Re: Curve25519/448 key agreement for SSH
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
I have submited -03 which adds a MUST check for the all-zero secret, and clarifies the mpint conversion further -- a reference to section 5 of RFC 4251 is added which explains this properly. Unfortunately, 4251§5 doesn't say that mpint's are prepended by an uint32 with the length of the data (or the example is wrong). Please holler if implementations do not have the uint32 in the mpint that is hashed, or generally if you believe the new section 2.1 could be clarified further. https://tools.ietf.org/html/draft-josefsson-ssh-curves-03 /Simon
signature.asc
(application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJWVj6+AAoJEIYLf7sy+BGd9ysH/RRpKVIJkrLRVRk1fdsIqVX0 KvVisPW6PJVafiKXYm5T3Ggw7AFAzEoYlYmy/WbSR8ovE9ZZBvqXwMvPo4xGmTh7 n//W7PoQWtC/ZtunvtawpsTYd+mY/SGLeR3qV6ZsJMX+f0C//dd2G/75RVrNvyV/ 0ACPibWStT2ZlDVFFPkvdvZXv/xFJ8itUXpeB/wP8mfeVTr8vE/jDey+cjlbtI4l 1ycdlPqd4hnLruduPNr5E55vCdA0BdG2cnAe/hHAs4c93ON0kP5/OF9NiswWeuLv Fb7NrWUrcDnYeuMdJ5M/iibYNrikmGO9VVG+ws06xRlrUuqvddtg1B88Z/y+Y88= =r+as -----END PGP SIGNATURE-----