Re: draft-baushke-ssh-dh-group-sha2-01 (was Re: DH group exchange)

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
denis bider <[email protected]> writes:

> Comments:
>
>
> - If we're being comprehensive, we should include a position with
> regard to Curve25519 and Curve448:
>
> https://tools.ietf.org/html/draft-josefsson-ssh-curves-03
>
> I suggest we take the following positions:
>
> curve25519-sha256    SHOULD
> curve448-sha256      SHOULD, or MAY?
>
> That being said:
>
>
> - Given the recent NSA recommendations, it seems to me it would be
> prudent to update the Curve25519/Curve448 draft, and to replace the
> SHA-256 algorithm with SHA-512 for Curve448. This would create the
> method "curve448-sha512" instead of "curve448-sha256".
>
> Simon, what do you think? Could your draft be updated to do that?

Yes, that will be part of -04.  For what's it worth: I support
curve25519-sha256 as MUST and curve448-sha512 as MAY in
draft-baushke-ssh-dh-group-sha2.

/Simon
signature.asc (application/pgp-signature, 472 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJWzvPhAAoJEIYLf7sy+BGdtUYIALJM2dYXfdAsl3tPy0hnYZR0
Lc7qX6Npa236NCkeb96MbczE1vAOK76D8n/jJTnOoXWscmPV5CEBYpKGVVUAwM/V
Dgkn+HKAisiIpl7UDlegunTYBMNUcycj1HewHQNHp7/zxHrRSbYmWBLhSyNi02b+
I/KBppRcJHO9Zj3aI4EM1pAmJv71oFGESf2wHBcRNHx37OxA1ovbety8rsnXCHid
QtWkhxjLyw38pu/QoSDV2HF835WtRNVlbA/ZXrv8E9+g6ILCrZ6EvEwacilbO+H/
2gR2Wsz6Baxp2AlJV1qI5/QrE9HZDR/YbaKVY/3URy/Q/Xhx/MGd3voMEkyZ2Zs=
=bCzK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.