Re: [Ssh] Re: draft charter
Jeffrey Hutzelman <[email protected]> Thu, 15 Aug 2024 08:28:03 -0400
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <CALF+FNz2MNMvtg9q2wZbvvoyXN_tUStoP9aEM7dXzgsiBOKywA@mail.gmail.com> |
--0000000000002c5485061fb7faf2 Content-Type: text/plain; charset="UTF-8" On Thu, Aug 15, 2024, 07:15 Mouse <[email protected]> wrote: > > > I think it would be beneficial with a single documented and > > recommended way to plug in new AEAD-style algorithms in SSH, since > > those weren't a thing when the original protocol was designed. In > > particular, [...] > > I don't have the time right now to give this the thought it needs (in > particular, I'm not sure whether I agree about MACs). This strikes me > as something worth discussing - perhaps discussing how to handle new > algorithm classes, such as AEAD, should be within the charter? > Sounds like an excellent idea to me. As for Simon's document, and others like it, I think those are clearly within the scope of the charter as written: > while defining how SSH uses cryptographic algorithms is in scope, defining the algorithms themselves is out of scope. ... so the new group should be free to adopt that document if desired. --0000000000002c5485061fb7faf2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div><br><br><div class=3D"gmail_quote"><div dir=3D"ltr" = class=3D"gmail_attr">On Thu, Aug 15, 2024, 07:15 Mouse <<a href=3D"mailt= o:[email protected]" rel=3D"noreferrer noreferrer noreferrer" targ= et=3D"_blank">[email protected]</a>> wrote:<br></div><blockquot= e class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px s= olid rgb(204,204,204);padding-left:1ex"><br> > I think it would be beneficial with a single documented and<br> > recommended way to plug in new AEAD-style algorithms in SSH, since<br> > those weren't a thing when the original protocol was designed.=C2= =A0 In<br> > particular, [...]<br> <br> I don't have the time right now to give this the thought it needs (in<b= r> particular, I'm not sure whether I agree about MACs).=C2=A0 This strike= s me<br> as something worth discussing - perhaps discussing how to handle new<br> algorithm classes, such as AEAD, should be within the charter?<br> </blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto">Soun= ds like an excellent idea to me.</div><div dir=3D"auto"><br></div><div dir= =3D"auto">As for Simon's document, and others like it, I think those ar= e clearly within the scope of the charter as written:</div><div dir=3D"auto= "><br></div><div dir=3D"auto">> while defining how SSH uses cryptographi= c algorithms is in scope, defining the algorithms themselves is out of scop= e.</div><div dir=3D"auto"><br></div><div dir=3D"auto">... so the new group = should be free to adopt that document if desired.=C2=A0</div></div> --0000000000002c5485061fb7faf2--