
From housley@vigilsec.com  Fri Feb 15 08:53:56 2013
Return-Path: <housley@vigilsec.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 028D921F8803 for <saag@ietfa.amsl.com>; Fri, 15 Feb 2013 08:53:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[AWL=-0.001, BAYES_00=-2.599, HTML_MESSAGE=0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NzVX-seSjqIa for <saag@ietfa.amsl.com>; Fri, 15 Feb 2013 08:53:54 -0800 (PST)
Received: from odin.smetech.net (mail.smetech.net [208.254.26.82]) by ietfa.amsl.com (Postfix) with ESMTP id 1A4AA21F851C for <saag@ietf.org>; Fri, 15 Feb 2013 08:53:54 -0800 (PST)
Received: from localhost (unknown [208.254.26.81]) by odin.smetech.net (Postfix) with ESMTP id 374D09A4002 for <saag@ietf.org>; Fri, 15 Feb 2013 11:54:13 -0500 (EST)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([208.254.26.82]) by localhost (ronin.smetech.net [208.254.26.81]) (amavisd-new, port 10024) with ESMTP id X1m1Snn7WIMr for <saag@ietf.org>; Fri, 15 Feb 2013 11:53:32 -0500 (EST)
Received: from [192.168.8.119] (unknown [207.87.202.130]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id 11F419A400D for <saag@ietf.org>; Fri, 15 Feb 2013 11:54:07 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-261-387937919
Date: Fri, 15 Feb 2013 11:53:47 -0500
References: <D7A0423E5E193F40BE6E94126930C4930BF3EA109E@MBCLUSTER.xchange.nist.gov>
To: IETF SAAG <saag@ietf.org>
Message-Id: <FC293C3E-5CF4-43BC-B480-29A39E39D8DF@vigilsec.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
Subject: [saag] Fwd: Use of full entropy in NIST Special Pub 800-90 series
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Feb 2013 16:53:56 -0000

--Apple-Mail-261-387937919
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

FYI

Begin forwarded message:

> From: "Caswell, Sara J." <sara.caswell@nist.gov>
> Date: February 14, 2013 1:05:59 PM EST
> To: "housley@vigilsec.com" <housley@vigilsec.com>
> Subject: Use of full entropy in NIST Special Pub 800-90 series
>=20
> NIST is in the process of adjudicating all comments received during =
the SP 800-90B and SP 800-90C public comment period.  In doing so, it =
has been determined that the concept of full entropy as used in these =
Special Publications only serves to confuse the entropy discussion.  For =
example, since true full entropy cannot be measured, the attempts to =
draw a distinction between 0.9999668 bits of min-entropy per bit output =
and full entropy do not provide meaningful results.  As a result, a =
decision was made to remove full entropy from the documents.  This has =
the following impact:
>=20
> =B7         NIST SP 800-90A will be revised to remove references to =
full entropy sources.
> =B7         NIST SP 800-90B will focus on the components and =
evaluation of entropy sources.  The validation tests provided will all =
produce a min-entropy estimate.  No additional qualifiers (such as =93full=
 entropy=94) will be provided, since the entropy estimate is the only =
result needed.
> =B7         NIST SP 800-90C will no longer include the XOR NRBG =
Construction.  It will contain the other RBG constructions, along with a =
description of how to use a validated entropy source (i.e., a guide =
explaining how to use the entropy source to get the entropy needed, =
given the entropy estimate).=20
>=20
> SP 800-90A and the initial drafts of SP 800-90B and C are available at =
http://csrc.nist.gov/publications/PubsSPs.html.
>=20
> NIST believes that this change will result in clearer, more useable =
documentation.  Please send any comments or concerns to =
rbg_comments@nist.gov by March 1, 2013 using =93Comments on Full =
Entropy=94 in the subject line.
>=20


--Apple-Mail-261-387937919
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1252

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; =
">FYI<br><div><br><div>Begin forwarded message:</div><br =
class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px;"><span style=3D"font-family:'Helvetica'; =
font-size:medium; color:rgba(0, 0, 0, 1);"><b>From: </b></span><span =
style=3D"font-family:'Helvetica'; font-size:medium;">"Caswell, Sara J." =
&lt;<a =
href=3D"mailto:sara.caswell@nist.gov">sara.caswell@nist.gov</a>&gt;<br></s=
pan></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px;"><span =
style=3D"font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, =
1);"><b>Date: </b></span><span style=3D"font-family:'Helvetica'; =
font-size:medium;">February 14, 2013 1:05:59 PM EST<br></span></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px;"><span style=3D"font-family:'Helvetica'; =
font-size:medium; color:rgba(0, 0, 0, 1);"><b>To: </b></span><span =
style=3D"font-family:'Helvetica'; font-size:medium;">"<a =
href=3D"mailto:housley@vigilsec.com">housley@vigilsec.com</a>" &lt;<a =
href=3D"mailto:housley@vigilsec.com">housley@vigilsec.com</a>&gt;<br></spa=
n></div><div style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: =
0px; margin-left: 0px;"><span style=3D"font-family:'Helvetica'; =
font-size:medium; color:rgba(0, 0, 0, 1);"><b>Subject: </b></span><span =
style=3D"font-family:'Helvetica'; font-size:medium;"><b>Use of full =
entropy in NIST Special Pub 800-90 series</b><br></span></div><br><span =
class=3D"Apple-style-span" style=3D"border-collapse: separate; =
font-family: Helvetica; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: =
none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div =
lang=3D"EN-US" link=3D"blue" vlink=3D"purple"><div class=3D"WordSection1" =
style=3D"page: WordSection1; "><p class=3D"MsoNormal" style=3D"margin-top:=
 0in; margin-right: 0in; margin-bottom: 10pt; margin-left: 0in; =
line-height: 17px; font-size: 11pt; font-family: Calibri, sans-serif; =
">NIST is in the process of adjudicating all comments received during =
the SP 800-90B and SP 800-90C public comment period.&nbsp; In doing so, =
it has been determined that the concept of full entropy as used in these =
Special Publications only serves to confuse the entropy =
discussion.&nbsp; For example, since true full entropy cannot be =
measured, the attempts to draw a distinction between 0.9999668 bits of =
min-entropy per bit output and full entropy do not provide meaningful =
results.&nbsp; As a result, a decision was made to remove full entropy =
from the documents.&nbsp; This has the following impact:</p><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0.5in; =
margin-bottom: 0.0001pt; line-height: 17px; font-size: 11pt; =
font-family: Calibri, sans-serif; text-indent: -0.25in; "><span =
style=3D"font-family: Symbol; "><span>=B7<span style=3D"font: normal =
normal normal 7pt/normal 'Times New Roman'; =
">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span></span></span></span>NIST =
SP 800-90A will be revised to remove references to full entropy =
sources.</div><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0.5in; margin-bottom: 0.0001pt; line-height: 17px; =
font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in; =
"><span style=3D"font-family: Symbol; "><span>=B7<span style=3D"font: =
normal normal normal 7pt/normal 'Times New Roman'; =
">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span></span></span></span>NIST =
SP 800-90B will focus on the components and evaluation of entropy =
sources.&nbsp; The validation tests provided will all produce a =
min-entropy estimate.&nbsp; No additional qualifiers (such as =93full =
entropy=94) will be provided, since the entropy estimate is the only =
result needed.</div><p class=3D"MsoListParagraphCxSpLast" =
style=3D"margin-top: 0in; margin-right: 0in; margin-bottom: 10pt; =
margin-left: 0.5in; line-height: 17px; font-size: 11pt; font-family: =
Calibri, sans-serif; text-indent: -0.25in; "><span style=3D"font-family: =
Symbol; "><span>=B7<span style=3D"font: normal normal normal 7pt/normal =
'Times New Roman'; =
">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span></span></span></span>NIST =
SP 800-90C will no longer include the XOR NRBG Construction.&nbsp; It =
will contain the other RBG constructions, along with a description of =
how to use a validated entropy source (i.e., a guide<span =
class=3D"Apple-converted-space">&nbsp;</span><span style=3D"color: =
black; ">explaining how to use the entropy source to get the entropy =
needed, given the entropy estimate).&nbsp;</span></p><p =
class=3D"MsoNormal" style=3D"margin-top: 0in; margin-right: 0in; =
margin-bottom: 10pt; margin-left: 0in; line-height: 17px; font-size: =
11pt; font-family: Calibri, sans-serif; ">SP 800-90A and the initial =
drafts of SP 800-90B and C are available at<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://csrc.nist.gov/publications/PubsSPs.html" style=3D"color: =
blue; text-decoration: underline; =
">http://csrc.nist.gov/publications/PubsSPs.html</a>.</p><p =
class=3D"MsoNormal" style=3D"margin-top: 0in; margin-right: 0in; =
margin-bottom: 10pt; margin-left: 0in; line-height: 17px; font-size: =
11pt; font-family: Calibri, sans-serif; ">NIST believes that this change =
will result in clearer, more useable documentation.&nbsp; Please send =
any comments or concerns to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:rbg_comments@nist.gov?subject=3DComments%20on%20Full%20Entr=
opy" style=3D"color: blue; text-decoration: underline; =
">rbg_comments@nist.gov</a><span =
class=3D"Apple-converted-space">&nbsp;</span>by March 1, 2013 using =
=93Comments on Full Entropy=94 in the subject =
line.</p></div></div></span></blockquote></div><br></body></html>=

--Apple-Mail-261-387937919--
