
From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Nov  7 15:16:06 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC57F21F8B1C for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 15:16:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y4QPNMhAphjW for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 15:16:06 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 47AE521F8B1A for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon,  7 Nov 2011 15:16:03 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id C44DB14A41E; Mon,  7 Nov 2011 23:16:00 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8DA0F14A41D for <ietf-ssh@NetBSD.org>; Mon,  7 Nov 2011 23:15:59 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id dxDIlS0JKrq5 for <ietf-ssh@NetBSD.org>; Mon,  7 Nov 2011 23:15:59 +0000 (UTC)
Received: from exprod7og123.obsmtp.com (exprod7og123.obsmtp.com [64.18.2.24]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id A93ED14A241 for <ietf-ssh@NetBSD.org>; Mon,  7 Nov 2011 23:15:58 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob123.postini.com ([64.18.6.12]) with SMTP; Mon, 07 Nov 2011 15:15:58 PST
Received: from magenta.juniper.net (172.17.27.123) by P-EMHUB01-HQ.jnpr.net (172.24.192.33) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 7 Nov 2011 15:02:37 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id pA7N2Zh92222;	Mon, 7 Nov 2011 15:02:35 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id C87BD1141B;	Mon,  7 Nov 2011 15:02:35 -0800 (PST)
To: <ietf-ssh@NetBSD.org>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?
X-Phone: +1 408 745-2952 (Work)
X-Mailer: MH-E 8.2; nmh 1.2; GNU Emacs 22.1.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Mon, 7 Nov 2011 15:02:35 -0800
Message-ID: <92480.1320706955@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Is anyone going to present the draft-dbider-sha2-mac-for-ssh-02 (-03?)
to the IETF 82 in Taipei Taiwa Nov 13-18 as a standards or informational
track RFC?

Given multiple implementations (e.g., OpenSSH 5.9, TTSH 2.58,
WinSSHD) supporting SSH2 MAC algorithms: hmac-sha2-256,
hmac-sha2-256-96, hmac-sha2-512, hmac-sha2-512-96 exist, it would seem
at least an informational RFC is desirable.

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Nov  7 21:00:30 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 236AE11E80F4 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 21:00:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TRlhw7uZIsHs for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 21:00:29 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 71DC311E80EC for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon,  7 Nov 2011 21:00:29 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 4EFF014A433; Tue,  8 Nov 2011 05:00:21 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 8BDEF14A42F for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:00:19 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id eGulsycfueVd for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:00:19 +0000 (UTC)
Received: from skroderider.denisbider.com (skroderider.denisbider.com [50.18.172.175]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 0B31D14A22F for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:00:18 +0000 (UTC)
X-Footer: ZGVuaXNiaWRlci5jb20=
Received: from localhost ([127.0.0.1]) by skroderider.denisbider.com (using TLSv1/SSLv3 with cipher AES128-SHA (128 bits)); Tue, 8 Nov 2011 04:00:13 +0000
Message-ID: <03EA6F2494C84B9FAC9B6EFD122B63C1@element>
From: "denis bider \(Bitvise\)" <ietf-ssh2@denisbider.com>
To: <ietf-ssh@NetBSD.org>, "Mark D. Baushke" <mdb@juniper.net>
References: <92480.1320706955@eng-mail01.juniper.net>
In-Reply-To: <92480.1320706955@eng-mail01.juniper.net>
Subject: Re: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?
Date: Mon, 7 Nov 2011 21:59:04 -0600
MIME-Version: 1.0
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Windows Mail 6.0.6002.18197
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6002.18463
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Thank you for bringing this up.

It would be nice if someone did pick it up, to make it final.


----- Original Message ----- 
From: "Mark D. Baushke" <mdb@juniper.net>
To: <ietf-ssh@NetBSD.org>
Sent: Monday, November 07, 2011 17:02
Subject: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?


Is anyone going to present the draft-dbider-sha2-mac-for-ssh-02 (-03?)
to the IETF 82 in Taipei Taiwa Nov 13-18 as a standards or informational
track RFC?

Given multiple implementations (e.g., OpenSSH 5.9, TTSH 2.58,
WinSSHD) supporting SSH2 MAC algorithms: hmac-sha2-256,
hmac-sha2-256-96, hmac-sha2-512, hmac-sha2-512-96 exist, it would seem
at least an informational RFC is desirable.

-- Mark



From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Nov  7 21:19:32 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDAE911E80EC for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 21:19:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.599
X-Spam-Level: 
X-Spam-Status: No, score=-7.599 tagged_above=-999 required=5 tests=[AWL=1.000, BAYES_00=-2.599, GB_I_LETTER=-2, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bVVuJRkJLP5E for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon,  7 Nov 2011 21:19:32 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 3B00821F87C9 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon,  7 Nov 2011 21:19:32 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id C27F814A0D4; Tue,  8 Nov 2011 05:19:30 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 73CD014A0AA for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:19:27 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id ORzkDPOmQROV for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:19:26 +0000 (UTC)
Received: from exprod7og112.obsmtp.com (exprod7og112.obsmtp.com [64.18.2.177]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id BB13B14A3F8 for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 05:19:25 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob112.postini.com ([64.18.6.12]) with SMTP; Mon, 07 Nov 2011 21:19:25 PST
Received: from magenta.juniper.net (172.17.27.123) by P-EMHUB01-HQ.jnpr.net (172.24.192.33) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 7 Nov 2011 20:43:39 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id pA84hdh46999;	Mon, 7 Nov 2011 20:43:39 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 59ED41149C;	Mon,  7 Nov 2011 20:43:39 -0800 (PST)
To: "denis bider (Bitvise)" <ietf-ssh2@denisbider.com>
CC: <ietf-ssh@NetBSD.org>
Subject: Re: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ? 
In-Reply-To: <03EA6F2494C84B9FAC9B6EFD122B63C1@element> 
References: <92480.1320706955@eng-mail01.juniper.net> <03EA6F2494C84B9FAC9B6EFD122B63C1@element>
Comments: In-reply-to: "denis bider \(Bitvise\)" <ietf-ssh2@denisbider.com> message dated "Mon, 07 Nov 2011 21:59:04 -0600."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.2; nmh 1.2; GNU Emacs 22.1.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Mon, 7 Nov 2011 20:43:39 -0800
Message-ID: <1484.1320727419@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi Denis,

My understanding is that it is possible to do this all via e-mail rather
than f2f at the IETF 82 meeting...

Reading http://www.ietf.org/tao.html ...

seems to indicate that petitioning the Security Area Advisory Group
(SAAG) could be asked to look at the ietf-ssh mail archives and bring it
up for consideration/arguments on the IETF 82 agenda.

I think you need to re-issue your draft-dbider-sha2-mac-for-ssh-02 draft
as draft-dbider-sha2-mac-for-ssh-03 to have one which is not expired
send a notcie to both ietf-ssh@NetBSD.org and saag@ietf.org with a
subject like:

  draft-dbider-sha2-mac-for-ssh-03 submission for Draft Standard

A cover email letter pointing at multiple interoperable implementations
means that folks get to argue about the names or the spec a bit, but I
think it is ready to go as-is...

	-- Mark

 ------- original message -------
From: "denis bider \(Bitvise\)" <ietf-ssh2@denisbider.com>
To: <ietf-ssh@NetBSD.org>, "Mark D. Baushke" <mdb@juniper.net>
Subject: Re: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?
Date: Mon, 7 Nov 2011 21:59:04 -0600
X-Mailer: Microsoft Windows Mail 6.0.6002.18197
X-SBScore: 0 (Spam Threshold: 20) (Block Threshold: 5)

Thank you for bringing this up.

It would be nice if someone did pick it up, to make it final.


----- Original Message ----- 
From: "Mark D. Baushke" <mdb@juniper.net>
To: <ietf-ssh@NetBSD.org>
Sent: Monday, November 07, 2011 17:02
Subject: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?


Is anyone going to present the draft-dbider-sha2-mac-for-ssh-02 (-03?)
to the IETF 82 in Taipei Taiwa Nov 13-18 as a standards or informational
track RFC?

Given multiple implementations (e.g., OpenSSH 5.9, TTSH 2.58,
WinSSHD) supporting SSH2 MAC algorithms: hmac-sha2-256,
hmac-sha2-256-96, hmac-sha2-512, hmac-sha2-512-96 exist, it would seem
at least an informational RFC is desirable.

-- Mark


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue Nov  8 03:56:04 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D717821F8B29 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue,  8 Nov 2011 03:56:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.096
X-Spam-Level: 
X-Spam-Status: No, score=-3.096 tagged_above=-999 required=5 tests=[AWL=1.503, BAYES_00=-2.599, GB_I_LETTER=-2]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xBqko1K7eXI8 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue,  8 Nov 2011 03:56:04 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id E5ABD21F8B06 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue,  8 Nov 2011 03:56:03 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 98E2414A46B; Tue,  8 Nov 2011 11:55:56 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 3A91814A46A for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 11:55:52 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id vjSWSBi7R6ZZ for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 11:55:51 +0000 (UTC)
Received: from mail.btconnect.com (c2beaomr09.btconnect.com [213.123.26.187]) by mail.netbsd.org (Postfix) with ESMTP id EE8B014A442 for <ietf-ssh@NetBSD.org>; Tue,  8 Nov 2011 11:55:49 +0000 (UTC)
Received: from host86-177-208-97.range86-177.btcentralplus.com (HELO pc6) ([86.177.208.97]) by c2beaomr09.btconnect.com with SMTP id FBU19211; Tue, 08 Nov 2011 11:55:42 +0000 (GMT)
Message-ID: <01f601cc9e04$36a45960$4001a8c0@gateway.2wire.net>
From: "t.petch" <ietfc@btconnect.com>
To: "denis bider \(Bitvise\)" <ietf-ssh2@denisbider.com>, "Mark D. Baushke" <mdb@juniper.net>
Cc: <ietf-ssh@NetBSD.org>
References: <92480.1320706955@eng-mail01.juniper.net> <03EA6F2494C84B9FAC9B6EFD122B63C1@element> <1484.1320727419@eng-mail01.juniper.net>
Subject: Re: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ? 
Date: Tue, 8 Nov 2011 11:50:14 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Mirapoint-IP-Reputation: reputation=Fair-1, source=Queried, refid=tid=0001.0A0B0303.4EB918BE.004D, actions=tag
X-Junkmail-Premium-Raw: score=7/50, refid=2.7.2:2011.11.8.110015:17:7.586, ip=86.177.208.97, rules=__HAS_MSGID, __OUTLOOK_MSGID_1, __SANE_MSGID, __TO_MALFORMED_2, __BOUNCE_CHALLENGE_SUBJ, __BOUNCE_NDR_SUBJ_EXEMPT, __MIME_VERSION, __CT, CT_TP_8859_1, __CT_TEXT_PLAIN, __CTE, __HAS_X_PRIORITY, __HAS_MSMAIL_PRI, __HAS_X_MAILER, USER_AGENT_OE, __OUTLOOK_MUA_1, __USER_AGENT_MS_GENERIC, __ANY_URI, __CP_URI_IN_BODY, BODYTEXTP_SIZE_3000_LESS, BODY_SIZE_2000_2999, __MIME_TEXT_ONLY, RDNS_GENERIC_POOLED, BODY_SIZE_5000_LESS, RDNS_SUSP_GENERIC, __OUTLOOK_MUA, RDNS_SUSP, BODY_SIZE_7000_LESS
X-Junkmail-Status: score=10/50, host=c2beaomr09.btconnect.com
X-Junkmail-Signature-Raw: score=unknown, refid=str=0001.0A0B0206.4EB918C1.0128,ss=1,fgs=0, ip=0.0.0.0, so=2010-07-22 22:03:31, dmn=2009-09-10 00:05:08, mode=multiengine
X-Junkmail-IWF: false
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

----- Original Message -----
From: "Mark D. Baushke" <mdb@juniper.net>
To: "denis bider (Bitvise)" <ietf-ssh2@denisbider.com>
Cc: <ietf-ssh@NetBSD.org>
Sent: Tuesday, November 08, 2011 5:43 AM

> Hi Denis,

> My understanding is that it is possible to do this all via e-mail rather
> than f2f at the IETF 82 meeting...
>
> Reading http://www.ietf.org/tao.html ...
>
> seems to indicate that petitioning the Security Area Advisory Group
> (SAAG) could be asked to look at the ietf-ssh mail archives and bring it
> up for consideration/arguments on the IETF 82 agenda.
>
> I think you need to re-issue your draft-dbider-sha2-mac-for-ssh-02 draft
> as draft-dbider-sha2-mac-for-ssh-03 to have one which is not expired
> send a notcie to both ietf-ssh@NetBSD.org and saag@ietf.org with a
> subject like:
>
>   draft-dbider-sha2-mac-for-ssh-03 submission for Draft Standard

Errr ... no more:-(

RFC6410 abolished Draft Standard, we now have Proposed Standard and Internet
Standard.

You still need the active support of an AD to push things through (not that
RFC6410 mentions that;-).

Tom Petch

>
> A cover email letter pointing at multiple interoperable implementations
> means that folks get to argue about the names or the spec a bit, but I
> think it is ready to go as-is...
>
> -- Mark
>
>  ------- original message -------
> From: "denis bider \(Bitvise\)" <ietf-ssh2@denisbider.com>
> To: <ietf-ssh@NetBSD.org>, "Mark D. Baushke" <mdb@juniper.net>
> Subject: Re: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?
> Date: Mon, 7 Nov 2011 21:59:04 -0600
> X-Mailer: Microsoft Windows Mail 6.0.6002.18197
> X-SBScore: 0 (Spam Threshold: 20) (Block Threshold: 5)
>
> Thank you for bringing this up.
>
> It would be nice if someone did pick it up, to make it final.
>
>
> ----- Original Message -----
> From: "Mark D. Baushke" <mdb@juniper.net>
> To: <ietf-ssh@NetBSD.org>
> Sent: Monday, November 07, 2011 17:02
> Subject: draft-dbider-sha2-mac-for-ssh-02 for IETF 82 in Taipei ?
>
> Is anyone going to present the draft-dbider-sha2-mac-for-ssh-02 (-03?)
> to the IETF 82 in Taipei Taiwa Nov 13-18 as a standards or informational
> track RFC?
>
> Given multiple implementations (e.g., OpenSSH 5.9, TTSH 2.58,
> WinSSHD) supporting SSH2 MAC algorithms: hmac-sha2-256,
> hmac-sha2-256-96, hmac-sha2-512, hmac-sha2-512-96 exist, it would seem
> at least an informational RFC is desirable.
>
> -- Mark


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Nov 14 10:16:50 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6973111E8337 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 14 Nov 2011 10:16:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.099
X-Spam-Level: 
X-Spam-Status: No, score=-7.099 tagged_above=-999 required=5 tests=[AWL=-0.500, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0xnEl9WNebx8 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 14 Nov 2011 10:16:49 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 2DE7911E8338 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 14 Nov 2011 10:16:46 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id A7AC414A20E; Mon, 14 Nov 2011 18:16:32 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 4F22914A204 for <ietf-ssh@NetBSD.org>; Mon, 14 Nov 2011 18:16:30 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id fbAsPZGHH1T2 for <ietf-ssh@NetBSD.org>; Mon, 14 Nov 2011 18:16:29 +0000 (UTC)
Received: from exprod7og123.obsmtp.com (exprod7og123.obsmtp.com [64.18.2.24]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 7669E14A1A8 for <ietf-ssh@NetBSD.org>; Mon, 14 Nov 2011 18:16:29 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob123.postini.com ([64.18.6.12]) with SMTP ID DSNKTsFa/KF1iYqG480Oo3RIS5fiLYDppTba@postini.com; Mon, 14 Nov 2011 10:16:29 PST
Received: from magenta.juniper.net (172.17.27.123) by P-EMHUB01-HQ.jnpr.net (172.24.192.33) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 14 Nov 2011 10:09:38 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id pAEI9bh47757;	Mon, 14 Nov 2011 10:09:37 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 92FE71149F;	Mon, 14 Nov 2011 10:09:37 -0800 (PST)
To: <ietf-ssh@NetBSD.org>
Subject: draft-dbider-sha2-mac-for-ssh-03 available
In-Reply-To: <92480.1320706955@eng-mail01.juniper.net> 
References: <92480.1320706955@eng-mail01.juniper.net>
Comments: In-reply-to: "Mark D. Baushke" <mdb@juniper.net> message dated "Mon, 07 Nov 2011 15:02:35 -0800."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.2; nmh 1.2; GNU Emacs 22.1.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Mon, 14 Nov 2011 10:09:37 -0800
Message-ID: <95415.1321294177@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Be advised that I have augmented and reposted the expired
draft-dbider-sha2-mac-for-ssh Inetnet Draft.

text: http://www.ietf.org/id/draft-dbider-sha2-mac-for-ssh-03.txt
xml:  http://www.ietf.org/id/draft-dbider-sha2-mac-for-ssh-03.xml
html: http://tools.ietf.org/html/draft-dbider-sha2-mac-for-ssh-03
pdf:  http://tools.ietf.org/pdf/draft-dbider-sha2-mac-for-ssh-03.pdf

https://datatracker.ietf.org/doc/draft-dbider-sha2-mac-for-ssh/

I have added a few sections to get it ready to find a document shepherd
and go to the IESG.

Please let me know if there are any changes you believe should be made
to the document. 

[I have already learned that RFC 2434 has been obsoleted by RFC 5226 and
will fix that in the next draft. I will also be moving the RFC 2104 from
a Normative to an Informational reference.]

	Thank you,
	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon Nov 14 18:30:57 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 119A411E8360 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 14 Nov 2011 18:30:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.932
X-Spam-Level: 
X-Spam-Status: No, score=-6.932 tagged_above=-999 required=5 tests=[AWL=-0.333, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TbBzkGCh6fTy for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 14 Nov 2011 18:30:56 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 5864811E8105 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 14 Nov 2011 18:30:56 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id E338214A1CE; Tue, 15 Nov 2011 02:30:52 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id BFE1114A1CD for <ietf-ssh@NetBSD.org>; Tue, 15 Nov 2011 02:30:49 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id BMt_ekypLTb7 for <ietf-ssh@NetBSD.org>; Tue, 15 Nov 2011 02:30:49 +0000 (UTC)
Received: from exprod7og112.obsmtp.com (exprod7og112.obsmtp.com [64.18.2.177]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id DF90B14A1C9 for <ietf-ssh@NetBSD.org>; Tue, 15 Nov 2011 02:30:48 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob112.postini.com ([64.18.6.12]) with SMTP ID DSNKTsHO2OG2bdYLtTkx9ls90jGuoDn2U3SL@postini.com; Mon, 14 Nov 2011 18:30:48 PST
Received: from magenta.juniper.net (172.17.27.123) by P-EMHUB01-HQ.jnpr.net (172.24.192.33) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 14 Nov 2011 18:03:01 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id pAF230h67679;	Mon, 14 Nov 2011 18:03:00 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id 71D361141B;	Mon, 14 Nov 2011 18:03:00 -0800 (PST)
To: <ietf-ssh@NetBSD.org>
From: "Mark D. Baushke" <mdb@juniper.net>
Subject: fwd: New Version Notification for draft-dbider-sha2-mac-for-ssh-04.txt
X-Phone: +1 408 745-2952 (Work)
X-Mailer: MH-E 8.2; nmh 1.2; GNU Emacs 22.1.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Mon, 14 Nov 2011 18:03:00 -0800
Message-ID: <39914.1321322580@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi Folks,

I received some comments from Sean Turner and Jeff Hutzelman which have
been incorporated into this new version of the draft.

I know that this code has already been picked up in some open source
implementations of the SSH.

It should be understood that this is NOT the same as the
hmac-sha256@ssh.com (I recall that Tectia used a 16-byte HMAC key and
MindTerm used a 20-byte HMAC key and so they were not interoperable).

OpenSSH 5.9 has implemented this draft.

TeraTerm 4.71 has implemented this draft.

WinSSHD has a pre-release build of 5.24 from denis bider to implement
this draft.

PuTTY has a patch from Simon Tatham to implement this draft.

cryptlib has a patch from Peter Gutmann for this draft.

If possible, I would like for members of this list to reach consensus
here that hmac-sha2-256 is a a RECOMMENDED algorithm for SSH.

	Thank you,
	-- Mark

 ------- forwarded message -------
From: internet-drafts@ietf.org
To: mdb@juniper.net
Cc: ietf-ssh2@denisbider.com, mdb@juniper.net
Subject: New Version Notification for draft-dbider-sha2-mac-for-ssh-04.txt
Date: Mon, 14 Nov 2011 17:28:59 -0800

A new version of I-D, draft-dbider-sha2-mac-for-ssh-04.txt has been successfully submitted by Mark Baushke and posted to the IETF repository.

Filename:	 draft-dbider-sha2-mac-for-ssh
Revision:	 04
Title:		 SHA-2 Data Integrity Verification for the Secure Shell (SSH) Transport Layer Protocol
Creation date:	 2011-11-14
WG ID:		 Individual Submission
Number of pages: 5

Abstract:
   This memo defines algorithm names and parameters for use of some of
   the SHA-2 family of secure hash algorithms for data integrity
   verification in the Secure Shell (SSH) protocol.

   This document adds new Message Authentication Code (MAC) algorithms
   to the set defined in RFC 4253 [RFC4253].

                                                                                  


The IETF Secretariat

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue Nov 22 22:14:54 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7DEE1F0C57 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 22 Nov 2011 22:14:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.902
X-Spam-Level: 
X-Spam-Status: No, score=-4.902 tagged_above=-999 required=5 tests=[AWL=-2.197, BAYES_00=-2.599, FB_WORD2_END_DOLLAR=3.294, J_CHICKENPOX_63=0.6, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KaUcrd-PnVve for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 22 Nov 2011 22:14:54 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 62D471F0C52 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue, 22 Nov 2011 22:14:51 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id B2ED214A155; Wed, 23 Nov 2011 06:14:42 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 16BDD14A14F for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 06:14:39 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id IwO1FcDNg7Q0 for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 06:14:38 +0000 (UTC)
Received: from exprod7og110.obsmtp.com (exprod7og110.obsmtp.com [64.18.2.173]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.netbsd.org (Postfix) with ESMTPS id 1728E14A106 for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 06:14:37 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob110.postini.com ([64.18.6.12]) with SMTP ID DSNKTsyPTVWu5D5O/zVd8eJQRYUPQHyC09Bb@postini.com; Tue, 22 Nov 2011 22:14:38 PST
Received: from magenta.juniper.net (172.17.27.123) by P-EMHUB01-HQ.jnpr.net (172.24.192.33) with Microsoft SMTP Server (TLS) id 8.3.213.0; Tue, 22 Nov 2011 22:06:46 -0800
Received: from eng-mail01.juniper.net (eng-mail01.juniper.net [172.17.28.114]) by magenta.juniper.net (8.11.3/8.11.3) with ESMTP id pAN66jh66949;	Tue, 22 Nov 2011 22:06:45 -0800 (PST)	(envelope-from mdb@juniper.net)
Received: from eng-mail01.juniper.net (localhost [127.0.0.1])	by eng-mail01.juniper.net (Postfix) with ESMTP id CE3EA1149B;	Tue, 22 Nov 2011 22:06:45 -0800 (PST)
To: "openssh-unix-dev@mindrot.org" <openssh-unix-dev@mindrot.org>
CC: <saag@ietf.org>, <ietf-ssh@NetBSD.org>, <ondrej.sury@nic.cz>
Subject: Re: ssh-keygen -r should support SSHFP records for ECDSA (or at least return non-zero error code on failure) 
In-Reply-To: <4ECA6E4D.3030101@fifthhorseman.net> 
References: <4ECA6E4D.3030101@fifthhorseman.net>
Comments: In-reply-to: Daniel Kahn Gillmor <dkg@fifthhorseman.net> message dated "Mon, 21 Nov 2011 10:29:17 -0500."
From: "Mark D. Baushke" <mdb@juniper.net>
X-Phone: +1 408 745-2952 (Office)
X-Mailer: MH-E 8.2; nmh 1.2; GNU Emacs 22.1.1
X-Face: #8D_6URD2G%vC.hzU<dI&#Y9szHj$'mGtUq&d=rXy^L$-=G_-LmZ^5!Fszk:yXZp$k\nTF? 8Up0!v/%1Q[(d?ES0mQW8dRCXi18gK)luJu)loHk,}4{Vi`yX?p?crF5o:LL{6#eiO:(E:YMxLXULB k|'a*EjN.B&L+[J!PhJ*aX0n:5/
Date: Tue, 22 Nov 2011 22:06:45 -0800
Message-ID: <98237.1322028405@eng-mail01.juniper.net>
MIME-Version: 1.0
Content-Type: text/plain
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Hi Daniel,

Daniel Kahn Gillmor <dkg@fifthhorseman.net> writes:

> hi folks:
> 
> it looks like ssh-keygen -r can't export SSHFP records for ECDSA keys:
> 
> 0 dkg@pip:/tmp/cdtemp.oiRYAS$ ssh-keygen -f foobar -t ecdsa -q -P ''
> 0 dkg@pip:/tmp/cdtemp.oiRYAS$ ssh-keygen -r foobar -f foobar.pub
> export_dns_rr: unsupported algorithm
> 0 dkg@pip:/tmp/cdtemp.oiRYAS$
> 
> the first number in my prompt is the return code of the last command;
> note that ssh-keygen -r fails to produce an SSHFP DNS RR, but it returns 0.
> 
> at the least, it should return non-zero on failure.
> 
> 
> I note that the relevant RFC doesn't include an enumeration for ECDSA:
> 
>  https://tools.ietf.org/html/rfc4255#section-3.1.1
> 
> Could anyone on this list kick off the IETF process for allocating a new
> ID in that registry for ECDSA?  I'm not currently involved in the IETF's
> Network Working Group so i don't really know the political landscape there.

I believe that the SSH development community will need to support this
effort:

  http://tools.ietf.org/html/draft-os-ietf-sshfp-ecdsa-sha2-00

which specifies values for both the ECDSA algorithm and a SHA-256
fingerprint algorithm.

RFC 4255 enumerates the RSA and DSS algorithms and the SHA-1 fingerprint
type.

draft-os-ietf-sshfp-ecdsa-sha2-00 authored by O. Sury has a typo in the
draft suggesting that they update RFC 4225 which is wrong, but it seems
to be a simple typo as the body of the draft referecnes RFC 4255.

However, it does add ECDSA to the SSHFP RR types and SHA-256 to the
fingerprint types.

The draft expires on Dec 18, 2011.

This draft was sent to saag@ietf.org and the author also wrote a patch
for OpenSSH (portable) in

https://git.nic.cz/redmine/projects/ietf/repository/revisions/master/entry/ssh-sshfp-ecdsa.patch

See the message thread here:

  http://www.ietf.org/mail-archive/web/saag/current/msg03326.html
  http://www.ietf.org/mail-archive/web/saag/current/msg03327.html

Stephen Farrell <stephen.farrell@cs.tcd.ie> says that the author is
asking the AD to sponsor the work. And Warren Kumari <warren@kumari.net>
has added his support.

This seems like something that should be raised on the
ietf-ssh@NetBSD.org list with a CC to saag@ietf.org, so
I have added these to lists to my response to this message.

For the record, my vote is +1 for this draft.

	-- Mark

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed Nov 23 00:25:30 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3840821F8B2F for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 23 Nov 2011 00:25:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -98.705
X-Spam-Level: 
X-Spam-Status: No, score=-98.705 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FB_WORD2_END_DOLLAR=3.294, J_CHICKENPOX_63=0.6, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NeE8LE-RwYAd for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 23 Nov 2011 00:25:30 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id C59B821F8B29 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 23 Nov 2011 00:25:29 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 0ACD214A259; Wed, 23 Nov 2011 08:25:25 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 7614214A256 for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 08:25:20 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Authentication-Results: mail.NetBSD.org (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id mgd45OBg6LAt for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 08:25:19 +0000 (UTC)
Received: from scss.tcd.ie (hermes.cs.tcd.ie [IPv6:2001:770:10:200:889f:cdff:fe8d:ccd2]) by mail.netbsd.org (Postfix) with ESMTP id 0C95414A242 for <ietf-ssh@NetBSD.org>; Wed, 23 Nov 2011 08:25:15 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by hermes.scss.tcd.ie (Postfix) with ESMTP id 9CBCE15F54B; Wed, 23 Nov 2011 08:25:13 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; h= content-transfer-encoding:content-type:in-reply-to:references :subject:mime-version:user-agent:from:date:message-id:received :received:x-virus-scanned; s=cs; t=1322036713; bh=HtXUf6ENtVMY7n sMmUk7rw9OIZW5aM89ycpV2i6VWx4=; b=PYRZcCQ0zHWX2BddOnOIdVgaS/7QP+ AGBXFOEY1FooCCeuE7l5DLZWH6G0QeeA+EskZPOjN/i/a6bPA/Ue/rwWL55vuxbT dXgpTekVGKpXw8unup2Hf5g7B0O0SrQTE0u8klPKulN89GMf3E4MiOgKzToGfL/f pQhiPHwH4gezR7+fm96K6yH7MjGMvEOu2EZ6CvClA/MszKOl4/nzJFQyCcpCbDwR Z5YyxHLo4cU91uWubvk7M9P9Yb89HzDXTs2sfebfEE9VTIjIL6JHArDxtaUxVzyb g9QkpbjYvy3tWclacRfy/vys9j5aLLcGo+cYQ9IZwHvIkP13yzEaouwQ==
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from scss.tcd.ie ([127.0.0.1]) by localhost (scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10027) with ESMTP id YB5jt7-JKLzj; Wed, 23 Nov 2011 08:25:13 +0000 (GMT)
Received: from [10.87.48.4] (unknown [86.46.25.99]) by smtp.scss.tcd.ie (Postfix) with ESMTPSA id 807B815F5FB; Wed, 23 Nov 2011 08:25:09 +0000 (GMT)
Message-ID: <4ECCADE5.30708@cs.tcd.ie>
Date: Wed, 23 Nov 2011 08:25:09 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:8.0) Gecko/20111105 Thunderbird/8.0
MIME-Version: 1.0
To: "Mark D. Baushke" <mdb@juniper.net>
CC: "openssh-unix-dev@mindrot.org" <openssh-unix-dev@mindrot.org>,  ietf-ssh@NetBSD.org, saag@ietf.org, =?UTF-8?B?T25kxZllaiBTdXLDvQ==?= <ondrej.sury@nic.cz>
Subject: Re: [saag] ssh-keygen -r should support SSHFP records for ECDSA (or at least return non-zero error code on failure)
References: <4ECA6E4D.3030101@fifthhorseman.net> <98237.1322028405@eng-mail01.juniper.net>
In-Reply-To: <98237.1322028405@eng-mail01.juniper.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Thanks Mark,

Yes, I'm happy to AD sponsor. No one objected when I asked
before and it seems quite reasonable.

Ondřej - I'll start an IETF LC since there only seem to be
typos to be fixed.

Cheers,
S.

On 11/23/2011 06:06 AM, Mark D. Baushke wrote:
> Hi Daniel,
>
> Daniel Kahn Gillmor<dkg@fifthhorseman.net>  writes:
>
>> hi folks:
>>
>> it looks like ssh-keygen -r can't export SSHFP records for ECDSA keys:
>>
>> 0 dkg@pip:/tmp/cdtemp.oiRYAS$ ssh-keygen -f foobar -t ecdsa -q -P ''
>> 0 dkg@pip:/tmp/cdtemp.oiRYAS$ ssh-keygen -r foobar -f foobar.pub
>> export_dns_rr: unsupported algorithm
>> 0 dkg@pip:/tmp/cdtemp.oiRYAS$
>>
>> the first number in my prompt is the return code of the last command;
>> note that ssh-keygen -r fails to produce an SSHFP DNS RR, but it returns 0.
>>
>> at the least, it should return non-zero on failure.
>>
>>
>> I note that the relevant RFC doesn't include an enumeration for ECDSA:
>>
>>   https://tools.ietf.org/html/rfc4255#section-3.1.1
>>
>> Could anyone on this list kick off the IETF process for allocating a new
>> ID in that registry for ECDSA?  I'm not currently involved in the IETF's
>> Network Working Group so i don't really know the political landscape there.
>
> I believe that the SSH development community will need to support this
> effort:
>
>    http://tools.ietf.org/html/draft-os-ietf-sshfp-ecdsa-sha2-00
>
> which specifies values for both the ECDSA algorithm and a SHA-256
> fingerprint algorithm.
>
> RFC 4255 enumerates the RSA and DSS algorithms and the SHA-1 fingerprint
> type.
>
> draft-os-ietf-sshfp-ecdsa-sha2-00 authored by O. Sury has a typo in the
> draft suggesting that they update RFC 4225 which is wrong, but it seems
> to be a simple typo as the body of the draft referecnes RFC 4255.
>
> However, it does add ECDSA to the SSHFP RR types and SHA-256 to the
> fingerprint types.
>
> The draft expires on Dec 18, 2011.
>
> This draft was sent to saag@ietf.org and the author also wrote a patch
> for OpenSSH (portable) in
>
> https://git.nic.cz/redmine/projects/ietf/repository/revisions/master/entry/ssh-sshfp-ecdsa.patch
>
> See the message thread here:
>
>    http://www.ietf.org/mail-archive/web/saag/current/msg03326.html
>    http://www.ietf.org/mail-archive/web/saag/current/msg03327.html
>
> Stephen Farrell<stephen.farrell@cs.tcd.ie>  says that the author is
> asking the AD to sponsor the work. And Warren Kumari<warren@kumari.net>
> has added his support.
>
> This seems like something that should be raised on the
> ietf-ssh@NetBSD.org list with a CC to saag@ietf.org, so
> I have added these to lists to my response to this message.
>
> For the record, my vote is +1 for this draft.
>
> 	-- Mark
> _______________________________________________
> saag mailing list
> saag@ietf.org
> https://www.ietf.org/mailman/listinfo/saag
>

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Sun Nov 27 00:27:25 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CB9D821F8AC3 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 27 Nov 2011 00:27:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3
X-Spam-Level: ***
X-Spam-Status: No, score=3 tagged_above=-999 required=5 tests=[BAYES_95=3]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JBTlmejCJxJr for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Sun, 27 Nov 2011 00:27:25 -0800 (PST)
Received: from mail.netbsd.org (ns.NetBSD.org [IPv6:2001:4f8:3:7::53]) by ietfa.amsl.com (Postfix) with ESMTP id 73F7C21F8ACE for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Sun, 27 Nov 2011 00:27:25 -0800 (PST)
Received: by mail.netbsd.org (Postfix, from userid 605) id 359C514A39F; Sun, 27 Nov 2011 08:27:21 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 203A414A39E for <ietf-ssh@netbsd.org>; Sun, 27 Nov 2011 08:27:20 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id F7NdmhIXGzj2 for <ietf-ssh@netbsd.org>; Sun, 27 Nov 2011 08:27:19 +0000 (UTC)
Received: from mail07.svc.cra.dublin.eircom.net (mail07.svc.cra.dublin.eircom.net [159.134.118.23]) by mail.netbsd.org (Postfix) with SMTP id 5CA6314A39D for <ietf-ssh@netbsd.org>; Sun, 27 Nov 2011 08:27:18 +0000 (UTC)
Received: (qmail 22481 messnum 10024170 invoked from network[213.94.190.12/avas01.vendorsvc.cra.dublin.eircom.net]); 27 Nov 2011 08:27:16 -0000
Received: from avas01.vendorsvc.cra.dublin.eircom.net (213.94.190.12) by mail07.svc.cra.dublin.eircom.net (qp 22481) with SMTP; 27 Nov 2011 08:27:16 -0000
Received: from 81-179-25-66.dsl.pipex.com ([86.44.138.149]) by avas01.vendorsvc.cra.dublin.eircom.net with Cloudmark Gateway id 28T41i00f3Db5hi018T8v5; Sun, 27 Nov 2011 08:27:16 +0000
From: "Elena" <elenakir@nextmail.ru>
To: <assocsg@aon.at>
Subject: Brief
Date: Sun, 27 Nov 2011 12:27:06 +0400
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list
Message-Id: <20111127082721.359C514A39F@mail.netbsd.org>

Hi,
I saw your e-mail  and decide to send you this message from our city library.
My name is Elena and living in Russia. I have little daughter but no husband.
Due to crisis recently I losted job and can not pay the heating bills for our home anymore.
We urgent need heating because winter and the temperature in our home is very cold.
We have wood savings and it can give us heating for no cost, but we need a woodburner.
We unable buy it because it cost too much for us.
If you have any old portable woodburner that do not use, I pray you can gift to us and transport of it to our address.
I wait to your response.
Elena.
