[saag] Re: draft update on discussion on crypto practices at IETF
Eric Rescorla <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBN3TW7-MWd1Notz=Ko8J5fGTZCDqQk0S-a1-rUh7xQKMQ@mail.gmail.com> |
On Thu, Jan 23, 2025 at 12:09 PM Simon Josefsson <[email protected]> wrote: > Stephen Farrell <[email protected]> writes: > > > Hiya, > > > > On 23/01/2025 14:38, Eric Rescorla wrote: > >> Thanks for this example, as I think it shows that you've badly > >> mischaracterized my position. > > > > Sorry, I was trying to describe what I'm relatively > > sure some other folks took as being your position, > > but I guess I didn't phrase it well enough. I agree > > that their impression of your position differs from > > what you intended. > > Interesting. I read both Eric's original statement and the > clarification both expressing the identical message: "we don't want to > publish ntruprime-SSH as an RFC standard". As far as I can tell that is > Eric's position [1]. No. My position is that we should not publish ntruprime-SSH as an RFC standard without it being appropriately vetted. I thought the message you cite here as [1] is quite clear on this point, so I'm not sure how you came to that conclusion. I'm not expressing an opinion here about the NTRU Prime as an algorithm, but rather about what the appropriate process is. If CFRG or some other acceptable body were to approve NTRU Prime, I would be fine with the WG advancing it on the Standards Track with a SHOULD (though not a MUST). It would even be appropriate for the WG to formally ask CFRG for a review and hold the document until that's completed. However, until that time, I believe it should be Informational. > My interpretation of Eric's clarification being > identical to the original quote is based on the incorrect but often > repeated claim (even by IETF AD's) that the ntruprime-SSH draft is not > under IETF change control, and the related opinion that only > NIST-blessed crypto can "serve the IETF purpose". > That might be someone's opinion, but it's not mine, as made clear by the text quoted above. In fact, as you'll note, I explicitly list CFRG approval as a reasonable form of vetting and indeed I am an author on a document which uses CFRG-approved crypto ( https://datatracker.ietf.org/doc/draft-ietf-ppm-dap/). -Ekr > /Simon > > [1] https://mailarchive.ietf.org/arch/msg/ssh/CH6kRRISzwyorzF-l1NLiIUK05A/ > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]