Markdown Version

Session Date/Time: 22 Jul 2026 12:00

[00:00:04] Job Snijders: Thank

[00:00:08] Stephen Farrell: you. Yes.

[00:00:11] Job Snijders: Okay. Would somebody please close the door in the back to improve the acoustics? I I don't know. There is no yeah. His his hands

[00:00:23] Stephen Farrell: were full.

[00:00:24] Job Snijders: Yeah. I have my hands full.

[00:00:29] Stephen Farrell: Okay, folks. Welcome to the SSH maintenance working group this time. I'm Steven. This is Job. Job did the slides. So you do you wanna run the slides?

[00:00:39] Scott Fluhrer: Sure. For sure.

[00:00:44] Job Snijders: Welcome in Vienna. If you're not supposed to be in Vienna, please come talk to me after the session. Okay. First of all, we have a QR code hanging off the microphone. Please scan the QR codes, and this helps us with planning the capacity of the room at the next meeting. Our agenda for today will cover some online resources. The note will will be explained to you. We'll give an update on the various Internet drafts that are in the working group or past the working group or or adjacent to the working group. Then there will be a report on a hackathon activity, discussion on PQ signatures, and more discussion on PQ signatures. And then yeah. How much time do we have today?

[00:01:40] Stephen Farrell: Ninety minutes.

[00:01:41] Job Snijders: Ninety minutes. Alright. Plenty. There's two resources I wanna point everybody to. One is our mailing list. It's fairly low traffic, which is nice. The the the flame wars on on PQ have not yet spilled over to SSH, but we, as moderators, will keep a lid on it. So we'll make sure that the discussion is SSH focused. So anything more you wanna add to this?

[00:02:13] Stephen Farrell: Well yeah. So there there was a small there was, like, one mail bladed over from the TLS list, and our our intention with your approval is if that starts happening, we're gonna try and cut it off by blocking based on subject line or something. So just so you know, that's that that would be the plan if it starts investing our list. We'll come up with keywords. Yeah. If if people are okay with that, that that's the plan if it starts. But it it doesn't seem to have persisted, which is good.

[00:02:48] Job Snijders: And we have a Zoom chat channel, which I think is always nice to have a

[00:02:54] Alicja Krenska: way to to chat during the session. I will be monitoring the the Zulip room for for any questions that need to be relayed to the room in terms of audio.

[00:03:05] Stephen Farrell: And Rich has kindly agreed to take notes that we have described.

[00:03:08] Job Snijders: Thank you, Rich. No LLM. You have to write it by hand.

[00:03:12] Stephen Farrell: Becker has the LLM running already. So

[00:03:15] Scott Fluhrer: Yeah. Yeah. Yeah.

[00:03:17] Job Snijders: Notewell, We expect from you that you strive to behave most excellent towards others. So this means that we we are here as part of sort of a debate club, and we will offer each other arguments based on merit. No attacking each other on on affiliation or or, you know, whether you have glasses or not. No shouting at the microphone. If you're excited about something, that's okay. But just in a calm fashion, say, this upsets me. Right? That's fine. No no screaming at each other. Anything you say here is is considered an ITF contribution. There's a a number of documents that explain what exactly that is. And, yeah. I I mean, like, many, many words have been written on this topic, but it really it all boils down to respect each other. It's okay to not agree on everything and be nice to each other. And yeah. I'm sorry, Bob. I was just explaining that all the latecomers have to pay $10 into the SSH funds.

[00:04:36] Scott Fluhrer: So,

[00:04:44] Job Snijders: everybody, welcome to Vienna. I took this photo as I was strolling around yesterday. I thought it was super funny. I have a suspicion that it's not about music but about fish, but I don't know. If you do know, please tell me.

[00:05:03] Stephen Farrell: Fass is Fass is the name of a beer that used to be on sale of diamonds.

[00:05:08] Alicja Krenska: Alright.

[00:05:11] Job Snijders: Since our last meeting in it was what? Shenzhen? It was the one anyway, we have published two RFCs, and I'm, so congratulations to the offers and the working group on getting these documents out. One defines the SSH agent protocol, and I I am super excited that that has been standardized. That technology has been around for more than ten years, I think. But so it's it's this this means that we as a working group are doing the thing we are chartered for. We're we're specifying and standardizing existing deployed technology. Good job on us. And the other one, also represents a technology that has been deployed for a number of years. And I find it a bit of a tongue breaker. sftp-v6-v3. So, again, thank you to the authors for pulling through and investing the time to to get this document published. Then there is an Internet draft that is not a working group document, but it is sorry. I'm confused. This is a working group document, ML-KEM hybrid. It is currently with the RC editor, so this means that professional technical offers, are are not changing the documents or specification, but they are changing, like, the flow of sentences or spelling and grammar errors. They're making the documents as presentable as possible for RC publication. And this is really cool because in academic circles, you yourself are responsible for finding all grammar errors in your papers. But here in the IETF world, we have it luxurious, and we are assisted by very nice people at the RFC editor who help us polish these documents. This document has been there for about half a year ish. So I think it is it's passed its first edit rounds, and I I think it will be my guess, but there's no guarantees will be published somewhere in the next three to four months. Then there is a document that is not a working group document, but adjacent to SSH, commercial national security algorithm suite two dot zero. And this specification was sent to the independent stream editor where it's under review. So, yeah, if you're interested, take a look. All the blue words on my slides are clickable. So if you go to the data tracker and download the slides, you can click these links. And I put a lot of effort into trying make the links point to the thing under the words. Our active Internet drafts, these are drafts that are not sent forward for publication yet. Yeah. Let's let's go through them one by one, I guess. Cha cha polling. There has been some discussion where some some participants in the working group expressed concern that that standardization of this particular cipher might carry some risk if it's not implemented correctly to which other participants reply, well, you you need to implement according to specification. It has a dependency on strict. Strict, I think, this point in time is an expired draft, so a revision is needed to progress that one. And I think some weeks ago, you sent to the mailing list a summary to strengthen the dependency between the documents to resolve the the risk of, I think, is the attack. Yeah. But I don't think that's been done yet. What was the outcome?

[00:09:28] Stephen Farrell: I'm trying to remember. Yeah. So we we basically got hung up on a few essentially, a wording thing as to how we would refer to strict text from the ChaCha drafts. I think we had a solution. I don't think anybody yelled. Did I actually send it to the list? That's a good question. But I think we need to finish that off, basically, by just correcting the text that people found objectionable and how we refer to strict text from ChaCha. And I think it's quite doable, but I have to go back to the list and do it. So, I guess, put the action on us to make sure that we've summarized it. And then if people are happy with the outcome, we can just hopefully proceed. Yeah. Yeah. But, I mean, if I so if anybody has comments on Chacha or strict checks now is a good now is the time. But the plan would be that the chairs will try and well, the chairs will send our summary of where we think the discussion ended. We hope that will allow us to just then fix things and move forward. Any comments, sir? John?

[00:10:31] John Mattsson: Yeah. Yes. Because I commented

[00:10:33] Job Snijders: State your name, affiliation, and shoe size.

[00:10:48] John Mattsson: Especially targeted. Now the follow-up paper and the discussion on the list seems that the problem actually affect basically all ciphers. So it's not that it's SSH just general in general that is weak. So I think my my my comments on Chacha specifically has weakened. I am I I'm happy with whatever text will be there, I think. Yeah.

[00:11:15] Stephen Farrell: Thanks, Damian?

[00:11:19] Damien Miller: Yeah. I I was gonna say basically the same thing that that the the the subsequent results with regards to the terror and attack have shown that many other other ciphers are also vulnerable and and ChaCha20-Poly1305 isn't uniquely affected by it. So I think I think that argues that we need strict checks regardless. And I think it it I don't think it lessens the dependency between the two, but but I don't think it it it presents any particular impediment to to ChaCha progressing.

[00:11:58] Stephen Farrell: Great. Thanks. Okay. So the action on the chair is then to just suggest a wording tweak and then to the authors to to do the refresh needed, and then we'll consider I think that think we've already done working group last call for all these things, so it's essentially just tidying up the end of that.

[00:12:13] Job Snijders: We did working group last call for we did working group last call for ChaCha, but not for draft-ietf-sshm-hostkey-update, I think.

[00:12:21] Stephen Farrell: Let me start.

[00:12:22] Job Snijders: That's good. That's that's what I think we should start. Okay. And and, Damian, would you mind uploading a new revision of draft-ietf-sshm-hostkey-update? Because I think it's expired in the data tracker at this point in time.

[00:12:37] Damien Miller: No problem. I I actually intended to do that so last week, but data tracker was locked for the ahead of the ITF. So

[00:12:44] Job Snijders: yeah. Yeah. Thank you. Okay. That's that. draft-ietf-sshm-cert is in the working group. It was adopted. It's not in in working group last call. I think Damian holds the edit token on that one.

[00:13:06] Stephen Farrell: Yep. Yes.

[00:13:10] Job Snijders: Damian, would you mind sharing a a one minute update on where we are with the certificates?

[00:13:18] Damien Miller: Yeah. Sure. So I think since we since we last talked about this, I had some good feedback from Rich Sauls. I I don't feel like I personally don't feel like I've had quite enough feedback from enough people to have confidence that this is ready for the last call, but maybe other people feel differently. You know, this is that that that's a that's a way of asking for people to review this draft with more words. But Okay.

[00:13:52] Bas Westerbaan: So so let's see if we can

[00:13:54] Stephen Farrell: get some victims. Sorry. I apologize. Any was anybody willing to to commit to giving us a read through and sending us comments to the list? That would be great. Or we could just stop here and do nothing else?

[00:14:07] Job Snijders: I think last time we managed to volunteer Casper. Alright.

[00:14:11] Stephen Farrell: Bob waved and said yes.

[00:14:13] Job Snijders: Alright. And Casper also

[00:14:14] Scott Fluhrer: thank you. Great.

[00:14:15] Stephen Farrell: So Bob and Casper have said they'll do that review for you, Damian. And I I I guess it won't be in the next ten seconds, but hopefully in in the near future. Okay. Host key.

[00:14:35] Bas Westerbaan: Let me open up.

[00:14:39] Stephen Farrell: So, Damian, do do you wanna do the same kind of update on host key?

[00:14:43] Damien Miller: Yeah. Why why not? Yeah. So I guess this has been around for a while. I think a few implementations have adopted it. Again, I don't feel like I've had enough feedback on the draft itself to to have a lot of confidence in in the quality of my writing. So I again, I'd I'd appreciate more feedback.

[00:15:08] Stephen Farrell: How about it? Anybody feel the love for reading host key draft? Rich said yes. Thank you, Rich. And, Casper. Great. So we have a couple of reviewers, and and I guess we go from there.

[00:15:20] Damien Miller: Awesome. Thanks, Will.

[00:15:25] Job Snijders: Alright. Then next up, we we have I I grouped them as in in the non PQ category. Is Peter Goodman with us in the room?

[00:15:39] Stephen Farrell: I doubt it.

[00:15:40] Job Snijders: Cannot sense his presence. Oh, okay. Okay. Yeah. So the pre f pre off mechanism for SSH, I read the draft this morning. And if I summarize it correctly, it's it introduces a challenge response prior to authentication stage, and the idea is to make a little barrier against robots that are scanning for SSH hosts and make them do a little bit more work to to engage in SSH protocol. The draft is is periodically refreshed, but I there's not been a request for adoption as far as I know. And I think it's also I I don't know the deployment status or whether this is new. Yeah. I guess some feedback from

[00:16:36] Stephen Farrell: I I think it's new.

[00:16:37] Job Snijders: Yeah. It's new. Yeah. Alright. Yeah. So I guess I don't know too much about it.

[00:16:48] Bas Westerbaan: And looking at the audience, I think a lot

[00:16:50] Job Snijders: of people are like

[00:16:52] Scott Fluhrer: So

[00:16:56] Stephen Farrell: so, Bob, do wanna the microphone is a good thing? Thank you.

[00:17:10] Bob Beck: Bob Beck. Well, I guess that's OpenSSH for this one. Don't know that I've seen it in anything. I haven't been looking very hard. It it sounds like new work and not documenting the state of the world today. So, I mean, it's good to look at, but I don't know if it's in scope right now.

[00:17:29] Stephen Farrell: That that seems correct. Okay. So we'll we'll we'll you know, as a way, and if if it pops up and loads of people wanna do it, we'll talk about it. Otherwise, we don't need to Damien.

[00:17:38] Damien Miller: Yeah. I I had I'd I'd seen some comments on this when Peter sent it, I think, last year, early last year, maybe the year before. I I know that would it will break at least one private extension to the SSH protocol. I suggested an alternate method which was a slight relaxation of the rules for pre banner text. At the moment, the server is allowed to send lines before the banner. And if they don't start with the the magic string SSH hyphen, then they're they're silently ignored. I suggested relaxing the client side to allow the same, and you could implement this in a a pretty backwards compatible way. But yeah. I'm not I'm not sure what the status of it is or whether he intends to to move it forward at all. I think I think there's a better way of doing it.

[00:18:30] Stephen Farrell: Okay. Great. Thanks. Okay. So we'll come we'll come back to that as and when it pops up. Yeah. So

[00:18:40] Job Snijders: fixed AS GCM modes for SSH, a Miller draft. Damian, would you mind giving us a thirty second update?

[00:18:51] Damien Miller: Yeah. I mean, this is, like, this is a,

[00:18:55] Scott Fluhrer: like

[00:18:55] Damien Miller: embarrassingly simplistic draft. So a long time ago, there was a draft and and forgive me for forgetting the author's name from someone at the NSA who who specified AES GCM for the SSH protocol. Unfortunately, they ignored some feedback from the then quasi defunct SSH working group that the way they had specified the negotiation created a situation where two compliant peers could negotiate ASGCM and fail to negotiate the rest of the fail to negotiate other things. This draft is basically exactly their draft. Well, it it it it's not exactly their draft. It just refers to their draft for everything except for fixing the negotiation phase. So it's it's it's stupidly simplistic. Most implementations implement AES GCM. You know, I guess, again, this is a situation where I've not had a lot of feedback on the draft. So I'm I'm not very confident in the quality of the authorship. You know, maybe it's too simplistic. Maybe it needs to pull in more stuff from the other draft. Maybe it's okay the way that it it is. But it does it does make the charter criteria of documenting something that's widely deployed.

[00:20:15] Job Snijders: Okay. That sounds like you would like us to start a working group call for adoption.

[00:20:20] Damien Miller: If you're willing, absolutely.

[00:20:26] Stephen Farrell: So I don't see anybody claiming that's a crazy plan, so we'll probably go to this. Yep. Okay. Ted?

[00:20:40] Deb Cooley: This is Deb Coulee. Hey. So this is for Damian, actually. So that draft that's being referenced is probably a CNSA draft. Is that right? So it'll be informational?

[00:20:52] Damien Miller: I I could look it up, and I could tell you in about thirty seconds, but I don't wanna keep you

[00:20:57] Deb Cooley: Do you have an RFC do you have an RFC number?

[00:20:59] Scott Fluhrer: Oh, I'm

[00:21:00] Stephen Farrell: gonna do that. 567.

[00:21:04] Deb Cooley: Do you know?

[00:21:05] Damien Miller: 5647. Yeah.

[00:21:07] Deb Cooley: Is that a CNS aid? Is if if Steven's sitting there looking at it? So it's it's proposed standard? It's informational. It's informational. So when you do this I mean, I'm fine with doing this. Right? But we will have to there's a itty bitty step that will have to take place, which is fine. Which is, like, you're gonna you're gonna produce a assume a proposed standard draft that we will then have to do a down ref form. But the down ref is fine. I just we just need to make sure we remember that.

[00:21:36] Stephen Farrell: Yep. Sure.

[00:21:37] Deb Cooley: So I get slapped when you do that, and we don't tell them. So it's only a me problem, not a you problem.

[00:21:43] Damien Miller: Well, I mean and and I I guess this goes back to what I was saying a moment ago is is is the sort of simplistic way of approach this too simplistic? Or should I, you know, should we pull in more more content from the original draft and and and fully specify how the ASGCM mode works in SSH? Because at the moment, all I do is refer to the other other draft for for the for the mechanics and just talk about the negotiation method.

[00:22:12] Deb Cooley: So, I mean, this is in use today. Right? So do people actually reference that? They they don't because it's broken. Right? They don't reference

[00:22:20] Damien Miller: They don't don't use the old draft. They use they most most people, I think, use this one. Is that well, most most people don't use the old RFC. They use the draft.

[00:22:30] Deb Cooley: So I think I think that's fine. There's no reason to have to replicate something that's already written down. Like, I'm not I'm not a fan of that. Right? It's just I have to we will have to keep track. The chairs and I will have to keep track of this little this little thing that will get me slapped. It has nothing to do with you, and it's completely fine. And I I am thick skinned, so the slap won't bother me. But we'll just remember so it doesn't happen. Right?

[00:22:57] Stephen Farrell: Yeah. I mean, I I guess after we adopt it, we'll just put in updates fifty six forty seven, and then put it

[00:23:03] Scott Fluhrer: in the

[00:23:04] Stephen Farrell: Well, we'll

[00:23:04] Deb Cooley: just write it in the Shepard's right up and say that it's a downrift. Yeah. It's easy peasy. Lemon squeezy. And there's probably no reason to add it to the registry. Right?

[00:23:12] Stephen Farrell: Whatever we're currently doing. Yeah. It's all easy. Done.

[00:23:16] John Mattsson: Yep. John Matson, Ericsson. Will this will this be implemented and supported? There's already a problem in SSH that there is two different GCM. We have the RFC that you are referring to, and then we have the open SSH version of GCM, which I think is not compatible. So we will do we foresee that this will replace both of them, or or will this be a third option just complicating things?

[00:23:51] Damien Miller: My my intention was standardizing the the the one that open SSH implements, is also the one that I believe most other most other SSH implementations that that support AES GCM also implement the open SSH version just with a just with a non vended name.

[00:24:14] Deb Cooley: Can we make a best?

[00:24:18] Stephen Farrell: We can always do that. I'm not sure we need to or not. So I guess it's it comes down to the algorithm.

[00:24:22] Deb Cooley: Right? Obsolete the one that's broken. Right?

[00:24:25] Job Snijders: Yep. That's fine.

[00:24:26] Deb Cooley: That's an option. And can you make abyss and then make it proposed standard?

[00:24:32] Scott Fluhrer: How does that work? If if if need be She says.

[00:24:35] Deb Cooley: Yeah. Supposed to know the rules.

[00:24:36] Stephen Farrell: Every every time you make more word or every time you kinda refresh more words, but so it's a bit I guess we while we when we adopt this draft or we have a call for adoption, we can figure out how to process

[00:24:47] Deb Cooley: talk about whether you're gonna miss it or whether you're

[00:24:49] Job Snijders: gonna do something else.

[00:24:49] Deb Cooley: Because that would then that would then deprecate the broken one. Right?

[00:24:54] Job Snijders: We can obsolete the broken one

[00:24:57] Stephen Farrell: Yeah.

[00:24:59] Job Snijders: As part of

[00:25:00] Stephen Farrell: Okay. So we'll build start a call for adoption for the Miller ssh ASGCM. And as part of that, we'll figure out how it relates to fifty six forty seven.

[00:25:18] Job Snijders: Next up, lightweight secure shell signature formats. It describes a format that is compatible with SSH keys and wire formats.

[00:25:31] Stephen Farrell: Simon is in the room. So, Simon, do you wanna if you

[00:25:35] Job Snijders: Simon, you wanna grab the the microphone?

[00:25:38] Stephen Farrell: Yeah. Great. Hey.

[00:25:43] Job Snijders: We cannot hear you. Unmute. Shake the laptop. While we wait, can anybody identify what the games are in the upper left corner?

[00:26:03] Alicja Krenska: So

[00:26:07] Stephen Farrell: you're showing us muted in Meet Echo, Simon?

[00:26:11] Deb Cooley: Can you unmute him?

[00:26:12] Stephen Farrell: I don't think so.

[00:26:23] Job Snijders: Okay. Let's look if we have a backup assignment. Damian, you're also an author on the SSH SIG format. Maybe you can give us an update and pretend that you're Simon.

[00:26:38] Damien Miller: I I wouldn't presume to pretend. I guess yeah. This this this is something which has been has has had some adoption. So SSH SIG is basically repurposing of the SSH signature formats for detached signatures. We there is adoption in the Git ecosystem where you can use open PGP x five zero nine or SSH signatures to sign Git commits. Some people have used it for detached file signatures. So I I I you know, I'm extremely biased as a as an originator of this, but I think it's a a useful and and sort of minimal minimal extension that's that is worth writing up somewhere.

[00:27:32] Stephen Farrell: And then Simon pointed out in the room. He says this is just really documenting existing format. So Yeah.

[00:27:41] Job Snijders: Okay. With that, my request to the offers would be please upload a new non expired version into the data tracker, and then we can start a working group call for adoption.

[00:27:53] Stephen Farrell: So let's so the you

[00:27:56] Bas Westerbaan: could argue that this

[00:27:57] Stephen Farrell: is not within our charter.

[00:27:59] Job Snijders: Really?

[00:28:00] Stephen Farrell: Yeah. Because I think our charter talks about the SSH protocol. Now so I you know, what do people I don't think we need to recharter to do this. I think if we if if if the working group want to take on this work, it kind of fits everything else in the charter. It is SSH. It is existing stuff. It's documenting that. It will be useful to have it documented. So I guess I just wanna check. I Bob, you're not at the microphone again? Sorry. I can't I didn't hear what you said at this time.

[00:28:31] Scott Fluhrer: Lance's agenda is getting empty.

[00:28:32] Job Snijders: We can build it again.

[00:28:33] Stephen Farrell: Oh, Lance. No. You don't want me swearing at the microphone. So do people have any, you know, allergies about taking on this work or because it's not quite SSH protocol, but it is SSH. Are people okay with doing this? Let's let's do a poll.

[00:28:52] Job Snijders: Yes. Let's do a poll.

[00:28:54] Stephen Farrell: Okay.

[00:28:56] Job Snijders: But make the question a little bit ambiguous. If, yeah, a double negation is a good one.

[00:29:07] Stephen Farrell: So we're not actually There's a poll started there now. We're not actually asking about a drafted option. We just should should this be something that we take on, or should we go and go mad and recharter, or should we just never do it or whatever? So yes means it's worth it's worth looking at talking about, and let's let's try to do it without retriever. So we give that a couple more seconds. It is so it's on screen here.

[00:29:40] Scott Fluhrer: Yeah. The lifeline. You have to come on. Okay.

[00:29:44] Stephen Farrell: And we'll give you so we'll give you some more time. And and so I what I'm saying is 21 yes to no. If the if the people who clicked on no would would like to say why they clicked on no, that would be an excellent piece of info. Yeah. But maybe they don't. But if they do, if you if they wanna go to the mic or type in the chat, that would be good.

[00:30:05] Rich Salz: Rich Sauls. I clicked on yes, but I was just rereading the charter over Deb's shoulder. And it says, in particular, it will discuss. It doesn't say only. Those are examples.

[00:30:16] Stephen Farrell: It that's why it is arguable, so that's why I just wanted to get this in case somebody beats us up later. And I could say, oh, we asked the the working group, and our esteemed area director didn't crap on us and so on.

[00:30:26] Rich Salz: I don't know. Maybe she likes to be slapped.

[00:30:29] Stephen Farrell: Okay. So we got we got 22 yes, two no, six no opinion. Again, if the if the people who clicked on no would like to give us any more information about that, that would be welcome. They don't have to. I don't see anything in the chat for that. Okay. So what we'll do then is if the authors refresh that, then we'll do a working group adoption call first. Probably do these things in sequence as opposed to parallel or whatever. We'll see. Yeah. Great. Okay.

[00:31:03] Deb Cooley: Do you do have something in the chat?

[00:31:05] Stephen Farrell: What was in the chat?

[00:31:07] Deb Cooley: I got I know. Sorry.

[00:31:10] Stephen Farrell: I missed that. Tom. So, Tom, was that you see in the chat, Tom said that there may be different security requirements from regular SSH protocol.

[00:31:25] Job Snijders: Yeah. But he also said he doesn't think we shouldn't do it.

[00:31:29] Stephen Farrell: Okay. I don't think we shouldn't do it, he said. Okay. So that's not quite enough. Yeah. Okay.

[00:31:36] Bas Westerbaan: So we'll we'll we'll we'll get to

[00:31:38] Stephen Farrell: that after you call for that and so on. Grace. Do you want me to

[00:31:42] Job Snijders: Yeah. We're now at the MLDSA theme section of our sermon.

[00:31:47] Stephen Farrell: Should there's a couple of relevant presentations. So should we let those people do that first?

[00:31:51] Job Snijders: I think that makes perfect sense.

[00:31:53] Stephen Farrell: Great. Let's start. So I'll pop up their slides. Yep. Okay. Take away the slide clicker. And so we have two presentations. One includes some GS' API stuff, but we'll so which is not entirely relevant, but it's in the same slide deck, so we'll do it. But we go, I guess, with Scott first. That's at the slide. Oh, sorry. Pardon me. No. Stay there. I'll fix it. I'll fix it.

[00:32:36] Job Snijders: Come back.

[00:32:39] Deb Cooley: Send you a paper.

[00:32:41] Stephen Farrell: The The holy clicker.

[00:32:43] Scott Fluhrer: Oh my. Okay. Clickers all yours. Okay. I don't know to what extent I need to go through this. Hello. Okay. Okay. Don't know to what extent I need to go

[00:32:55] Stephen Farrell: through this, but I'll go through

[00:32:56] Scott Fluhrer: this anyway. Quantum computers, I looked at some some some time as published time estimates from various companies from 2029 to early twenty thirties. These are published. I can't say if they are marketing hype or overly optimistic expectations, but I don't know if we want to make that a security assumption that they are. And in addition, because for signatures, you also have the threat of trust now, authenticate later. Once we have a sync a public key and then we keep on trusting, it's hard to update at times. And so that once upon a quantum computer becomes there, they then somebody can forge. The other question, of course, is pure versus hybrid. Do we endorse using only a p PQC, like MLDSA signature, or do we combine them with classical? We need to really, we need to or do we or do we do we allow both options? Let's see. Because there's a bunch of drafts. One is so the the two MLDSA drafts are actually very similar. They just basically take RSA, scratch out where it says ML RSA, put an MLDSA, assign different code points, and we are done. The only difference between the two code point the two drafts are based basically, they pick different code points. I just wanna note that there are several different implementations of my draft. Of course, I don't I can't say that I either draft be fine. I also want to not mention that there's also a a s s eight m l s nope. Sorry. SLHDSA draft. That's a Jefferson draft. I think that's that's a a that's not for general use. It's a niche solution, but it but it it's it's out there and is a a a also post quantum. And for the hybrid signatures, there are two drafts out there. They are both basically take does a similar construction to the the lamps composite signatures. There are some technical differences between them and also from between them and the comp the how the LAMP's signatures work, but they're very, very similar. The only kind of thing is that for the second one, the Miller draft, there's only a single combination that's in the title. I don't see that that that as a be considered a a acceptable solution for everything. So we would have to add more options. It's relatively easy. I could but it would have to be done. There's also Josephine Josephine draft also provides hybrids. Now, what do I ask of the working group? I actually would I would personally ask that they provide both a pure MLDSA draft, either minor or Rubin's. And also in addition, one of the hybrid drafts and because I think they will be both be be needed. And also, one of the things I asked for is code points for for my draft. I just needed if if we do adopt the my draft. If you don't, who cares? I believe that's all I had. Any questions?

[00:36:51] Stephen Farrell: I don't believe you. I don't believe there's no question. So create our opinions. What what should we do? So I I I honestly don't believe that nobody has beans. Okay.

[00:37:06] Dmitry Belyavskiy: Thank you.

[00:37:07] Stephen Farrell: Great. Okay.

[00:37:10] Damien Miller: I'm I'm I'm I'm slightly terrified of of starting this conversation or continuing it at least. So I guess, I I have no objection to a a pure draft going ahead. I recognize there's there's people who prefer that approach. I I think, and I've articulated this on the list. I think if we are if we are going to deploy something within the next four years, my peace of mind would be much better with a hybrid at this point or a composite draft. I I totally accept Scott's criticism that my my draft is, again, absurdly minimal. I I tried to navigate the the sort of complexity of the Cartesian product of classical cross quantum cross combiner by picking a single one of each. Yeah. And I would I think if if if that is to be relaxed, then I think we'd wanna be very clear about what the other options we're choosing and and the justification for each of them though. I I don't I don't for for something which is explicitly transitional like a hybrid in in like 2026, 2027, I don't think it makes sense to pick any any post quantum algorithm up up than MLDSA 44. I don't I don't see the benefit of of of picking a a, you know, a more computationally expensive and longer signature version. You know, I there's I could see reasons why one might wanna choose a different a different classical signature algorithm. But again, I think, you know, the the whole purpose of my draft was trying to collapse that that possibility space, that superposition of of algorithms into into something concrete that we you know, that would would fit the needs for, you know, for the next couple of years until we're we're we're ready for for, you know, a pure algorithm. Mhmm.

[00:39:21] Scott Fluhrer: Yes. If I could respond. One nice thing about the pure is that that's relatively easy to specify. There's we can get out there really relatively quick draft out there relatively quickly. With hybrid, there's a bunch of tech of of of technical considerations to do, which mean of decisions we may have to make, which we end up arguing over.

[00:39:48] Bas Westerbaan: Yeah. So just to I mean, so one thing I wanted to

[00:39:50] Stephen Farrell: know how that what Damien said, which wasn't immediately obvious to me before, which is the I think Damien's arguing for a hybrid, which is MLDSA forty four and one and one elliptic curve as the only single hybrid on on the basis of that's a transitional thing. So I just I just wanna make sure that's clear to everybody where he's I don't think he's talking about having different lens of MLDSA combined with different elliptic curves. But, John?

[00:40:16] John Mattsson: Yeah. John Ericsson. I think we should adopt both. Pure MLDLS is very simple. Yes. Specify it, standardize it, implement it, and people that want to use that can use it. I also think it makes sense to standardize pure MLDSA now so that it can be standardized and implemented so that people can transition to it in, like, ten five, ten years. That you don't want to use it for five years doesn't mean we I think if you want to use something in five years, we should standardize and implement it now, and then you can switch in five years. It takes so much time to have. I also think we should standardize a hybrid. Some people seem to very much

[00:40:59] Stephen Farrell: Mhmm.

[00:41:00] John Mattsson: Prefer that. And then I think we should standardize something, see if RDA is very likely to look at hybrids So then I think we should standardize one of them. That does not decrease the security properties of MLDSA. And, I e, not the malleable I don't think we should standardize the malleable signatures as the signatures are general purpose. If you forbid the general purpose use case, I think malleable signals are probably okay.

[00:41:32] Stephen Farrell: So, John, just to just to to say I understood that, the end result of that would be three?

[00:41:39] John Mattsson: Two, I think. Two.

[00:41:40] Stephen Farrell: Okay. So I wasn't hearing that through

[00:41:42] John Mattsson: pure m one signature, preferably following the future CFRG work.

[00:41:53] Stephen Farrell: Sorry to meet you. Just I just wanna clarify that because so the what you're saying is is a one pure and then a a hybrid one, which is not malleable is what you're arguing for. Yes. And you're also saying we should wait on CFRG for that?

[00:42:08] John Mattsson: Yeah. Yeah. Yeah. Yeah. For the hybrid, yes. Today, there was a vote in CFRG and 40 people think CFRG should work on hybrid signatures. Yeah. I I think my view is that LAMP shouldn't this should have been done in c four g from the start. Now c four g is a bit late, but I think if you have general purpose signatures like the SSA signatures, I don't think the LAMP signatures be used.

[00:42:34] Stephen Farrell: Okay. So so that's a point for discussion for yeah.

[00:42:36] Scott Fluhrer: Thank you. The only issue I would have is by the time we wait for CFRG and then get a draft here, by the time we have a hybrid that we deploy, quantum a computer is there, so why bother?

[00:42:50] Dmitry Belyavskiy: I support adoption both of pure and hybrid. And I think that we should sanitize different lengths of MLD side, different security strengths because we will definitely meet the different requirements to have minimal security level for different scenarios.

[00:43:14] Stephen Farrell: When you say that, are you talking about different NMS memo, they say just for the pure or also for the high? Speaking frankly for both. You would like it for both. Okay. Yes. Okay. So there's another point of discussion. Baz?

[00:43:30] Bas Westerbaan: Buzz. It is not as bad as in TLS. They have a lot of options, but still, I think, people are already reaching out to me, asking me, which of the is it five drafts now in total of the option of the signature options? Which of them should we implement and which of the options? I think it would be really good if in some way we signal that there's one kind of preferred thing so that we can afford rather yesterday than than today. But so you're talking

[00:44:01] Scott Fluhrer: about recommendations or or or the actual drafts? Yeah. I don't think

[00:44:06] Bas Westerbaan: you have a recommended column in SSH. Right?

[00:44:08] Scott Fluhrer: So I think it's way premature for the to talk about recommended right now.

[00:44:12] Bas Westerbaan: No. But but there's

[00:44:15] Damien Miller: I don't know this actually

[00:44:16] Bas Westerbaan: so it is really important that people don't fragments too much. Right? You have to have an obvious option whether you call it recommended or not. That I don't care how

[00:44:25] Stephen Farrell: you Yeah.

[00:44:25] Bas Westerbaan: Spin it, but it's important to get an obvious option.

[00:44:30] Stephen Farrell: Okay. And again, just so so, yeah, I think you yeah. I think it's a fair point. You want a very you want it to be somehow very clear which one we're encouraging everybody to implement. Yeah. And for you, is that the the hybrid one?

[00:44:43] Alicja Krenska: Or I

[00:44:44] Bas Westerbaan: don't I don't care.

[00:44:44] Stephen Farrell: You don't care? Okay. Great.

[00:44:45] Rich Salz: Thank you. I I will jump the

[00:44:47] Stephen Farrell: queue now. Yeah. Yeah. Wait. You're actually you're on the queue.

[00:44:50] Deb Cooley: I am. But I'm gonna jump, Sophie. So not really, but, you know No.

[00:44:54] Bas Westerbaan: You're actually on top.

[00:44:55] Deb Cooley: Yeah. So read your charter. The charter says there has to be two interoperable implementations. Right? So whatever you pick, you have to be willing to implement it at least twice. Right? And it has to be interoperable. So think about the number of choices you wanna make because you will have to implement it or it won't we can't publish it. Right?

[00:45:19] Stephen Farrell: Yep. Thank you. Sorry?

[00:45:24] Sophie Schmieg: So, I have a fairly similar opinion to of, like, I would prefer less options. I I like the m l d s a four four at 25519 if if that's the option that you want. Maybe we need multiple sizes. I kinda dislike the fact that multiple sizes are a thing that somehow made it into cryptography, but that's some not something that we can solve here. The other thing that I would like to push back on is, like, the idea that we need strong unforgeability. The number of times that I've seen that strong unforgeability actually matters is, like, very, very low. I would rather have the hybrid that exists today than have a CFG hybrid that may or may not exist before quantum computer exists because they seem to work at similar speeds.

[00:46:26] Stephen Farrell: Okay. So in the chat, I'm not sure if Simon's audio is working. So in the chat, Simon said, I think we want some non MLDSA option as a fallback SLH DSA solves this. So it's but just reflecting from the chart.

[00:46:39] Scott Fluhrer: Mhmm. Obvious questions, you don't like MLDSA. What is it? FNDSA or what?

[00:46:45] Stephen Farrell: Well, no. He he he said SLH.

[00:46:46] Scott Fluhrer: Oh oh, SLH.

[00:46:47] Stephen Farrell: Yep. Tom?

[00:46:50] Tom Jones: I agree with, like, Paul and Sophie. We need to move sooner rather than later. I think that adopting one of each draft, so one pure, one hybrid is able to send a clear signal to people of which direction this working group is going on even if, like, the actual text wordsmithing takes a little bit longer. I think it's possible to get to a state where we can have, like, interoperable implementations way before we have RCs, but then people can start working with that. And I think that that will be helpful in sort of the timelines that we would like to see.

[00:47:39] Stephen Farrell: Thank you. So the queue seems to have drained for the moment. So what I was hearing, I think, was more or less what's on this slide

[00:47:52] Dmitry Belyavskiy: Mhmm.

[00:47:52] Stephen Farrell: In terms of calls for adoption. So and Mhmm. There will, I guess, be subsequent discussion, which will probably be inevitable about lengths and about strong affordability. I guess we'll just do that on the list, or do we wanna talk about it more today? So and then there's the question Bas raised about we should have a I know the people have kind of echoed that we there should be one thing that we clearly prefer, and we should figure out whatever mechanism that is to do that, whether it's a text in there or in the drafts or there is Diana kinda column, but it's not that clear maybe. So we need to we should do people agree we should have have one signature choice that we're strongly preferring? John, yeah?

[00:48:41] John Mattsson: Yeah. John Proton. I I strongly disagree that we should spend time. I think it will be a huge long discussion that will never end. So I think we should absolutely not spend time on choosing a recommend. Just just standardize both and let the market choose. Yeah.

[00:49:10] Rich Salz: Queen Dang at this. I understand what Bass wanted. That's something nice. You know, the there are some customers that really wanted the some guidance about, you know, which one I pick. But I I I hope we don't have to go over the the fight you we just had the last year again. Yeah. And and if we if we want to do this, potentially, it will happen again. And even even takes yeah. It would delay everything, and then it would it would kill me one more time.

[00:49:51] Stephen Farrell: Okay. So mhmm. Rich?

[00:49:57] Rich Salz: If we yeah. I'd adopt both of these drafts and let the market decide.

[00:50:03] Stephen Farrell: Mhmm. Yeah. Are you going to the microphone,

[00:50:12] Damien Miller: Bob? Yeah.

[00:50:19] Bob Beck: Bob Beck, many things. I think, you know, when I say that that that, you know, there should be one choice, I think you're looking for that. There's guidance for what people wanna use, and there's guidance for implementers. I will remind you that I think having alternative specified but that everyone is clearly implementing, SSH has a history of having alternatives available at any one given time so that later on when five, six, ten years down the road, there is some sort of flaw found, whether algorithmic or in the implementation, and the old clients have this, it is, hey. That's okay. There was this one. Just use that for now, and you get through it.

[00:51:00] Stephen Farrell: Okay. So I guess I I guess I heard two things. One is, you know, make one make it very clear we wanna pick one, and the other one is, you know, do two or and let the market decide. So I I'm hurting both those things.

[00:51:10] Scott Fluhrer: I think it's not one. It's one direction. It's not not one algorithm. Mhmm.

[00:51:14] Stephen Farrell: So Bob said one direction, not one algorithm.

[00:51:19] Job Snijders: I'm I'm hearing pick two.

[00:51:21] Stephen Farrell: Yeah. No. But I'm hearing specify two, but I earlier heard Yeah. Be very clear that what we want people to do now. I mean, I also heard the opposite of that. So oh, who's back? Thank you for being able to help with this.

[00:51:37] Bob Beck: I I'm back again. And be clear when I say more than one, I do not mean parameterized algorithm soup. Sure. I live in parameterized algorithm soup hell. We should never do that again.

[00:51:49] Stephen Farrell: Right. We don't yeah. So we don't want the 18 lamps choices. Right?

[00:51:52] Job Snijders: Yes.

[00:51:56] Stephen Farrell: Okay. So so I think the it's a bit ambiguous as to in my head as to whether Mhmm. The working group want to kind of anoint one as the thing to do now or not. There's the strong affordability issue, and there's the issue of lens. We don't need to we probably won't finalize this discussion in any quick way, so it'll be on the list,

[00:52:16] Job Snijders: I guess.

[00:52:17] John Mattsson: Yeah. I I think the there seem to be majority want two, and then I think we can have a interim meeting for everybody that wants to discuss, which should be preferred, and that would probably not lead anywhere. But we can delay that problem until later.

[00:52:37] Stephen Farrell: Okay. Yeah. Yeah. Maybe we'd organize an interim meeting when we if if if there's two things that people are happy to adopt and work on, and then we can do an interim meeting for everything else. That that might kinda help. Does that sound like we've done this without a 100 emails? Mhmm. Okay. So the the upshot is we'll does anybody care which the pure draft we proceed with, or should we just talk to the authors and see what they think?

[00:53:09] Scott Fluhrer: Yeah.

[00:53:10] Stephen Farrell: We'll talk to the authors and see which which of the drafts we'll actually say is up for adoption. And then I guess it's Damian's one for the the hybrid one. Yeah? Okay. We have a plan.

[00:53:27] Rich Salz: We have a plan. Magic.

[00:53:31] Stephen Farrell: Did you wanna go back and talk about more drafts now, or do we want to do Dimitri and Alicia? Let's let's let them go go down. Dmitry. Do you wanna go down? Yeah. Because it's semi related. I take away the clicker. Take away the slides. Add slides. No. These two things are good. I'm gonna add the clicker in one second.

[00:54:00] Dmitry Belyavskiy: So we are let's say, Krenska from Red Hat. We want to represent the results of Hackathon. Our Hackathon participation was supported by European grant project work. We're interested in providing post quantum capabilities to protocol in various configuration. So our topic covered two drafts. First is adding JSS API key exchange with hybrid ML-KEM, and the draft by will cover it in next slides. And the second stage support for pure MLDSA, we relied on Scott draft, but they are both identical. So Alitza, please.

[00:54:45] Alicja Krenska: So with GSS API, the situation is that the, basic authentication is using Kerberos, so it is, quantum secure. Unfortunately, it is used only to authenticate the key exchange. So if the key exchange itself is not quantum secure, the whole the whole key exchange is also not secure. The solution is, of course, just to switch from classical crypto to post quantum crypto. So just swap the primes to, like, the the curves to the hybrid kexes that we already have defined, and the specification is is there. So that's basically it. We have implementation in for OpenSSH and for DeepSSH. We also have ready to use container that you can just run and see how how they behave. There are three options there as we have three PQ transist traditional kick changes. And I think that's basically it. Yeah.

[00:56:01] Dmitry Belyavskiy: For MLDSA, we are aware of four, at least four, open source implementations. One is downstream implementation for OpenSSH. One is also downstream implementation for Label SSH. There is also Python per Python implementation, I think, SSH and implementation of OKS provider. So for implementations, they verified against each other. To to some extent, we did not manage to test against Scott Cisco station implementation, unfortunately. But, again, here, the link for container, feel free to experiment. We did testing on the wire. We did not try to cover the full metrics, but the report we got, either in private or in public issue on okay. It's a say repo confirmed that we have compatibility on all the implemented algorithms. We have one open question that is not covered by Scott draft. How do we which formats for private key we have? Yeah. So we can have because I say it format, we can use SIP, which is used, for example, by Damian in his implementation of hybrid. We can allow both. So so well, it's a question that should be covered by any draft, and I my personal opinion that we should support both seed and expanded format.

[00:57:50] Stephen Farrell: Okay. Thanks. I I think you'll have some some discussion about seeds. Scott?

[00:57:56] Scott Fluhrer: Oh, we're done. Yeah. My question was, of course, because as I'm the I'm in charge of the draft. What sort of private key format? You just said that you wanted both, which is yeah. We we could do that. That's annoying. I'd like to my opinion is just to seed, nothing else. But if that doesn't work for you guys, that's that that's fine. That's good feedback.

[00:58:27] Dmitry Belyavskiy: Well, people still tend to generate the OpenSage private keys using OpenSSL. Yeah. I I understand that it may be a behavior far from perfect, but we can't get feedback from the external format. And I think No.

[00:58:47] Scott Fluhrer: Actually, no. I do not believe you can convert the extended format back into Yes.

[00:58:51] Dmitry Belyavskiy: Yes. Yes. Yes. We can. We can.

[00:58:54] Stephen Farrell: So that's why I see a lot of people in the chat saying seed Mhmm. In capital letters.

[00:59:00] Dmitry Belyavskiy: I'm not against the having seed, but currently, it's a gap in all in the draft we were implementing. If it will be seed, it's okay to have seed. Okay.

[00:59:13] Scott Fluhrer: Question for the for the for the mailing list. Is there anybody who cannot live with t seed format? I'll follow that up with an email.

[00:59:24] Stephen Farrell: Okay. So I I I forget I Stop.

[00:59:27] Job Snijders: Stop. I'm feeling a bit dumb here. What is seed?

[00:59:30] Stephen Farrell: It's a it's a it's how you generate the private key. Yeah. There's you know, as in everything, there's multiple choices, and they're a pain in the ass.

[00:59:38] Rich Salz: And the fact

[00:59:40] Alicja Krenska: Basically basically, like, you you basically, it's like you start with a seed as just, like, with any RNG, and then you use that to generate the key to a private key, which is, like, one and a half kilobytes long. So, like, either you store the 32 bytes of entropy that you needed to generate the key or the expanded key. So given the the key generation is super trivial, like, very fast, so it's easier to just store those 32 bytes and have deterministic way to generate the the private key like that.

[01:00:09] Stephen Farrell: So so can I just I I I forget? Is the private key format in the signature drafts that we have today? No. No. No. Do we want it there, or do we wanna just say Yeah. You do want it there? Yeah. You want it there? Yeah. Okay. So then there's this will be a topic we we'll have to discuss. I know what the right answer is, but I'm not gonna say I I do have one other question. So for PKCS eight, if you did want that, don't you need an OID?

[01:00:37] Dmitry Belyavskiy: So no.

[01:00:37] Stephen Farrell: No. For inside the key format? Is that a private demo?

[01:00:41] Alicja Krenska: Need it because they're already like, then we would just reuse the LAMP's work. So, like, they we would reuse the OIDs that NIST has published.

[01:00:49] Stephen Farrell: So Yes. So you do need an OID, but LAMP has one already.

[01:00:52] Alicja Krenska: Yeah. NICE has published the the OID for it for that. So, yeah, we do have OID for for for pure MLDSA.

[01:01:00] Stephen Farrell: So we're

[01:01:00] Deb Cooley: I have to maybe publish an OID.

[01:01:02] Stephen Farrell: Yeah. So I'm just just checking.

[01:01:04] Alicja Krenska: Yeah.

[01:01:04] Stephen Farrell: If you're using the do have void is there.

[01:01:07] Alicja Krenska: Yes.

[01:01:07] Stephen Farrell: Okay. Great.

[01:01:09] Job Snijders: Can we please call them OIDs?

[01:01:12] Deb Cooley: Yeah.

[01:01:13] Stephen Farrell: Okay. Alright. So I get so the issue of seeds will will come up at some point. It's inevitable. Yep. So Grace, any other comments, questions on the hackathon presentation? Okay. Good to see what happened.

[01:01:31] Alicja Krenska: I mean, I do have kinda question. How bad would it be for proposing of adoption for the GSS API

[01:01:41] Deb Cooley: Oh. Hybrids? Okay.

[01:01:44] Alicja Krenska: Is there someone that is very opposed to

[01:01:47] Stephen Farrell: Can you go back to this? Go back to the slide and remind them. How many people remember what GSS API is? I'm I'm curious. Not not not a huge number. So, you know, it's a it's a relatively I was gonna say ancient. That's all. That's okay. So so there's a few people in the room know what JSON API is, some some won't.

[01:02:14] Alicja Krenska: So JSON API is the generic way to plug something in, and in 99% of cases, that something in is just Kerberos. So you first get a ticket, from the Kerberos. The server has their own identity and is registered with, with its principle. And then you can use Kerberos to identify the server, know how to talk with it, how to interpret the the authentication, cookies that it gives you. And this way, you can skip the whole thing with, trust on first use for host keys. Because, like, you have a trusted third party that certifies essentially that, yes, this is who they claim to be. That is the the server that is part of the domain that you also trust, and therefore, you can use those cookies to authenticate the the key exchange. So yeah. Just cover us, basically. That's how you need to think of it.

[01:03:21] Stephen Farrell: So I'm not seeing a huge I I I guess the question there will be, are there gonna be multiple multiple implementers? Do, you know, do we think that's never gonna happen, or is it possible to happen? And we I we probably need to find that out on the list.

[01:03:32] Job Snijders: Catch it off and find out.

[01:03:33] Stephen Farrell: Yeah. But that would be good. We I think

[01:03:35] Alicja Krenska: we do have two implementations already.

[01:03:39] Scott Fluhrer: That's not

[01:03:40] Job Snijders: independent. Yeah. Not speaking as chair, just as interested party. Mhmm. In the abstract of GSS-API key exchange, you mentioned extend the method for ML-KEM of hybrid KX. But we we have basically two RFCs within three months that that have a CACs that is PQ. So does it make sense to do both the PQ CACs methods in this draft for GSS?

[01:04:12] Alicja Krenska: Oh, well, the thing is that, like, I'm basically just well, the algorithm that you are advertising on the wire is GSS API dash and then key exchange type. So we need the call points. And the call points are different for GSS API than for regular kegs. So that's why you have the draft in the first place.

[01:04:37] Deb Cooley: Can I are you doing this in Kerberos?

[01:04:40] Alicja Krenska: Like, we are no. No. No. No. No. The Kerberos part is, completely untouched. Like, we don't care about, like, how the Kerberos part works. We are using very high level API, that allows us to to use it, and the Kerberos side doesn't even know what it's doing. Is

[01:04:59] Deb Cooley: this applicable to kitten?

[01:05:01] Alicja Krenska: To kitten? No. I don't I wouldn't say so. Because, like, the what we need for this stuff to work Yeah. Is a way for the client to advertise that it can do Kerberos authentication of the service identity, and this is on SSH level. So we need identifiers that are sent in s s by SSH client. Okay. Code points. We need code points.

[01:05:27] Deb Cooley: Okay. I I just have always seen GSS API and association with Kerberos. Yes. Yes. Which is kitten. Right? So Yep. Yes. Which is still active,

[01:05:36] Stephen Farrell: by the way.

[01:05:37] Deb Cooley: Yes. Yeah. I Sort of. Right.

[01:05:38] Alicja Krenska: We're not doing anything with to the Gerberos side. We are just, like, saying how you use Gerberos with SSH in a way that is post quantum safe.

[01:05:49] Stephen Farrell: But I I think you chatted with did you chat

[01:05:51] Job Snijders: with Alexi about this? Or With who?

[01:05:53] Stephen Farrell: Alexi, the chair of Kitten?

[01:05:55] Alicja Krenska: Yes. Yeah. I know. We did we did chat with with him yesterday, with Alexi.

[01:05:59] Stephen Farrell: So so Alexi is who's the chair of Kitten is aware of this.

[01:06:02] Alicja Krenska: Yeah. Yeah.

[01:06:03] Stephen Farrell: Just just so we know. Okay. So I think the thing to do with this will be, at some point, if you think you want it to be adopted, you ask us. We'll ask the list, and we'll see what happens.

[01:06:13] Alicja Krenska: Okay. Thank you very much. Okay.

[01:06:18] Stephen Farrell: So now it's back to your slides. Take the clicker.

[01:06:32] Job Snijders: So we have twenty five minutes left. That's not bad.

[01:06:36] Stephen Farrell: Well, we got through the signature thing. Yeah. Sorry. We talked about the no. Sorry.

[01:06:57] Job Snijders: Yeah. This is the final slides on documents related to our working group that are not adopted by this working group. I don't know much about these.

[01:07:20] Stephen Farrell: So so I so was the first one the CS enabled? Or These

[01:07:23] Scott Fluhrer: are both the hybrid switch to our hybrid versions of them all. Yes. I

[01:07:30] Stephen Farrell: No. The first one says key exchange.

[01:07:32] Scott Fluhrer: Oh, key exchange. Correct. Never mind.

[01:07:33] Stephen Farrell: The first one's the pure Yeah. Yeah. So but is it was that part of CSNA or not? I can't

[01:07:40] Scott Fluhrer: remember. Yes.

[01:07:42] Stephen Farrell: I Yeah. So I think that first one won't be our business because it'll be going to the independent submissions elder. So we don't need to talk about it.

[01:07:50] Job Snijders: Alright. We'll mentally strike through the first one.

[01:07:53] Stephen Farrell: The second one, we just discussed. We talked about. Yeah. And then the Sphinx is Like another signature. That's the which we just talked about. This slide is done. K.

[01:08:03] Job Snijders: You can nice.

[01:08:04] Deb Cooley: Click

[01:08:04] Job Snijders: her. Click. Damien is in the queue.

[01:08:10] Damien Miller: Yeah. I guess, Simon well, Simon's mic's not working. I'll be using to look here. He he mentioned a couple of times that having a having a non MLDSA signatures signature scheme for SSH might be a worthwhile fallback as a as a PQ or as a PQ fallback. And this is like SLHDSA is the obvious choice at the moment.

[01:08:40] Stephen Farrell: Yeah. So so I I I think as a result of the other discussion, I think the plan would be roughly we'll try and do the calls for adoption for the signature drafts that people are most pressingly interested in, and then we'll organize an interim meeting at which we can consider lengths and strong affordability and things like SLHDSA. So we'll try and get the the stuff people wanna get done more quickly out of the way first or at least on the on the path first, and then we'll have an interim meeting where we can discuss things like SLHDSA or additional lengths of combiners or whatever. That all all of those kind issues can come up then. So they're after we've I think after we've gotten adoption for the signature things people want most pressingly. So hopefully, that that's that's reasonable from Simon and your your point of view, Damien. In so you're at the end of your slides?

[01:09:36] Job Snijders: Simon is typing a message.

[01:09:38] Stephen Farrell: Okay. Sorry. So so,

[01:09:42] Job Snijders: Simon, I recognize that that people who have working audio have a three d printer in the back, but you don't. So is there any correlation?

[01:09:50] Stephen Farrell: So Simon Simon says, I guess nobody cares about hybrid soft CMA for MLDSA then. Well, I think John does. Yes. John confirms that John does care about that. And so that will be discussed, I guess, as we adopt a hybrid signature format. So we'll we'll make John happy. We'll make John unhappy or something else.

[01:10:23] John Mattsson: John? Yeah. But if we I think my opposition to malleable signature is softened if we also adopt, like, pure MLDSA and or pure SLHDSA, which are not malleable. Okay. So yeah.

[01:10:43] Stephen Farrell: So we might make you moderately unhappy, but no worse.

[01:10:48] Deb Cooley: Yeah.

[01:10:52] Stephen Farrell: Okay. And then yes. Okay. I think we're at the any other business point of the agenda. Yep. So does anybody have other business either here in the room or in online?

[01:11:05] Job Snijders: Are there any to do items that you're waiting on from the chairs and that we somehow forgot because our memory is malleable? Who is

[01:11:17] Stephen Farrell: the calling? Seemingly not.

[01:11:20] John Mattsson: For adoption.

[01:11:22] Stephen Farrell: So we mentioned having an interim. It'll I think we'll get the calls for adoption and the working class call stuff done first, so the interim might be more likely later in the year, not not September, but maybe a bit after. Terrell?

[01:11:35] Tero Kivinen: Terrell, I think I did promise this earlier, but I have completely forgotten it and did something. But we first talk about the file transfer, and I think we actually do be publishing that one. And I was promising to make, you know, version of that, but that's a v six and v three in in the same draft. And I will be working on that, and I hope we'll get that one done because it's that's one of the biggest things that we haven't standardized, which is very widely in use. Sure. Both the v six and v three version of that.

[01:12:06] Stephen Farrell: Great. Thanks. So so that's waiting on you to kind of get the edits done, and then you'll come back to the list and say it's

[01:12:12] Job Snijders: So so, actually,

[01:12:14] Tero Kivinen: the question is, should I just publish a new version of the draft, or should I just try to ask, you know, you know, pro proportional changes or whatever? Because current draft is written by I don't know who is outro.

[01:12:28] Stephen Farrell: So the question was, should he publish should he just publish a new update to the draft, or should he ask on the list

[01:12:33] Tero Kivinen: and the list? Publish it as a new name with or or just, you know, replace the current one. But it's going to be there's going to be changes quite a lot on the, you know, because I need to add, you know, stuff for for from v six and v three.

[01:12:45] Job Snijders: And with the current one

[01:12:47] Tero Kivinen: The current one now only has

[01:12:49] Stephen Farrell: a v three. But, like, you're you're you know, it's gonna cause trouble anyway. Yes. So And

[01:12:55] Bas Westerbaan: I want to I want to have

[01:12:56] Tero Kivinen: a v six because that's actually one of the things that they are used by the non Unix operating systems.

[01:13:01] Job Snijders: Sure. What are those?

[01:13:03] Tero Kivinen: You know, Windows mainframes, IBM mainframes, you know, all that that that kind of things. You know? The things that actually run the world.

[01:13:11] Rich Salz: Sure. You know, all the banking systems Okay. Okay. We None

[01:13:13] Tero Kivinen: of them usually do.

[01:13:14] Stephen Farrell: Yeah. Yeah. Okay. I my suggestion, unless people wanna and if people think it's wrong, then go ahead and correct me. But my suggestion would be to fire ahead and push out a draft. Drafts are, you know, they're not objectionable. They're they're not cheap necessarily in terms of effort. But I think, you know, there's gonna be discussion and trouble anyway. Not trouble. But there be some disagreement on what to put in, what's not put in. I think you may as well shoot out a draft, and then we can have the disagreement as opposed to trying to just disagree and then not have a draft. Alright. That's my suggestion. If people have other opinions, then knowing that will be good. I don't see any other opinions right now in the chat or in the room. So when Terrell gets to pop pop that out, then we'll come back to it. Yeah. Okay. Any other other business? Not seeing anything? I guess there's probably some coffee somewhere in the world with no sugar, and we'll see you guys next time. Thank you.

[01:14:12] Job Snijders: See you in San Francisco. Thank you for your time.

[01:14:18] Stephen Farrell: Thanks, Mitch, for taking notes as well.

[01:14:38] Job Snijders: Nice. Alright. It's very rare. Those working groups end a little bit earlier.

[01:14:44] Stephen Farrell: Oh, man. Too bad.

[01:14:47] Job Snijders: Okay.