Re: [core] DTLS and Epochs

"weigengyu" <weigengyu@vip.sina.com> Fri, 02 June 2017 00:28 UTC

Return-Path: <weigengyu@vip.sina.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 32D3F12947A for <core@ietfa.amsl.com>; Thu, 1 Jun 2017 17:28:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.812
X-Spam-Level:
X-Spam-Status: No, score=0.812 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_BL=0.01, RCVD_IN_MSPIKE_L3=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AwOpP5cHWN7L for <core@ietfa.amsl.com>; Thu, 1 Jun 2017 17:28:43 -0700 (PDT)
Received: from smtp-6-48.vip.sina.com.cn (r3-63.sinamail.sina.com.cn [202.108.3.63]) by ietfa.amsl.com (Postfix) with SMTP id DE43C129476 for <core@ietf.org>; Thu, 1 Jun 2017 17:28:40 -0700 (PDT)
Received: from unknown (HELO WeiGengyuPC)([114.255.40.63]) by vip.sina.com with ESMTP 2 Jun 2017 08:28:35 +0800 (CST)
X-Sender: weigengyu@vip.sina.com
X-Auth-ID: weigengyu@vip.sina.com
X-SMAIL-MID: 71911265930
Message-ID: <4AAF54CE210B4FB99D4A1BF1F2F7790E@WeiGengyuPC>
From: weigengyu <weigengyu@vip.sina.com>
To: Jim Schaad <ietf@augustcellars.com>, 'Carsten Bormann' <cabo@tzi.org>
Cc: 'Klaus Hartke' <hartke@tzi.org>, core@ietf.org
Date: Fri, 02 Jun 2017 08:28:36 +0800
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"; charset="UTF-8"; reply-type="response"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3528.331
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3528.331
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/G5LH6w15AlPZLwmlU3UQF3ScbKI>
Subject: Re: [core] DTLS and Epochs
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Jun 2017 00:28:46 -0000

Hi,

> Please note - I did not say that the epoch was not changed, I said that it 
> does not tell me that the epoch has changed.
> From a strictly security point of view there is no reason to do so if, for 
> example, the epoch changed just because the key was rolled over.

Why the epoch changed event must tell "me", i.e. the upper layer entity?

Regards,

Gengyu WEI
Network Technology Center
School of Computer
Beijing University of Posts and Telecommunications
-----原始邮件----- 
From: Jim Schaad
Sent: Friday, June 02, 2017 1:45 AM
To: 'Carsten Bormann'
Cc: 'weigengyu' ; 'Klaus Hartke' ; core@ietf.org
Subject: RE: [core] DTLS and Epochs



-----Original Message-----
From: Carsten Bormann [mailto:cabo@tzi.org]
Sent: Thursday, June 1, 2017 9:36 AM
To: Jim Schaad <ietf@augustcellars.com>
Cc: weigengyu <weigengyu@bupt.edu.cn>; Klaus Hartke <hartke@tzi.org>;
core@ietf.org
Subject: Re: [core] DTLS and Epochs

On Jun 1, 2017, at 18:10, Jim Schaad <ietf@augustcellars.com> wrote:
>
> Please note - I did not say that the epoch was not changed, I said that it 
> does not tell me that the epoch has changed.  From a strictly security 
> point of view there is no reason to do so if, for example, the epoch 
> changed just because the key was rolled over.

Right, and the question for me is:  How do we get from the overly
restrictive spec in 7252 to something that is still secure and can be
supported by TLS libraries that are out there.

[JLS] I believe that the only way is to do an update to 7252.  I originally
thought that I would file an errata, but I do not believe that is a correct
use of the errata system.  It is used for things which are unclear or
technically wrong.  This is not wrong, just misguided. It might be easiest
to just do a delta RFC unless there is a good number of errata that need to
be rolled into an updated document.

Jim


Grüße, Carsten