Re: [core] Eric Rescorla's Discuss on draft-ietf-core-coap-tcp-tls-08: (with DISCUSS and COMMENT)

Adam Roach <adam@nostrum.com> Wed, 24 May 2017 01:22 UTC

Return-Path: <adam@nostrum.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7972312EB05; Tue, 23 May 2017 18:22:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.481
X-Spam-Level:
X-Spam-Status: No, score=-0.481 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RP_MATCHES_RCVD=-0.001, T_SPF_HELO_PERMERROR=0.01, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qLb_0ea-UWWC; Tue, 23 May 2017 18:22:44 -0700 (PDT)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A4011279EB; Tue, 23 May 2017 18:22:44 -0700 (PDT)
Received: from Orochi.local (99-152-146-228.lightspeed.dllstx.sbcglobal.net [99.152.146.228]) (authenticated bits=0) by nostrum.com (8.15.2/8.15.2) with ESMTPSA id v4O1MXs5004052 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO); Tue, 23 May 2017 20:22:34 -0500 (CDT) (envelope-from adam@nostrum.com)
X-Authentication-Warning: raven.nostrum.com: Host 99-152-146-228.lightspeed.dllstx.sbcglobal.net [99.152.146.228] claimed to be Orochi.local
To: Brian Raymor <Brian.Raymor@microsoft.com>, Hannes Tschofenig <hannes.tschofenig@gmx.net>, Carsten Bormann <cabo@tzi.org>, Eric Rescorla <ekr@rtfm.com>
Cc: "core-chairs@ietf.org" <core-chairs@ietf.org>, The IESG <iesg@ietf.org>, "core@ietf.org" <core@ietf.org>, "draft-ietf-core-coap-tcp-tls@ietf.org" <draft-ietf-core-coap-tcp-tls@ietf.org>
References: <149411155754.23175.15150224037348429928.idtracker@ietfa.amsl.com> <A1046D25-8D1A-4267-9705-16624E727D35@tzi.org> <28837957-421a-eeff-8304-cfafb80ca234@gmx.net> <BY2PR21MB0084BB12DF9C5C684857AD9F83FE0@BY2PR21MB0084.namprd21.prod.outlook.com>
From: Adam Roach <adam@nostrum.com>
Message-ID: <2ba93ff7-c2f2-c5e4-cd67-0f7c1d412051@nostrum.com>
Date: Tue, 23 May 2017 20:22:28 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:52.0) Gecko/20100101 Thunderbird/52.1.1
MIME-Version: 1.0
In-Reply-To: <BY2PR21MB0084BB12DF9C5C684857AD9F83FE0@BY2PR21MB0084.namprd21.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/cTACaTWN9zGaxEV4tmf_rb2RzOg>
Subject: Re: [core] Eric Rescorla's Discuss on draft-ietf-core-coap-tcp-tls-08: (with DISCUSS and COMMENT)
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 01:22:45 -0000

On 5/23/17 20:11, Brian Raymor wrote:
>      I can give you the motivation why we are interested in CoAP over TLS /TCP. We have an existing implementation of LWM2M,
>      which uses CoAP. We spent a lot of time getting that implementation rock-solid. Some enterprise deployments, which happen
>      to have interesting firewall policies, do not allow us to use UDP. Hence, we were interested to add a TCP-based transport to CoAP.
>      Making this enhancement turns out to be reasonably simple.


I'll note that the rationale for using WebSockets for this purpose 
appears to be significantly less clear, and the combination of TCP and 
WebSockets into a single document even more so.

/a