Re: [saag] Using ED25519 in SSHFP Resource Records - draft-moonesamy-sshfp-ed25519-01

Shumon Huque <shuque@gmail.com> Fri, 28 March 2014 19:16 UTC

Return-Path: <shuque@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF6B81A0967 for <saag@ietfa.amsl.com>; Fri, 28 Mar 2014 12:16:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uh0XSt9xBzj9 for <saag@ietfa.amsl.com>; Fri, 28 Mar 2014 12:16:25 -0700 (PDT)
Received: from mail-pb0-x22b.google.com (mail-pb0-x22b.google.com [IPv6:2607:f8b0:400e:c01::22b]) by ietfa.amsl.com (Postfix) with ESMTP id DC8D01A06EE for <saag@ietf.org>; Fri, 28 Mar 2014 12:16:24 -0700 (PDT)
Received: by mail-pb0-f43.google.com with SMTP id um1so5425924pbc.30 for <saag@ietf.org>; Fri, 28 Mar 2014 12:16:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=numxQFinPx8eUxpF6v0MOiRQfd7/Hm1OgyNZbLI0CIU=; b=nIBMxgTabkEazuGp3aOHWQoGWMx2hjLAaR6Wmpuq+/pZMwGqhsnf/yh6UZMhpKEfzg mz8dDs4cutaQicvsIsFp+sMDI6d9hKWBmkSvt0RsszPPjza0KO4kIFP7Cu/uCFIYQK58 xfveyobgnpji1HOvUWtGDDywqSJTHKq3/fBftlzk4l5tTJAzpiqgVBFwjRxnGGzpJPBP GjkvdXG3j6BrNZg6iFkkMo5RLVFxD6ggrGRbZuMTyf5eDCOXh4xSHe1cVV/8erEQuI+C YDX7VE7s6m53ou32Bj6XAxqeBnPJ0iWpYR9JI7ZYzXH3HsJt4jhir7mKhSGPk21yAZs8 lCbw==
MIME-Version: 1.0
X-Received: by 10.66.240.130 with SMTP id wa2mr10485225pac.73.1396034182710; Fri, 28 Mar 2014 12:16:22 -0700 (PDT)
Received: by 10.68.196.138 with HTTP; Fri, 28 Mar 2014 12:16:22 -0700 (PDT)
In-Reply-To: <alpine.LSU.2.00.1403281857280.31260@hermes-1.csi.cam.ac.uk>
References: <6.2.5.6.2.20140204112023.0aec4c90@elandsys.com> <23AC0B40-66B5-468C-B96D-17B52F1F42A4@checkpoint.com> <530A45F8.1010202@cs.tcd.ie> <530AB805.1060308@redhat.com> <6.2.5.6.2.20140327104428.0d056f58@resistor.net> <alpine.LSU.2.00.1403281857280.31260@hermes-1.csi.cam.ac.uk>
Date: Fri, 28 Mar 2014 15:16:22 -0400
Message-ID: <CAHPuVdVKtZE-x18D-owzVZ+Y+bu5=-8_+KS-1LyK7ykgnrgfyg@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
To: Tony Finch <dot@dotat.at>
Content-Type: multipart/alternative; boundary="047d7b15a4b78e0dcc04f5af897b"
Archived-At: http://mailarchive.ietf.org/arch/msg/saag/gSogKfq4ySFDv50yN_VQQ0qCEns
Cc: S Moonesamy <sm+ietf@elandsys.com>, saag@ietf.org
Subject: Re: [saag] Using ED25519 in SSHFP Resource Records - draft-moonesamy-sshfp-ed25519-01
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: shuque@gmail.com
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Mar 2014 19:16:27 -0000

On Fri, Mar 28, 2014 at 3:06 PM, Tony Finch <dot@dotat.at> wrote:

>
> On a tangent...
>
> Do you know what the situation is wrt standardized ssh certificate
> authentication? A colleague of mine found an awkward interop bug in
> OpenSSH which allows a server offering certificate authentication to
> make the client skip SSHFP authentication.
>
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742513
>
> Tony.
>

Well, there's RFC 6187 (Standards Track):

      http://tools.ietf.org/html/rfc6187

Does OpenSSH implement this? Or more generally, which implementations
support this?

--Shumon.