Re: GSoC 2018 - Modern cryptographic algorithms to netpgp, netpgpverify

Alistair Crooks <[email protected]> Mon, 19 Mar 2018 21:04:36 -0700
Newsgroups gmane.os.netbsd.devel.crypto
Message-ID <CAN5gJXqssLf2o9Zp+yiwytSFfb6Txm8VYHnOjFePqsPRwJwz_g@mail.gmail.com>
--00000000000070fa9e0567d02d0b
Content-Type: text/plain; charset="UTF-8"

Yeah, netpgpverify is the new, all-in-one, no pre-reqs codebase solely for
the verification part of signatures.

ed25519 also needs to be added to netpgp, which is the older and more
crufty code base which covers signing and verification.

But before any code is touched, we'd need to know what gpg constants uses
for these algorithms, since they're not in RFC 4880, and so we can
interoperate with gpg in verifying and signing.

We need to know what extra parts are needed (from different sources, along
with their licences), and any other prereqs we might need for both
netpgpverify and netpgp.

And we need to know tests for making sure that the implementation is
correct, and for auditing, including a walk-through to make sure that any
keys are discarded in a safe manner.

And rest assured that your implementation will be used, since pkgsrc uses
netpgpverify to verify signatures on signed packages - see how Joyent have
done this.

But there, I've just written a big part of your proposal for you :)

On 19 March 2018 at 19:54, Harsh Khatore <[email protected]>
wrote:

> Hi Alistair,
>
> It's great to hear from you. And okay, I will follow those instructions.
> Regarding the project, we need to implement  ed25519 and salsa20 in the
> 'netpgpverify' package right, like there are already implementations for
> sha1, sha2, md5 etc. hashing schemes, we need to add the implementation of
> these two signature schemes and cipher to the package?
> I guess the file would be here: ftp://ftp.netbsd.org/
> pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/
>
> And yes, I can work with C and I understand it's workflow.
> So, how should I begin with writing a proposal and get started with the
> implementation?
>
> Thanks,
> Harsh Khatore
>
>
> On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <[email protected]> wrote:
>
>> Hi Harsh,
>>
>> I've been talking to others about it, but yours is the first mail I've
>> received.
>>
>> C proficiency is necessary. C++ not needed.
>>
>> I can help you out with any specific questions you have - please mail
>> them here (i.e. to tech-crypto, CC me).
>>
>> Thanks,
>> Alistair
>>
>> On 18 March 2018 at 10:57, Harsh Khatore <[email protected]>
>> wrote:
>>
>>> Hi Alistair,
>>>
>>> Sorry for contacting you soo late for the above-mentioned project. Could
>>> you provide me with help regarding the project so that I can work on it for
>>> GSoC? Also, do you have anyone else preparing for it or can I continue with
>>> this?
>>>
>>> My knowledge of C and C++ languages is intermediate.
>>>
>>> Thanks,
>>> Harsh Khatore
>>>
>>>
>>>
>>

--00000000000070fa9e0567d02d0b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Yeah, netpgpverify is the new, all-in-one, no pre-reqs cod=
ebase solely for the verification part of signatures.<div><br></div><div>ed=
25519 also needs to be added to netpgp, which is the older and more crufty =
code base which covers signing and verification.</div><div><br></div><div>B=
ut before any code is touched, we&#39;d need to know what gpg constants use=
s for these algorithms, since they&#39;re not in RFC 4880, and so we can in=
teroperate with gpg in verifying and signing.</div><div><br></div><div>We n=
eed to know what extra parts are needed (from different sources, along with=
 their licences), and any other prereqs we might need for both netpgpverify=
 and netpgp.</div><div><br></div><div>And we need to know tests for making =
sure that the implementation is correct, and for auditing, including a walk=
-through to make sure that any keys are discarded in a safe manner.</div><d=
iv><br></div><div>And rest assured that your implementation will be used, s=
ince pkgsrc uses netpgpverify to verify signatures on signed packages - see=
 how Joyent have done this.</div><div><br></div><div>But there, I&#39;ve ju=
st written a big part of your proposal for you :)</div></div><div class=3D"=
gmail_extra"><br><div class=3D"gmail_quote">On 19 March 2018 at 19:54, Hars=
h Khatore <span dir=3D"ltr">&lt;<a href=3D"mailto:khatore.harsh.github@gmai=
l.com" target=3D"_blank">[email protected]</a>&gt;</span> wrot=
e:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Hi Alistair,=C2=A0<br=
><br>It&#39;s great to hear from you. And okay, I will follow those instruc=
tions.<br>Regarding the project, we need to implement=C2=A0 <span style=3D"=
color:rgb(0,0,0);font-family:Tahoma,sans-serif;font-size:small;font-style:n=
ormal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:40=
0;letter-spacing:normal;text-align:left;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text=
-decoration-style:initial;text-decoration-color:initial;float:none;display:=
inline">ed25519 and salsa20 in the &#39;netpgpverify&#39; package right, li=
ke there are already implementations for sha1, sha2, md5 etc. hashing schem=
es, we need to add the implementation of these two signature schemes and ci=
pher to the package?<br>I guess the file would be here:=C2=A0<a href=3D"ftp=
://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/" t=
arget=3D"_blank">ftp://ftp.netbsd.org/<wbr>pub/pkgsrc/current/pkgsrc/<wbr>s=
ecurity/netpgpverify/files/</a><br><br>And yes, I can work with C and I und=
erstand it&#39;s workflow.<br>So, how should I begin with writing a proposa=
l and get started with the implementation?<br><br>Thanks,<br>Harsh Khatore<=
/span></div><div class=3D"HOEnZb"><div class=3D"h5"><br><br><div class=3D"g=
mail_quote"><div dir=3D"ltr">On Tue, Mar 20, 2018 at 12:13 AM Alistair Croo=
ks &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Hi H=
arsh,<div><br></div><div>I&#39;ve been talking to others about it, but your=
s is the first mail I&#39;ve received.</div><div><br></div><div>C proficien=
cy is necessary. C++ not needed.</div><div><br></div><div>I can help you ou=
t with any specific questions you have - please mail them here (i.e. to tec=
h-crypto, CC me).</div><div><br></div><div>Thanks,</div><div>Alistair</div>=
</div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 18 March=
 2018 at 10:57, Harsh Khatore <span dir=3D"ltr">&lt;<a href=3D"mailto:khato=
[email protected]" target=3D"_blank">khatore.harsh.github@gmail.<wb=
r>com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"m=
argin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"l=
tr">Hi Alistair,<br><br>Sorry for contacting you soo late for the above-men=
tioned project. Could you provide me with help regarding the project so tha=
t I can work on it for GSoC? Also, do you have anyone else preparing for it=
 or can I continue with this?<div><br>My knowledge of=C2=A0C and C++ langua=
ges is intermediate.<br><br>Thanks,<br>Harsh Khatore<br><br><br></div></div=
>
</blockquote></div><br></div>
</blockquote></div>
</div></div></blockquote></div><br></div>

--00000000000070fa9e0567d02d0b--