Re: Curve25519/448 key agreement for SSH

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
This is another update, clarifying the encoding issue a bit further and
improving language (thank you Denis).

  https://tools.ietf.org/html/draft-josefsson-ssh-curves-02

A discussion on CFRG came up recently about checking for the all-zero
shared secret.  Does anyone know if libssh or OpenSSH (or anyone else)
performs this check?  Not doing that has apparently led to real security
problems.  For more background, see:

  http://thread.gmane.org/gmane.ietf.irtf.cfrg/6228

Thoughts on whether we should add a MUST to require checking the derived
secret for the all-zero value?

/Simon
signature.asc (application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJWTOHyAAoJEIYLf7sy+BGdLkwH/16XJUaxsddNhMV+lZwEKfpZ
U5nR2jLs8VD8ILZHrXEkDSVI1OYtjRydZJBslfDFbg+hemU9yctsfAin6vmcRCyM
7P2m2bUoAnFVDqZB8PWsPyJu3nFvbiTbWSkvOsLhlTejHpNyG0Bb3p13LSymYRuq
QHmoemwgfxd5mHPacyzM6vi9tsbT+F0SsrW82h3mVLnMzrvPse7gtfYac/PwQ2lD
o//OHMoinXbBhIucJse+bQbp1khZOpzoQ4o+FKL0RJ8+rNa3p7lDttMKmnT8opbn
U+r9600WPSc92d3wp2GrtotJTfadE4Ecg4IA/fRKmrv0Gt8Q0bbX63RbS+FGbWo=
=TmR8
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.