11 Nov 2008 16:59
Re: Elliptic-Curve Algorithm Integration in the Secure Shell Transport Layer
Jan Pechanec <Jan.Pechanec <at> Sun.COM>
2008-11-11 15:59:19 GMT
2008-11-11 15:59:19 GMT
On Wed, 1 Oct 2008, Douglas Stebila wrote: > A new version of the ECC in SSH draft is now available for review. > > http://www.ietf.org/internet-drafts/draft-green-secsh-ecc-03.txt hi Douglas, I like the draft, and have some comments. - section 1, ECMQV has been dropped from the National Security Agency's Suite B. I don't know when but it's not there now: http://www.nsa.gov/ia/industry/crypto_suite_b.cfm I'm wondering if an inclusion of that in this draft may not cast some shadow on it in general as including something that might have potential legal issues if used. - section 4, this might be just a language issue; does this imply that the remote key pair is ephemeral as well or not? Or would it be better to say "and ephemeral remote public key"? The Elliptic Curve Diffie-Hellman (ECDH) key exchange method generates a shared secret from an ephemeral elliptic curve local private key and remote public key. - section 4, you may want to reference RFC 4251, 4.1 (Host Keys) and section 9.3.4 (Man-in-the-middle) in the "*" paragraph. Same in section 5. Or it could be at one common place so that it's not duplicated.(Continue reading)
RSS Feed