Re: MODP group modulus derivation [was: Re: I can has SHA-1 hashes for RFC 2409/3526 MODP groups?]
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.tls,gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
On 03/12/2014 01:19 PM, Jeffrey Hutzelman wrote: > The MODP groups given in RFC5114 are taken from DSS and NIST SP-800-56A, > and do not have this same structure. The RFC has nothing to say on how > they were selected, and my recollection from the last time I looked was > that the NIST publications don't say anything either. It's not clear to me that there is any advantage in a DH key exchange to using the RFC 5114 discrete log groups. The selection of a discrete log group with a subgroup of targeted size q (instead of using a group with a safe prime modulus, which only allows subgroups of at worst (p-1)/2 if you exclude (p-1) as a valid public key) makes it costly to check whether the peer is forcing your shared secret into one of the other smaller subgroups. Note that this kind of subgroup-forcing attack was used in the DHE variant of Bhargavan et al's recent attack against client certification in TLS (other mistakes in the TLS protocol played a role in these attacks too, of course) Using a group with a known safe prime modulus should avoid this concern. --dkg _______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
signature.asc
(application/pgp-signature, 1010 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 Comment: Using GnuPG with Icedove - http://www.enigmail.net/ iQJ8BAEBCgBmBQJTIJuzXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFQjk2OTEyODdBN0FEREUzNzU3RDkxMUVB NTI0MDFCMTFCRkRGQTVDAAoJEKUkAbEb/fpcjOcQALChFpJeivX2wF4odGMw5M9k DLIeDft4hUEa12tjGF0N0cWXtTk9cuhG9uwAQS1wmJJmMTpaELlX2kBan9L77tos 8YEKi/G7ZqU/0VwW5tGE6kV3J602Xojb5z1ZJFz+q4+PksG1PZDD6unCklHpmxQo XOW67JjekFFKNpL2W8WUHAHIAyBW/XVZaSN+MLc4S2h/SZNW8HCIuOA+GXO+hsdT OX4itYHvK9piWNwm2No41cgSnO47WfRiSms3gHcqDQ1I1jUEdwp41VvbH0+xD5u7 nbgwKKWed9NgRjdAE3jn6+uDDTOvKNIPR7/FNvlZW59cIMV//kSAfQpEfbgccKhB lp8EL8KAvh1yBWqQ++hJ7ORjGr31hn7My+d8utAp+G5WPPu78T3Q9V8ybnFS8hIb Nz4joyBcnbYHdJyWTpzJ0f0cMjiWHno7ob6p52OXLA+6eKVWGxK+OoivhDtmX+uI IQ39oR7GmRSBo3or0BBwdXJYxKyLKtw9Jgti4goBjZ/fSMVU8M/Eh8CkK0h7EiLN xl+SVfNvkRkqWyfEP95iFbvfGgUWm+KESBWClIM5U/7vFCwcDOcjEar8FX/Qg27K ryRJg+OQC/h89PCWeBzPbnXbj9od+Jy5wZcBOmlJ3f+FJnDNm7eK2CLGBZJt5YUr dd8aX2wcgK/dpu3sOnNJ =BW9w -----END PGP SIGNATURE-----