Re: Curve25519/448 key agreement for SSH

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
Den Mon, 22 Feb 2016 10:08:32 +0100
skrev Re: Curve25519/448 key agreement for SSH:

> "Mark D. Baushke" <[email protected]> writes:
> 
> > If so, why is the Key Exchange Method name "curve448-sha256" rather
> > than "curve488-sha512" ?
> 
> I think Damien Miller's argument for using sha512 here makes sense:
> "curve448 is a backup against as-yet-unknown attacks on curve25519.
> Since we're not likely to need it, we might as well pair it with
> SHA512 as a backup against as-yet-unknown attacks on SHA256."

Hello Mark and Niels.  Indeed there appears to be strong support from
several people to couple Curve448 with SHA-512 instead of SHA-256.  We
are making this change and there will be a -04 out shortly.  Mark's
RFC quoting is a strong reason to make this change, but I believe there
were sufficient motivation to do it anyway because of the hedge aspect.

/Simon
signature.asc (application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzusDAAoJEIYLf7sy+BGdSncIALHBL8hsPFMZlOHf/25wD96R
Kzv7/tZdMYF1uNdZYM+vm0Wf/2cfQKpwtdSfD2Yw6rYQA+MXJwZcyZXhFdn4zoOk
HdvKxEokLkZjxQw6UFw8HZxNrRrPiVcCD3bw8hssTS6tcAGlT05xYhdIWmb6nAgE
xczKgDE7ZVtngUDI7JaX29JV/bjplWuDC7+/w4/+p4zzv9xJSQlC6BIQc9onP9YY
TJwvKt3cqov7dExI98nuToQ5QPcJPCwdpi0OUumVpLYdo47gDncZNwoqDO/3zeeg
8yXCPib7y1qiQFQrTPwzme3rE9igWc9HucreKumf7fBEhSxQNAP4HlUmp3o2Wcw=
=JQql
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.