[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] DNSSEC considering adopting GOST R 34.10-2001 and GOST R 34.11-94



At 6:00 AM -0700 4/27/09, David McGrew wrote:
>some other important questions: how widely reviewed is that algorithm? 

I believe that Ólafur would like CFRG to determine the answer to that question. The expertise for "how widely reviewed" is in this group, not in DNSEXT.

>What are the claimed security levels?  

And herein lies a problem. The GOST specs are in Russian. I do not believe that there are any official English translations, and that the unofficial ones are expensive. (I would love to be wrong about either of those statements.) I have Cc' the author of the relevant draft on this message so he can help.

>Where is guidance on how to use the algorithm?

In the draft itself: <http://www.ietf.org/internet-drafts/draft-dolmatov-dnsext-dnssec-gost-00.txt>


>I cannot find any references to it in the peer-reviewed literature.   
>Perhaps I am not using the right keyword or something.

Here are a few:

<http://www.iacr.org/conferences/asiacrypt2005/rump/Dunkelman_AC05_Rump.pdf>

<https://online.tu-graz.ac.at/tug_online/voe_main2.getVollText?pDocumentNr=80200&pCurrPk=36649>

<https://online.tu-graz.ac.at/tug_online/voe_main2.getvolltext?pDocumentNr=81262>

>If anyone on the CFRG list has reviewed the algorithm, it would be great if we could hear from them.

Yes, please!

--Paul Hoffman, Director
--VPN Consortium