Re: GSoC 2018 - Modern cryptographic algorithms to netpgp, netpgpverify
Harsh Khatore <[email protected]> Tue, 20 Mar 2018 05:41:54 +0000
| Newsgroups | gmane.os.netbsd.devel.crypto |
|---|---|
| Message-ID | <CANd4RugKrJWd-77Q2eX+RR6VZ2tzn_BXD=MLcqKmNy4jcFSy2Q@mail.gmail.com> |
--000000000000cb52cc0567d188cd Content-Type: text/plain; charset="UTF-8" > > > > > On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, <[email protected]> wrote: > >> Yeah, netpgpverify is the new, all-in-one, no pre-reqs codebase solely >> for the verification part of signatures. >> >> ed25519 also needs to be added to netpgp, which is the older and more >> crufty code base which covers signing and verification. >> > > So, as netpgpverify is the new code base for verification part, netpgp > will be used for only the signing part or for both as it used to do? > >> >> But before any code is touched, we'd need to know what gpg constants uses >> for these algorithms, since they're not in RFC 4880, and so we can >> interoperate with gpg in verifying and signing. >> > > > We can get the ed25519 specifications from RFC8023 and see for the > constants but I have a doubt as to what are these constants that you > referred? > > >> We need to know what extra parts are needed (from different sources, >> along with their licences), and any other prereqs we might need for both >> netpgpverify and netpgp. >> > > I am not able to get what do you mean by extra parts and pre-reqs, can you > explain please? > > >> And we need to know tests for making sure that the implementation is >> correct, and for auditing, including a walk-through to make sure that any >> keys are discarded in a safe manner. >> > > Yes, sure. > > >> And rest assured that your implementation will be used, since pkgsrc uses >> netpgpverify to verify signatures on signed packages - see how Joyent have >> done this. >> >> But there, I've just written a big part of your proposal for you :) >> > > Yes, thanks :D :) > > >> On 19 March 2018 at 19:54, Harsh Khatore <[email protected]> >> wrote: >> >>> Hi Alistair, >>> >>> It's great to hear from you. And okay, I will follow those instructions. >>> Regarding the project, we need to implement ed25519 and salsa20 in the >>> 'netpgpverify' package right, like there are already implementations for >>> sha1, sha2, md5 etc. hashing schemes, we need to add the implementation of >>> these two signature schemes and cipher to the package? >>> I guess the file would be here: >>> ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/ >>> >>> And yes, I can work with C and I understand it's workflow. >>> So, how should I begin with writing a proposal and get started with the >>> implementation? >>> >>> Thanks, >>> Harsh Khatore >>> >>> >>> On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <[email protected]> wrote: >>> >>>> Hi Harsh, >>>> >>>> I've been talking to others about it, but yours is the first mail I've >>>> received. >>>> >>>> C proficiency is necessary. C++ not needed. >>>> >>>> I can help you out with any specific questions you have - please mail >>>> them here (i.e. to tech-crypto, CC me). >>>> >>>> Thanks, >>>> Alistair >>>> >>>> On 18 March 2018 at 10:57, Harsh Khatore < >>>> [email protected]> wrote: >>>> >>>>> Hi Alistair, >>>>> >>>>> Sorry for contacting you soo late for the above-mentioned project. >>>>> Could you provide me with help regarding the project so that I can work on >>>>> it for GSoC? Also, do you have anyone else preparing for it or can I >>>>> continue with this? >>>>> >>>>> My knowledge of C and C++ languages is intermediate. >>>>> >>>>> Thanks, >>>>> Harsh Khatore >>>>> >>>>> >>>>> >>>> >> --000000000000cb52cc0567d188cd Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr">= <br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bord= er-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto"><div><div dir=3D= "auto"><br></div><div dir=3D"auto"><br></div><br><br><div class=3D"gmail_qu= ote"><div dir=3D"ltr">On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, <<a = href=3D"mailto:[email protected]" rel=3D"noreferrer noreferrer noreferrer nore= ferrer noreferrer noreferrer" target=3D"_blank">[email protected]</a>> wrot= e:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo= rder-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Yeah, netpgpver= ify is the new, all-in-one, no pre-reqs codebase solely for the verificatio= n part of signatures.<div><br></div><div>ed25519 also needs to be added to = netpgp, which is the older and more crufty code base which covers signing a= nd verification.</div></div></blockquote></div></div><div dir=3D"auto"><br>= </div><div dir=3D"auto"></div><div dir=3D"auto"><span style=3D"font-family:= sans-serif">So, as netpgpverify is the new code base for verification part,= netpgp will be used for only the signing part or for both as it used to do= ?</span><br></div><div dir=3D"auto"></div><div dir=3D"auto"><div class=3D"g= mail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo= rder-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><br></div>= <div>But before any code is touched, we'd need to know what gpg constan= ts uses for these algorithms, since they're not in RFC 4880, and so we = can interoperate with gpg in verifying and signing.</div><div></div></div><= /blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br><= /div><div dir=3D"auto">We can get the ed25519 specifications from RFC8023 a= nd see for the constants but I have a doubt as to what are these constants = that you referred?</div><div dir=3D"auto"><br></div><div dir=3D"auto"><div = class=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0= 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div>= <br></div><div>We need to know what extra parts are needed (from different = sources, along with their licences), and any other prereqs we might need fo= r both netpgpverify and netpgp.</div><div></div></div></blockquote></div></= div><div dir=3D"auto"><br></div><div dir=3D"auto">I am not able to get what= do you mean by extra parts and pre-reqs, can you explain please?=C2=A0</di= v><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote">= <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><br></div><div>And we = need to know tests for making sure that the implementation is correct, and = for auditing, including a walk-through to make sure that any keys are disca= rded in a safe manner.</div><div></div></div></blockquote></div></div><div = dir=3D"auto"><br></div><div dir=3D"auto">Yes, sure.=C2=A0</div><div dir=3D"= auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote"><blockquote cl= ass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p= adding-left:1ex"><div dir=3D"ltr"><div><br></div><div>And rest assured that= your implementation will be used, since pkgsrc uses netpgpverify to verify= signatures on signed packages - see how Joyent have done this.</div><div><= br></div><div>But there, I've just written a big part of your proposal = for you :)</div></div><div class=3D"gmail_extra"></div></blockquote></div><= /div><div dir=3D"auto"><br></div><div dir=3D"auto">Yes, thanks :D :)=C2=A0<= /div><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quot= e"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left= :1px #ccc solid;padding-left:1ex"><div class=3D"gmail_extra"><br><div class= =3D"gmail_quote">On 19 March 2018 at 19:54, Harsh Khatore <span dir=3D"ltr"= ><<a href=3D"mailto:[email protected]" rel=3D"noreferrer no= referrer noreferrer noreferrer noreferrer noreferrer noreferrer" target=3D"= _blank">[email protected]</a>></span> wrote:<br><blockquote= class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc soli= d;padding-left:1ex"><div dir=3D"ltr">Hi Alistair,=C2=A0<br><br>It's gre= at to hear from you. And okay, I will follow those instructions.<br>Regardi= ng the project, we need to implement=C2=A0 <span style=3D"color:rgb(0,0,0);= font-family:Tahoma,sans-serif;font-size:small;font-style:normal;font-varian= t-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:= normal;text-align:left;text-indent:0px;text-transform:none;white-space:norm= al;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style= :initial;text-decoration-color:initial;float:none;display:inline">ed25519 a= nd salsa20 in the 'netpgpverify' package right, like there are alre= ady implementations for sha1, sha2, md5 etc. hashing schemes, we need to ad= d the implementation of these two signature schemes and cipher to the packa= ge?<br>I guess the file would be here:=C2=A0<a href=3D"ftp://ftp.netbsd.org= /pub/pkgsrc/current/pkgsrc/security/netpgpverify/files/" rel=3D"noreferrer = noreferrer noreferrer noreferrer noreferrer noreferrer noreferrer" target= =3D"_blank">ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/security/netpgpv= erify/files/</a><br><br>And yes, I can work with C and I understand it'= s workflow.<br>So, how should I begin with writing a proposal and get start= ed with the implementation?<br><br>Thanks,<br>Harsh Khatore</span></div><di= v class=3D"m_-3652540538282676177m_-4120515430808345271m_-15283883274236962= 4m_-7058979744402979362m_80729991776723791m_2938130422020416977m_-110759790= 7703545291HOEnZb"><div class=3D"m_-3652540538282676177m_-412051543080834527= 1m_-152838832742369624m_-7058979744402979362m_80729991776723791m_2938130422= 020416977m_-1107597907703545291h5"><br><br><div class=3D"gmail_quote"><div = dir=3D"ltr">On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <<a href=3D= "mailto:[email protected]" rel=3D"noreferrer noreferrer noreferrer noreferrer = noreferrer noreferrer noreferrer" target=3D"_blank">[email protected]</a>> = wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e= x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Hi Harsh,<d= iv><br></div><div>I've been talking to others about it, but yours is th= e first mail I've received.</div><div><br></div><div>C proficiency is n= ecessary. C++ not needed.</div><div><br></div><div>I can help you out with = any specific questions you have - please mail them here (i.e. to tech-crypt= o, CC me).</div><div><br></div><div>Thanks,</div><div>Alistair</div></div><= div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 18 March 2018 a= t 10:57, Harsh Khatore <span dir=3D"ltr"><<a href=3D"mailto:khatore.hars= [email protected]" rel=3D"noreferrer noreferrer noreferrer noreferrer nore= ferrer noreferrer noreferrer" target=3D"_blank">khatore.harsh.github@gmail.= com</a>></span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar= gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr= ">Hi Alistair,<br><br>Sorry for contacting you soo late for the above-menti= oned project. Could you provide me with help regarding the project so that = I can work on it for GSoC? Also, do you have anyone else preparing for it o= r can I continue with this?<div><br>My knowledge of=C2=A0C and C++ language= s is intermediate.<br><br>Thanks,<br>Harsh Khatore<br><br><br></div></div> </blockquote></div><br></div> </blockquote></div> </div></div></blockquote></div><br></div> </blockquote></div></div></div></blockquote></div></div> --000000000000cb52cc0567d188cd--