Re: [Ace] Review Comments on -03

Jim Schaad <ietf@augustcellars.com> Tue, 31 July 2018 14:38 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7778A130FF4; Tue, 31 Jul 2018 07:38:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level:
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iriE3AN0XA9I; Tue, 31 Jul 2018 07:38:45 -0700 (PDT)
Received: from mail2.augustcellars.com (augustcellars.com [50.45.239.150]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A960F130FB5; Tue, 31 Jul 2018 07:38:43 -0700 (PDT)
Received: from Jude (73.180.8.170) by mail2.augustcellars.com (192.168.0.56) with Microsoft SMTP Server (TLS) id 15.0.1347.2; Tue, 31 Jul 2018 07:35:02 -0700
From: Jim Schaad <ietf@augustcellars.com>
To: 'Olaf Bergmann' <bergmann@tzi.org>
CC: draft-ietf-ace-dtls-authorize@ietf.org, 'ace' <ace@ietf.org>
References: <00dc01d41c9e$af8ad9b0$0ea08d10$@augustcellars.com> <87va8vfwbr.fsf@tzi.org>
In-Reply-To: <87va8vfwbr.fsf@tzi.org>
Date: Tue, 31 Jul 2018 07:38:34 -0700
Message-ID: <05e801d428dc$2ae2cd90$80a868b0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQISnfGbyY4/fVbcu1WJoEsmubpuZwGgCwxIpB972eA=
Content-Language: en-us
X-Originating-IP: [73.180.8.170]
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/HMDpZBDZD5MfTF8y1WTEeU3spLc>
Subject: Re: [Ace] Review Comments on -03
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 Jul 2018 14:38:51 -0000

No, I do not believe that you should disallow TLS 1.2 as it is going to be here for quite a while still.  I don't believe that we should be documenting how to use TLS 1.2 features that are not being carried forward.

Jim


> -----Original Message-----
> From: Olaf Bergmann <bergmann@tzi.org>
> Sent: Tuesday, July 31, 2018 5:01 AM
> To: Jim Schaad <ietf@augustcellars.com>
> Cc: draft-ietf-ace-dtls-authorize@ietf.org; 'ace' <ace@ietf.org>
> Subject: Re: [Ace] Review Comments on -03
> 
> Hi Jim,
> 
> Thank you for your detailed review and good comments. I will come up with
> proposed changes within the next days.
> 
> One thing is not clear to me, see below:
> 
> Jim Schaad <ietf@augustcellars.com> writes:
> 
> > * Section 4.2 - Remove everything to do with renegotiation of TLS - It
> > is no longer present in 1.3
> 
> I understand that you want a protocol that works immediately with TLS 1.3, and
> everybody would like every version prior 1.3 to vanish immediately.
> But does this mean that we do not address TLS1.2 in this protocol at all?
> 
> Grüße
> Olaf