 Jan 2016 22:49:00 +0000
Date: Fri, 29 Jan 2016 22:49:00 +0000
Subject: Re: suggestion for new ssh maintenance wg
X-User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
Message-ID: <1364567000-252@skroderider.denisbider.com>
X-Priority: 3
Importance: Normal
In-Reply-To: <1361670077-596@skroderider.denisbider.com>
MIME-Version: 1.0
From: denis bider <ietf-ssh3@denisbider.com>
To: denis bider <ietf-ssh3@denisbider.com>, =?UTF-8?q?Niels_M=C3=B6ller?= <nisse@lysator.liu.se>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: ietf-ssh@NetBSD.org, Watson Ladd <watsonbladd@gmail.com>, Daniel Migault <daniel.migault@ericsson.com>, Curdle Chairs <curdle-chairs@ietf.org>, mdb@juniper.net
Content-Type: multipart/alternative; boundary="=-0CoMnllLvveeu4p53sAp"
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

--=-0CoMnllLvveeu4p53sAp
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

> SFTP v3 - as implemented by OpenSSH and everyone who wants to interoperat=
e with it

Gah, sorry, wrong version. That's SFTP v4, which is also implemented by man=
y clients and servers. However, most that implemented v4 by now also implem=
ent v6.

This is version 3:

https://tools.ietf.org/html/draft-ietf-secsh-filexfer-02


denis bider <ietf-ssh3@denisbider.com> , 1/29/2016 9:59 PM:
With regard to AEAD:

I think we should just make the following simple and clear statement:

MAC algorithms are secondary to encryption algorithms, and are evaluated on=
ly if the encryption algorithm is not AEAD. If an AEAD encryption algorithm=
 is negotiated, the outcome of MAC negotiation is irrelevant and must be ig=
nored. If no mutual MAC algorithms are available, this causes key exchange =
to fail if, and only if, the negotiated encryption algorithm is not AEAD.

I believe this is what aesXXX-gcm@openssh.com does, and is the behavior tha=
t makes most sense to me.


With regard to SFTP:

We may not have an agreement in what SFTP should be; but by necessity, we h=
ave an agreement in what it is.

I suggest we should simply do the minimum work possible to promote the foll=
owing drafts to some type of RFC, and call it a day:

SFTP v3 - as implemented by OpenSSH and everyone who wants to interoperate =
with it
https://tools.ietf.org/html/draft-ietf-secsh-filexfer-04

SFTP v6 - implemented by many (perhaps most?) clients and servers
https://tools.ietf.org/html/draft-ietf-secsh-filexfer-13
https://tools.ietf.org/html/draft-galb-filexfer-extensions-00

This is the de facto SFTP as we have it. Implementers have to follow these =
drafts, so they might as well be RFCs.


 ----- Original Message -----=20
 From: Niels "M=C3=B6ller"  Sent: Friday, January 29, 2016 15:34 To: Stephe=
n Farrell  Cc: ietf-ssh@NetBSD.org ; denis bider ; Watson Ladd ; Daniel Mig=
ault ;  Curdle Chairs ; mdb@juniper.net  Subject: Re: suggestion for new ss=
h maintenance wg =C2=A0 Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:=
 =C2=A0 > If you think such an ssh maintenance wg is a bad plan, > please a=
lso do say that and why you think that. =C2=A0 There's definitely some work=
 that needs to be done. I'm not very familiar with ietf processes, so I'm n=
ot sure a new working group  would make it easier to make progress. I guess=
 what's needed is either an active wg chair, or an active area director, or=
 someone informally accepting (and being accepted) in a similar role. =C2=
=A0 > PPS: Note that this could be short-lived wg that never > needs to mee=
t face-to-face, or maybe it'd not be like that, > but don't get fussed abou=
t having to go to IETF meetings > to get this work done - if it's maintenan=
ce then that may > well not be needed. =C2=A0 Don't worry about IETF meetin=
gs. I felt I was deeply involved during  the work on the ssh rfc:s. And I'v=
e never been to a secsh wg meeting,  only on the mailing list. (I've actual=
ly been to one ietf meeting in my  life, but the secsh wg didn't meet that =
time). =C2=A0 >> Extension negotiation for SSH:  >> https://datatracker.iet=
f.org/doc/draft-ssh-ext-info =C2=A0 An extension mechanism makes sense to m=
e, but I find most of the proposed extensions questionable and/or hard to g=
et right. =C2=A0 >> In addition to the above, I very much agree that  aes-g=
cm@openssh.com >> needs standardization. =C2=A0 I think the single issue th=
at might motivate forming a new wg is how  to properly negotiate the use of=
 aead crypt in ssh. There should be no difference between aes-gcm (which I'=
m not very fond of) and chacha-poly1305. =C2=A0 >> Among other things, the =
erstwhile SSH working group never  finalized >> the SFTP spec due to lack o=
f consensus. We now have two SFTP  specs, >> version 3 implemented by OpenS=
SH, and version 6 implemented by  most >> everyone else. =C2=A0 I honestly =
doubt we'll see much progress there, wg or not. It was a  bit too much of s=
econd system syndrome. But if some others have the  energy to revive it, I =
can't object, of course. =C2=A0 Regards, /Niels =C2=A0 --  Niels M=C3=B6lle=
r. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subj=
ect to wholesale government surveillance.=

--=-0CoMnllLvveeu4p53sAp
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body>&gt; SFTP v3 - as implemented by OpenSSH and every=
one who wants to interoperate with it<br><br>Gah, sorry, wrong version. Tha=
t's SFTP v4, which is <i>also</i> implemented by many clients and servers. =
However, most that implemented v4 by now also implement v6.<br><br>This is =
version 3:<br><br>https://tools.ietf.org/html/draft-ietf-secsh-filexfer-02<=
br><br><br><div><span data-mailaddress=3D"ietf-ssh3@denisbider.com" data-co=
ntactname=3D"denis bider" class=3D"clickable"><span title=3D"ietf-ssh3@deni=
sbider.com">denis bider</span><span class=3D"detail"> &lt;ietf-ssh3@denisbi=
der.com&gt;</span></span> , 1/29/2016 9:59 PM:<br><blockquote class=3D"mori=
" style=3D"margin:0 0 0 .8ex;border-left:2px blue solid;padding-left:1ex;">=
<div><div>With regard to <b>AEAD:</b><br><br>I think we should just make th=
e following simple and clear statement:<br><br>MAC algorithms are secondary=
 to encryption algorithms, and are evaluated only if the encryption algorit=
hm is not AEAD. If an AEAD encryption algorithm is negotiated, the outcome =
of MAC negotiation is irrelevant and must be ignored. If no mutual MAC algo=
rithms are available, this causes key exchange to fail if, and only if, the=
 negotiated encryption algorithm is not AEAD.<br><br>I believe this is what=
 <a href=3D"mailto:aesXXX-gcm@openssh.com" title=3D"mailto:aesXXX-gcm@opens=
sh.com" class=3D"mailto">aesXXX-gcm@openssh.com</a> does, and is the behavi=
or that makes most sense to me.<br><br><br>With regard to<b> SFTP:</b><br><=
br>We may not have an agreement in what SFTP <i>should</i> be; but by neces=
sity, we have an agreement in what it <i>is</i>.<br><br>I suggest we should=
 simply do the minimum work possible to promote the following drafts to som=
e type of RFC, and call it a day:<br><br>SFTP v3 - as implemented by OpenSS=
H and everyone who wants to interoperate with it<br><a href=3D"https://tool=
s.ietf.org/html/draft-ietf-secsh-filexfer-04" target=3D"_blank" title=3D"ht=
tps://tools.ietf.org/html/draft-ietf-secsh-filexfer-04">https://tools.ietf.=
org/html/draft-ietf-secsh-filexfer-04</a><br><br>SFTP v6 - implemented by m=
any (perhaps most?) clients and servers<br><a href=3D"https://tools.ietf.or=
g/html/draft-ietf-secsh-filexfer-13" target=3D"_blank" title=3D"https://too=
ls.ietf.org/html/draft-ietf-secsh-filexfer-13">https://tools.ietf.org/html/=
draft-ietf-secsh-filexfer-13</a><br><a href=3D"https://tools.ietf.org/html/=
draft-galb-filexfer-extensions-00" target=3D"_blank" title=3D"https://tools=
.ietf.org/html/draft-galb-filexfer-extensions-00">https://tools.ietf.org/ht=
ml/draft-galb-filexfer-extensions-00</a><br><br>This is the de facto SFTP a=
s we have it. Implementers have to follow these drafts, so they might as we=
ll be RFCs.<br><br><br></div>
<div>----- Original Message ----- <br></div>
<div>From: Niels "M=C3=B6ller" </div>
<div>Sent: Friday, January 29, 2016 15:34</div>
<div>To: Stephen Farrell </div>
<div>Cc: <a href=3D"mailto:ietf-ssh@NetBSD.org" title=3D"mailto:ietf-ssh@Ne=
tBSD.org" class=3D"mailto">ietf-ssh@NetBSD.org</a> ; denis bider ; Watson L=
add ; Daniel Migault ;=20
Curdle Chairs ; <a href=3D"mailto:mdb@juniper.net" title=3D"mailto:mdb@juni=
per.net" class=3D"mailto">mdb@juniper.net</a> </div>
<div>Subject: Re: suggestion for new ssh maintenance wg</div>
<div>&nbsp;</div>
<div>Stephen Farrell &lt;<a href=3D"mailto:stephen.farrell@cs.tcd.ie" title=
=3D"mailto:stephen.farrell@cs.tcd.ie" class=3D"mailto">stephen.farrell@cs.t=
cd.ie</a>&gt; writes:</div>
<div>&nbsp;</div>
<div>&gt; If you think such an ssh maintenance wg is a bad plan,</div>
<div>&gt; please also do say that and why you think that.</div>
<div>&nbsp;</div>
<div>There's definitely some work that needs to be done. I'm not very</div>
<div>familiar with ietf processes, so I'm not sure a new working group=20
would</div>
<div>make it easier to make progress. I guess what's needed is either an</d=
iv>
<div>active wg chair, or an active area director, or someone informally</di=
v>
<div>accepting (and being accepted) in a similar role.</div>
<div>&nbsp;</div>
<div>&gt; PPS: Note that this could be short-lived wg that never</div>
<div>&gt; needs to meet face-to-face, or maybe it'd not be like that,</div>
<div>&gt; but don't get fussed about having to go to IETF meetings</div>
<div>&gt; to get this work done - if it's maintenance then that may</div>
<div>&gt; well not be needed.</div>
<div>&nbsp;</div>
<div>Don't worry about IETF meetings. I felt I was deeply involved during=20
the</div>
<div>work on the ssh rfc:s. And I've never been to a secsh wg meeting,=20
only</div>
<div>on the mailing list. (I've actually been to one ietf meeting in my=20
life,</div>
<div>but the secsh wg didn't meet that time).</div>
<div>&nbsp;</div>
<div>&gt;&gt; Extension negotiation for SSH: </div>
<div>&gt;&gt; <a href=3D"https://datatracker.ietf.org/doc/draft-ssh-ext-inf=
o" target=3D"_blank" title=3D"https://datatracker.ietf.org/doc/draft-ssh-ex=
t-info">https://datatracker.ietf.org/doc/draft-ssh-ext-info</a></div>
<div>&nbsp;</div>
<div>An extension mechanism makes sense to me, but I find most of the</div>
<div>proposed extensions questionable and/or hard to get right.</div>
<div>&nbsp;</div>
<div>&gt;&gt; In addition to the above, I very much agree that=20
<a href=3D"mailto:aes-gcm@openssh.com" title=3D"mailto:aes-gcm@openssh.com"=
 class=3D"mailto">aes-gcm@openssh.com</a></div>
<div>&gt;&gt; needs standardization.</div>
<div>&nbsp;</div>
<div>I think the single issue that might motivate forming a new wg is how=20
to</div>
<div>properly negotiate the use of aead crypt in ssh. There should be no</d=
iv>
<div>difference between aes-gcm (which I'm not very fond of) and</div>
<div>chacha-poly1305.</div>
<div>&nbsp;</div>
<div>&gt;&gt; Among other things, the erstwhile SSH working group never=20
finalized</div>
<div>&gt;&gt; the SFTP spec due to lack of consensus. We now have two SFTP=20
specs,</div>
<div>&gt;&gt; version 3 implemented by OpenSSH, and version 6 implemented b=
y=20
most</div>
<div>&gt;&gt; everyone else.</div>
<div>&nbsp;</div>
<div>I honestly doubt we'll see much progress there, wg or not. It was a=20
bit</div>
<div>too much of second system syndrome. But if some others have the=20
energy</div>
<div>to revive it, I can't object, of course.</div>
<div>&nbsp;</div>
<div>Regards,</div>
<div>/Niels</div>
<div>&nbsp;</div>
<div>-- </div>
<div>Niels M=C3=B6ller. PGP-encrypted email is preferred. Keyid C0B98E26.</=
div>
<div>Internet email is subject to wholesale government surveillance.</div><=
/div></blockquote></div></body></html>=

--=-0CoMnllLvveeu4p53sAp--
