Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non-EC MTI Algorithm #474

Closed
stpeter opened this issue Jul 30, 2022 · 4 comments · Fixed by #478
Closed

Non-EC MTI Algorithm #474

stpeter opened this issue Jul 30, 2022 · 4 comments · Fixed by #478
Assignees
Labels

Comments

@stpeter
Copy link
Collaborator

stpeter commented Jul 30, 2022

In his ArtArt review, Cullen Jennings wrote:

Given the requirements for crypto agility, I think this there should be at
least one MTI algorithm that does not rely on EC. Pinning all your hopes on a
single algorithm surely is not the best security advice the IETF can provide.
If a EC did have a problem, clearly we would want something already build and
deployed that we could switch too.

I think the authors neglected to discuss this issue when we were working on -10.

@thomas-fossati
Copy link
Collaborator

I don't think there's anything left (in usable state) for 1.2: DHE negotiation is broken and static RSA is out of the question.

@stpeter
Copy link
Collaborator Author

stpeter commented Jul 30, 2022

@stpeter
Copy link
Collaborator Author

stpeter commented Aug 1, 2022

List discussion seems to be leading in the direction of not adding a non-EC cipher suite.

@stpeter
Copy link
Collaborator Author

stpeter commented Aug 3, 2022

As far as I can see based on further list discussion, no new text is needed. I will wait another ~24 hours before closing this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants