Re: GSoC 2018 - Modern cryptographic algorithms to netpgp, netpgpverify

Harsh Khatore <[email protected]> Tue, 20 Mar 2018 05:41:54 +0000
Newsgroups gmane.os.netbsd.devel.crypto
Message-ID <CANd4RugKrJWd-77Q2eX+RR6VZ2tzn_BXD=MLcqKmNy4jcFSy2Q@mail.gmail.com>
--000000000000cb52cc0567d188cd
Content-Type: text/plain; charset="UTF-8"

>
>
>
>
> On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, <[email protected]> wrote:
>
>> Yeah, netpgpverify is the new, all-in-one, no pre-reqs codebase solely
>> for the verification part of signatures.
>>
>> ed25519 also needs to be added to netpgp, which is the older and more
>> crufty code base which covers signing and verification.
>>
>
> So, as netpgpverify is the new code base for verification part, netpgp
> will be used for only the signing part or for both as it used to do?
>
>>
>> But before any code is touched, we'd need to know what gpg constants uses
>> for these algorithms, since they're not in RFC 4880, and so we can
>> interoperate with gpg in verifying and signing.
>>
>
>
> We can get the ed25519 specifications from RFC8023 and see for the
> constants but I have a doubt as to what are these constants that you
> referred?
>
>
>> We need to know what extra parts are needed (from different sources,
>> along with their licences), and any other prereqs we might need for both
>> netpgpverify and netpgp.
>>
>
> I am not able to get what do you mean by extra parts and pre-reqs, can you
> explain please?
>
>
>> And we need to know tests for making sure that the implementation is
>> correct, and for auditing, including a walk-through to make sure that any
>> keys are discarded in a safe manner.
>>
>
> Yes, sure.
>
>
>> And rest assured that your implementation will be used, since pkgsrc uses
>> netpgpverify to verify signatures on signed packages - see how Joyent have
>> done this.
>>
>> But there, I've just written a big part of your proposal for you :)
>>
>
> Yes, thanks :D :)
>
>
>> On 19 March 2018 at 19:54, Harsh Khatore <[email protected]>
>> wrote:
>>
>>> Hi Alistair,
>>>
>>> It's great to hear from you. And okay, I will follow those instructions.
>>> Regarding the project, we need to implement  ed25519 and salsa20 in the
>>> 'netpgpverify' package right, like there are already implementations for
>>> sha1, sha2, md5 etc. hashing schemes, we need to add the implementation of
>>> these two signature schemes and cipher to the package?
>>> I guess the file would be here:
>>> ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/
>>>
>>> And yes, I can work with C and I understand it's workflow.
>>> So, how should I begin with writing a proposal and get started with the
>>> implementation?
>>>
>>> Thanks,
>>> Harsh Khatore
>>>
>>>
>>> On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <[email protected]> wrote:
>>>
>>>> Hi Harsh,
>>>>
>>>> I've been talking to others about it, but yours is the first mail I've
>>>> received.
>>>>
>>>> C proficiency is necessary. C++ not needed.
>>>>
>>>> I can help you out with any specific questions you have - please mail
>>>> them here (i.e. to tech-crypto, CC me).
>>>>
>>>> Thanks,
>>>> Alistair
>>>>
>>>> On 18 March 2018 at 10:57, Harsh Khatore <
>>>> [email protected]> wrote:
>>>>
>>>>> Hi Alistair,
>>>>>
>>>>> Sorry for contacting you soo late for the above-mentioned project.
>>>>> Could you provide me with help regarding the project so that I can work on
>>>>> it for GSoC? Also, do you have anyone else preparing for it or can I
>>>>> continue with this?
>>>>>
>>>>> My knowledge of C and C++ languages is intermediate.
>>>>>
>>>>> Thanks,
>>>>> Harsh Khatore
>>>>>
>>>>>
>>>>>
>>>>
>>

--000000000000cb52cc0567d188cd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr">=
<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto"><div><div dir=3D=
"auto"><br></div><div dir=3D"auto"><br></div><br><br><div class=3D"gmail_qu=
ote"><div dir=3D"ltr">On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, &lt;<a =
href=3D"mailto:[email protected]" rel=3D"noreferrer noreferrer noreferrer nore=
ferrer noreferrer noreferrer" target=3D"_blank">[email protected]</a>&gt; wrot=
e:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Yeah, netpgpver=
ify is the new, all-in-one, no pre-reqs codebase solely for the verificatio=
n part of signatures.<div><br></div><div>ed25519 also needs to be added to =
netpgp, which is the older and more crufty code base which covers signing a=
nd verification.</div></div></blockquote></div></div><div dir=3D"auto"><br>=
</div><div dir=3D"auto"></div><div dir=3D"auto"><span style=3D"font-family:=
sans-serif">So, as netpgpverify is the new code base for verification part,=
 netpgp will be used for only the signing part or for both as it used to do=
?</span><br></div><div dir=3D"auto"></div><div dir=3D"auto"><div class=3D"g=
mail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><br></div>=
<div>But before any code is touched, we&#39;d need to know what gpg constan=
ts uses for these algorithms, since they&#39;re not in RFC 4880, and so we =
can interoperate with gpg in verifying and signing.</div><div></div></div><=
/blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br><=
/div><div dir=3D"auto">We can get the ed25519 specifications from RFC8023 a=
nd see for the constants but I have a doubt as to what are these constants =
that you referred?</div><div dir=3D"auto"><br></div><div dir=3D"auto"><div =
class=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0=
 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div>=
<br></div><div>We need to know what extra parts are needed (from different =
sources, along with their licences), and any other prereqs we might need fo=
r both netpgpverify and netpgp.</div><div></div></div></blockquote></div></=
div><div dir=3D"auto"><br></div><div dir=3D"auto">I am not able to get what=
 do you mean by extra parts and pre-reqs, can you explain please?=C2=A0</di=
v><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote">=
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><br></div><div>And we =
need to know tests for making sure that the implementation is correct, and =
for auditing, including a walk-through to make sure that any keys are disca=
rded in a safe manner.</div><div></div></div></blockquote></div></div><div =
dir=3D"auto"><br></div><div dir=3D"auto">Yes, sure.=C2=A0</div><div dir=3D"=
auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote"><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p=
adding-left:1ex"><div dir=3D"ltr"><div><br></div><div>And rest assured that=
 your implementation will be used, since pkgsrc uses netpgpverify to verify=
 signatures on signed packages - see how Joyent have done this.</div><div><=
br></div><div>But there, I&#39;ve just written a big part of your proposal =
for you :)</div></div><div class=3D"gmail_extra"></div></blockquote></div><=
/div><div dir=3D"auto"><br></div><div dir=3D"auto">Yes, thanks :D :)=C2=A0<=
/div><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quot=
e"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left=
:1px #ccc solid;padding-left:1ex"><div class=3D"gmail_extra"><br><div class=
=3D"gmail_quote">On 19 March 2018 at 19:54, Harsh Khatore <span dir=3D"ltr"=
>&lt;<a href=3D"mailto:[email protected]" rel=3D"noreferrer no=
referrer noreferrer noreferrer noreferrer noreferrer noreferrer" target=3D"=
_blank">[email protected]</a>&gt;</span> wrote:<br><blockquote=
 class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc soli=
d;padding-left:1ex"><div dir=3D"ltr">Hi Alistair,=C2=A0<br><br>It&#39;s gre=
at to hear from you. And okay, I will follow those instructions.<br>Regardi=
ng the project, we need to implement=C2=A0 <span style=3D"color:rgb(0,0,0);=
font-family:Tahoma,sans-serif;font-size:small;font-style:normal;font-varian=
t-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:=
normal;text-align:left;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style=
:initial;text-decoration-color:initial;float:none;display:inline">ed25519 a=
nd salsa20 in the &#39;netpgpverify&#39; package right, like there are alre=
ady implementations for sha1, sha2, md5 etc. hashing schemes, we need to ad=
d the implementation of these two signature schemes and cipher to the packa=
ge?<br>I guess the file would be here:=C2=A0<a href=3D"ftp://ftp.netbsd.org=
/pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/" rel=3D"noreferrer =
noreferrer noreferrer noreferrer noreferrer noreferrer noreferrer" target=
=3D"_blank">ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/security/netpgpv=
erify/files/</a><br><br>And yes, I can work with C and I understand it&#39;=
s workflow.<br>So, how should I begin with writing a proposal and get start=
ed with the implementation?<br><br>Thanks,<br>Harsh Khatore</span></div><di=
v class=3D"m_-3652540538282676177m_-4120515430808345271m_-15283883274236962=
4m_-7058979744402979362m_80729991776723791m_2938130422020416977m_-110759790=
7703545291HOEnZb"><div class=3D"m_-3652540538282676177m_-412051543080834527=
1m_-152838832742369624m_-7058979744402979362m_80729991776723791m_2938130422=
020416977m_-1107597907703545291h5"><br><br><div class=3D"gmail_quote"><div =
dir=3D"ltr">On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks &lt;<a href=3D=
"mailto:[email protected]" rel=3D"noreferrer noreferrer noreferrer noreferrer =
noreferrer noreferrer noreferrer" target=3D"_blank">[email protected]</a>&gt; =
wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e=
x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Hi Harsh,<d=
iv><br></div><div>I&#39;ve been talking to others about it, but yours is th=
e first mail I&#39;ve received.</div><div><br></div><div>C proficiency is n=
ecessary. C++ not needed.</div><div><br></div><div>I can help you out with =
any specific questions you have - please mail them here (i.e. to tech-crypt=
o, CC me).</div><div><br></div><div>Thanks,</div><div>Alistair</div></div><=
div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 18 March 2018 a=
t 10:57, Harsh Khatore <span dir=3D"ltr">&lt;<a href=3D"mailto:khatore.hars=
[email protected]" rel=3D"noreferrer noreferrer noreferrer noreferrer nore=
ferrer noreferrer noreferrer" target=3D"_blank">khatore.harsh.github@gmail.=
com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr=
">Hi Alistair,<br><br>Sorry for contacting you soo late for the above-menti=
oned project. Could you provide me with help regarding the project so that =
I can work on it for GSoC? Also, do you have anyone else preparing for it o=
r can I continue with this?<div><br>My knowledge of=C2=A0C and C++ language=
s is intermediate.<br><br>Thanks,<br>Harsh Khatore<br><br><br></div></div>
</blockquote></div><br></div>
</blockquote></div>
</div></div></blockquote></div><br></div>
</blockquote></div></div></div></blockquote></div></div>

--000000000000cb52cc0567d188cd--