Re: Curve25519/448 key agreement for SSH
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
Den Mon, 22 Feb 2016 10:08:32 +0100 skrev Re: Curve25519/448 key agreement for SSH: > "Mark D. Baushke" <[email protected]> writes: > > > If so, why is the Key Exchange Method name "curve448-sha256" rather > > than "curve488-sha512" ? > > I think Damien Miller's argument for using sha512 here makes sense: > "curve448 is a backup against as-yet-unknown attacks on curve25519. > Since we're not likely to need it, we might as well pair it with > SHA512 as a backup against as-yet-unknown attacks on SHA256." Hello Mark and Niels. Indeed there appears to be strong support from several people to couple Curve448 with SHA-512 instead of SHA-256. We are making this change and there will be a -04 out shortly. Mark's RFC quoting is a strong reason to make this change, but I believe there were sufficient motivation to do it anyway because of the hedge aspect. /Simon
signature.asc
(application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJWzusDAAoJEIYLf7sy+BGdSncIALHBL8hsPFMZlOHf/25wD96R Kzv7/tZdMYF1uNdZYM+vm0Wf/2cfQKpwtdSfD2Yw6rYQA+MXJwZcyZXhFdn4zoOk HdvKxEokLkZjxQw6UFw8HZxNrRrPiVcCD3bw8hssTS6tcAGlT05xYhdIWmb6nAgE xczKgDE7ZVtngUDI7JaX29JV/bjplWuDC7+/w4/+p4zzv9xJSQlC6BIQc9onP9YY TJwvKt3cqov7dExI98nuToQ5QPcJPCwdpi0OUumVpLYdo47gDncZNwoqDO/3zeeg 8yXCPib7y1qiQFQrTPwzme3rE9igWc9HucreKumf7fBEhSxQNAP4HlUmp3o2Wcw= =JQql -----END PGP SIGNATURE-----