IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: SSH in ECC Internet Draft



On Tue, Oct 10, 2006 at 12:51:27PM -0400, Bill Sommerfeld wrote:
> On Tue, 2006-10-10 at 11:17 -0500, Nicolas Williams wrote:
> > On Wed, Oct 11, 2006 at 01:52:24AM +1000, Damien Miller wrote:
> > > IMO that (some) ECC libraries happen to use ASN.1 is not a good reason
> > > to use it as protocol element.
> > 
> > The draft defines one ASN.1 type ('curves', a SEQUENCE of OIDs) where
> > existing SSHv2 constructs could be used instead.  The draft's other uses
> > of ASN.1/DER do not require an implementation of SSHv2 to implement
> > ASN.1/DER outside ECC libraries, but this one type does.
> 
> actually, it looks to me like there may be a deeper problem: the same
> "two level negotiation" issue which affected the gssapi key exchange.

Yeah, that was pointed out elsewhere.  Do we have consensus on how best
to deal with extensions that tie KEX/host key algs so intimately?



Home | Main Index | Thread Index | Old Index