
From nobody Mon May  8 09:56:32 2017
Return-Path: <beverloo@google.com>
X-Original-To: webpush@ietfa.amsl.com
Delivered-To: webpush@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD485128D44 for <webpush@ietfa.amsl.com>; Mon,  8 May 2017 09:56:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u7pW9npVmMgF for <webpush@ietfa.amsl.com>; Mon,  8 May 2017 09:56:28 -0700 (PDT)
Received: from mail-yw0-x22f.google.com (mail-yw0-x22f.google.com [IPv6:2607:f8b0:4002:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E91CB1200F1 for <webpush@ietf.org>; Mon,  8 May 2017 09:56:27 -0700 (PDT)
Received: by mail-yw0-x22f.google.com with SMTP id 203so32391372ywe.0 for <webpush@ietf.org>; Mon, 08 May 2017 09:56:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=ozZrYPHC/Wo4AmsKDaSn+8MyURWnHQzrFpknQnYPVnM=; b=pud2oJBzUrneCi/8AJ95uuysvstsWwBEqzUHpKjtHhD3z5f7gNZLD1Q1US7oNs60h6 avQ/MxCMLofvgr+1wqGjR4t0r9bTdiomeieLMEZyDXcGvcxbPy12KZ55n3wHkCz1sCOK Tg0LazmiRvDeAcKZNon+z8gDq02mC1PsUc8+6rXyfGKoo554K/rnO12enx37wHXQEnkT NnYfW5nUYF6JLQwSkAQ6DpmTvxpn88/VZdB+/af9X+gMtbVe6HGUFzxvjUqVpy99jb9p LQNGJzXPJzrd9G6GxE5ByeQNmj50OwA6hvdBQ7mljdsKDB9/+gL0ZBjyRnLSxMi35Vcd pRww==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=ozZrYPHC/Wo4AmsKDaSn+8MyURWnHQzrFpknQnYPVnM=; b=QWF8W3QOtJ6dEjyXufx0Rb8K2wkDZGjNSZxwyCEQ1MMvuJAW68zZB8d7j1fzZR4Asv VxBAYF49AOeQUkCRcjOnLdvuyyffbl4+hN5CTGA1AToSoiccasjx0w/v9yTYDcS1EveS MCdDohTDJEpMbVcKdJXIkwx/y2gCYJ9ARsbI81nckh2sFGymROuuH5qhpLcK3MSNhqIn w6Rqda/81fSnIaO0YfjcMvNqGaIg7IfR1VuFGO6y7SlRjG9aNipDd6wWlX6v+2f/Zqsn wK58QAgqzioTJ7OQ4TC59n2YOiZLky9u5ZHrdUcdpZ1tCIQDWagTAzOEcaaoWg1Buj9R WzPA==
X-Gm-Message-State: AN3rC/52zqj3AgA0gMJv8sWwe8yeFUcZNqKQQRHQj0M7Y+xYhGzgGEny 5pGkGB35fbxMfs76/UGPr8I2OrkTrggk
X-Received: by 10.129.131.211 with SMTP id t202mr20532383ywf.107.1494262587150;  Mon, 08 May 2017 09:56:27 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.129.26.1 with HTTP; Mon, 8 May 2017 09:56:26 -0700 (PDT)
In-Reply-To: <CABkgnnXD9u48qpXFL94v4A0DBAHLOxQ7HFJFTcJSEg9HzgFMgg@mail.gmail.com>
References: <CABF6JR0-dvEp4+cF7qp89UYevoA_PZ56L8R0OvtiBHL+NLqw3w@mail.gmail.com> <CABkgnnXD9u48qpXFL94v4A0DBAHLOxQ7HFJFTcJSEg9HzgFMgg@mail.gmail.com>
From: Peter Beverloo <beverloo@google.com>
Date: Mon, 8 May 2017 17:56:26 +0100
Message-ID: <CALt3x6nMTBOQad1Vcb4uWD2ZvPw_YD-_o0g4epJfsmdxjbT13A@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
Cc: Phil Sorber <sorber@apache.org>, "webpush@ietf.org" <webpush@ietf.org>
Content-Type: multipart/alternative; boundary=94eb2c07a516b5b1ed054f061e3f
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/5UmnBVvJQuogB1m5dtGqr1-UxuM>
Subject: Re: [Webpush] WGLC for draft-ietf-webpush-encryption-08
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 May 2017 16:56:30 -0000

--94eb2c07a516b5b1ed054f061e3f
Content-Type: text/plain; charset=UTF-8

+1

The draft looks great to me, thank you for driving this Martin! I sent a PR
with a few editorial suggestions. I've verified the example and will
provide an implementation of the draft for Chrome.

Thanks,
Peter

On Wed, Apr 26, 2017 at 7:25 AM, Martin Thomson <martin.thomson@gmail.com>
wrote:

> Aside from thinking that this is ready (author bias notwithstanding),
> if you want to send nits (or open issues), the draft is on github
> here:
>
> https://github.com/webpush-wg/webpush-encryption
>
> I'd be happy to take an input there.
>
> On 26 April 2017 at 08:04, Phil Sorber <sorber@apache.org> wrote:
> > 2. If you only find nits, they can be sent directly to the author(s)
>
> _______________________________________________
> Webpush mailing list
> Webpush@ietf.org
> https://www.ietf.org/mailman/listinfo/webpush
>

--94eb2c07a516b5b1ed054f061e3f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">+1<div><br></div><div>The draft looks great to me, thank y=
ou for driving this Martin! I sent a PR with a few editorial suggestions. I=
&#39;ve verified the example and will provide an implementation of the draf=
t for Chrome.</div><div><br></div><div>Thanks,</div><div>Peter</div></div><=
div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Wed, Apr 26, 20=
17 at 7:25 AM, Martin Thomson <span dir=3D"ltr">&lt;<a href=3D"mailto:marti=
n.thomson@gmail.com" target=3D"_blank">martin.thomson@gmail.com</a>&gt;</sp=
an> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;=
border-left:1px #ccc solid;padding-left:1ex">Aside from thinking that this =
is ready (author bias notwithstanding),<br>
if you want to send nits (or open issues), the draft is on github<br>
here:<br>
<br>
<a href=3D"https://github.com/webpush-wg/webpush-encryption" rel=3D"norefer=
rer" target=3D"_blank">https://github.com/webpush-wg/<wbr>webpush-encryptio=
n</a><br>
<br>
I&#39;d be happy to take an input there.<br>
<span class=3D""><br>
On 26 April 2017 at 08:04, Phil Sorber &lt;<a href=3D"mailto:sorber@apache.=
org">sorber@apache.org</a>&gt; wrote:<br>
&gt; 2. If you only find nits, they can be sent directly to the author(s)<b=
r>
<br>
</span>______________________________<wbr>_________________<br>
Webpush mailing list<br>
<a href=3D"mailto:Webpush@ietf.org">Webpush@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/webpush" rel=3D"noreferrer=
" target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/webpush</a><=
br>
</blockquote></div><br></div>

--94eb2c07a516b5b1ed054f061e3f--


From nobody Thu May 11 12:03:43 2017
Return-Path: <beverloo@google.com>
X-Original-To: webpush@ietfa.amsl.com
Delivered-To: webpush@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A9010131465 for <webpush@ietfa.amsl.com>; Thu, 11 May 2017 12:03:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mj0QibLgWwyb for <webpush@ietfa.amsl.com>; Thu, 11 May 2017 12:03:39 -0700 (PDT)
Received: from mail-yw0-x229.google.com (mail-yw0-x229.google.com [IPv6:2607:f8b0:4002:c05::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 505841242F5 for <webpush@ietf.org>; Thu, 11 May 2017 11:57:22 -0700 (PDT)
Received: by mail-yw0-x229.google.com with SMTP id l135so963651ywb.2 for <webpush@ietf.org>; Thu, 11 May 2017 11:57:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:from:date:message-id:subject:to:cc; bh=V4Ahl1NmEwqV6xj8ntZiHsW3qW0pprhd8tGxnYhU6vw=; b=pqFtU1NP6e6xdPjIgJdG8FbuzWt7qsUNBytoAmIVWl5/ecaUkHhqG98NLeD8xatP1N 9JdF8uKvSnLFosjt2PrN3a3DB0okJ0LajD3TIqMf1KA1Mitq947CyzQFUbcsr+YTdAb7 rAsQkP08irO59z3Ax1k6xf4CgQua4tJVSPxgUcrsw7gCNrvs4N7xGYP17QBnTnXM1I2A 1mx31e0dbp6XoTIt9M15DZvH/daP5P8IPDAYqUbSbiOpb9mjV0KeChamcaEQevVRWy22 WzbXv+HfsP06JPgRnPqOBsoriABVrjt0GZAbRLi2wq7f6eIf+Snh8afHHO1vHTq9rFM1 id/w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to:cc; bh=V4Ahl1NmEwqV6xj8ntZiHsW3qW0pprhd8tGxnYhU6vw=; b=du52FKt2Xff03pHXCKssSLj7TC1YCya4gViTbQo9DmCIb9qUE7FfxcB4WgHOT8/HkZ zf5uRFH8Dd5lyR6tI+P99CyVGo5b9KqPBZnC8IIhHhEpMlQjnNNmcer/1b/+phmbBFC4 c3YeAzw/GRvG4blBe4H0Be73bS7Fjy87xNQesQJyhRUKt5MG+aT2q7T74JXEFH8E45CT AQ1Yl/td/I7G42hY0FZMmii8bbAd0GXR9uBKJMyZp5I8klR6O4IstI585lUP+5vJp72J uUiVg0TzESFb9lHXlzBZE0Ok2xJP9A5/9E7MfqsLoBAJxF5/sD4d42/O/oZJqUKj+QQU O60w==
X-Gm-Message-State: AODbwcCyLrzGlOc0VyyB+3u0QZX8crbi3/Txpj8ZqZdC2VTUaAH3uqR0 eRqs3fTNPKJp5tePJa2dseZHFOlIuQfd
X-Received: by 10.129.177.72 with SMTP id p69mr32896ywh.184.1494529041470; Thu, 11 May 2017 11:57:21 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.129.26.1 with HTTP; Thu, 11 May 2017 11:57:21 -0700 (PDT)
From: Peter Beverloo <beverloo@google.com>
Date: Thu, 11 May 2017 19:57:21 +0100
Message-ID: <CALt3x6n5vzKp1bnRs9son=X-7JvH4L08RRRVipKNzxaOLfW80Q@mail.gmail.com>
To: "webpush@ietf.org" <webpush@ietf.org>, Martin Thomson <martin.thomson@gmail.com>
Cc: Quan Nguyen <quannguyen@google.com>
Content-Type: multipart/alternative; boundary="94eb2c13cddca01d9a054f44289c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/Lld0a8uRGD5T5pkJDSN4gdvqBGw>
Subject: [Webpush] Suggestion regarding curve validation in draft-ietf-webpush-encryption
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 May 2017 19:03:42 -0000

--94eb2c13cddca01d9a054f44289c
Content-Type: text/plain; charset="UTF-8"

Relaying for Quan Nguyen (cc'd):

      I would suggest adding a section about verifying peer's public key
      is on the private key's curve in ECDH protocol. Without this check,
      for the curve that they use P-256, it would allow attacker to
      extract the private key.

Thanks,
Peter

--94eb2c13cddca01d9a054f44289c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Relaying for Quan Nguyen (cc&#39;d):<br></div><div><b=
r></div><div>=C2=A0 =C2=A0 =C2=A0 I would suggest adding a section about ve=
rifying peer&#39;s public key</div><div>=C2=A0 =C2=A0 =C2=A0 is on the priv=
ate key&#39;s curve in ECDH protocol. Without this check,</div><div>=C2=A0 =
=C2=A0 =C2=A0 for the curve that they use P-256, it would allow attacker to=
</div><div>=C2=A0 =C2=A0 =C2=A0 extract the private key.</div><div><br></di=
v><div>Thanks,</div><div>Peter</div><div><br></div></div>

--94eb2c13cddca01d9a054f44289c--


From nobody Thu May 11 17:31:39 2017
Return-Path: <martin.thomson@gmail.com>
X-Original-To: webpush@ietfa.amsl.com
Delivered-To: webpush@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 20FA712EAD9 for <webpush@ietfa.amsl.com>; Thu, 11 May 2017 17:31:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dXcQXFnTEBYO for <webpush@ietfa.amsl.com>; Thu, 11 May 2017 17:31:36 -0700 (PDT)
Received: from mail-wr0-x22a.google.com (mail-wr0-x22a.google.com [IPv6:2a00:1450:400c:c0c::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AFC56129B84 for <webpush@ietf.org>; Thu, 11 May 2017 17:26:31 -0700 (PDT)
Received: by mail-wr0-x22a.google.com with SMTP id w50so33452050wrc.0 for <webpush@ietf.org>; Thu, 11 May 2017 17:26:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=O4IQIwjEQ7596KkwkGMFJ4OVI8fuayx5qC4q911CMIo=; b=rXdx9FofK4CyqbY7RPBg3G65ZTJhOuLJq0mRGSH1jmy8EyP9Gjf/UkUSu3Z2gA1va1 txHBYJM16EZILIV1hgNdk/0O1Fgqy2JXfF+g/khqHzwM3KHSI0w1GMoeezLU/fPrvT+0 dD5s8Gcs6itMNZ8INwY5GFTCJlOzmOIgJ+WF6IusQVC5IFtbzYe023o92LpnCJZO37kj NN8W3mLSMX5GClfOZn2ysBgEeJYNWwDwCH/cwOKR42oghKthzl/WaS1noHu9UxFgW0Od j6HcCoHVIoqvQx+861iH69H6CXMu8oREaI4C40Rk4msNUn9vyAJAjBwTOvh+qFnUedub r3iw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=O4IQIwjEQ7596KkwkGMFJ4OVI8fuayx5qC4q911CMIo=; b=OHC4n6KohDazaSbSNZ4mI5/gBCsKsYX+hstSIMtvrrDsoNYYCQXsCes/WHj8yeorzw keSLTVI2rz19SrPjcAqx8uoI2bpZ1ihHkV5C/xCNNC+dFvD3SU9L9hwTgmNxSB4nARjz d2VcDsFGrs0glVb7MfcMNdwH7VEyBVxqKyqMkisrk7hpbpDflIznKEbx4yBFFnsAGwc2 8ySKWl4O4KpCdHK1icp0Rfd0piQv1NtnlxxM1KBaew3PNqRNJfngHsXNDVl8FdMKBeBJ 93dYPxdtAwrr+i7yf69OVKwtY0hSfCr31houyVoFaj0jiFTTixzO5Y2hL8uXP0LXgeBc 87VA==
X-Gm-Message-State: AODbwcDp0XwSlbslcZONc1At8ci6AdQw5sI+aSyvtn3eQINo63Q7/Dsz mdxdLnjrdvLrW+jyxgHBJTqbVV2i8Q==
X-Received: by 10.46.19.18 with SMTP id 18mr321287ljt.103.1494548790224; Thu, 11 May 2017 17:26:30 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.46.83.2 with HTTP; Thu, 11 May 2017 17:26:29 -0700 (PDT)
In-Reply-To: <CALt3x6n5vzKp1bnRs9son=X-7JvH4L08RRRVipKNzxaOLfW80Q@mail.gmail.com>
References: <CALt3x6n5vzKp1bnRs9son=X-7JvH4L08RRRVipKNzxaOLfW80Q@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Fri, 12 May 2017 10:26:29 +1000
Message-ID: <CABkgnnUt2A3aM26mhdTDg8AeMeS-Gpmvchq8v7CO68w2Yx4-TA@mail.gmail.com>
To: Peter Beverloo <beverloo@google.com>
Cc: "webpush@ietf.org" <webpush@ietf.org>, Quan Nguyen <quannguyen@google.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/8UKrWbdkHGosSSdDAXo6sxF4VEY>
Subject: Re: [Webpush] Suggestion regarding curve validation in draft-ietf-webpush-encryption
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 May 2017 00:31:38 -0000

Yeah, probably not a bad idea.  I originally assumed that this was
part of most libraries (NSS does this always), but since writing the
draft I've learned that not every library does this properly.

I've updated my private copy of the draft.  I've also checked that my
implementations of the draft aren't vulnerable (I only traced the
code, but it appears that they all end up in the openssl key import
code, which validates points:
https://github.com/openssl/openssl/blob/master/crypto/ec/ec_lib.c#L741).

On 12 May 2017 at 04:57, Peter Beverloo <beverloo@google.com> wrote:
> Relaying for Quan Nguyen (cc'd):
>
>       I would suggest adding a section about verifying peer's public key
>       is on the private key's curve in ECDH protocol. Without this check,
>       for the curve that they use P-256, it would allow attacker to
>       extract the private key.
>
> Thanks,
> Peter
>


From nobody Sat May 13 13:22:14 2017
Return-Path: <sorber@apache.org>
X-Original-To: webpush@ietfa.amsl.com
Delivered-To: webpush@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 281D2127601 for <webpush@ietfa.amsl.com>; Sat, 13 May 2017 13:22:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.522
X-Spam-Level: 
X-Spam-Status: No, score=-4.522 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y5eyKVukO0cV for <webpush@ietfa.amsl.com>; Sat, 13 May 2017 13:22:11 -0700 (PDT)
Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by ietfa.amsl.com (Postfix) with SMTP id 2C3BF129B9C for <webpush@ietf.org>; Sat, 13 May 2017 13:19:09 -0700 (PDT)
Received: (qmail 42340 invoked by uid 99); 13 May 2017 20:19:08 -0000
Received: from mail-relay.apache.org (HELO mail-relay.apache.org) (140.211.11.15) by apache.org (qpsmtpd/0.29) with ESMTP; Sat, 13 May 2017 20:19:08 +0000
Received: from mail-io0-f169.google.com (mail-io0-f169.google.com [209.85.223.169]) by mail-relay.apache.org (ASF Mail Server at mail-relay.apache.org) with ESMTPSA id 1FF251A0A04 for <webpush@ietf.org>; Sat, 13 May 2017 20:19:08 +0000 (UTC)
Received: by mail-io0-f169.google.com with SMTP id o12so56183839iod.3 for <webpush@ietf.org>; Sat, 13 May 2017 13:19:08 -0700 (PDT)
X-Gm-Message-State: AODbwcAmHqlZTAOCsX3HSf3Pssrp9WMEQRGmWdAvT8S/wWAPZ0Rbr8Fy Nm02PFdRqhQD1jfaiOeB+7gxB66umw==
X-Received: by 10.107.170.201 with SMTP id g70mr9623458ioj.187.1494706747402;  Sat, 13 May 2017 13:19:07 -0700 (PDT)
MIME-Version: 1.0
References: <CABF6JR0-dvEp4+cF7qp89UYevoA_PZ56L8R0OvtiBHL+NLqw3w@mail.gmail.com> <CABkgnnXD9u48qpXFL94v4A0DBAHLOxQ7HFJFTcJSEg9HzgFMgg@mail.gmail.com> <CALt3x6nMTBOQad1Vcb4uWD2ZvPw_YD-_o0g4epJfsmdxjbT13A@mail.gmail.com>
In-Reply-To: <CALt3x6nMTBOQad1Vcb4uWD2ZvPw_YD-_o0g4epJfsmdxjbT13A@mail.gmail.com>
From: Phil Sorber <sorber@apache.org>
Date: Sat, 13 May 2017 20:18:56 +0000
X-Gmail-Original-Message-ID: <CABF6JR2TaRP_Ky=T4b57=YiTHDc5B5xNvKLGCvOghiCVkr7LVg@mail.gmail.com>
Message-ID: <CABF6JR2TaRP_Ky=T4b57=YiTHDc5B5xNvKLGCvOghiCVkr7LVg@mail.gmail.com>
To: Peter Beverloo <beverloo@google.com>, Martin Thomson <martin.thomson@gmail.com>
Cc: "webpush@ietf.org" <webpush@ietf.org>
Content-Type: multipart/alternative; boundary="001a11426ae8b91148054f6d88a6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/webpush/hZynTe8076aw88kA3BFh2VzZ3AM>
Subject: Re: [Webpush] WGLC for draft-ietf-webpush-encryption-08
X-BeenThere: webpush@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of potential IETF work on a web push protocol <webpush.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webpush>, <mailto:webpush-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webpush/>
List-Post: <mailto:webpush@ietf.org>
List-Help: <mailto:webpush-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webpush>, <mailto:webpush-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 13 May 2017 20:22:13 -0000

--001a11426ae8b91148054f6d88a6
Content-Type: text/plain; charset="UTF-8"

Ok, it seems like we have consensus on this doc as well. I am going to move
this doc to "waiting for writeup" and I'll shepherd it also.

Thanks everybody!

On Mon, May 8, 2017 at 12:56 PM Peter Beverloo <beverloo@google.com> wrote:

> +1
>
> The draft looks great to me, thank you for driving this Martin! I sent a
> PR with a few editorial suggestions. I've verified the example and will
> provide an implementation of the draft for Chrome.
>
> Thanks,
> Peter
>
> On Wed, Apr 26, 2017 at 7:25 AM, Martin Thomson <martin.thomson@gmail.com>
> wrote:
>
>> Aside from thinking that this is ready (author bias notwithstanding),
>> if you want to send nits (or open issues), the draft is on github
>> here:
>>
>> https://github.com/webpush-wg/webpush-encryption
>>
>> I'd be happy to take an input there.
>>
>> On 26 April 2017 at 08:04, Phil Sorber <sorber@apache.org> wrote:
>> > 2. If you only find nits, they can be sent directly to the author(s)
>>
>> _______________________________________________
>> Webpush mailing list
>> Webpush@ietf.org
>> https://www.ietf.org/mailman/listinfo/webpush
>>
>
>

--001a11426ae8b91148054f6d88a6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><span style=3D"color:rgb(33,33,33);font-size:13px">Ok, it =
seems like we have consensus on this doc as well. I am going to move this d=
oc to &quot;waiting for writeup&quot; and I&#39;ll shepherd it also.</span>=
<div style=3D"color:rgb(33,33,33);font-size:13px"><br></div><div style=3D"c=
olor:rgb(33,33,33);font-size:13px">Thanks everybody!</div><br><div class=3D=
"gmail_quote"><div dir=3D"ltr">On Mon, May 8, 2017 at 12:56 PM Peter Beverl=
oo &lt;<a href=3D"mailto:beverloo@google.com">beverloo@google.com</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex=
;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">+1<div><br><=
/div><div>The draft looks great to me, thank you for driving this Martin! I=
 sent a PR with a few editorial suggestions. I&#39;ve verified the example =
and will provide an implementation of the draft for Chrome.</div><div><br><=
/div><div>Thanks,</div><div>Peter</div></div><div class=3D"gmail_extra"><br=
><div class=3D"gmail_quote"></div></div><div class=3D"gmail_extra"><div cla=
ss=3D"gmail_quote">On Wed, Apr 26, 2017 at 7:25 AM, Martin Thomson <span di=
r=3D"ltr">&lt;<a href=3D"mailto:martin.thomson@gmail.com" target=3D"_blank"=
>martin.thomson@gmail.com</a>&gt;</span> wrote:<br></div></div><div class=
=3D"gmail_extra"><div class=3D"gmail_quote"><blockquote class=3D"gmail_quot=
e" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">=
Aside from thinking that this is ready (author bias notwithstanding),<br>
if you want to send nits (or open issues), the draft is on github<br>
here:<br>
<br>
<a href=3D"https://github.com/webpush-wg/webpush-encryption" rel=3D"norefer=
rer" target=3D"_blank">https://github.com/webpush-wg/webpush-encryption</a>=
<br>
<br>
I&#39;d be happy to take an input there.<br>
<span><br>
On 26 April 2017 at 08:04, Phil Sorber &lt;<a href=3D"mailto:sorber@apache.=
org" target=3D"_blank">sorber@apache.org</a>&gt; wrote:<br>
&gt; 2. If you only find nits, they can be sent directly to the author(s)<b=
r>
<br>
</span></blockquote></div></div><div class=3D"gmail_extra"><div class=3D"gm=
ail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bor=
der-left:1px #ccc solid;padding-left:1ex">_________________________________=
______________<br>
Webpush mailing list<br>
<a href=3D"mailto:Webpush@ietf.org" target=3D"_blank">Webpush@ietf.org</a><=
br>
<a href=3D"https://www.ietf.org/mailman/listinfo/webpush" rel=3D"noreferrer=
" target=3D"_blank">https://www.ietf.org/mailman/listinfo/webpush</a><br>
</blockquote></div><br></div>
</blockquote></div></div>

--001a11426ae8b91148054f6d88a6--

