Fwd: [Ssh] SSH side meeting at IETF 120

Stephen Farrell <[email protected]> Tue, 30 Jul 2024 23:07:10 +0100
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
--------------DIpF02BJZwEELP6sSsk7vyYb
Content-Type: multipart/mixed; boundary="------------yFgSpZvti11QMF4bInzIkN3U";
 protected-headers="v1"
From: Stephen Farrell <[email protected]>
To: "[email protected]" <[email protected]>
Message-ID: <[email protected]>
Subject: Fwd: [Ssh] SSH side meeting at IETF 120
References: <CAGgd1Od_hXig9yD5vD2FnAzL3FFktXXJ5txRvqn-Ddj7XUaQXw@mail.gmail.com>
In-Reply-To: <CAGgd1Od_hXig9yD5vD2FnAzL3FFktXXJ5txRvqn-Ddj7XUaQXw@mail.gmail.com>

--------------yFgSpZvti11QMF4bInzIkN3U
Content-Type: multipart/mixed; boundary="------------odWfC6YlQ0y4WFX2lflRu77p"

--------------odWfC6YlQ0y4WFX2lflRu77p
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit


Hi all,

See below - I was asked to forward this message from one of
the IETF security area directors to this list in case people
aren't aware of the initiative to re-open an SSH working
group in the IETF.

Cheers,
S.

-------- Forwarded Message --------
Subject: [Ssh] SSH side meeting at IETF 120
Date: Tue, 30 Jul 2024 15:34:31 -0400
From: Deb Cooley <[email protected]>
To: [email protected]
CC: Paul Wouters <[email protected]>, Theo de Raadt 
<[email protected]>, Roman Danyliw <[email protected]>

I want to thank everyone that attended Tuesday evening's side meeting in 
person or remotely.  I also want to thank those that worked to bring 
people together for that meeting.  I also want to thank Francois Michel 
who chaired the session and to David Schinazi who jumped into moderate. 
I'm sure I've left out people, for which I will apologize.

It was a healthy, positive discussion about potentially forming a SSH 
working group and how it would add value to everyone without 
unnecessarily increasing the burden on implementers. It was great seeing 
many people with different goals and concerns agree to work together.

The charter will have clauses about the existence of implementations, 
recognizing that maintaining interoperability is crucial.

We discussed a number of work items which include the following 
(*reflects work that may/may not follow on later):

1.  Updating algorithms (deprecating very old MTI algorithms and 
updating IANA).
2.  Cleanup and publish selected drafts (agent draft, SFTP)
3.  Adding new PQ algorithms (hybrid in the near term).
4.  Reacting to relevant formal analysis results, e.g. from ufmrg or 
elsewhere (initial key exchange, user authentication protocol, machine 
verification of strict kex).
*5.  Certificates - to understand the landscape - SSH style, X.509, 
public trust
*6.  New ideas and experiments - later on, drafts can be written, 
implement for testing.

Going forward:  It is possible to get a working group chartered without 
a BOF.  But we need to get the charter drafted soonest, so we can get it 
through the process (there are multiple review windows that take some time).

Charter:  This is step 1.  Just remember that charters are not forever, 
we need an initial working charter that will get the work started, not 
one that will stand for the ages.  What is posted is a first draft, 
please feel free to post PRs and/or issues that you see.  First draft 
charter language is posted here: 
https://github.com/DavidSchinazi/ssh-charter/blob/main/charter.md

If there are issues attending meetings (either in person or remote), 
please contact the Security ADs (me and/or Paul Wouters).

I look forward to helping to facilitate this work!

Deb

--------------odWfC6YlQ0y4WFX2lflRu77p
Content-Type: text/plain; charset=UTF-8; name="Attached Message Part"
Content-Disposition: attachment; filename="Attached Message Part"
Content-Transfer-Encoding: base64

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KU3NoIG1h
aWxpbmcgbGlzdCAtLSBzc2hAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFp
bCB0byBzc2gtbGVhdmVAaWV0Zi5vcmcK

--------------odWfC6YlQ0y4WFX2lflRu77p--

--------------yFgSpZvti11QMF4bInzIkN3U--

--------------DIpF02BJZwEELP6sSsk7vyYb
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCZqlkDwUDAAAAAAAKCRDk2On5l6gz3Vm7
AQCx+UAAtjpBc0k+vyvsJlDXYtnjWCThmHsp0WUGHnT5hQD8DKNp7xc1cClqsqTEfEzRFkkgs7EF
XjxbBV40PWxpqgc=
=WbO8
-----END PGP SIGNATURE-----

--------------DIpF02BJZwEELP6sSsk7vyYb--