Re: GSoC 2018 - Modern cryptographic algorithms to netpgp, netpgpverify
Harsh Khatore <[email protected]> Wed, 21 Mar 2018 01:03:09 +0000
| Newsgroups | gmane.os.netbsd.devel.crypto |
|---|---|
| Message-ID | <CANd4RugjJ8o6W5KPSSZ7iCQ1fk2YWUYsax0qgc-A9ukoK1Hx3Q@mail.gmail.com> |
--94eb2c088500c39b240567e1c1fb Content-Type: text/plain; charset="UTF-8" On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, <[email protected]> wrote: > Yeah, netpgpverify is the new, all-in-one, no pre-reqs codebase solely for > the verification part of signatures. > > ed25519 also needs to be added to netpgp, which is the older and more > crufty code base which covers signing and verification. > So, as netpgpverify is the new code base for verification part, netpgp will be used for only the signing part or for both as it used to do? > > But before any code is touched, we'd need to know what gpg constants uses > for these algorithms, since they're not in RFC 4880, and so we can > interoperate with gpg in verifying and signing. > We can get the ed25519 specifications from RFC8023 and see for the constants but I have a doubt as to what are these constants that you referred? > We need to know what extra parts are needed (from different sources, along > with their licences), and any other prereqs we might need for both > netpgpverify and netpgp. > I am not able to get what do you mean by extra parts and prereqs, can you explain, please? > And we need to know tests for making sure that the implementation is > correct, and for auditing, including a walk-through to make sure that any > keys are discarded in a safe manner. > Yes, sure. > And rest assured that your implementation will be used, since pkgsrc uses > netpgpverify to verify signatures on signed packages - see how Joyent have > done this. > > But there, I've just written a big part of your proposal for you :) > Yes, thanks :D :) On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <[email protected]> wrote: > Hi Harsh, > > I've been talking to others about it, but yours is the first mail I've > received. > > C proficiency is necessary. C++ not needed. > > I can help you out with any specific questions you have - please mail them > here (i.e. to tech-crypto, CC me). > > Thanks, > Alistair > > On 18 March 2018 at 10:57, Harsh Khatore <[email protected]> > wrote: > >> Hi Alistair, >> >> Sorry for contacting you soo late for the above-mentioned project. Could >> you provide me with help regarding the project so that I can work on it for >> GSoC? Also, do you have anyone else preparing for it or can I continue with >> this? >> >> My knowledge of C and C++ languages is intermediate. >> >> Thanks, >> Harsh Khatore >> >> >> > --94eb2c088500c39b240567e1c1fb Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"> <span class=3D"gmail-im" style=3D"color:rgb(80,0,80);font-family:arial,sans= -serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;fon= t-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:star= t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;b= ackground-color:rgb(255,255,255);text-decoration-style:initial;text-decorat= ion-color:initial"><div><div class=3D"gmail_quote"><div dir=3D"ltr">On Tue = 20 Mar, 2018, 9:34 AM Alistair Crooks, <<a href=3D"mailto:[email protected]= " rel=3D"noreferrer" target=3D"_blank" style=3D"color:rgb(17,85,204);text-d= ecoration:none">[email protected]</a>> wrote:<br></div><blockquote class=3D= "gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(2= 04,204,204);padding-left:1ex"><div dir=3D"ltr">Yeah, netpgpverify is the ne= w, all-in-one, no pre-reqs codebase solely for the verification part of sig= natures.<div><br></div><div>ed25519 also needs to be added to netpgp, which= is the older and more crufty code base which covers signing and verificati= on.</div></div></blockquote></div></div><div dir=3D"auto"><br></div><div di= r=3D"auto"></div></span><div dir=3D"auto" style=3D"color:rgb(34,34,34);font= -family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-li= gatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:norm= al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;= word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:in= itial;text-decoration-color:initial"><span style=3D"font-family:sans-serif"= >So, as netpgpverify is the new code base for verification part, netpgp wil= l be used for only the signing part or for both as it used to do?</span><br= ></div><span class=3D"gmail-im" style=3D"color:rgb(80,0,80);font-family:ari= al,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:nor= mal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-ali= gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin= g:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-= decoration-color:initial"><div dir=3D"auto"></div><div dir=3D"auto"><div cl= ass=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0= px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div = dir=3D"ltr"><div><br></div><div>But before any code is touched, we'd ne= ed to know what gpg constants uses for these algorithms, since they're = not in RFC 4880, and so we can interoperate with gpg in verifying and signi= ng.</div><div></div></div></blockquote></div></div><div dir=3D"auto"><br></= div><div dir=3D"auto"><br></div></span><div dir=3D"auto" style=3D"color:rgb= (34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;= font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;lett= er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit= e-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-deco= ration-style:initial;text-decoration-color:initial">We can get the ed25519 = specifications from RFC8023 and see for the constants but I have a doubt as= to what are these constants that you referred?</div><span class=3D"gmail-i= m" style=3D"color:rgb(80,0,80);font-family:arial,sans-serif;font-size:12.8p= x;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;= font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text= -transform:none;white-space:normal;word-spacing:0px;background-color:rgb(25= 5,255,255);text-decoration-style:initial;text-decoration-color:initial"><di= v dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote"><bloc= kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:= 1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div><br></di= v><div>We need to know what extra parts are needed (from different sources,= along with their licences), and any other prereqs we might need for both n= etpgpverify and netpgp.</div><div></div></div></blockquote></div></div><div= dir=3D"auto"><br></div></span><div dir=3D"auto" style=3D"color:rgb(34,34,3= 4);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-var= iant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spaci= ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:= normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-s= tyle:initial;text-decoration-color:initial">I am not able to get what do yo= u mean by extra parts and prereqs, can you explain, please?=C2=A0</div><spa= n class=3D"gmail-im" style=3D"color:rgb(80,0,80);font-family:arial,sans-ser= if;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-va= riant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;te= xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;backg= round-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-= color:initial"><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"= gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px = 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"= ltr"><div><br></div><div>And we need to know tests for making sure that the= implementation is correct, and for auditing, including a walk-through to m= ake sure that any keys are discarded in a safe manner.</div><div></div></di= v></blockquote></div></div><div dir=3D"auto"><br></div></span><div dir=3D"a= uto" style=3D"color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12= .8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:norm= al;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;t= ext-transform:none;white-space:normal;word-spacing:0px;background-color:rgb= (255,255,255);text-decoration-style:initial;text-decoration-color:initial">= Yes, sure.=C2=A0</div><span class=3D"gmail-im" style=3D"color:rgb(80,0,80);= font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-varian= t-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:= normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor= mal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-styl= e:initial;text-decoration-color:initial"><div dir=3D"auto"><br></div><div d= ir=3D"auto"><div class=3D"gmail_quote"><blockquote class=3D"gmail_quote" st= yle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padd= ing-left:1ex"><div dir=3D"ltr"><div><br></div><div>And rest assured that yo= ur implementation will be used, since pkgsrc uses netpgpverify to verify si= gnatures on signed packages - see how Joyent have done this.</div><div><br>= </div><div>But there, I've just written a big part of your proposal for= you :)</div></div><div class=3D"gmail_extra"></div></blockquote></div></di= v><div dir=3D"auto"><br></div></span><div dir=3D"auto" style=3D"color:rgb(3= 4,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;fo= nt-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter= -spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-= space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decora= tion-style:initial;text-decoration-color:initial">Yes, thanks :D :)=C2=A0</= div> <br></div><br><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Tue, Mar 2= 0, 2018 at 12:13 AM Alistair Crooks <<a href=3D"mailto:[email protected]">a= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" sty= le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div d= ir=3D"ltr">Hi Harsh,<div><br></div><div>I've been talking to others abo= ut it, but yours is the first mail I've received.</div><div><br></div><= div>C proficiency is necessary. C++ not needed.</div><div><br></div><div>I = can help you out with any specific questions you have - please mail them he= re (i.e. to tech-crypto, CC me).</div><div><br></div><div>Thanks,</div><div= >Alistair</div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quo= te">On 18 March 2018 at 10:57, Harsh Khatore <span dir=3D"ltr"><<a href= =3D"mailto:[email protected]" target=3D"_blank">khatore.harsh.= [email protected]</a>></span> wrote:<br><blockquote class=3D"gmail_quote"= style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><d= iv dir=3D"ltr">Hi Alistair,<br><br>Sorry for contacting you soo late for th= e above-mentioned project. Could you provide me with help regarding the pro= ject so that I can work on it for GSoC? Also, do you have anyone else prepa= ring for it or can I continue with this?<div><br>My knowledge of=C2=A0C and= C++ languages is intermediate.<br><br>Thanks,<br>Harsh Khatore<br><br><br>= </div></div> </blockquote></div><br></div> </blockquote></div> --94eb2c088500c39b240567e1c1fb--