Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
denis bider <[email protected]> writes: > Comments: > > > - If we're being comprehensive, we should include a position with > regard to Curve25519 and Curve448: > > https://tools.ietf.org/html/draft-josefsson-ssh-curves-03 > > I suggest we take the following positions: > > curve25519-sha256 SHOULD > curve448-sha256 SHOULD, or MAY? > > That being said: > > > - Given the recent NSA recommendations, it seems to me it would be > prudent to update the Curve25519/Curve448 draft, and to replace the > SHA-256 algorithm with SHA-512 for Curve448. This would create the > method "curve448-sha512" instead of "curve448-sha256". > > Simon, what do you think? Could your draft be updated to do that? Yes, that will be part of -04. For what's it worth: I support curve25519-sha256 as MUST and curve448-sha512 as MAY in draft-baushke-ssh-dh-group-sha2. /Simon
signature.asc
(application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJWzvPhAAoJEIYLf7sy+BGdtUYIALJM2dYXfdAsl3tPy0hnYZR0 Lc7qX6Npa236NCkeb96MbczE1vAOK76D8n/jJTnOoXWscmPV5CEBYpKGVVUAwM/V Dgkn+HKAisiIpl7UDlegunTYBMNUcycj1HewHQNHp7/zxHrRSbYmWBLhSyNi02b+ I/KBppRcJHO9Zj3aI4EM1pAmJv71oFGESf2wHBcRNHx37OxA1ovbety8rsnXCHid QtWkhxjLyw38pu/QoSDV2HF835WtRNVlbA/ZXrv8E9+g6ILCrZ6EvEwacilbO+H/ 2gR2Wsz6Baxp2AlJV1qI5/QrE9HZDR/YbaKVY/3URy/Q/Xhx/MGd3voMEkyZ2Zs= =bCzK -----END PGP SIGNATURE-----