Re: GSoC 2018 - Modern cryptographic algorithms to netpgp, netpgpverify

Harsh Khatore <[email protected]> Tue, 27 Mar 2018 06:45:12 +0000
Newsgroups gmane.os.netbsd.devel.crypto
Message-ID <CANd4Rui=5dfC5sy7RBSSuQTKVQ173+jg9gpPqah96T+5ANLQNw@mail.gmail.com>
--001a114e4f9e145a2705685f3cdc
Content-Type: text/plain; charset="UTF-8"

There is no such exact implementation for ed25519 or salsa20 hash, but
there are few open source modified implementations, I can take reference
from them( as they have different licenses so cannot use them directly )
and implement the required algorithms based on our need, combining with
reading the relevant papers and documents.

On Tue 27 Mar, 2018, 12:00 PM Hubert Feyrer, <[email protected]> wrote:

> Hi,
>
>    - Is the project a port of software, or a rewrite? (remember: No GPL
>    in the NetBSD kernel!)
>
>
>    - No. But it will use already existing algorithms and implementation
>    of those algorithms.
>
> what existing implementation do you intend to use?
>
>
> -Hubert
>
>
>
>
> Am 26.03.2018 um 20:36 schrieb Harsh Khatore <
> [email protected]>:
>
> Hi Alistair,
>
> Please go through the proposal for GSoC project. Here is the link: GSoC
> proposal
> <https://docs.google.com/document/d/1QayByVOYj2FINohvL4Mr-_Xq9Cb0TnwrrscfXgjPnDo/edit>
>
> Please provide your valuable comments, as to how can I be selected as I
> really want to be a part of this experience.
>
> Formatting is not quite good. Please suggest on formatting also, as
> nothing was mentioned in the guidelines.
>
> Thanks,
> Harsh Khatore
>
> On Wed, Mar 21, 2018 at 11:45 AM, Alistair Crooks <[email protected]> wrote:
>
>> When you read the answers below, I can understand if you think I'm being
>> difficult.
>>
>> But this is how we can work out whether you've understood the task, and
>> have thought about how you'd go about it.
>>
>> On 20 March 2018 at 18:03, Harsh Khatore <[email protected]>
>> wrote:
>>
>>> On Tue 20 Mar, 2018, 9:34 AM Alistair Crooks, <[email protected]> wrote:
>>>
>>>> Yeah, netpgpverify is the new, all-in-one, no pre-reqs codebase solely
>>>> for the verification part of signatures.
>>>>
>>>> ed25519 also needs to be added to netpgp, which is the older and more
>>>> crufty code base which covers signing and verification.
>>>>
>>>
>>> So, as netpgpverify is the new code base for verification part, netpgp
>>> will be used for only the signing part or for both as it used to do?
>>>
>>
>> See the project specification - both are needed.
>>
>>
>>>
>>>
>>>> But before any code is touched, we'd need to know what gpg constants
>>>> uses for these algorithms, since they're not in RFC 4880, and so we can
>>>> interoperate with gpg in verifying and signing.
>>>>
>>>
>>>
>>> We can get the ed25519 specifications from RFC8023 and see for the
>>> constants but I have a doubt as to what are these constants that you
>>> referred?
>>>
>>
>> Look further.
>>
>> Think of the job that netpgpverify and netpgp do, and how they
>> interoperate with other software.
>>
>>
>>>
>>>
>>>> We need to know what extra parts are needed (from different sources,
>>>> along with their licences), and any other prereqs we might need for both
>>>> netpgpverify and netpgp.
>>>>
>>>
>>> I am not able to get what do you mean by extra parts and prereqs, can
>>> you explain, please?
>>>
>>
>> Think of other things that will be necessary to accomplish the task.
>>
>> In summary, I'd like to see what you think will be necessary. I'd like to
>> see the thoughts that go into how to accomplish a design and programming
>> task, what tests are necessary, and what to be wary of in the
>> implementation. Not in email, but in the proposal that you write - how you
>> will accomplish (and surpass) the goals.
>>
>> You (and anyone else) should now have enough information -- from the
>> project specification, and from previous email --  to generate a proposal
>> for the project.
>>
>> Regards,
>> Alistair
>>
>> PS. One copy of email is enough, thanks :)
>>
>>
>>
>>>
>>> On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks <[email protected]> wrote:
>>>
>>>> Hi Harsh,
>>>>
>>>> I've been talking to others about it, but yours is the first mail I've
>>>> received.
>>>>
>>>> C proficiency is necessary. C++ not needed.
>>>>
>>>> I can help you out with any specific questions you have - please mail
>>>> them here (i.e. to tech-crypto, CC me).
>>>>
>>>> Thanks,
>>>> Alistair
>>>>
>>>> On 18 March 2018 at 10:57, Harsh Khatore <
>>>> [email protected]> wrote:
>>>>
>>>>> Hi Alistair,
>>>>>
>>>>> Sorry for contacting you soo late for the above-mentioned project.
>>>>> Could you provide me with help regarding the project so that I can work on
>>>>> it for GSoC? Also, do you have anyone else preparing for it or can I
>>>>> continue with this?
>>>>>
>>>>> My knowledge of C and C++ languages is intermediate.
>>>>>
>>>>> Thanks,
>>>>> Harsh Khatore
>>>>>
>>>>>
>>>>>
>>>>
>>
>

--001a114e4f9e145a2705685f3cdc
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">There is no such exact implementation for ed25519 or sals=
a20 hash, but there are few open source modified implementations, I can tak=
e reference from them( as they have different licenses so cannot use them d=
irectly )=C2=A0 and implement the required algorithms based on our need, co=
mbining with reading the relevant papers and documents.=C2=A0</div><br><div=
 class=3D"gmail_quote"><div dir=3D"ltr">On Tue 27 Mar, 2018, 12:00 PM Huber=
t Feyrer, &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; =
wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e=
x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto"><div></div=
><div><div>Hi,</div><ul class=3D"m_6415615749405175474lst-kix_lqm4x2n07pcs-=
0" style=3D"list-style-type:none;padding:0px;margin:0px"><li style=3D"paddi=
ng:12pt 0px 18pt 0pt;line-height:1.4181818181818182;margin:0px 0px 0px 36pt=
"><span style=3D"vertical-align:baseline;background-color:rgba(255,255,255,=
0)">Is the project a port of software, or a rewrite? (remember: No GPL in t=
he NetBSD kernel!)</span></li></ul><ul class=3D"m_6415615749405175474lst-ki=
x_lqm4x2n07pcs-1 m_6415615749405175474start" style=3D"list-style-type:none;=
padding:0px;margin:0px"><li style=3D"padding:12pt 0px 18pt 0pt;line-height:=
1.4181818181818182;margin:0px 0px 0px 72pt"><span style=3D"vertical-align:b=
aseline;background-color:rgba(255,255,255,0)">No. But it will use already e=
xisting algorithms and implementation of those algorithms.</span></li></ul>=
</div><div><span style=3D"background-color:rgba(255,255,255,0)">what existi=
ng implementation do you intend to use?</span></div><div><span style=3D"bac=
kground-color:rgba(255,255,255,0)"><br></span></div><div><br></div><div> -H=
ubert=C2=A0</div><div><br></div><div><br></div><div><br></div><div><br>Am 2=
6.03.2018 um 20:36 schrieb Harsh Khatore &lt;<a href=3D"mailto:khatore.hars=
[email protected]" target=3D"_blank" rel=3D"noreferrer">khatore.harsh.gith=
[email protected]</a>&gt;:<br><br></div><blockquote type=3D"cite"><div><div dir=
=3D"ltr">Hi Alistair,<br><br>Please go through the proposal for GSoC projec=
t. Here is the link:=C2=A0<a href=3D"https://docs.google.com/document/d/1Qa=
yByVOYj2FINohvL4Mr-_Xq9Cb0TnwrrscfXgjPnDo/edit" target=3D"_blank" rel=3D"no=
referrer">GSoC proposal</a><br><br>Please provide your valuable comments, a=
s to how can I be selected as I really want to be a part of this experience=
.<br><br>Formatting is not quite good. Please suggest on formatting also, a=
s nothing was mentioned in the guidelines.<div><br></div><div>Thanks,<br>Ha=
rsh Khatore</div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_q=
uote">On Wed, Mar 21, 2018 at 11:45 AM, Alistair Crooks <span dir=3D"ltr">&=
lt;<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">a=
[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div =
dir=3D"ltr"><div class=3D"gmail_extra">When you read the answers below, I c=
an understand if you think I&#39;m being difficult.</div><div class=3D"gmai=
l_extra"><br></div><div class=3D"gmail_extra">But this is how we can work o=
ut whether you&#39;ve understood the task, and have thought about how you&#=
39;d go about it.</div><div class=3D"gmail_extra"><br><div class=3D"gmail_q=
uote"><span>On 20 March 2018 at 18:03, Harsh Khatore <span dir=3D"ltr">&lt;=
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"=
noreferrer">[email protected]</a>&gt;</span> wrote:<br><blockq=
uote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr"><span>

<span class=3D"m_6415615749405175474m_-7292100075572547699m_-45431464367640=
44190gmail-im" style=3D"color:rgb(80,0,80);font-family:arial,sans-serif;fon=
t-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-=
caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-=
color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:=
initial"><div><div class=3D"gmail_quote"><div dir=3D"ltr">On Tue 20 Mar, 20=
18, 9:34 AM Alistair Crooks, &lt;<a href=3D"mailto:[email protected]" rel=3D"n=
oreferrer noreferrer" style=3D"color:rgb(17,85,204);text-decoration:none" t=
arget=3D"_blank">[email protected]</a>&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex"><div dir=3D"ltr">Yeah, netpgpverify is the=
 new, all-in-one, no pre-reqs codebase solely for the verification part of =
signatures.<div><br></div><div>ed25519 also needs to be added to netpgp, wh=
ich is the older and more crufty code base which covers signing and verific=
ation.</div></div></blockquote></div></div><div dir=3D"auto"><br></div><div=
 dir=3D"auto"></div></span><div dir=3D"auto" style=3D"color:rgb(34,34,34);f=
ont-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant=
-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style=
:initial;text-decoration-color:initial"><span style=3D"font-family:sans-ser=
if">So, as netpgpverify is the new code base for verification part, netpgp =
will be used for only the signing part or for both as it used to do?</span>=
</div></span></div></blockquote><div><br></div></span><div>See the project =
specification - both are needed.</div><span><div>=C2=A0</div><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p=
adding-left:1ex"><div dir=3D"ltr"><span><div dir=3D"auto" style=3D"color:rg=
b(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal=
;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-dec=
oration-style:initial;text-decoration-color:initial"><br></div><span class=
=3D"m_6415615749405175474m_-7292100075572547699m_-4543146436764044190gmail-=
im" style=3D"color:rgb(80,0,80);font-family:arial,sans-serif;font-size:12.8=
px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal=
;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(2=
55,255,255);text-decoration-style:initial;text-decoration-color:initial"><d=
iv dir=3D"auto"></div><div dir=3D"auto"><div class=3D"gmail_quote"><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px=
 solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div><br></div><=
div>But before any code is touched, we&#39;d need to know what gpg constant=
s uses for these algorithms, since they&#39;re not in RFC 4880, and so we c=
an interoperate with gpg in verifying and signing.</div><div></div></div></=
blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></=
div></span><div dir=3D"auto" style=3D"color:rgb(34,34,34);font-family:arial=
,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:norma=
l;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align=
:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:=
0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-de=
coration-color:initial">We can get the ed25519 specifications from RFC8023 =
and see for the constants but I have a doubt as to what are these constants=
 that you referred?</div></span></div></blockquote><div><br></div></span><d=
iv>Look further.</div><div><br></div><div>Think of the job that netpgpverif=
y and netpgp do, and how they interoperate with other software.</div><span>=
<div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8=
ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><span><spa=
n class=3D"m_6415615749405175474m_-7292100075572547699m_-454314643676404419=
0gmail-im" style=3D"color:rgb(80,0,80);font-family:arial,sans-serif;font-si=
ze:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps=
:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;background-colo=
r:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:init=
ial"><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quot=
e"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bord=
er-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>=
<br></div><div>We need to know what extra parts are needed (from different =
sources, along with their licences), and any other prereqs we might need fo=
r both netpgpverify and netpgp.</div><div></div></div></blockquote></div></=
div><div dir=3D"auto"><br></div></span></span><div dir=3D"auto" style=3D"co=
lor:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:=
normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:4=
00;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:no=
ne;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);te=
xt-decoration-style:initial;text-decoration-color:initial">I am not able to=
 get what do you mean by extra parts and prereqs, can you explain, please?<=
/div></div></blockquote><div><br></div></span><div><span style=3D"color:rgb=
(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;f=
ont-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decor=
ation-style:initial;text-decoration-color:initial;float:none;display:inline=
">Think of other things that will be necessary to accomplish the task.</spa=
n>=C2=A0</div><div><br></div><div>In summary, I&#39;d like to see what you =
think will be necessary. I&#39;d like to see the thoughts that go into how =
to accomplish a design and programming task, what tests are necessary, and =
what to be wary of in the implementation. Not in email, but in the proposal=
 that you write - how you will accomplish (and surpass) the goals.</div><di=
v>=C2=A0</div><div>You (and anyone else) should now have enough information=
 -- from the project specification, and from previous email --=C2=A0 to gen=
erate a proposal for the project.<div><br></div><div>Regards,</div><div><sp=
an style=3D"color:rgb(34,34,34);font-family:arial,sans-serif;font-size:smal=
l;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;=
font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(25=
5,255,255);text-decoration-style:initial;text-decoration-color:initial;floa=
t:none;display:inline">Alistair</span></div><div><br></div><div>PS. One cop=
y of email is enough, thanks :)<br style=3D"color:rgb(34,34,34);font-family=
:arial,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:=
normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spa=
cing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;te=
xt-decoration-color:initial"><br class=3D"m_6415615749405175474m_-729210007=
5572547699gmail-Apple-interchange-newline"></div>=C2=A0</div><span><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc s=
olid;padding-left:1ex"><br><div class=3D"gmail_quote"><span><div dir=3D"ltr=
">On Tue, Mar 20, 2018 at 12:13 AM Alistair Crooks &lt;<a href=3D"mailto:ag=
[email protected]" target=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; w=
rote:<br></div></span><div><div class=3D"m_6415615749405175474m_-7292100075=
572547699h5"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;b=
order-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Hi Harsh,<div>=
<br></div><div>I&#39;ve been talking to others about it, but yours is the f=
irst mail I&#39;ve received.</div><div><br></div><div>C proficiency is nece=
ssary. C++ not needed.</div><div><br></div><div>I can help you out with any=
 specific questions you have - please mail them here (i.e. to tech-crypto, =
CC me).</div><div><br></div><div>Thanks,</div><div>Alistair</div></div><div=
 class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 18 March 2018 at 1=
0:57, Harsh Khatore <span dir=3D"ltr">&lt;<a href=3D"mailto:khatore.harsh.g=
[email protected]" target=3D"_blank" rel=3D"noreferrer">khatore.harsh.github@=
gmail.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=
=3D"ltr">Hi Alistair,<br><br>Sorry for contacting you soo late for the abov=
e-mentioned project. Could you provide me with help regarding the project s=
o that I can work on it for GSoC? Also, do you have anyone else preparing f=
or it or can I continue with this?<div><br>My knowledge of=C2=A0C and C++ l=
anguages is intermediate.<br><br>Thanks,<br>Harsh Khatore<br><br><br></div>=
</div>
</blockquote></div><br></div>
</blockquote></div></div></div>
</blockquote></span></div><br></div></div>
</blockquote></div><br></div>
</div></blockquote></div></blockquote></div>

--001a114e4f9e145a2705685f3cdc--