[JIRA] (OSJ-355) ConcatKDF parameter requirements too restrictive in ECDH
Stefan Santesson (Jira)
jira at shibboleth.atlassian.net
Tue Jun 28 15:17:02 UTC 2022
Stefan Santesson ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=5e1f387fa531f30ca3849078 ) *commented* on OSJ-355 ( https://shibboleth.atlassian.net/browse/OSJ-355?atlOrigin=eyJpIjoiYzYyZGE2YTBmMDNiNGJiY2FjMmE4NWE2MzdjMWFjYTMiLCJwIjoiaiJ9 )
Re: ConcatKDF parameter requirements too restrictive in ECDH ( https://shibboleth.atlassian.net/browse/OSJ-355?atlOrigin=eyJpIjoiYzYyZGE2YTBmMDNiNGJiY2FjMmE4NWE2MzdjMWFjYTMiLCJwIjoiaiJ9 )
I’d say that it is both in this case. The example is clearly wrong as AlgorithmID="00" PartyUInfo="" PartyVInfo="" lacks the required padding declaration.
However, I think the value AlgorithmID="00" PartyUInfo="00" PartyVInfo="00" should be considered valid.
This is based both on how XML enc is written as well as NIST SP 800-56A. However, that statement can probably be contested as NIST specifies these fields as non null when used in a “one-step” key derivation, but adds a lot of ifs and buts. The XML enc standard that has the power to decide what is required makes this optional. And in no case is this static “Fixedinfo” used for anything. It has no function. Therefore it makes little sense to enforce a value if you have no value that makes sense. Adding an extra “00” makes little sense unless that “00” has a meaning in context of NIST SP 800 56A.
I stil think the reasonable path here is to allow AlgorithmID="00" PartyUInfo="00" PartyVInfo="00"
I agree otherwise on the Postel position in general. But in this case I think it makes sense.
( https://shibboleth.atlassian.net/browse/OSJ-355#add-comment?atlOrigin=eyJpIjoiYzYyZGE2YTBmMDNiNGJiY2FjMmE4NWE2MzdjMWFjYTMiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/OSJ-355#add-comment?atlOrigin=eyJpIjoiYzYyZGE2YTBmMDNiNGJiY2FjMmE4NWE2MzdjMWFjYTMiLCJwIjoiaiJ9 )
Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100201- sha1:66eda1f )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9e015832/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-383c4f15-3fbd-415c-9d98-cade0cb37474
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9e015832/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-7c8b5515-0295-40f3-9983-4085f02d1e5f
Type: image/png
Size: 425 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9e015832/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-1ddddf80-0644-4511-9a2b-b76ccfeb1ee8
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220628/9e015832/attachment-0005.png>
More information about the commits
mailing list