
From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Apr  3 22:18:53 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF53C124D37 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  3 Apr 2017 22:18:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aUdt4Ma6okOk for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  3 Apr 2017 22:18:50 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E2B5124D68 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon,  3 Apr 2017 22:18:50 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id DC5E9855AB; Tue,  4 Apr 2017 05:18:47 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 972558558D; Tue,  4 Apr 2017 05:18:47 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id B2793855C3 for <ietf-ssh@netbsd.org>; Mon,  3 Apr 2017 20:03:42 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id jiBPlkzqRxcV for <ietf-ssh@netbsd.org>; Mon,  3 Apr 2017 20:03:42 +0000 (UTC)
Received: from serpens.de (serpens.de [195.22.142.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id E219D84CDB for <ietf-ssh@netbsd.org>; Mon,  3 Apr 2017 20:03:40 +0000 (UTC)
Received: from serpens.de (spz@localhost [127.0.0.1]) by serpens.de (8.15.2/8.13.3) with ESMTPS id v33K325L028514 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 3 Apr 2017 22:03:21 +0200 (MEST)
Received: (from spz@localhost) by serpens.de (8.15.2/8.12.11) id v33K2sHZ001940; Mon, 3 Apr 2017 22:02:59 +0200 (MEST)
Date: Mon, 3 Apr 2017 22:02:51 +0200
From: "S.P.Zeidler" <spz@serpens.de>
To: "denis bider (Bitvise)" <ietf-ssh3@denisbider.com>
Cc: ietf-ssh@netbsd.org, djm@mindrot.org, Simon Tatham <anakin@pobox.com>
Subject: Re: Fixing exchange of host keys in the SSH key exchange
Message-ID: <20170403200250.GB21972@serpens.de>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan>
X-message-flag: Please send plain text messages only. Thank you.
User-Agent: Mutt/1.8.0 (2017-02-23)
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi,

if I may stick an oar in sideways: if you go to all the trouble,
could you add a mechanism by which the server could advise that
the host key used by the client was still valid but deprecated,
and to download the new host key once connected?

Speaking as an admin of a bunch of servers whose users -do- ask
when the host key changes, I currently feel a need for a better
mechanism for updates to longer keys than "send mail".

regards,
	spz
-- 
spz@serpens.de (S.P.Zeidler)

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Apr  6 13:34:25 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1E8B127871 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu,  6 Apr 2017 13:34:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.899
X-Spam-Level:
X-Spam-Status: No, score=-2.899 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=denisbider.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wXVphQ2IaYn5 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu,  6 Apr 2017 13:34:23 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87387129489 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu,  6 Apr 2017 13:34:23 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 6988385647; Thu,  6 Apr 2017 20:34:22 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 1C74485645; Thu,  6 Apr 2017 20:34:22 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 327E0855BA for <ietf-ssh@netbsd.org>; Tue,  4 Apr 2017 07:27:38 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=denisbider.com
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id K00YLVbiKLCw for <ietf-ssh@netbsd.org>; Tue,  4 Apr 2017 07:27:37 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 9310C855AD for <ietf-ssh@netbsd.org>; Tue,  4 Apr 2017 07:27:37 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=denisbider.com; s=mail; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to: references; bh=wzD+eD0auApPJSkReqRHbgkYdFv2Ixh5L+JJHJALZyU=; b=PXYKK8+Tjf3ARdP98UO3Bbfp3vxls4LI2/T5i1H75msAnW9ckeep+J+PIfEHDm41ySpB8KhsNgOnU SSZc3PkDaRM4sn4m6YR/rerRRQ62vSVGCnMUkme+eTaiIT+bcafBqECQrx7eZDsUeKzHXuzfzNJ4jf 9s4na5X3whmLByix0i5VRHj2dS/yPWkYHu9TfHJZD89dqOuWrQTxXtdWd/R7sXcxhHIyEAoqpZQFSg K4qUaAelZLRXyWrbeGzWq4yym5cCYdGVFP0vLIQWtwDuGMaDxnKNtOuMRImcO/o57AEJsl/puxgojq yi4MVoOeGLGVcKqdWLojhiqRe5Nu8og==
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com with ESMTPSA (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)); Tue, 4 Apr 2017 08:27:30 +0100
Message-ID: <05DC33124D144EC0B39A5BF58C8E3A33@Khan>
From: "denis bider \(Bitvise\)" <ietf-ssh3@denisbider.com>
To: "S.P.Zeidler" <spz@serpens.de>
Cc: <ietf-ssh@netbsd.org>, <djm@mindrot.org>, "Simon Tatham" <anakin@pobox.com>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <20170403200250.GB21972@serpens.de>
In-Reply-To: <20170403200250.GB21972@serpens.de>
Subject: Re: Fixing exchange of host keys in the SSH key exchange
Date: Tue, 4 Apr 2017 01:27:25 -0600
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0290_01D2ACE2.9D879320"
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3528.331
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3528.331
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

This is a multi-part message in MIME format.

------=_NextPart_000_0290_01D2ACE2.9D879320
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

OpenSSH documents this as a private extension:

https://github.com/openssh/openssh-portable/blob/master/PROTOCOL#L286

Our SSH Server and Client do not implement this mechanism at this time, =
but it=E2=80=99s something I would like us to support.

denis


From: S.P.Zeidler=20
Sent: Monday, April 3, 2017 14:02
To: denis bider (Bitvise)=20
Cc: ietf-ssh@netbsd.org ; djm@mindrot.org ; Simon Tatham=20
Subject: Re: Fixing exchange of host keys in the SSH key exchange

Hi,

if I may stick an oar in sideways: if you go to all the trouble,
could you add a mechanism by which the server could advise that
the host key used by the client was still valid but deprecated,
and to download the new host key once connected?

Speaking as an admin of a bunch of servers whose users -do- ask
when the host key changes, I currently feel a need for a better
mechanism for updates to longer keys than "send mail".

regards,
spz
--=20
spz@serpens.de (S.P.Zeidler)

------=_NextPart_000_0290_01D2ACE2.9D879320
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD></HEAD>
<BODY dir=3Dltr>
<DIV dir=3Dltr>
<DIV style=3D"FONT-SIZE: 10pt; FONT-FAMILY: 'Arial'; COLOR: #000000">
<DIV>OpenSSH documents this as a private extension:</DIV>
<DIV>&nbsp;</DIV>
<DIV><A=20
title=3Dhttps://github.com/openssh/openssh-portable/blob/master/PROTOCOL#=
L286=20
href=3D"https://github.com/openssh/openssh-portable/blob/master/PROTOCOL#=
L286">https://github.com/openssh/openssh-portable/blob/master/PROTOCOL#L2=
86</A></DIV>
<DIV>&nbsp;</DIV>
<DIV>Our SSH Server and Client do not implement this mechanism at this =
time, but=20
it=E2=80=99s something I would like us to support.</DIV>
<DIV>&nbsp;</DIV>
<DIV>denis</DIV>
<DIV>&nbsp;</DIV>
<DIV=20
style=3D'FONT-SIZE: small; TEXT-DECORATION: none; FONT-FAMILY: =
"Calibri"; FONT-WEIGHT: normal; COLOR: #000000; FONT-STYLE: normal; =
DISPLAY: inline'>
<DIV style=3D"FONT: 10pt tahoma">
<DIV>&nbsp;</DIV>
<DIV style=3D"BACKGROUND: #f5f5f5">
<DIV style=3D"font-color: black"><B>From:</B> <A title=3Dspz@serpens.de=20
href=3D"mailto:spz@serpens.de">S.P.Zeidler</A> </DIV>
<DIV><B>Sent:</B> Monday, April 3, 2017 14:02</DIV>
<DIV><B>To:</B> <A title=3Dietf-ssh3@denisbider.com=20
href=3D"mailto:ietf-ssh3@denisbider.com">denis bider (Bitvise)</A> =
</DIV>
<DIV><B>Cc:</B> <A title=3Dietf-ssh@netbsd.org=20
href=3D"mailto:ietf-ssh@netbsd.org">ietf-ssh@netbsd.org</A> ; <A=20
title=3Ddjm@mindrot.org =
href=3D"mailto:djm@mindrot.org">djm@mindrot.org</A> ; <A=20
title=3Danakin@pobox.com href=3D"mailto:anakin@pobox.com">Simon =
Tatham</A> </DIV>
<DIV><B>Subject:</B> Re: Fixing exchange of host keys in the SSH key=20
exchange</DIV></DIV></DIV>
<DIV>&nbsp;</DIV></DIV>
<DIV=20
style=3D'FONT-SIZE: small; TEXT-DECORATION: none; FONT-FAMILY: =
"Calibri"; FONT-WEIGHT: normal; COLOR: #000000; FONT-STYLE: normal; =
DISPLAY: inline'>Hi,<BR><BR>if=20
I may stick an oar in sideways: if you go to all the trouble,<BR>could =
you add a=20
mechanism by which the server could advise that<BR>the host key used by =
the=20
client was still valid but deprecated,<BR>and to download the new host =
key once=20
connected?<BR><BR>Speaking as an admin of a bunch of servers whose users =
-do-=20
ask<BR>when the host key changes, I currently feel a need for a=20
better<BR>mechanism for updates to longer keys than "send=20
mail".<BR><BR>regards,<BR>spz<BR>-- <BR>spz@serpens.de=20
(S.P.Zeidler)<BR></DIV></DIV></DIV></BODY></HTML>

------=_NextPart_000_0290_01D2ACE2.9D879320--


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu Apr  6 13:35:07 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E94ED12941D for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu,  6 Apr 2017 13:35:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6xrVoAbrZnR6 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu,  6 Apr 2017 13:35:06 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C2BD12965B for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu,  6 Apr 2017 13:35:03 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 5EDF285654; Thu,  6 Apr 2017 20:34:45 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 16C4D85645; Thu,  6 Apr 2017 20:34:45 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 5DC598557E for <ietf-ssh@NetBSD.org>; Wed,  5 Apr 2017 08:03:14 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id ITEfuVJGr1A9 for <ietf-ssh@netbsd.org>; Wed,  5 Apr 2017 08:03:13 +0000 (UTC)
Received: from Stone.Rodents-Montreal.ORG (Stone.Rodents-Montreal.ORG [98.124.61.89]) by mail.netbsd.org (Postfix) with ESMTP id E55F6856D4 for <ietf-ssh@NetBSD.org>; Tue,  4 Apr 2017 22:06:58 +0000 (UTC)
Received: (from mouse@localhost) by Stone.Rodents-Montreal.ORG (8.8.8/8.8.8) id SAA17278; Tue, 4 Apr 2017 18:06:58 -0400 (EDT)
Date: Tue, 4 Apr 2017 18:06:58 -0400 (EDT)
From: Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <201704042206.SAA17278@Stone.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
X-Composition-Start-Date: Tue, 4 Apr 2017 18:04:03 -0400 (EDT)
To: ietf-ssh@NetBSD.org
Subject: Re: Fixing exchange of host keys in the SSH key exchange
In-Reply-To: <20170403200250.GB21972@serpens.de>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <20170403200250.GB21972@serpens.de>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> if I may stick an oar in sideways: if you go to all the trouble,
> could you add a mechanism by which the server could advise that the
> host key used by the client was still valid but deprecated, and to
> download the new host key once connected?

That actually is a very interesting argument I hadn't thought of for
something operationally like the proposed scheme: it permits the server
to support multiple host keys at once for a single algorithm.  (The
client, of course, already can, since in the current design it's the
one judging host key validity.)

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri Apr  7 14:02:27 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A75E3127867 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri,  7 Apr 2017 14:02:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y39dGYCKHHC2 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri,  7 Apr 2017 14:02:25 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ECAC812786A for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri,  7 Apr 2017 14:02:25 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 00ADB84D73; Fri,  7 Apr 2017 21:02:24 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id A398B84CE2; Fri,  7 Apr 2017 21:02:24 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id DE2A484D74 for <ietf-ssh@NetBSD.org>; Fri,  7 Apr 2017 20:41:51 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id FOrDVtHedFH4 for <ietf-ssh@netbsd.org>; Fri,  7 Apr 2017 20:41:51 +0000 (UTC)
Received: from Stone.Rodents-Montreal.ORG (Stone.Rodents-Montreal.ORG [98.124.61.89]) by mail.netbsd.org (Postfix) with ESMTP id 7DC94859C9 for <ietf-ssh@NetBSD.org>; Fri,  7 Apr 2017 15:29:33 +0000 (UTC)
Received: (from mouse@localhost) by Stone.Rodents-Montreal.ORG (8.8.8/8.8.8) id LAA27568; Fri, 7 Apr 2017 11:29:32 -0400 (EDT)
Date: Fri, 7 Apr 2017 11:29:32 -0400 (EDT)
From: Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <201704071529.LAA27568@Stone.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
X-Composition-Start-Date: Fri, 7 Apr 2017 11:08:21 -0400 (EDT)
To: ietf-ssh@NetBSD.org
Subject: Re: Fixing exchange of host keys in the SSH key exchange
In-Reply-To: <05DC33124D144EC0B39A5BF58C8E3A33@Khan>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <20170403200250.GB21972@serpens.de> <05DC33124D144EC0B39A5BF58C8E3A33@Khan>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

>> if I may stick an oar in sideways: if you go to all the trouble,
>> could you add a mechanism by which the server could advise that the
>> host key used by the client was still valid but deprecated, and to
>> download the new host key once connected?

> OpenSSH documents this as a private extension: [...]

They say, when describing hostkeys-00@openssh.com and
hostkeys-prove-00@openssh.com, that "[i]t also supports graceful key
rotation: a server may offer multiple keys of the same type for a
period (to give clients an opportunity to learn them using this
extension) before removing the deprecated key from those offered".

I cannot see how this is even possible, at least not without a custom
kex algorithm.  With, for example, Diffie-Hellman as defined in 4253
section 8, the server presents only one host key to the client, and
must choose which one to present before kex (and thus authentication)
completes.  This then gives no room to "offer multiple keys of the same
type".

The only way I can see that making any sense at all is if the server
continues to use the old key, but advertises both keys with
hostkeys-00@ for a period before bringing the new key into use.  Maybe
that's what they're talking about, but if so I think the wording is
rather confusing.  I much prefer the client-specified list of host keys
such as is made possible by what we started out this thread discussing.

I also don't see anything in the OpenSSH stuff that allows the server
to indicate that certain of the keys listed in hostkeys-00@ are
deprecated, which is at least part of what I read spz as asking for.

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri Apr  7 20:48:49 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 463C612709D for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri,  7 Apr 2017 20:48:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NXUuDwfcOXhP for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri,  7 Apr 2017 20:48:47 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 26F8A12778E for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri,  7 Apr 2017 20:48:41 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id C1D4784D9C; Sat,  8 Apr 2017 03:48:39 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id B21F284D91 for <ietf-ssh@netbsd.org>; Sat,  8 Apr 2017 03:48:37 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id aLnK8OZ-a4NW for <ietf-ssh@netbsd.org>; Sat,  8 Apr 2017 03:48:37 +0000 (UTC)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 62AB784D79 for <ietf-ssh@netbsd.org>; Sat,  8 Apr 2017 03:48:35 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1491623316; x=1523159316; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=sErPhGsQYvbhOruAWqPgIlHmZMG66/ZW/xnP9ucx2Ug=; b=kh6xPAox+XWgRNlOfFs7p+Tu8KOWBoBKfXlpGJPJlkove6JVUn7PpVdl rAQXySc3TPO4I3JZASfYsbSCjvaFNeYEcxF28f1dGXyNQhIVycThtRVIR rnDTrvbA7Ekguo8dMi2p4CESaiy8Q8t1ITy1Qu51dsticz4x05VANG+TL Jb9O5fWTE7xrjaqdP2MpzMAPpolkqqtL674g14huLdnY60MzcPN1w74h1 Lxfbon/to6/EA2rPlhHP4D/AsASqVg3Bu7uBxVcFwxV32v2hDPQSYH5bg K1eFM7zrBm+9zGxQCn2h/0jqvkiBK/QoGkY61NVZEFt8tx4/ueoSbDj3I Q==;
X-IronPort-AV: E=Sophos;i="5.37,169,1488798000";  d="scan'208";a="148585242"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 10.6.2.3 - Outgoing - Outgoing
Received: from uxcn13-ogg-b.uoa.auckland.ac.nz ([10.6.2.3]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 08 Apr 2017 15:48:33 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz (10.6.2.5) by uxcn13-ogg-b.UoA.auckland.ac.nz (10.6.2.3) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Sat, 8 Apr 2017 15:48:32 +1200
Received: from uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.25]) by uxcn13-ogg-d.UoA.auckland.ac.nz ([10.6.2.25]) with mapi id 15.00.1263.000; Sat, 8 Apr 2017 15:48:33 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Mouse <mouse@Rodents-Montreal.ORG>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: Re: Fixing exchange of host keys in the SSH key exchange
Thread-Topic: Fixing exchange of host keys in the SSH key exchange
Thread-Index: AQHSrQL9CktYPaoqMkm97HMyMuzyS6G0Bp+AgAU9sgCAAZeYMw==
Date: Sat, 8 Apr 2017 03:48:32 +0000
Message-ID: <1491623291953.19014@cs.auckland.ac.nz>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <20170403200250.GB21972@serpens.de> <05DC33124D144EC0B39A5BF58C8E3A33@Khan>,<201704071529.LAA27568@Stone.Rodents-Montreal.ORG>
In-Reply-To: <201704071529.LAA27568@Stone.Rodents-Montreal.ORG>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [130.216.158.4]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Mouse <mouse@Rodents-Montreal.ORG> writes:=0A=
=0A=
>They say, when describing hostkeys-00@openssh.com and hostkeys-=0A=
>prove-00@openssh.com, that "[i]t also supports graceful key rotation: a=0A=
>server may offer multiple keys of the same type for a period (to give clie=
nts=0A=
>an opportunity to learn them using this extension) before removing the=0A=
>deprecated key from those offered".=0A=
>=0A=
>I cannot see how this is even possible, at least not without a custom kex=
=0A=
>algorithm. With, for example, Diffie-Hellman as defined in 4253 section 8,=
=0A=
>the server presents only one host key to the client, and must choose which=
=0A=
>one to present before kex (and thus authentication) completes.  This then=
=0A=
>gives no room to "offer multiple keys of the same type".=0A=
=0A=
I assumed the offered keys are via "hostkeys-00@openssh.com", not in the=0A=
keyex.  As the text says, it offers those for awhile, then when it seems al=
l=0A=
clients have got a copy it switches the keyex from the old to the new key.=
=0A=
=0A=
Peter.=0A=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sat Apr  8 09:48:08 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D32FC12943B for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sat,  8 Apr 2017 09:48:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.19
X-Spam-Level:
X-Spam-Status: No, score=-2.19 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_DKIM_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (2048-bit key) reason="fail (body has been altered)" header.d=denisbider.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QHlpj8tkPSqg for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sat,  8 Apr 2017 09:48:06 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D2279128D3E for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sat,  8 Apr 2017 09:48:06 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id D363F84DBF; Sat,  8 Apr 2017 16:48:05 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 8013D84DCA; Sat,  8 Apr 2017 16:48:05 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id E1A1E84DBA for <ietf-ssh@NetBSD.org>; Sat,  8 Apr 2017 11:00:45 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=denisbider.com
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id Bn1rXX8NqPX3 for <ietf-ssh@netbsd.org>; Sat,  8 Apr 2017 11:00:45 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1.1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 4413F84DB5 for <ietf-ssh@NetBSD.org>; Sat,  8 Apr 2017 11:00:45 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=denisbider.com; s=mail; h=from:subject:date:message-id:to:mime-version:content-type:in-reply-to: references; bh=RkpXSyBSwHhbHwVUwDCT7PqYdIHAyWcKA+o+eYSl/0c=; b=HyIBZuN8Bpq5Lo/dQFhXUiVvX4tjy3EQTYo4z33Mk1y10yMr1AcLQAe/HJF3xsGg2psLNxCaObiFL USUwq/o+rqFzPVG4W2jzeqUjYh1KGJIsqPxzNNBTi3l9k1aY9VhV9izCsfSjCF5BAnZl2pSNF2QXtV QsYVAjc0KeiP64OzpPv6Qp1COGctUl2hjQzKjGx+cFLTJkd06jwTNdwlSXwYZsDYd0AB11yanDaLIs J9W7M28VqT6iEuPtpl3x5Rg8ZkhmXaMrp2IvaJWTOnZagrMX0ppNwTy0GidueBIJ8EDhNUqR3DOkjW FfL5s3YebmN+i0alKhmTLb6qzig2wEg==
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com with ESMTPSA (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)); Sat, 8 Apr 2017 12:00:20 +0100
Message-ID: <8B467D57DE1D4B71AA6539977B6F5D0F@Khan>
From: "denis bider \(Bitvise\)" <ietf-ssh3@denisbider.com>
To: "Peter Gutmann" <pgut001@cs.auckland.ac.nz>, "Mouse" <mouse@Rodents-Montreal.ORG>, <ietf-ssh@NetBSD.org>
References: <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <20170403200250.GB21972@serpens.de><05DC33124D144EC0B39A5BF58C8E3A33@Khan>,<201704071529.LAA27568@Stone.Rodents-Montreal.ORG> <1491623291953.19014@cs.auckland.ac.nz>
In-Reply-To: <1491623291953.19014@cs.auckland.ac.nz>
Subject: Re: Fixing exchange of host keys in the SSH key exchange
Date: Sat, 8 Apr 2017 05:00:31 -0600
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0169_01D2B025.0C6F8780"
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3528.331
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3528.331
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

This is a multi-part message in MIME format.

------=_NextPart_000_0169_01D2B025.0C6F8780
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Yes =E2=80=93 that is my understanding as well.


From: Peter Gutmann=20
Sent: Friday, April 7, 2017 21:48
To: Mouse ; ietf-ssh@NetBSD.org=20
Subject: Re: Fixing exchange of host keys in the SSH key exchange

Mouse <mouse@Rodents-Montreal.ORG> writes:

>They say, when describing hostkeys-00@openssh.com and hostkeys-
>prove-00@openssh.com, that "[i]t also supports graceful key rotation: a
>server may offer multiple keys of the same type for a period (to give =
clients
>an opportunity to learn them using this extension) before removing the
>deprecated key from those offered".
>
>I cannot see how this is even possible, at least not without a custom =
kex
>algorithm. With, for example, Diffie-Hellman as defined in 4253 section =
8,
>the server presents only one host key to the client, and must choose =
which
>one to present before kex (and thus authentication) completes.  This =
then
>gives no room to "offer multiple keys of the same type".

I assumed the offered keys are via "hostkeys-00@openssh.com", not in the
keyex.  As the text says, it offers those for awhile, then when it seems =
all
clients have got a copy it switches the keyex from the old to the new =
key.

Peter.

------=_NextPart_000_0169_01D2B025.0C6F8780
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD></HEAD>
<BODY dir=3Dltr>
<DIV dir=3Dltr>
<DIV style=3D"FONT-SIZE: 10pt; FONT-FAMILY: 'Arial'; COLOR: #000000">
<DIV>Yes =E2=80=93 that is my understanding as well.</DIV>
<DIV>&nbsp;</DIV>
<DIV=20
style=3D'FONT-SIZE: small; TEXT-DECORATION: none; FONT-FAMILY: =
"Calibri"; FONT-WEIGHT: normal; COLOR: #000000; FONT-STYLE: normal; =
DISPLAY: inline'>
<DIV style=3D"FONT: 10pt tahoma">
<DIV>&nbsp;</DIV>
<DIV style=3D"BACKGROUND: #f5f5f5">
<DIV style=3D"font-color: black"><B>From:</B> <A =
title=3Dpgut001@cs.auckland.ac.nz=20
href=3D"mailto:pgut001@cs.auckland.ac.nz">Peter Gutmann</A> </DIV>
<DIV><B>Sent:</B> Friday, April 7, 2017 21:48</DIV>
<DIV><B>To:</B> <A title=3Dmouse@Rodents-Montreal.ORG=20
href=3D"mailto:mouse@Rodents-Montreal.ORG">Mouse</A> ; <A=20
title=3Dietf-ssh@NetBSD.org=20
href=3D"mailto:ietf-ssh@NetBSD.org">ietf-ssh@NetBSD.org</A> </DIV>
<DIV><B>Subject:</B> Re: Fixing exchange of host keys in the SSH key=20
exchange</DIV></DIV></DIV>
<DIV>&nbsp;</DIV></DIV>
<DIV=20
style=3D'FONT-SIZE: small; TEXT-DECORATION: none; FONT-FAMILY: =
"Calibri"; FONT-WEIGHT: normal; COLOR: #000000; FONT-STYLE: normal; =
DISPLAY: inline'>Mouse=20
&lt;mouse@Rodents-Montreal.ORG&gt; writes:<BR><BR>&gt;They say, when =
describing=20
hostkeys-00@openssh.com and hostkeys-<BR>&gt;prove-00@openssh.com, that =
"[i]t=20
also supports graceful key rotation: a<BR>&gt;server may offer multiple =
keys of=20
the same type for a period (to give clients<BR>&gt;an opportunity to =
learn them=20
using this extension) before removing the<BR>&gt;deprecated key from =
those=20
offered".<BR>&gt;<BR>&gt;I cannot see how this is even possible, at =
least not=20
without a custom kex<BR>&gt;algorithm. With, for example, Diffie-Hellman =
as=20
defined in 4253 section 8,<BR>&gt;the server presents only one host key =
to the=20
client, and must choose which<BR>&gt;one to present before kex (and thus =

authentication) completes.&nbsp; This then<BR>&gt;gives no room to =
"offer=20
multiple keys of the same type".<BR><BR>I assumed the offered keys are =
via=20
"hostkeys-00@openssh.com", not in the<BR>keyex.&nbsp; As the text says, =
it=20
offers those for awhile, then when it seems all<BR>clients have got a =
copy it=20
switches the keyex from the old to the new=20
key.<BR><BR>Peter.<BR></DIV></DIV></DIV></BODY></HTML>

------=_NextPart_000_0169_01D2B025.0C6F8780--


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Apr 24 21:39:56 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B8D37120326 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 21:39:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.09
X-Spam-Level:
X-Spam-Status: No, score=-4.09 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zTXOYRAGMcBh for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 21:39:50 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DB121317C9 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 24 Apr 2017 21:39:50 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id B501A84DC1; Tue, 25 Apr 2017 04:39:48 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id F03DC84D7F for <ietf-ssh@NetBSD.org>; Tue, 25 Apr 2017 04:39:45 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id wiZQxGCaIFRO for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 04:39:45 +0000 (UTC)
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (mail-dm3nam03on0715.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe49::715]) by mail.netbsd.org (Postfix) with ESMTP id 46BB684CE2 for <ietf-ssh@NetBSD.org>; Tue, 25 Apr 2017 04:39:43 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=ajpumCC5d9xjiqBPTNKyluc3plUuDKGA66AtlT2e0FU=; b=PAYfIB1avMgHWq4ePR8kZAVp4AvBSE5AXUrBELSKZxrnc9NCtZbKmJq1ZL2TuOGxM+oJQgWuZNDfcb5E4A4SCvgLAzWVUYZzhQbxcEDRrlbz5pn4J8h1LgOgK+Cu3cPXvLOJfEMz4PKJxOhu/sHMF+rTdpF3U06NhamEYONZtbs=
Received: from DM5PR05CA0017.namprd05.prod.outlook.com (10.173.226.27) by DM2PR05MB733.namprd05.prod.outlook.com (10.141.178.18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1047.6; Tue, 25 Apr 2017 04:39:41 +0000
Received: from DM3NAM05FT025.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e51::206) by DM5PR05CA0017.outlook.office365.com (2603:10b6:3:d4::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1061.6 via Frontend Transport; Tue, 25 Apr 2017 04:39:41 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.12) smtp.mailfrom=juniper.net; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by DM3NAM05FT025.mail.protection.outlook.com (10.152.98.135) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.1019.24 via Frontend Transport; Tue, 25 Apr 2017 04:39:40 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Mon, 24 Apr 2017 21:39:39 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v3P4dcmW022864;	Mon, 24 Apr 2017 21:39:38 -0700	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 5FBA71145A;	Mon, 24 Apr 2017 21:39:37 -0700 (PDT)
To: <ietf-ssh@NetBSD.org>
CC: <curdle@ietf.org>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: eddsa25519 & eddsa448 for use with SSH
Date: Mon, 24 Apr 2017 21:39:37 -0700
Message-ID: <53117.1493095177@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12;IPV:NLI;CTRY:US;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(39400400002)(39860400002)(39410400002)(39840400002)(39450400003)(39850400002)(2980300002)(199003)(189002)(9170700003)(2906002)(8936002)(76506005)(86362001)(356003)(81166006)(2810700001)(106466001)(2351001)(110136004)(54356999)(53416004)(105596002)(7696004)(8676002)(5660300001)(48376002)(50986999)(4326008)(38730400002)(50466002)(77096006)(7126002)(117636001)(966004)(47776003)(6916009)(19273905006)(189998001)(5003940100001)(53936002)(6392003)(55016002)(6266002)(6306002)(305945005)(42262002)(562404015)(563064011);DIR:OUT;SFP:1102;SCL:1;SRVR:DM2PR05MB733;H:p-emfe01a-sac.jnpr.net;FPR:;SPF:SoftFail;MLV:sfv;A:1;MX:1;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM3NAM05FT025;1:/RcStLfBQm+g71QYoDc4zsk43JpkhafxPDPOY0lD3iG6D6c62adPwa1+vAkXuQf98DPXxPQZOCwh6HsW+oqavXBFHOqIE0A3zXP0jjTJ0RyznLve8tgSrgX8uqf1gIpNRf0pZWsQpC53HtRP3u6j0+PXQEL6FykB0tAfBU+0cqjlC5b5mRHRFXoDOZuHHH+qvjHF+IK57QxXJ2gUfReBRl+2TJaEFFs0et6WVcWirDi7/twbPB9T09cCaf3pp3+pb1TTle4gZ6Fw8UQMNBxWZhd2z1JLwwId6FEVYUZNeAiHJshrwZLPWbZChnAfuv9l0aidTeVARpubBDQd7CskIY4ohOAX8kTdEbWdruQy+1B3d9XCNOJ8y6Femkd+ZC+cniKhm4bABXw3fB1UVxmzqWb6ZZzgMPGvwf5Pckmfudoh16dJAz1+RG1ZsyG5u71aT0HW49eulfyjYthE5p/huFCzxglBq100qHeBe8oOfBQLHd0uNQIClDdJFnv6UGkLyRYeRqjI/Gi/G+0q6Sc86AY+F1O6RKkRnGT1kkTiQp6cwK1pov7gNwGrbHXmpYORi4JHLOFiVLBSbQ+OZOywte7xCPOoqoc3nsdaeYzFDO0=
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 64e55013-b485-4084-ceaf-08d48b951634
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(2017030254075)(201703131423075)(201703031133081);SRVR:DM2PR05MB733;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;3:aVddYUuSh5mDhlfD6580QI/FSpgZUNsc0xlnr7Tt2cDex5ilDYpm4BT+rW8pYFN7l4ZfVc0ECWD7j8i11d5OW6PLCbr/5NHoGmtKSSHrqz1zLcQyPrksTtei1lsG1Nhm8pk9j7abC9oIORqJgLLd40tnt5LvEZBdCrwoqNdL8FfY3N43zhUKSIlJIB4dnTAGznPBrMjpxZF9y90G/ZeVXP1/n/5er0PUE3Al51fMYZ29qNHdnS/mhT0ztZw/7bHphBuXPAKR/aGQChmwE82Wgn+jBKura3fEq6zBl5BAkE4K9Z/AWbC1rG+OOXOWCkxUWiickPctycKuvukgjlfDlHSf5vVj9rCr9wuoRMnT70dnrSJ8nevY9D4t6jogXGv79+2kq5bGgtH+6rhgAFMDqliqQeA5j/H1SBRenh5iocji4dWgrBYu9QO/h9YGF3YUnTlPHRJedV1BtaXBuxJXAA==
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;25:5ojcJysFHyWpnT+aAii1OQ1QIY1dBWW7tK1WvU+L5zIeRjIDoOQ+YoLj6a1iSDP6l50qs7d34eNljyqL+FBR+zydL9XMDJknjO5a6NB7ekWr9Mu6gGjhmXqwApR+gKNxLN8XViTP2g0uAzVur5WcrKDRxQzu38MJUvwR3AntRMx1ycFG0yxC52n9izh5fFT1SN+ItrPssYEl7fCL5XJUHWhNL99CrsusiCaI4h4FwWoZuDvk+bDu9KvVu6v56QvquRDdEzfvhSTaPGcAd5CySM4a5YAdz3s7gaVUm+9Hve9YywuXZglz24OONYeCS3PKVSOmV5BHMF66vfthRH8P8NswTerbmW3uzh789peFfLwXiKRC5GmLYxlWF9Fo+Rp68dRd8sUzUPHAFNKIgRPp9d5vj2dEQTtvMkDDfAr+ugTjdBve11ec9ln0BEC/5NaJRu9W3tvQah9gqTeQF2j4nW07ZjUGhkHB0kjTlxujMFA=;31:isk/TdP+IpGJLXKSKleucITIUKsZuuqDbakRGiIn9QFXr4TcfdrNqwElUl6xTMO9zrXBxgk88Dyua3Va6wkp7oKv22ptl+HO+V44lFAgtX1VkSvXPh1BZyrgNS2ymPyDwdcwdH3Mzm/0U3WPiP2cxwoTWOP+0X7G19WzN07T64PcOw1dMGrFwqM8iu5DCoPqA7hF+S8g7QL3/AEH0g/KD6YvDwO0c7geZ1DxoAE8iomWPnSDXUBFLiHeNeYma0Mp
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;20:QDJPHAdt5dqlr2rN/kUTl4vgXr5ByaYZOL+eccfU+eWswcvDPfhelurOXd2U3WlpkkzSqatQOQTXsVMVB+LWeTD7lXQWpOvtVL63sitTbhEUE6ZOnNlsifNM+sC32DQUFG87P9P+pjZmxmt2WLiQbBpZLlOsRIFqd7Bl0nLjYcmjuE9Mk6OeHclTo78Jt0Otd+ukLj/4o08BvbYS3CpR3Al9HaI+fJGxkW3hoRABT8nqR26Jgtg9GG7qUYE/SoXE94DAT+mB0VmcSpfKSQF/IqzBjEFzJQS+7UOhOlmc72RG+tzahpQtSPzuM3r7X4PVCWzn07MObZIx1vlDv/UdSJl5GbEH43AcsP4Zzm8B17RiIHwBpEYdgmbeNcoY8yPUIgy9G9vOTShDfFlypyawAJp7UFu7kXMDAW0FtQqwgqMqXpduXCpAcI04Pm0Mwq0Vx6i8MHahSb9PMP3AtzKl7Mj1Uqo1yFtr7HaxSS/c0NFpRHrKGh4wXxwoBAN5P5vC
X-Microsoft-Antispam-PRVS: <DM2PR05MB7331BFA47E1F57543680DD4BF1E0@DM2PR05MB733.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(1591387915157);
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(6040450)(601004)(2401047)(8121501046)(13015025)(5005006)(13017025)(13023025)(13024025)(13018025)(10201501046)(3002001)(93006095)(93003095)(6055026)(6041248)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(20161123560025)(20161123564025)(20161123562025)(6072148);SRVR:DM2PR05MB733;BCL:0;PCL:0;RULEID:;SRVR:DM2PR05MB733;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;4:f3+35M+kzKPGnE9YrazRcl9gIq8LNHraExsofGvXiBGziNJtMwNff+QitIJO8F/lkXq4sr72rd1nsZVOlKhP3jaZdUUBsKBaW1z+mJx45TT7JiNzIGFS6mX5SZ1kE5cUiuz9IInUioheEwbBXcD9sU/BiDFJ14t8rW6ARC2EFNkcXVZ+OiPAvVQGA7FA/L1T2s6TmnS9ygEkZaNF1HhCbO7JSzBkngFsGNZ9GC9+ytjKeeSH5XRlVVmOI2N1mymsIs66cxjw7ilkzn0TVGScB6I+stflXBfptKGCPWsIGN71rQZ5QyOz8YAWGhnaHfxG6KbUpTj/MriO1FG+EIXNHtgRCmVjPmseiX2mUX+DNZii0HYnwV2rlPSiUWSSp6GEs33x/vd6NOCn8sMNo78veSMf7EnWbX/I/Q21HusgGzViA9UPH9MzsKzJEy6qG2hQ3pqd/XNJIjPrpP92J8J4BxV1VzIVmIEdWAsUlAV4Fgw05N3tmp6Uf1PAL6nE8eb2gdNbQIcndCLBHwinO4DnA1bL6VBptmIKsUHJ2lwqbueT7Ow9JahPwigBMInFhDbUV866kZhg5HuivL9FMF2HxgtU7+jPCdWsC+MNNUy2VUlWZCmdwSR/vrb4F7aZTZjrntBIvQgZlsTUzUI5rS2B5HJkHG3QalTuJRYRByOUbYxJvJr5exoRKleCfn3VjirvdDMqi9srqC9h0GGqA9gLtNQ4c0FFPFfpOgyKld53ReFOXSJMy3inOVPpXJLrrxkijQrQLW/93mfe/jTCVfZ0rmwxwWb31+oT7Zzc2bFcleAtFIVBo45lkvgrGWVjICVfphfir+zXIOx3XpqiYtf80czViG5XgfwsHLmLAW2Oc29qDrOC0Nvjs8MYL3FOodvc
X-Forefront-PRVS: 0288CD37D9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;DM2PR05MB733;23:uVPFgbchl4LvHglqjHYsk3/5CsCsfh8ZPJbqVOvurc?= =?us-ascii?Q?PHL9hANvpQ2Gv/reXuFgYbzIxR8AHYqkKvl5tlZFyMNhlIPtusl09lVRCHj5?= =?us-ascii?Q?MSLUAlvan6LABI+xHV1jYANxXzQFa7MeCBIb7cVPbFem2vMm55eKDcn3M/MS?= =?us-ascii?Q?gQXWZ6R0cqagdEEAJ71E845seJII1+LBquqvztQ4/G5SS9XdjsHMz9OmBi3v?= =?us-ascii?Q?C5uSc7qRdFSg6bBEMoABDPc1RYle55fZAhL9ZD7QMrePYahU06ahIfJRpVg5?= =?us-ascii?Q?X9kOBY17X+UuiVmsSerZvbm3n83CmYm7gnTdvo1RkyCJcyzTFSz6dY0bLGx1?= =?us-ascii?Q?WiL4XUEp/Bf/815Dk9om5GM2ns9rnAc2tEfgc2TO/qpOLOf8+AsYU3CYwfyI?= =?us-ascii?Q?Xz1cKdjUStvaGwaBGL8uj9xWdvjrIH61CCJYaA+yanbuugWaJdwPrLkbKimZ?= =?us-ascii?Q?CyfLdPQ3gKzOA4DcDKtsXonbSrrC6FUHP3YJVxATdhPwwuRvaMeIALnNuprW?= =?us-ascii?Q?kdVzfc1i6trdnzq6aQhK4lv6EcuubMhVIJl+nC46B2Q0khnkj/bCqCmonSBS?= =?us-ascii?Q?yzQw6JFYIWZM2iOr7q0AUGbTe1F8H5f+D4dFhZxW18FChpEumfQmrCNuP265?= =?us-ascii?Q?XJXdrYwe7E699OIGMG0GICxv8W6Zjf2oqVdKYW4PMOVn3ITuuTMZFlmmXuur?= =?us-ascii?Q?UxfjEW5UAqw4l7S77G45FvO0656scK5TpkoCXqCJdavIbVskd3zDa0Cm25Dn?= =?us-ascii?Q?pVTZ+K2KcPuzOoBuwKv2C4drwd77RDrB+sMcJSHbIT9KgvGbiGU1YkLwGREK?= =?us-ascii?Q?R/2NPawZUzKqcl9g6SOz1THRQkdJThEYmeacNvJVzuWORYfkG+T9eJ7j/153?= =?us-ascii?Q?+6a05Oujpv05OfLLUarHonG6KgoH6Bsf6E2QaeSBvcif6MnYeumUdRFO8WTe?= =?us-ascii?Q?pKV1MkiOqefaCXaN2cZrIX8AHn7pocKh+JxPSzJUID7hsxT86raIdeI0pVBA?= =?us-ascii?Q?8CCWQJN3gNOf8BNIY/fo9vunS1trV/9OOVEc+TfWg8w2Axm0h3vfisYQDmC+?= =?us-ascii?Q?3+PNe3lppN/EF+1brXjT7xR2MUtTQZ/F/maiP0MgMJuoMjpGIkeAjwyCPW0c?= =?us-ascii?Q?8M5nxq0dYFgCFcy9RgLQXt5nm6MxBXaA6LqjegF6fg4to1cyXoVc0Iic5Hk0?= =?us-ascii?Q?lmiqSFbaZMEcjb9+N30D0JP1IThbLW61XWVG50UPiObuJjVljlmul2kg=3D?= =?us-ascii?Q?=3D?=
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;6:4Gp0BPEzKRlcL2GrKtGto5e/BKS66oUpPiKw3gdY3fY2ITdH1st8dpaIulH/DQdu6gnpEzlIm+XqTqwTh4U07O16xAPWpjB5kcxD8y+22VBkI8oiPw3yGDhsZr8KR4/YwNCPOMD9SmQXkoLbYTOdrtwH6ITpiBpd7hL2qFGFK+KYte/nQXXDJav22tC7yry6/yhizoglyb3XWI5Y3CCb7EN6UbX73frd1RsnJzLs2gxAwXiI5Ieq9m1vf8HxAjGAJ5nydYDDoybeZ3mvt01oKa1wk9SrBWqvxHNCICW2btTK7c2TuT+klCxDyK0He2FwKXM00/pCHfagr/2oSkkvBMUrVMtugSLCwK8U7rdgw9Z3Aw4aDvYmTSg395sKLouXOXHhP9MB8xKNyYV5Uc5D+dVzn8pnw4MpyF1Q92ER9gj9EAotSE4Iyco1U9duEe4yBx4P+9vPET6t6EoXCxvrSr3Plnkpn9OTcw49xZB7c3BThpMWu5BtT1oQ72AqxV02w+Z8YYkuXVTWCHYBiKl2eSQTxjQM1kSKeE8p6H79RLE=;5:Llwi+3gIH+OtOYI6pIXh+QZxepAJE80nTSIei0ZXSVIjVeG4fbcWQbOmEEkBA1bnX14a7Ln9BqLMG8ugWYAenIfxgPGNHUxeajgsO74+Sk9hG5cEIpDnS91wyRTc2Q48s8tCEtlJPcmS3GoxAXsVew==;24:nvRU2YjXLeBvGWShkHe1c6oMHrygEe+3ku0pYSq33KrsPQ5vztgQN/6kyZy/paJtj4uuadRW35kuiZ1BMoBdeDjM3js5BgQ8tRMH1Vu9LKc=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1;DM2PR05MB733;7:JNfycSsHY5Yti3MqF/z33MfkH88bJERAnSVYTRrkNSOdQNeCbMZSIzSzZI40Yb5kAQYXb3iOsK7a2TPnUw3Fkd28oDxqq+GGgKWVth6XabC7LyNMNxZLErKBcOL38HxNLGXICHcSVCWznhMPvUzTMu7dUM93obn2FFRv69tA5spjSZMtBH8xT7CXvQf5lliQH9rBwrFPRFFqBVLYT3t4i6TkyU50vYfx73ItbUwJi/HxPLQX7EUH3oiDfS5dFS5746lzK056afkKg41BiYv5MOQOLC0RqommGeSbzYWdO65DPIMnfO4v/mMUITb3bO9x7lExerDeSpRu/xGoEiIlWg==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Apr 2017 04:39:40.3408 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.12];Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR05MB733
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

Hi Folks,

Looking at

  RFC 8032 - Edwards-Curve Digital Signature Algorithm (EdDSA)

I am curious to know if there is a desire to create public key algorithm
names for SSH using it?

http://ssh-comparison.quendi.de/comparison/hostkey.html
shows 11 implementations of ssh-ed25519 and 3 implementations of
ssh-ed25519-cert-v01@openssh.com.

I have not yet compared the RFC against the SSH implementations of
ssh-ed25519.

I do know that the use of the SHAKE256 as a hash function for Ed448
would be the first SHA-3 family function used in the SSH protocol.

If they are the same, then it would be good to writeup something
to add ssh-ed25519 to the IANA 
https://www.iana.org/assignments/ssh-parameters/ssh-parameters.xhtml#ssh-parameters-19

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Apr 24 22:36:13 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53BB61319B7 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 22:36:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xmIPfUbybVSI for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 22:36:12 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:470:a085:999::25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1E527131868 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 24 Apr 2017 22:36:12 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 5100484DD7; Tue, 25 Apr 2017 05:36:11 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 0E8B884DD4; Tue, 25 Apr 2017 05:36:11 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 3BEF984CE3 for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 02:55:08 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id 6hLbvvTgDh6D for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 02:55:07 +0000 (UTC)
Received: from Stone.Rodents-Montreal.ORG (Stone.Rodents-Montreal.ORG [98.124.61.89]) by mail.netbsd.org (Postfix) with ESMTP id 43E7F84CDA for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 02:55:06 +0000 (UTC)
Received: (from mouse@localhost) by Stone.Rodents-Montreal.ORG (8.8.8/8.8.8) id WAA22499; Mon, 24 Apr 2017 22:55:05 -0400 (EDT)
Date: Mon, 24 Apr 2017 22:55:05 -0400 (EDT)
From: Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <201704250255.WAA22499@Stone.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
X-Composition-Start-Date: Mon, 24 Apr 2017 22:47:48 -0400 (EDT)
To: ietf-ssh@netbsd.org
Subject: Re: Fixing exchange of host keys in the SSH key exchange
In-Reply-To: <201703251227.IAA20189@Stone.Rodents-Montreal.ORG>
References: <201703251227.IAA20189@Stone.Rodents-Montreal.ORG> <2216143EDEE342A3A5C9BB786F7FEF7A@Khan> <1490340148872.12344@cs.auckland.ac.nz>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

Back on March 25th, I wrote (in the thread about making the client tell
the server what host keys it's able to authenticate using, pre-kex)

> Hmm, I think I'll give moussh a configuration option to send things
> before the ID string, for exactly that reason.

I've now done this.  See the -pre-banner command-line option and the
pre-banner config-file variable.

As the manpage notes,

                             Generating a line beginning `SSH-' with this
             mechanism will break the protocol; moussh contains no checks to
             ensure this isn't done.

I'm not sure whether I think this is the Right Thing.  I came down in
favour of this behaviour, but not by much; if anyone cares to argue in
favour of either position (either the above stance or making sure that
doesn't happen), I'd be interested.

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Apr 24 22:36:57 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B8D8126CF6 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 22:36:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.888
X-Spam-Level:
X-Spam-Status: No, score=-3.888 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_ADSP_CUSTOM_MED=0.001, DKIM_SIGNED=0.1, FREEMAIL_FORGED_FROMDOMAIN=0.199, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (2048-bit key) reason="fail (body has been altered)" header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mcX8uXag5kt1 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 24 Apr 2017 22:36:55 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6FA081250B8 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 24 Apr 2017 22:36:55 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id F0A1484DDD; Tue, 25 Apr 2017 05:36:54 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 9B3D984DD9; Tue, 25 Apr 2017 05:36:54 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 1914A84DC1 for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 05:20:00 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id RffjCL944l_n for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 05:19:59 +0000 (UTC)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 6130384CE2 for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 05:19:59 +0000 (UTC)
Received: by mail-qt0-x234.google.com with SMTP id m36so131220622qtb.0 for <ietf-ssh@netbsd.org>; Mon, 24 Apr 2017 22:19:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=XXck/aA6jYLms1CeiM/oDKO19Fjck+2kQA0kCDHx6aM=; b=OMakthKyqiCodswCBAN5pcSgIQg+OilRW0p8lTBCqUXFcHUxMzlk5DcwKStgqISUV1 ogNwGiu7hwDttQB2iQgRvEtu5Bh2wnmnUzuxMdORA7XW34iIrhuqD43MOgh9FguqLOqp m9b14tIeNs2lC9nBfZJ7lQYR03EzwCviTXADQELUoafOUC4r4A2YrxZGyfrWMasJAYKt lOytxs8C1ChakEvqt4tAGTRT/ycKgl8/p4pxZr+KJVIW3PngBVTW+YgOcdikXNomlLm3 /b180h2JR1nfKw6MwJsYZAYQt8X/9d7/qqwdbtg/DUyc0Jo4kZB8U5PJEEpKVkBnhFPw 5qQQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=XXck/aA6jYLms1CeiM/oDKO19Fjck+2kQA0kCDHx6aM=; b=c5n4cRzrpbh237fjnOB5dMqK0y98dCarMfff5EhlMZ2ChayBmCgzXsWJqEmtrSrhTg oeZj6/i5umRScoo64dQOJi7//YuvV5y2xuMs5PH7I6nF97LJuX0lNBfi8ZhbLaWMGXMq KpH+x2GC9d9PC6P9vx6GlMew5ZAzsGJziEbYvokO6U4trc8Wv3MTnKzMKP7fRtLXhbgo LVeX6qs/1tmJYfpzevaGPMhOsRQvs65e2oUco2gW8mJKTxK/yiHGI3d4vqc+kYD6v2/d BPOc3mTiPv1erM+WAzA/yr2GTSUCkvgmgJ/oAQcw+bYnwIvWxiG+09y0IgRaGYowsN2j pWMg==
X-Gm-Message-State: AN3rC/6Z5nDO7IgA8Zay7OJnPp9ltlsFtideHTG+i42pU/ftCyjFIItv fTTq9DX0fyvNyUkoR5EvCcM2D/FtOKAzl/A=
X-Received: by 10.200.54.7 with SMTP id m7mr28774023qtb.177.1493097598492; Mon, 24 Apr 2017 22:19:58 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.12.138.239 with HTTP; Mon, 24 Apr 2017 22:19:57 -0700 (PDT)
In-Reply-To: <53117.1493095177@eng-mail01.juniper.net>
References: <53117.1493095177@eng-mail01.juniper.net>
From: denis bider <denisbider.ietf@gmail.com>
Date: Mon, 24 Apr 2017 23:19:57 -0600
Message-ID: <CADPMZDBEasXekZv9kGTJdArxy8CCy-sZnTY4yjtGvy39sftHDQ@mail.gmail.com>
Subject: Re: [Curdle] eddsa25519 & eddsa448 for use with SSH
To: "Mark D. Baushke" <mdb@juniper.net>
Cc: ietf-ssh@netbsd.org, curdle <curdle@ietf.org>
Content-Type: multipart/alternative; boundary=001a113e43d2f923f2054df6df9e
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

--001a113e43d2f923f2054df6df9e
Content-Type: text/plain; charset=UTF-8

I believe the spec for ssh-ed25519 is already an active draft under the
purview of Curdle:

https://tools.ietf.org/html/draft-ietf-curdle-ssh-ed25519-00

On Mon, Apr 24, 2017 at 10:39 PM, Mark D. Baushke <mdb@juniper.net> wrote:

> Hi Folks,
>
> Looking at
>
>   RFC 8032 - Edwards-Curve Digital Signature Algorithm (EdDSA)
>
> I am curious to know if there is a desire to create public key algorithm
> names for SSH using it?
>
> http://ssh-comparison.quendi.de/comparison/hostkey.html
> shows 11 implementations of ssh-ed25519 and 3 implementations of
> ssh-ed25519-cert-v01@openssh.com.
>
> I have not yet compared the RFC against the SSH implementations of
> ssh-ed25519.
>
> I do know that the use of the SHAKE256 as a hash function for Ed448
> would be the first SHA-3 family function used in the SSH protocol.
>
> If they are the same, then it would be good to writeup something
> to add ssh-ed25519 to the IANA
> https://www.iana.org/assignments/ssh-parameters/ssh-parameters.xhtml#ssh-
> parameters-19
>
>         -- Mark
>
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle
>

--001a113e43d2f923f2054df6df9e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I believe the spec for ssh-ed25519 is already an active dr=
aft under the purview of Curdle:<div><br></div><div><a href=3D"https://tool=
s.ietf.org/html/draft-ietf-curdle-ssh-ed25519-00">https://tools.ietf.org/ht=
ml/draft-ietf-curdle-ssh-ed25519-00</a><br></div></div><div class=3D"gmail_=
extra"><br><div class=3D"gmail_quote">On Mon, Apr 24, 2017 at 10:39 PM, Mar=
k D. Baushke <span dir=3D"ltr">&lt;<a href=3D"mailto:mdb@juniper.net" targe=
t=3D"_blank">mdb@juniper.net</a>&gt;</span> wrote:<br><blockquote class=3D"=
gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-=
left:1ex">Hi Folks,<br>
<br>
Looking at<br>
<br>
=C2=A0 RFC 8032 - Edwards-Curve Digital Signature Algorithm (EdDSA)<br>
<br>
I am curious to know if there is a desire to create public key algorithm<br=
>
names for SSH using it?<br>
<br>
<a href=3D"http://ssh-comparison.quendi.de/comparison/hostkey.html" rel=3D"=
noreferrer" target=3D"_blank">http://ssh-comparison.quendi.<wbr>de/comparis=
on/hostkey.html</a><br>
shows 11 implementations of ssh-ed25519 and 3 implementations of<br>
<a href=3D"mailto:ssh-ed25519-cert-v01@openssh.com">ssh-ed25519-cert-v01@op=
enssh.<wbr>com</a>.<br>
<br>
I have not yet compared the RFC against the SSH implementations of<br>
ssh-ed25519.<br>
<br>
I do know that the use of the SHAKE256 as a hash function for Ed448<br>
would be the first SHA-3 family function used in the SSH protocol.<br>
<br>
If they are the same, then it would be good to writeup something<br>
to add ssh-ed25519 to the IANA<br>
<a href=3D"https://www.iana.org/assignments/ssh-parameters/ssh-parameters.x=
html#ssh-parameters-19" rel=3D"noreferrer" target=3D"_blank">https://www.ia=
na.org/<wbr>assignments/ssh-parameters/<wbr>ssh-parameters.xhtml#ssh-<wbr>p=
arameters-19</a><br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 -- Mark<br>
<br>
______________________________<wbr>_________________<br>
Curdle mailing list<br>
<a href=3D"mailto:Curdle@ietf.org">Curdle@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/curdle" rel=3D"noreferrer"=
 target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/curdle</a><br=
>
</blockquote></div><br></div>

--001a113e43d2f923f2054df6df9e--

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue Apr 25 15:31:17 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41B9E1205F0 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 25 Apr 2017 15:31:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.09
X-Spam-Level:
X-Spam-Status: No, score=-4.09 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y_61mP5RJ2n0 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 25 Apr 2017 15:31:15 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78BFB1294E4 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue, 25 Apr 2017 15:31:13 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id CAC0184DAD; Tue, 25 Apr 2017 22:31:11 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 67AC884D93 for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:09 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id Wq_jNzxDNGAS for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:08 +0000 (UTC)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0703.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe42::703]) by mail.netbsd.org (Postfix) with ESMTP id BBA3D84D7F for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:07 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=eO+0pvHOsenrLu2aIUvNN/k5kIK/eDcZoA7wSJUFbEc=; b=JeOE/OZckfRQme8bY7/u2Pe+DSyJR765Rs34tBzSf4ElFM1W+xfbEikcrkCVcovxu0trTpcCpDAEKVlYxys1cpd7EZl8C9pBlXvA58imC+obhmtoUsOD9CWgUepUpTgs0FgnvIQCuukUExmEIzjH2iDhXPILc2duAUnTgNMyrE0=
Received: from BLUPR05CA0072.namprd05.prod.outlook.com (10.141.20.42) by BLUPR05MB037.namprd05.prod.outlook.com (10.255.210.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1061.6; Tue, 25 Apr 2017 22:31:05 +0000
Received: from DM3NAM05FT050.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e51::205) by BLUPR05CA0072.outlook.office365.com (2a01:111:e400:855::42) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1061.6 via Frontend Transport; Tue, 25 Apr 2017 22:31:05 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.12) smtp.mailfrom=juniper.net; gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by DM3NAM05FT050.mail.protection.outlook.com (10.152.98.164) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.1019.24 via Frontend Transport; Tue, 25 Apr 2017 22:31:05 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 25 Apr 2017 15:31:00 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v3PMUxhe006164;	Tue, 25 Apr 2017 15:31:00 -0700	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 35B4D11446;	Tue, 25 Apr 2017 15:30:59 -0700 (PDT)
To: denis bider <denisbider.ietf@gmail.com>, Ben Harris <bjh21@bjh21.me.uk>
CC: <ietf-ssh@netbsd.org>, curdle <curdle@ietf.org>
Subject: Re: [Curdle] eddsa25519 & eddsa448 for use with SSH 
In-Reply-To: <CADPMZDBEasXekZv9kGTJdArxy8CCy-sZnTY4yjtGvy39sftHDQ@mail.gmail.com> 
References: <53117.1493095177@eng-mail01.juniper.net> <CADPMZDBEasXekZv9kGTJdArxy8CCy-sZnTY4yjtGvy39sftHDQ@mail.gmail.com>
Comments: In-reply-to: denis bider <denisbider.ietf@gmail.com> message dated "Mon, 24 Apr 2017 23:19:57 -0600."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Tue, 25 Apr 2017 15:30:59 -0700
Message-ID: <17136.1493159459@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12;IPV:NLI;CTRY:US;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(39410400002)(39850400002)(39450400003)(39840400002)(39400400002)(39860400002)(2980300002)(54094003)(199003)(189002)(9170700003)(2950100002)(7696004)(54356999)(38730400002)(50986999)(76176999)(76506005)(229853002)(6306002)(86362001)(4326008)(53416004)(117636001)(2906002)(2810700001)(5660300001)(50466002)(39060400002)(6246003)(77096006)(55016002)(356003)(5003940100001)(6392003)(7846003)(106466001)(6266002)(47776003)(7126002)(8936002)(48376002)(54906002)(81166006)(305945005)(105596002)(8676002)(53936002)(189998001)(42262002);DIR:OUT;SFP:1102;SCL:1;SRVR:BLUPR05MB037;H:p-emfe01a-sac.jnpr.net;FPR:;SPF:SoftFail;MLV:ovrnspm;A:1;MX:1;PTR:InfoDomainNonexistent;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM3NAM05FT050;1:Bft8weHrFwfl8EJyFTDRVb75JTkMVeSbm69Z+//C2ioAJVAacWJF3O8oc/nF5eUt0FDmbkaI99gRBDa1Blb8tZiVd+h83mel46lqjdcm2POTNIsuZc4goiSrtoHmYlxJc4c1D0Dkn+dNzehrgp5WedatoKFSsvwqajI13g7Jx/mBZLO0J8eylrzlIbc3KqxxgKt9FGPAlS1GX0Pjmx6L0wf1fsLkHR3Q9E71HlZtwTWWHupsbC32af6vrILrxWGTS4Xv/aCeHJkj9ctfMJIYZv4l75KpPbEftP6jJDJWTCQvgYHiYQ3GE4UNiOtpuLEobVJouJFAFFqa09c35NBHnfVAuuUQ6ggokgtV+Sdrx5EfdG9m3aGT6bR9krzgOXJCDoeO9dQ1WWQ5AAo0N/edwu2QxKK2otefpuAqt7t+55L5fdcsl3fog/CDNHPcraQgvuRkHwyNTxcf0aZyQrjmtADypSDdeowH3n3E9nnORELFkKAcfiexONfX0curnNYWEgWurwf7+YrsBi7TMzkWoUnzP8DJc6W0oIUAIrfMpAW0oS0/527obxavgNqKMJ8A
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 06c00d13-74bc-4cb8-ef07-08d48c2ac2ff
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(2017030254075)(201703131423075)(201703031133081)(201702281549075);SRVR:BLUPR05MB037;
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;3:P2CL9JdN7yFJe8lQYNA77UI4QcOWxTtIZWHXLSAWHUWCkEynTXTXAxYH+gSNc3RSuF3GbemGTdLFC85gWkRux4tGxrZafEcKJ3BqkhXZVGeWtPISSE6UX2/ZBDtXUy+YybVrxvhXLGNc3W4xVOUL9QWqXRMtxqYm4o5if1rBmJ3LDwHKNetL0T/aMvQDhHgfiunp1toODhwKIKzDeEpmxMbFDawngWnmuHEmfsGWPZ8PVTg4twgb9CXkgbu9TDLyGn9YqCRlk/nVBpG5zw6UKGEsH+I7yqRhefQpxidULUL3uMYARQxX4yXDcY+Gofp1UrfZsr43n6d5l6knLS+57dgr9f3fVcqSuQWlgcK4yflVbJosRifSTfbQkt3O+jewZKCY0xqwQXy2x96Qnj1gdRrbldC6IgIIS/cjpUUTaXlYRNRVckQK9xOV/aXY8RZBdq2aLsjwV+6aNI0MApTXFDDvtZ31VBDc94oRgxktKm7aky9vHDAxLML2YH+2Bcm3
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;25:iY2ybhCr7gVNUzSNiqsVWjZFwtPUpvuMIciBNkI5EFpH63a7ZyjxpQBRPpawggU8AHRLsgrvKw+ht71HxWzJYpwk5jCbgbaeq1/yE4nAcrOLPqFyvQIZKj1RuPxQ8GbEahSOc4ruTBsUDwBHbXYPjHSU+P9fitpUkTVvLlTVaUfjdoXC3I8hFKGst7gFjNmGigaIcMJjHDKbHr2tEc9b27TkfzSPTXO3CPzm5cwuKnvw4F45NoFEwLNFiu8VslcsP/+QQSsVia339U8polEoUeraku2BNEIFclupwkssOm+n3qAIDT0oHV2anHy7I1RjM8HEE6vn21YSZH1HXmCVDjTvaBJeVH4aD8SVThd0kJ1aaQtc2e0o8JvC71pujOVDMMSjdGxLOB3EGYOi3dYw4a9CXujU1F7jGRW+KruOf7dPDoqKSRtILDdZGPc2cLO0ge2TP+CuDhDXWXMScSWePdWnw+yF6NYiwMFsXUytmbM=;31:HMbk5mC4HM0NhrLc7K8Z3Dstx52tUmbTvg8NmbAYGSweSfV1PgRi/8UYGTTYHox5mjfA3UQ6n3K+p0g5KvtBmQByFlna2B74C5FJuQXZVl3daVyAOA/ty6p409U6cxXOM6IoDJ7dDXjPdPcYNiqX/PNMf6nDFqzcEVssULpMGH9PNNT8/bw/4MeGTUCgSKcXuSGVlddHis0XFPShwk1nnuGfghnioFJS3BwiEu9Zw0/du2xUmRAi2A7NiWFKply0Z4Voti08FXmWUsgeR9izblPQZOGedbB1++v0gy+LqGo=
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;20:I8UxpD8P1+Mpl7xzY5n6wfRImjT29judV4ZvTr3dRSUdqvoTSZCv62LZOFL7GerAW2BTPdzyhK2U8pa0EfcO4xxDs34syV6qKixJ7KUiBSNt0xNumyXFXOgUOwnNF7RVWLHcvhObN7Vpffvfe8XY1GcchywziLhPA7oNNHjmhaN79HJ6VboFc89a2rX/IJqjjWAbbLp68mKf2/AAiUXUebADXKVYxwGjP0B3GL1Mo21UfDKn0C+YeI+61Ph6MjETVW3zy9H6bVDs2GWagZbxOGXHthFl4co/blsmegAgAAMQVBwdRoNX35jmR1Mq4GM1cKKJmdWwyIufaV5Q5Ltqem07i9Q1eR8pECCa5OuHnCo7P34PSfXVbM5Mou7dLaTcxt9ir8/pDdE+sY5TcbCx6bmwsGhoAuY19CWjb9+g4nCZXmUWWtcfj53Z7C7A+9kODNiWL4Q1eWFsgBcj2oFCT44DgpRk5r7oDDpJdOmYCLmCw4FSVz5+reKmZf7UqgyW
X-Microsoft-Antispam-PRVS: <BLUPR05MB0373BC2297A023F30E966DBBF1E0@BLUPR05MB037.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(6040450)(601004)(2401047)(13017025)(5005006)(8121501046)(13015025)(13023025)(13024025)(13018025)(10201501046)(3002001)(93006095)(93003095)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123562025)(20161123558100)(20161123564025)(20161123560025)(6072148);SRVR:BLUPR05MB037;BCL:0;PCL:0;RULEID:;SRVR:BLUPR05MB037;
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;4:/GqEVMnmmJtqHdhNPgzhM33K+EIBXxh8ukUQp2sjF7cfaH3BealXc3JP0qY/mGpCDH2kZVz4wDXHcIuG94WDsNQUJl+mVax2m2+a1Z74RqUzym6/df62liW/Wn9qZ7cl0m5w5ooAUnzTYjgxuLZarluaFcw/1Ebp4uf+tjR8i8U4RBIp6O97GNuUmXBwOgNbBY8cJ75aJbex01JoTPclBpt1QfkcEaCdZi43I+R5S39n4lDBgnZCKg0KvzawCz42a3z7kouS5cZzL8398uN+/XKZx7x7mCb2j4yuLMVmkw+uVEhfmhiRRIaCPByf3DdMso5RPOHWIbD0Dq0Uj6i/0WVzQH+KRBTcnlXESs3RrjfjiKdkTs87uKtze5rC35nhSvlK8dbWSpbe9J5U0ZjxdPCCSi0jtITb8Dwqvgz3NGznHktsaPk0ea3HVkmCLx2d8TzkVruNvmeSIZ8LSIBvYR7gbjXvcc+DcswwrP49wpdx/I2mMDqXVH2sMlcQPkOMG+g5PClcRKOxkqSkdz/dqsmtJdJLvPGvqlsPq9toE5tCkHyCW/PVlKC8lBTtefsLfHfRbUbcDbo2SnerboPrdeasiW43yYhKAO323CccCkaAhpVR/eIXOQ0HZ/NIPkY/EioIV5/aW7cU7L7Cz7aOaT8tO9t8++WDcQzJQ9jLc4Lm6uglmSb+0elfAJELL+Xh58OhaM+HMnIVv1OqTiCJo8NXqNsnG6qDBCOHmSc1V9Pzije36TM9y+vKBO6PfTNM8RrkhcxbuIRur8rKaeZ0aM2iG68ZzTKRqsRczml+s1KzPSmEiRZJnxT7xwmvnyTIZ9nC6wYN6WQ5SyG7DmxCiN/UZwOCRBNMIrrzfrhuxgghP1djI4aXnOjPRiFM7eh2f4PY9EqRJXP/zrpr0wppgg==
X-Forefront-PRVS: 0288CD37D9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;BLUPR05MB037;23:xGPLeQxdZHUpOaRBNgMypqD7rRJj5LEUuDxdxNrNEz?= =?us-ascii?Q?KZDwIkDu9lKeIV8wORlOvfbJnYsrejyr2YhU7hUyTPLNSHQjlNCKiXEwEpNl?= =?us-ascii?Q?u6pXLJMiip7XvFuMe3BjI5yb/kSUeX/13KtNv5uMxA1g8GO7tzwi9sc0pzVW?= =?us-ascii?Q?vl/88RCLIyF+YWsOn7OSFtoFAMn+QMKmvCXlnoEXPTMYu1JSw/p9Yt900HzK?= =?us-ascii?Q?AA0RhwVTKuE+mHE57YDUXPU+XM5z9VZ6vaPOOavR6EoYD8ZSucu6aon9BEnt?= =?us-ascii?Q?Yz+BsL+51m3Aci0bagFiwcj0smWZ5H+c/l9/q0/262IAb3DkKDubEUUQndCd?= =?us-ascii?Q?+NAUQqFCaffvlO/S6+KAp3B88rBmcyUZMwf4DJXTl3A90xanPv/zN1Y2ztOT?= =?us-ascii?Q?Xk4A/XlSqWi84qZUrCB8patikOQliNQKeZ4H7mQllfdxL885ZeV4u9t/ZNPJ?= =?us-ascii?Q?9hFpFRUVpKcmlCNcqMHeu8jBXa/Rm61znJNo2KUk6c2BjfWZehTt0aN7PS/q?= =?us-ascii?Q?IOLEMDGeVrbP15hQo7RbTm9i/SIhog4jnFz2hyrrWJcpfly/A9OgjCG4LvfX?= =?us-ascii?Q?0DwSn8zcM2/EFzXwMXIBbJzuV7fODN6gnpbXsJoIjLludTvReMVK8hk30+if?= =?us-ascii?Q?wDtR4RIgfnX06dsBj/2q0TiTgf9zPXadSQFUDWP+Ucq7cCJhzGL7gtl/BqqE?= =?us-ascii?Q?asNAma/QImqXw/IVNE83GH65W4eknjCH87aJBba9S/QfOZQ2GOyaTI5n8HmM?= =?us-ascii?Q?d230a11lATZBbaJKwHY0YP/f+64l72UQv1YHrfVBW9Xwf6BImhddVP8+yztJ?= =?us-ascii?Q?oGOcWb12IcQmGhHoKzJtLl1U0eAtqxWKB2/AKYOB4pQtC4VOAa4rweBi4yz/?= =?us-ascii?Q?gq/y27Js2x57hTCzMDCCn6ZlWiRcE3mIyBkRFVuUvfPlZ8saI+9n3xpwcfkl?= =?us-ascii?Q?rpkWDPr9aYV3lng+Souo7eA2HQPj0i7eJFixkzfmCiUWYRZbZcJyrJETC6FL?= =?us-ascii?Q?y9+byYO6T9Mc+29OeRHeydCNU5ORCk1g6n+h2zWix+PUYieVoVYrsFLr6CUA?= =?us-ascii?Q?PlQPYJP5J51J48Ea3d6W5+3g5W13QyWdmzCbCbIBb01X9EwnuiiebrbF5OeD?= =?us-ascii?Q?h05pP1BsFE+Kcxk1HfZ2CLDNinFrA5KODna7X261F5lzBGrI9NnTmAwwgbqR?= =?us-ascii?Q?WPRa31revrbuXEa5GrWXe3P8whf/9j+b3YdhYJezoSrvy7+PMRLKDkCCf1VO?= =?us-ascii?Q?EVh0D9jAG7vuAyQYuH08HO2xK1kvkpYp79GIvO?=
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;6:cCGEkaOp6ZcRt0hgyJ4PtOm2/q3Ln7Gq7Ms/BWPy2H9LjzW2ClxqZMRqw5UCO7vVKBu71xIqNo8Dc+bJuH9U6By9/x4Y89uXu7f5ayHCaXZe3gLIP9qTaLGKqWB+MntCG9+WNbeKN2NqrGZ7OYhfYCywI0UFyygVd9DfUhedujwpefp42UItE1b/InqouG4Hz4wlIY6FJYecOXM++JtigrWHZwSyfsEGFF7T9QgZuTIG2+0Ng2BLp6KQzCXDRFBZG7bLN/kqJLWqLAvSO1v0yr3mk+LPL6Z8tiPRmx/qK6mz1RZ0ppAsp4Ze4KE74EGYjd3Q0sOnchVvP5pVeG/hyVt/wPO5SOQwiNmNZYl4NNOBPVSOlnZFhU8+nQklpFhuNQv36fjswjJ59+3rirWxnhmwVkPNJjmVpLqYKleKy81Wpog5aj5LaHLhWuKmTgC7E0bzmwUbuRx3Nl5lWnm5k0qWPsiWiCzyp2ZH+490pPeNgdTwCwPdv77h1D5jrprDpsBkbvihJqjhcgdBwZVbCnN4Om2phUNfQrw4j3w8V7c=;5:Vc/jCq3ZzoYi2QRY43cr/S+LBC61ZYdkz6ELZQa21WiCnVfp32ufypnrmk6CZbVfHgTNYfEd5JYD4a+krH738X8zlVeGO7ovgBgcv6DdUtHxW6S+H4/dVyuBDEyUcpAIDrFsKEmc7unj0nLu7f1h4w==;24:7DQELB/0MkVftweNiDjaBhJ11BPIPjjMSEfSsavJTssUfFjpp0cajdD+hw+lVknM1/m4kkiUTEtUTuXfH/1t4/Zfa5oU606nGmn1T0ppV64=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1;BLUPR05MB037;7:vbbGKESFxFFko5cnLUGg9MBxxkyCZ34JzOG/PUzs5jor5DrFYwPjR2EM1ggFefwm0ss6uo0cIMlZ00Yzs2bg1/ANj6QHPsjpkCfk6DlV76sO7/qk9JCEGHKPgRiNn5kXlwrDnwLhKI9whOc7hZZO4VINFEL+RIP1fnC26ZSoMklf2ex7Zvbcvtg9u3zqdNpImlGe/UcBcl1iJDjP+J1E1yPwiI3ezxcaizmGGqc4K2Snn5jbSKaAKmpDJTGk6qzmTybV/eCdQea/U+Qg0qRxghtR/depTm4O9+hQCrKYR42oILele7MkfcH722e6I9L0WRZVhvpw7WxlsQXfj0nkhw==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Apr 2017 22:31:05.1646 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.12];Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR05MB037
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

denis bider <denisbider.ietf@gmail.com> writes:

> I believe the spec for ssh-ed25519 is already an active draft under
> the purview of Curdle:
> 
> https://tools.ietf.org/html/draft-ietf-curdle-ssh-ed25519-00

You are correct. This one is expired. I wonder if Ben Harris is likely
to resubmit it?

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue Apr 25 15:31:19 2017
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 379AB12EC2F for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 25 Apr 2017 15:31:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.09
X-Spam-Level:
X-Spam-Status: No, score=-4.09 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Sf7M2jlZN_on for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 25 Apr 2017 15:31:17 -0700 (PDT)
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B1121128D8B for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue, 25 Apr 2017 15:31:17 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 8A39B84DAB; Tue, 25 Apr 2017 22:31:14 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 057F484D93 for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:12 +0000 (UTC)
X-Virus-Scanned: amavisd-new at netbsd.org
Authentication-Results: mail.netbsd.org (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id uPPdWjJtdGop for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:11 +0000 (UTC)
Received: from NAM03-CO1-obe.outbound.protection.outlook.com (mail-co1nam03on070f.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe48::70f]) by mail.netbsd.org (Postfix) with ESMTP id 6A25784D7F for <ietf-ssh@netbsd.org>; Tue, 25 Apr 2017 22:31:10 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=eO+0pvHOsenrLu2aIUvNN/k5kIK/eDcZoA7wSJUFbEc=; b=JeOE/OZckfRQme8bY7/u2Pe+DSyJR765Rs34tBzSf4ElFM1W+xfbEikcrkCVcovxu0trTpcCpDAEKVlYxys1cpd7EZl8C9pBlXvA58imC+obhmtoUsOD9CWgUepUpTgs0FgnvIQCuukUExmEIzjH2iDhXPILc2duAUnTgNMyrE0=
Received: from BL2PR05MB035.namprd05.prod.outlook.com (10.255.228.154) by BL2PR05MB035.namprd05.prod.outlook.com (10.255.228.154) with ShadowRedundancy id 15.1.1061.6; Tue, 25 Apr 2017 22:31:08 +0000
Received: from BLUPR05MB037.namprd05.prod.outlook.com (10.255.210.145) by BL2PR05MB035.namprd05.prod.outlook.com (10.255.228.154) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1061.6; Tue, 25 Apr 2017 22:31:06 +0000
Received: from DM3NAM05FT050.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e51::205) by BLUPR05CA0072.outlook.office365.com (2a01:111:e400:855::42) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1061.6 via Frontend Transport; Tue, 25 Apr 2017 22:31:05 +0000
Authentication-Results: spf=softfail (sender IP is 66.129.239.12) smtp.mailfrom=juniper.net; gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=fail action=none header.from=juniper.net;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning juniper.net discourages use of 66.129.239.12 as permitted sender)
Received: from p-emfe01a-sac.jnpr.net (66.129.239.12) by DM3NAM05FT050.mail.protection.outlook.com (10.152.98.164) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.1019.24 via Frontend Transport; Tue, 25 Apr 2017 22:31:05 +0000
Received: from p-mailhub01.juniper.net (10.160.2.17) by p-emfe01a-sac.jnpr.net (172.24.192.21) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 25 Apr 2017 15:31:00 -0700
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by p-mailhub01.juniper.net (8.14.4/8.11.3) with ESMTP id v3PMUxhe006164;	Tue, 25 Apr 2017 15:31:00 -0700	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 35B4D11446;	Tue, 25 Apr 2017 15:30:59 -0700 (PDT)
To: denis bider <denisbider.ietf@gmail.com>, Ben Harris <bjh21@bjh21.me.uk>
CC: <ietf-ssh@netbsd.org>, curdle <curdle@ietf.org>
Subject: Re: [Curdle] eddsa25519 & eddsa448 for use with SSH 
In-Reply-To: <CADPMZDBEasXekZv9kGTJdArxy8CCy-sZnTY4yjtGvy39sftHDQ@mail.gmail.com> 
References: <53117.1493095177@eng-mail01.juniper.net> <CADPMZDBEasXekZv9kGTJdArxy8CCy-sZnTY4yjtGvy39sftHDQ@mail.gmail.com>
Comments: In-reply-to: denis bider <denisbider.ietf@gmail.com> message dated "Mon, 24 Apr 2017 23:19:57 -0600."
From: "Mark D. Baushke" <mdb@juniper.net>
Date: Tue, 25 Apr 2017 15:30:59 -0700
Message-ID: <17136.1493159459@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
X-EOPAttributedMessage: 0
X-MS-Office365-Filtering-HT: Tenant
X-Forefront-Antispam-Report: CIP:66.129.239.12;IPV:NLI;CTRY:US;EFV:NLI;SFV:NSPM;SFS:(10019020)(6009001)(39840400002)(39450400003)(39400400002)(39860400002)(39410400002)(39850400002)(2980300002)(54094003)(199003)(189002)(189998001)(229853002)(7126002)(6306002)(4326008)(2810700001)(305945005)(7696004)(2906002)(39060400002)(48376002)(50466002)(86362001)(5660300001)(117636001)(2950100002)(77096006)(6246003)(38730400002)(6436002)(6266002)(105596002)(7846003)(55016002)(106466001)(53416004)(76506005)(53936002)(8936002)(5003940100001)(50986999)(54906002)(6392003)(54356999)(8676002)(81166006)(47776003)(76176999)(42262002);DIR:OUT;SFP:1102;SCL:1;SRVR:BL2PR05MB035;H:BLUPR05MB037.namprd05.prod.outlook.com;FPR:;SPF:SoftFail;MLV:ovrnspm;A:1;MX:1;PTR:InfoDomainNonexistent;LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM3NAM05FT050;1:Bft8weHrFwfl8EJyFTDRVb75JTkMVeSbm69Z+//C2ioAJVAacWJF3O8oc/nF5eUt0FDmbkaI99gRBDa1Blb8tZiVd+h83mel46lqjdcm2POTNIsuZc4goiSrtoHmYlxJc4c1D0Dkn+dNzehrgp5WedatoKFSsvwqajI13g7Jx/mBZLO0J8eylrzlIbc3KqxxgKt9FGPAlS1GX0Pjmx6L0wf1fsLkHR3Q9E71HlZtwTWWHupsbC32af6vrILrxWGTS4Xv/aCeHJkj9ctfMJIYZv4l75KpPbEftP6jJDJWTCQvgYHiYQ3GE4UNiOtpuLEobVJouJFAFFqa09c35NBHnfVAuuUQ6ggokgtV+Sdrx5EfdG9m3aGT6bR9krzgOXJCDoeO9dQ1WWQ5AAo0N/edwu2QxKK2otefpuAqt7t+55L5fdcsl3fog/CDNHPcraQgvuRkHwyNTxcf0aZyQrjmtADypSDdeowH3n3E9nnORELFkKAcfiexONfX0curnNYWEgWurwf7+YrsBi7TMzkWoUnzP8DJc6W0oIUAIrfMpAW0oS0/527obxavgNqKMJ8A
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 06c00d13-74bc-4cb8-ef07-08d48c2ac2ff
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(2017030254075)(201703131423075)(201703031133081)(201702281549075);SRVR:BL2PR05MB035;
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;3:OjaJp1VYZ7ikUz6z7+QB1eEvkl80kwvHUViDXXrR2zuNe2TlZJP3kG70922dg0cz4g+lws9SpLGehd4P8yscaY5KaEl0AbKQNKjf9bm5lSwTwofMIxhEOKPtrCGC55mr1Y0sAXsWkw/l2J/g7FP9HZN75uvzfhKVj+1YQ7njXheRKCcqMyINZpVZYzcct6p7+OBmBtvZquwcOSNMdxpieHj2PKR5ybu85zOGxqeN2SaF82sxZhFKNV8/h1rl/k5/bZksOmWpBchQf+UlubzbP3s6cVE1vaFjilHJ1te0PBokmApkBqeoNlrxatMFYWE6bxf20It79wifTipiURio73umPXXH8N4edp5kaiYFqYy3eM4P6xp2O1ILte7wpP98UNaxBRqmouoWWgsh82ptID5hnd9DVYwVaZpNOCiNBaQjSW3Kyvkik+BVu7zE8xh22iZUV7ev/xEBDY+E1ui3A7GbBywjrISYhYx/PsGXKOKn2D7h1CGoOeHVAdUGqWkH
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;25:FVaO0z+1yqgSwk/U6YgKomh801q+GNvy6pgHStnMgwFUE36oG4yiSwzp3Gi5FOi3OAZQyxOCMphOEWE7GXcAdyQq8BxDh4b+rq9/+ZXJeW9dRKQgIjGrf03foklYBlJIRssurIb9l8XptTmzkEGouARWSe4OfeiFd5Esf+bof4QEpMEfJUbkGPpXMBr15M1x/1RaZ+Vn03/A730UzfpbA4r+EXFXKEAI4WipghAK/KLydWCYbtxwmm3WO/YseRctP9SntDOMn9u51166hSYirttZVeYwWbfM+zO/GUMZLDNTS3WgmNN8ip6n5+hMmljFInj5s5lt7ORxc8/5kVHCjF3x2PgTmwZSQT91NEHTd5MVTbgwn3RSLf8784572f7C7VNg28/7I/iq8qkSS8SzRWP8Z2of+WflNDymq9nSrGJl7uIftOtFwpvBOSXa0DVZFDCfNtxlKETS1elSuznbulihlG509kyGltyCFlo6GSk=;31:C5Ct8DqBJeAUtGdpp+hW7cNdKgeiSSJKsI4HvTqK7QijXkiNOIYdfVwXzBNSYC/gROCyHYLybbx+RqpOpYGOsHdIX2aasv9RNBJ3fpl3o1RLUm/fTfQsosmbCDiYOGHRSlJ8J18ed/FytSMRWWBofnAu5mjIn27VdPR/+E+EsKFN9yRLl1SAxMOwY3QTxmrr0HI0n6lmU8oLw0D6hxCVPdfefCL2/dzfczx+CVLcSpVfamGocky6HzGkzx7DF0N/ZthKY0zUwIL1ga7NTb+iIHRYgxvlCiJQKO/MIJSxOTc=
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;20:/meTFCDN0BdrADFv92Lm5CkZUZFIl/ZnpwXqSmtM4WExezwDPVdcAZK/5TGFm1Bar5fcr1/Soktzp29VkmW+S/yWwpzmG7NvmQsWj/XrARm1cgKaJ7s+pnsDPHT0DCc4NL+h98/+6CIPa3IxWxWoaaE7XLyLtUdKmFgELb/HZWumflR7pyqtBEj2wh7g23w4+rh3DM7fyLlzlpnsn7qCx/vmrJpSqrGpZ8O/hw2hJycHmKP/bkFNe9owiYLvnwqUkooeM84S47A9eVvg1u0b6GzXHZpPTDJtZoFj/N/LBRzreO8/7WD+OXcuPjQM6edd0VE2yvxV9TTp4uMp0Z99h+Po6fXRrXlQdrbGeQ9NICtLmWhZ6AWAAEMy3ev9mIl1f+9TTpIse36rdu5OUo3qZY9N2ls9zHHuJbKmgaaol5+WFUS+Ku2tBnXnVH/14S/Q/dsOAXn6syIna8wbiKKw2VTvvGa6BcfjZiUsyYptvopSBbof4fBQJezfj0pr1vSq
X-Microsoft-Antispam-PRVS: <BL2PR05MB035EF8A70CE47CA80B545F0BF1E0@BL2PR05MB035.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(6040450)(601004)(2401047)(13017025)(13015025)(5005006)(8121501046)(13024025)(13023025)(13018025)(10201501046)(3002001)(93006095)(93003095)(6055026)(6041248)(20161123560025)(20161123562025)(20161123564025)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(6072148);SRVR:BL2PR05MB035;BCL:0;PCL:0;RULEID:;SRVR:BL2PR05MB035;
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;4:LCPeU3ozwA6EEJWMCU+xHVcRXEpmW0wItdJ1pZ3EUdohYP2OhEROoLAlfDHusXmYVHUGQN+YXjtUn99aFkDU/TjVsyf7T3LgAiw+Xpskxj5WZK1EOJ62yeRCipU1EvxlpjwjsN6e338eSiXpaWshxrrPiUThvrShz25fkXO6CK7Hv6gBiU8irOj1QZw71jf4wOH9SerXJkS3e1Zs0PMfaNkAoDocZO/Sgc2167dbXVLrL6IQs93JXm84+Ek1DwAI5BwxUcEJQCCXuPLccsBAi1JTGeyC/tkJ0giZRd6FefnMccfQiUbFHqyfkvQ9pdLxyTjZf36hD9h6tcKrJPaypqx/ZfToDuIjSX+Rl+5I+y491s0qWmLD4Futmgh4i2ZbBK2UNBozpRaMrotnmTaE7bGnTt8U9Gbjbd6jjmv7urUHqTBRZ6gHvZyD5feSAq++M2p9pcOdjlmH7mXTJCte+Yj5lpM2THXssrsfaL13arC4xUYSRwO4cARE2uReYL4SuKG0rWa5LLBtjKRsYnv5AQYypmPHlO2iYDYY17OAoQcbJRpDPszE2pV3874LexRPt7JqPoLpJp5G+ZJbLhj0B2dZiLIbwwBmJDG+rUmg+epYHNoGFpMdVzSmiLK3RaQTVBPeZ2KlMk8Q2XZ0oyq3DNKsvw33u45/cBVF55JqYZZ4OtZjcBD4HF9Am7mUXh8CsyCxjGMtxJgt6sJwaQLEkDJpa5roR8JcP9kYzO2b3JzMsMPueilsa3mwx9JKjc5NCLEg38PtapgLEUzyfwnX1ADY/H6DQT0yRTs7ZT5e+GAn5snRRtfBaTiHFUy0Dn3zWGZDmT7E0bM9MDPBNf7pbwL2qw1gOmhurWDTeBH6DuccF85CJAnsqXj/+xfWloPIg7GjswrnV+iMNW4Xa1hIEw==
X-Forefront-PRVS: 0288CD37D9
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1;BL2PR05MB035;23:nDasmtmk9DoVqzu+Uz+xCgZdDo366jXRQPlzeLY1Yl?= =?us-ascii?Q?kENvACRwP1dWdra05WeZFRMvRtr5ROVKe39ljYFe25qXi3qBoy1okJFhIrnw?= =?us-ascii?Q?PVtAO8AJmhspkm6IYQNaSuKgXMpoXSsi9CoBCde/KS25hvXqpxtDV/cxt90P?= =?us-ascii?Q?m98+Kwck7xjRVnv2pMdAZrGumgmotEIglnFSEeQbNf67f5nIbZzePNZQ/Fml?= =?us-ascii?Q?hJ6HPsBGl3JUNJhbrMwgY0jPSkyIlCdceTx+dqdkdIQLrfmeEEsw6SyRI1jj?= =?us-ascii?Q?V6eY6ig6L3d4MMg7XHy7m157JhVKe8ZQn2v9az/OCj3xPcz7kMeXMQD7fcZ6?= =?us-ascii?Q?NFaknBuDwOJNE1Wntnox/eMCfJLvh4geY3FeII8skd27kMkMsxwHSYcFGGhK?= =?us-ascii?Q?QOdobQfkBdG/qiorT4WS8ZwXqSGEx7oEhSGzi3REBofNuBHPtQxqDzXD4T1L?= =?us-ascii?Q?KN8/GCigkIV09KHBUBvYJ+1+ZD5N8LJOH3oEq+b99wtBuHbxk1uTNP8DDhB0?= =?us-ascii?Q?wDHiZyxrYtOsZj+pE4hb/FJhkA2e+FmVlPEC8vjNTdilHIqwH/ZaBJC2Hy8R?= =?us-ascii?Q?QrkSkKO9nEF2Vb2r096jdUlcWPyxw16unXgjTxQNQy5iX8v+82c3tQu/vrcq?= =?us-ascii?Q?6A7Fxvb20TmhwY8wPoKT/DuMci/FggFg0bbH8csjv6qq8GUiLXmKw7/hPR2u?= =?us-ascii?Q?OWmvI6sEF95PWhrtbbwvjKiNX9UCCE/IvxFA7zfZFGb2RYoqQL2PoID9RTmF?= =?us-ascii?Q?fXDaYdz0OyvucDC+M51UJqXdzYeh7LYpU67KRRVxsW2p0PQcverBFEc17ZFX?= =?us-ascii?Q?j4rdgQm1JByPIEYxkS/v77M7QOuUynsHh0IoxUlukMMGxc3DDCu/S5XcooVo?= =?us-ascii?Q?iVG3FXbThVmpLR4ZV/66Hox7puLy1t2cNMxlFXfQ4YAEqCt70pBzN10omTOH?= =?us-ascii?Q?0GFofehAPs6oUFLcsUteMumWKo09/lSZxgvmTB1Vcl+1/1CtuImIUQP5tgzL?= =?us-ascii?Q?gul+ny9/95DFYN7raAifK5K8ghJRrwMOKVvy5vQ8+xnTuBZ3QVWZVtyoESe6?= =?us-ascii?Q?mZACG8BQqRbKZ/dP5+0wF3tX4ERSIBSQlqGc6hXP6KgY58LgVUfzPbRY7XfK?= =?us-ascii?Q?KpXHDlctpndEryxBtDwtiS8/3S9NBlGFrHGPLQeDgVjbis+hnWZowpPmZPth?= =?us-ascii?Q?KwzqPml7OmBaE7KaBN+KOuS9+3kOIeMTf5X4lcEd38h+uHkzPhpiypiw=3D?= =?us-ascii?Q?=3D?=
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;6:rbK2rfQJfNAYSH1bdBpRtAC7u7LuQP9bfeCBum0ZFhW1qqvyKcqt9Fx4eOhCqPfSZ8Dh1Uf8Lh5rh2wmUH7nHWGRx1TnW74m0qf4MPIERViSiTiDJtOuRhWoportsYSXnDruiUsft1y791LBXlbL6/j3oVhnVMN4wYJMbqCI6v5MoriBgeDwyvbNVLoeLSjiQqlWfX37Gb8kaZP+P/2Zk8BC6lfM465cqTZvUCTu8YoVTtiTmhjPYZsERykT7pqKgeyRwvdXnmD5HUxXEcZ0g6qrJ9T2KiEgSmfysxs52oY9P8AemC3C6pICatAjRzt5qNVBnXFyVDd4JIz40kFAp25cF6FtysHsZMORgr2A+0tEzk9V5gM6/IAnMXwtB/Et7yhyj/thqeEiSjuxNQREb45lVti+VtZmnEkQcHzCwQ8kOf8l91yJimylIvWfYNeT6FdeJtzOAJM2AmudYTdTW+wuVwm/P2UqlgQwpzGgxjIljWS7E8iZ53ribluzJoHAII4gznqPwuA39feeKTsYhsXj5Q5+P6fgXuuodyurYSY=;5:bxkeADjy+feLwT1awJJXrCX6tMh7dWXgJs9rxU0FRuRybuvjkQxAAoLoXEvQqeEQ09I8kXmm8OPu6IQS3GkMicHwRCq75RmYyV9C24setdV/Hw7k0zfutZQtgp36WMJpluwHMezlZa/tu9xZi8zCHw==;24:NQ8KO9Yj9O2KLQUWgWKJ+1LPEPC4lxeYefKqLrdIVIwWpbBmbi+wZS+9l3Pi51pJNfJC+gd36BbmdyOYeTnT14PyNyOzuvIkU9raomaH0X4=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1;BL2PR05MB035;7:eTO4oBClcr7uz4/H40UnUYUoWLH3ryFH+SqL+2UJqdfsL7L+VrK+VByEi15Siujn3aormnDt+EM3/l7uj69ahOVG+RowABJ+9iC4SSmvu5VIaCZRxcTHdhugI4Q3V66bJ9VLeKaAdpz3kuD18mRwcvbbfPG2us4TW6yDyPnsfApO10ZH+TeGmvITm9eNE+9cuTNETfkbh+7mGwrauROXkwBA/YxNyw8eP3NT7Py31yhLF/MTxuAFtQsBktsvvJ+CSo6P3ivYpSCN6NJSg2NoMZsYQuidvRu4vRlsCJ1aJm5TYTsYJdVFKIYkbMwqxh66BsDif0KUTOitFj9YbXyx8w==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Apr 2017 22:31:05.1646 (UTC)
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=bea78b3c-4cdb-4130-854a-1d193232e5f4;Ip=[66.129.239.12];Helo=[p-emfe01a-sac.jnpr.net]
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2PR05MB035
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
List-Unsubscribe: <mailto:majordomo@NetBSD.org?subject=Unsubscribe%20ietf-ssh&body=unsubscribe%20ietf-ssh>

denis bider <denisbider.ietf@gmail.com> writes:

> I believe the spec for ssh-ed25519 is already an active draft under
> the purview of Curdle:
> 
> https://tools.ietf.org/html/draft-ietf-curdle-ssh-ed25519-00

You are correct. This one is expired. I wonder if Ben Harris is likely
to resubmit it?

	-- Mark
