Re: [TLS] preliminary AD review of draft-ietf-tls-oldversions-deprecate-05

2020-05-12 Thread Stephen Farrell
Hi, It's now four and a bit months later. It's true those have been very distracting months for us all but when are we hoping to progress this draft? Thanks, S. On 06/01/2020 15:16, Stephen Farrell wrote: > > Hi all, > > I've just submitted -06 that (I think/hope:-) addresses > the issues in

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Torsten Schütze
Hi Hugo, hi Quynh,   on Monday, 2020-05-11 Hugo Krawzcyk wrote:    > I haven't looked at the revisions. But in previous versions you needed lawyer  > skills to go through the language to see that RFC 5869 was indeed compliant > with the NIST recommendation. It would be nice if this time it would m

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Dang, Quynh H. (Fed)
Hi Torsten, Thank you for the review. I think the review helps many people to understand the HKDF's spec and its NIST's approval better. In SP 800-108 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-108.pdf, at the end of Section 5. (before 5.1), it says that " Alternat

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Torsten Schütze
Hi Quynh, thank you for your quick response. I knew that omitting some fields was allowed, but not that permutations are allowed, too. Okay, this makes HKDF RFC 5869 definitely to a NIST SP800-56C rev 2 compliant KDF. But what to do about the CAVP tests or approved test vectors. Couldn't NIST p

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Dan Brown
Hi Hugo, Some curious molehill questions. Please take with a grain of salt. In short, does HKDF-Extract suffer from related-salt and repeated-IKM? To elaborate: Phillip raises a good point below about HMAC suffering from key-extension (by zero bytes). You are right that this is no

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Phillip Hallam-Baker
On Tue, May 12, 2020 at 12:31 PM Dan Brown wrote: > Hi Hugo, > > > > Some curious molehill questions. Please take with a grain of salt. > > > > In short, does HKDF-Extract suffer from related-salt and repeated-IKM? > > > > To elaborate: > > > > Phillip raises a good point below about HMAC sufferi

Re: [TLS] [Cfrg] NIST crypto group and HKDF (and therefore TLS 1.3)

2020-05-12 Thread Hugo Krawczyk
On Tue, May 12, 2020 at 12:31 PM Dan Brown wrote: > Hi Hugo, > > > > Some curious molehill questions. Please take with a grain of salt. > > > > In short, does HKDF-Extract suffer from related-salt and repeated-IKM? > > > > To elaborate: > > > > Phillip raises a good point below about HMAC sufferi