From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Noam Postavsky Newsgroups: gmane.emacs.bugs Subject: bug#31946: 27.0.50; The NSM should warn about more TLS problems Date: Tue, 26 Jun 2018 08:44:23 -0400 Message-ID: <874lhppviw.fsf@gmail.com> References: <87fu1apchn.fsf@gmail.com> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1530016994 9992 195.159.176.226 (26 Jun 2018 12:43:14 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 26 Jun 2018 12:43:14 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) Cc: Lars Ingebrigtsen , 31946@debbugs.gnu.org To: Jimmy Yuen Ho Wong Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Jun 26 14:43:10 2018 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fXnJM-0002Rd-2n for geb-bug-gnu-emacs@m.gmane.org; Tue, 26 Jun 2018 14:43:08 +0200 Original-Received: from localhost ([::1]:52510 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fXnLT-0006hR-FO for geb-bug-gnu-emacs@m.gmane.org; Tue, 26 Jun 2018 08:45:19 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:49607) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fXnLH-0006hE-7L for bug-gnu-emacs@gnu.org; Tue, 26 Jun 2018 08:45:13 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fXnLC-0000fr-Bd for bug-gnu-emacs@gnu.org; Tue, 26 Jun 2018 08:45:07 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:56073) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fXnLC-0000fn-6v for bug-gnu-emacs@gnu.org; Tue, 26 Jun 2018 08:45:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fXnLB-0005z2-OK for bug-gnu-emacs@gnu.org; Tue, 26 Jun 2018 08:45:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Noam Postavsky Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 26 Jun 2018 12:45:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 31946 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 31946-submit@debbugs.gnu.org id=B31946.153001707422946 (code B ref 31946); Tue, 26 Jun 2018 12:45:01 +0000 Original-Received: (at 31946) by debbugs.gnu.org; 26 Jun 2018 12:44:34 +0000 Original-Received: from localhost ([127.0.0.1]:35737 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fXnKj-0005y2-Pr for submit@debbugs.gnu.org; Tue, 26 Jun 2018 08:44:33 -0400 Original-Received: from mail-it0-f44.google.com ([209.85.214.44]:52461) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fXnKh-0005xo-LI for 31946@debbugs.gnu.org; Tue, 26 Jun 2018 08:44:32 -0400 Original-Received: by mail-it0-f44.google.com with SMTP id m194-v6so2094971itg.2 for <31946@debbugs.gnu.org>; Tue, 26 Jun 2018 05:44:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=dv4fyfgkxg5cp1/8VeioF1Cy5wGjR/1Y9ix503OZ0IM=; b=S64od94+C3+MhqiKxUWicQXkspEiPEEo6ppN0HSuI2rtUXjjAJTXqs0IMJpVtT5hSN UH0NEVivKRD9McVA67k8VMV9/TwBkpRtoE6YU91d3ls7zXNfAbdkFkNydoPkcrHgKsKW bzOv4Fya0zpPYuVDlCivamunf3dSy5u4Bgj7Jrdms2fIOjiDN/1xAFkwAr7mfZZGA6f1 GyhRLcGtLt4PMQGpD6PMb0UUuau7QEH/7zVQbDdp6uqxpJFRxlH9YVvXIQbcsZ3EgpMS zrSBqye1vGduGvoKqPRuW8xpuFIUTHEgxmfsoABBCf+PNkdOLHff7Jl++KP3KQLuSY5r TQZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=dv4fyfgkxg5cp1/8VeioF1Cy5wGjR/1Y9ix503OZ0IM=; b=E1sz48bTaga/WFam8PbreTBaihChV2JdpRvxSceYHlcX8hzcpWIwnmgj9FTX1jYEfv BpiHaEX8V3FRe9dPMmlIXcd7EkPW1fp5E3DYKGoLBMHB7+1QpkRZJCekq/xd7Cy8HVsJ HYUZIgo9H9fudItrRVDrOYtFj3WChgSdXwuECtZ+L9FUIf8sPazZRToJ5UIgyt/efTFD mSmym9zTzZmyjZyiTwm/onmKGWtxvu1mBlgDEIoQ8EBKKliTy0Ze/6YcrbrQF8Id/eLk 3Hse+MvpC5G5DlkzRlp/qS8Esmy7ZwQN0xWuMgdUH0LPWDD0GQOPBlYconT7fiqrk443 g6Ng== X-Gm-Message-State: APt69E3X+QJLh2beXXY3/BpmkgcUbI8jVm4vWMb+NzH/kGCGKzPtBGzL izxlqrcAFyqcsy4XbZYHD6/pxQ== X-Google-Smtp-Source: AAOMgpe0RtOvN542iSdpoN8mgXmEckuAwrWgVMaCuX/s++j3qg+cN70fHwjyuV8EJOJ+vYY6VW2GBA== X-Received: by 2002:a02:4b84:: with SMTP id q126-v6mr1146879jaa.130.1530017065957; Tue, 26 Jun 2018 05:44:25 -0700 (PDT) Original-Received: from zebian (cbl-45-2-119-34.yyz.frontiernetworks.ca. [45.2.119.34]) by smtp.googlemail.com with ESMTPSA id l142-v6sm506379itb.21.2018.06.26.05.44.24 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Tue, 26 Jun 2018 05:44:25 -0700 (PDT) In-Reply-To: (Jimmy Yuen Ho Wong's message of "Tue, 26 Jun 2018 07:26:20 +0100") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:147833 Archived-At: Jimmy Yuen Ho Wong writes: > 4. For dh-small-subgroup and dh-composite, the only way to check this in > LISP seems to be to supply `:min-prime-bits 2048` to > `gnutls-boot-parameters`. It only blocks dh-composite, not dh-small-subgroup for me. And I think that's just a coincidence: dh-composite.badssl.com site sends a 2047 bit DH "prime" while dh-small-subgroup.badssl.com sends a 2048 bit DH prime. But it's certainly possible to send a 2048 bit composite as the "prime" which would wouldn't be blocked either. I would guess the 2047 bit parameter was intended to be 2048, but the top bit just happened to generate as 0.