Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Mediocrity finds safety in standardization. -- Frederick Crane


devel / comp.protocols.kerberos / Re: Using PKINIT with ECC

SubjectAuthor
o Re: Using PKINIT with ECCCarson Gaspar

1
Re: Using PKINIT with ECC

<mailman.58.1700414008.2263420.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=436&group=comp.protocols.kerberos#436

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: car...@taltos.org (Carson Gaspar)
Newsgroups: comp.protocols.kerberos
Subject: Re: Using PKINIT with ECC
Date: Sun, 19 Nov 2023 09:13:21 -0800
Organization: TNet Consulting
Lines: 22
Message-ID: <mailman.58.1700414008.2263420.kerberos@mit.edu>
References: <8984fe41-f9a0-434b-a09c-df2bc88125dc@sec4mail.de>
<ae76ed5c-1399-401e-988c-ed2dbdfff6e7@mit.edu>
<202311191700.3AJH0hJD016758@hedwig.cmf.nrl.navy.mil>
<6e03e115-5845-4f6e-bdae-fac432a08d53@taltos.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="12891"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla Thunderbird
To: kerberos@mit.edu
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=fail reason="signature verification failed" (1024-bit key, unprotected)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.a=rsa-sha256 header.s=selector2-mitprod-onmicrosoft-com
header.b=vJ+krIsJ;
dkim=fail reason="signature verification failed" (1024-bit key, unprotected)
header.d=taltos.org header.i=@taltos.org header.a=rsa-sha256 header.s=mesmtp
header.b=UNIvjFyT;
dkim=fail reason="signature verification failed" (2048-bit key,
unprotected) header.d=messagingengine.com header.i=@messagingengine.com
header.a=rsa-sha256 header.s=fm1 header.b=1l/W9Llw
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=MvSuyy3wj2rcJP2K6b2/ZBTpiLctiGfSHQK9ud+FhXBE1okA1zUUCQ3uXz8ivwFY9WYQ0E/dQWZxXbIWo2jON02tQ/JuZi3uzJaGmiL9hgjLGVGgIvtejrMjwMWTREPRN8vzdluYSbW3POnjYB3pp2BRcxHIX79agvCqv320UlPwtdWSfgHHJp8/k4wi0Yk7LOmaUT2y0A7l2utN57TgEhjEcGVqmm2cGWcaUhSklGDYScCTJmqAPG2kG7UQAYkjpq/n+jiyr1+idCi123ibuYzF6yYhCRj1mwWEVDBOFNHS5t0FKTEaAA3NQ//xMOMY+wKqDs/cXo0v+Z03yXu3Fg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=2tIapbvpPGjHP82Cfv26tRM5aUz8D25V4uax3CA94R4=;
b=IsLRu8vYOmt6vMi2WRJMrMEyZvwaQdIVhVvVplmrbs1LSOim5MC5lMK6micqxwRoXNEoLFheP1sXIDjEQw101tuq/KwO+VdN0AQEvu1TPbsXawJD8jgSIFIkOHiHOik2dNF5KkxWRyKccjwz03InF4bk2stNuUKzvagckhB65yIuMWWTx0NwoRHvZnu022OSNeIMWQiRFDXRcWBhROY/VBgeLdXgC/PbTAmWey3W8yDR23XoNvAb8PS9z2EQPV11mhqcpKodW7x5b0hoO8eMIgUKL8UNYABzdjhuKMOmikUJbOBnmdks/rTx/dDV5F9sZxadi8sFSYi/GXTwQFFMAg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
66.111.4.29) smtp.rcpttodomain=mit.edu smtp.mailfrom=taltos.org;
dmarc=bestguesspass action=none header.from=taltos.org; dkim=pass (signature
was verified) header.d=taltos.org; dkim=pass (signature was verified)
header.d=messagingengine.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=2tIapbvpPGjHP82Cfv26tRM5aUz8D25V4uax3CA94R4=;
b=vJ+krIsJG11LdyRvn8L4m0f5Ea6B3daGQlDuCJrWyDQ2QJA3CPADbG/kNhxYxsEqiR8aDJ1edr3aqE6z6XzbcWakbFzZBH02rDSo3FP9kEFybb+n1BI5z9iwbNHbBccyveAIuHfBTiNfRrwrhV+vYLEZZqzHBoYkQGK95FC3WnQ=
Authentication-Results: spf=pass (sender IP is 66.111.4.29)
smtp.mailfrom=taltos.org; dkim=pass (signature was verified)
header.d=taltos.org;dmarc=bestguesspass action=none header.from=taltos.org;
Received-SPF: Pass (protection.outlook.com: domain of taltos.org designates
66.111.4.29 as permitted sender) receiver=protection.outlook.com;
client-ip=66.111.4.29; helo=out5-smtp.messagingengine.com; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=taltos.org; h=cc
:content-type:content-type:date:date:from:from:in-reply-to
:in-reply-to:message-id:mime-version:references:reply-to:sender
:subject:subject:to:to; s=mesmtp; t=1700414003; x=1700500403;
bh=2tIapbvpPGjHP82Cfv26tRM5aUz8D25V4uax3CA94R4=; b=UNIvjFyTbw+v
ptNzMd6+zbLIexcj1JvN5zFgL8Kfn1elcI5fAqMBjOqTkrZHm05tGln9oI2M66G0
4xfFX5EmJH6RyhiTXQp96OOQ91NAaBLt8eRMqvNx7wmaTBz2KjxFgjTNnKP+JvBy
HbAxUM4OHNXDsZ3lFdTWZIk0wgXR588=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
messagingengine.com; h=cc:content-type:content-type:date:date
:feedback-id:feedback-id:from:from:in-reply-to:in-reply-to
:message-id:mime-version:references:reply-to:sender:subject
:subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender
:x-sasl-enc; s=fm1; t=1700414003; x=1700500403; bh=2tIapbvpPGjHP
82Cfv26tRM5aUz8D25V4uax3CA94R4=; b=1l/W9LlwQ9LRoSbU4la44FY+OpaPJ
dTf89t6Zdv+PwHR92M3zz0+YR8lWqm2UPdGLwG+jLJ3cO3MRY5+VyA7UVJf7kWP2
ibVsz5lywcuwRlS/w+rUfkVWI7Wythx9reLEyEvNUqT/aZW5TOy9Qa5GjCDgZg+T
x4N/+Tkpn0T2uehFsT6KGHG6i0IUPuHr+IJgrppJRIQTmZ0jAr74AQjorvXSh/wR
aPsj/TENSAd5JRj4UFMz0sFgrO03S12asYREfnnxIZhhAKj0fRbRrlcawb1v7r60
yfKMjWZDpqJXdCQlaXLrohXYabIAq1ercMOM/kv0qjTbEE04IjBsdSTyg==
X-ME-Sender: <xms:MkJaZVebWeU60hfGoPFFhfFojkWhYNxLfLS9CLFyiqV-yoOwWQV1Pg>
<xme:MkJaZTNq4RbZdmLfPx579VrlyQc-m3By0xMDlKOM1HzQgVulhe-tPEOV_doZIbWE-
bGOk2wUfZzhLO-X>
X-ME-Received: <xmr:MkJaZehhyFsSnQgoM8UOq3VpHgAtTEw-JkpPLraXIOdbwbTlJRTbMVR0rGie5M0D6fLH5dg6fCa2e8__Ne8awP4I0tgQbthXfLU1oJ8>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvkedrudeggedgleekucetufdoteggodetrfdotf
fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen
uceurghilhhouhhtmecufedttdenucenucfjughrpegtkfffgggfuffvfhfhjgesrgdtre
ertddvjeenucfhrhhomhepvegrrhhsohhnucfirghsphgrrhcuoegtrghrshhonhesthgr
lhhtohhsrdhorhhgqeenucggtffrrghtthgvrhhnpeejudeufeevheetvedugeefueetgf
dufeehffevkeehheejjeehueduleeiheduieenucevlhhushhtvghrufhiiigvpedtnecu
rfgrrhgrmhepmhgrihhlfhhrohhmpegtrghrshhonhesthgrlhhtohhsrdhorhhg
X-ME-Proxy: <xmx:M0JaZe-LC9OM2igz4bIQxhCrUdxN5pgiCVhrNiR3R6NalgVUoxEXlQ>
<xmx:M0JaZRsTO7rQ7xvwx2VEBQRVeh8ZqO1MSufUzcXiobaO8xtcuoouZg>
<xmx:M0JaZdEAHOYQqCU6tlOzKVbSK22BjC2gsZzsDEMwwCkBM1kb4KzUZg>
<xmx:M0JaZW6QJ2qmmM9iWCVKEvFsYuP_JagZPRC2olKVNUo_nKIhhfrWkA>
Feedback-ID: i75e441e0:Fastmail
Content-Language: en-US
In-Reply-To: <202311191700.3AJH0hJD016758@hedwig.cmf.nrl.navy.mil>
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BL02EPF0001A0FF:EE_|SA3PR01MB8473:EE_
X-MS-Office365-Filtering-Correlation-Id: e9b1bb71-4306-4271-039f-08dbe922d649
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: yt5x1IfhwTUGxeRAflLExYR6scwJuu81o5kSB7g79vKcCZs3ZfUEL3M1GuYUhyM5VoL5i/V1eKpM3OYimYxBjQmmrQQENQy1W2mSzCWLK5DpJkL5GH9sVRV8xwroyQjQsOZ+FAOTRVADVEnDtccaAI9fCLTvf0F9UR1ctfl3GalMkBiisoJYsg3oW4tum6VV1ZPdeuBr2/b9f9G8cG1/c0jvQFqT0N717QKpppY/pMkrYV+CGl9I+KKaOzoewvaDEuWwPwD/g34rPlFB13Z4ZdyTeB4D4TawrQZHb835wQt+Cgz/GhoITZxXrjg0YXlOCOmgy+xvTgJnv5J9Prf+KbrkmYA6tXzhh1CUdnIKNVnNbc8jECQOMrFKIGyhP843vZOAzjLYtv3XtmLAcC3oi9jnZKULbe35dIQkUzRiFs8/H7w+3W+x+pbeayn/Mgx4KGZt9vkVa6I3fdfyJteOX+1IeAofjILkpPyTAS77iRWjpRc0KmgUtsWEZf/ztxPJKaEG8lT/wZsIGstvzltVDGeCIy2BQAFhgD+fiZPSKh42+sWFM4K9fK0mn6AYSbAQkzXInKxysAz01r6FcqLbnAFqRycz0PPukaI/z6fhToZfPeYG9cA1wtqieqzE0ty5tVy9gsF1PuHbRSxSkzVXy/4qSaV7OHxfA8S8RJzeC2BPpXkcjtaNI4XiAojTu8r0vIX6lfdIVyL9IvBXPGukhg==
X-Forefront-Antispam-Report: CIP:66.111.4.29; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:out5-smtp.messagingengine.com;
PTR:out5-smtp.messagingengine.com; CAT:NONE;
SFS:(13230031)(4636009)(39860400002)(346002)(136003)(376002)(396003)(64100799003)(451199024)(48200799006)(61400799012)(83380400001)(336012)(6266002)(36756003)(31696002)(86362001)(3480700007)(7636003)(356005)(7596003)(68406010)(70586007)(42186006)(8676002)(34206002)(786003)(316002)(6966003)(5660300002)(2906002)(31686004)(33964004)(53546011)(2616005)(26005)(498600001)(43740500002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Nov 2023 17:13:23.5857 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: e9b1bb71-4306-4271-039f-08dbe922d649
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BL02EPF0001A0FF.namprd03.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA3PR01MB8473
X-OriginatorOrg: mitprod.onmicrosoft.com
X-Content-Filtered-By: Mailman/MimeDel 2.1.34
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <6e03e115-5845-4f6e-bdae-fac432a08d53@taltos.org>
X-Mailman-Original-References: <8984fe41-f9a0-434b-a09c-df2bc88125dc@sec4mail.de>
<ae76ed5c-1399-401e-988c-ed2dbdfff6e7@mit.edu>
<202311191700.3AJH0hJD016758@hedwig.cmf.nrl.navy.mil>
 by: Carson Gaspar - Sun, 19 Nov 2023 17:13 UTC

On 11/19/2023 9:00 AM, Ken Hornstein via Kerberos wrote:
> I have mentioned this before, but ... is there any interest in adding
> additional trace points for every place where the old "pkiDebug" calls
> are made? Hidden errors when doing PKINIT are the bane of my existence
> and I feel that I'm not the only one. I understand there are concerns
> about making the trace log too verbose but I think every error could
> generate a trace message and it wouldn't add too much to the trace output
> when everything was working.

Consider this a +1 for some way to enable useful PKINIT debugging
without a recompile. The number of times I've had to install a debug
plugin .so just to figure out basic config issues...

Hell, even just adding an autoconf option to enable it so I didn't have
to hand-edit the include file would be a win... (yeah, I could probably
pass in a custom CPPFLAGS option, but by the time I find the !@#$% macro
I'm already in the include file, so...)

--

Carson

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor