[Dance] Re: [secdir] Re: draft-ietf-dance-client-auth-09 ietf last call Secdir review
Shumon Huque <shuque@gmail.com> Mon, 26 January 2026 15:48 UTC
Return-Path: <shuque@gmail.com>
X-Original-To: dance@mail2.ietf.org
Delivered-To: dance@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4B9AAAD23BBC for <dance@mail2.ietf.org>; Mon, 26 Jan 2026 07:48:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8sx7_Z94wkVd for <dance@mail2.ietf.org>; Mon, 26 Jan 2026 07:48:30 -0800 (PST)
Received: from mail-oa1-x36.google.com (mail-oa1-x36.google.com [IPv6:2001:4860:4864:20::36]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F2148AD23B9F for <dance@ietf.org>; Mon, 26 Jan 2026 07:48:29 -0800 (PST)
Received: by mail-oa1-x36.google.com with SMTP id 586e51a60fabf-4041b3c1fa1so1414270fac.3 for <dance@ietf.org>; Mon, 26 Jan 2026 07:48:29 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1769442503; cv=none; d=google.com; s=arc-20240605; b=Qaipov4bcb2NprDjzQZDCVSBjECfKqlsDWepd7aMrmTFFDzvK3EMma9Amd6QY4q6WP 6J25zZ/fjbiKS4fS4EFTX7ZtF9iiq4204B+X8/QBPaZ20Mwl5oQNYOuQcJrDyr/k1Jds DDFrawGO9dgYfROu3l0ekd6bXgHpu952b6JFjgxdwRyYfHYTH5GotTNHrb6yKw66dB00 ySm+a6a0PmpEek2px8muwNpqnsu9oQkQT2dVPmlF7MZfd+r7JTQo/vzMIX+qxhwx4fGi xMduWjHcy2z4OpOAuh0RqR54QRJhGGjNqB6PDu7EhpwHjZRu9xI859wBbrNrnZSYW1ju pY6w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=28Dm6cLlB7rZS78q1MHbMkN0uSkX1LvTtRfpKf+KpGE=; fh=G48spM3zGdhY3KWwEobcqfh1VAHbfbfg3CZuny1sjz4=; b=YkaLLo/K2Fc09tyvRqTa9lJwunCE2U6hshFUX8R6Py+0rpFxFV6hLhefDTGdbDJthn kk72kBEdrDol0tcgGvMCHvHDgOnVKaGqeIg2gA9gQiT6p8MrYijmd9iSemTNS+W+nyuw GoYp7Tvdeeo8dLpChSmHlvvQzR+zFd4dee1svE0niGVYF4xXTwkhx5ByLX2f3j2aPoMK WXD1660Og4rQef9CxRIy0vahhV6yODreWn5HSqNUZCDcveGa4kSqjOXH/MeUWyJNnO2k HI+rmnFT+f2kKzebmccQ962EDyw7CAMLN/Tl6bylOHFegdxc/9iJgiadF32T3Y6i7rlj VGZw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769442503; x=1770047303; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=28Dm6cLlB7rZS78q1MHbMkN0uSkX1LvTtRfpKf+KpGE=; b=FalAotu/bPlzEXJbvJs8sYhivj+Bw7D9r3ZWHFiznV21dBRZD/W2nt3ujh2Y0QpizW Iz0XSUIt72T0xV4SB7AcibvAyk2EDA+U0nWdLuxtEQN9uAnmsCkfOl3YwBVfQBayUALp S4miXyUE5+q+ukE3O9k07J0/t+EddX8DmtnAoxSkHA8uxYntxN5mKoLlSybnUvjwOZKw Zxr9LNx6zk6F33JkP9qjCk63YXFRmSblAz8V5XYttZOddHssIq7OeCuBSB1IT7RiszvZ iybQvPKj35lQT5B+9nQUIcMnmPjl4JCj3ZbThrnrsNBy8XVgUI32VYVQyR5UteQjdSZD nm8A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769442503; x=1770047303; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=28Dm6cLlB7rZS78q1MHbMkN0uSkX1LvTtRfpKf+KpGE=; b=n6kgs6aOcGumw88bQSlo/mWEblgSQou6kKQ2v3QzNYApo1ZkPbwtkHHYvaGf0TYPCy 9ZfchLGVivR+ACE/xvx+qd9z0BsGXZT7t18MO5X+Cxymepj2/b3K7iX1/1svKj5hcto/ UJpEe2Zb3iMIUbJGZ2JeOnheyCm/HuSH0aVQ21UQBQtFgHnDCkBeh6uG+rs9piXdDTJj iwTdEkruzRa4IH1XOGtS/IglVM4jzjafY6LG/yN24ROaa0R10m/xRj9ZomQqrWYndj04 86+cspskdB1s34U/YwKguT5az6Z8TGBZyNnsvIDqB9c9hW0s8oO0axeHSlRjoGBktHLq LDaQ==
X-Forwarded-Encrypted: i=1; AJvYcCVk4tPws8HxYDQHuwoJe3VVBhCs54tNYabYdqs/e+eY+iCdHLaetaGHqGAmdajvtNAy5nUndQ==@ietf.org
X-Gm-Message-State: AOJu0Yz9lOZSK1wg4YVbD70vsnlP7oA6Z3hYwsbAnIZcbYZUpe+oxAUX 1Y4JC+GIg98BHB4dycDZbeV0tJCTpexdNt2TME0mYi4j+Er8NiCui6uPF4ryfCruWd7VLwfdQp6 dB1AKHKAE34QSnh925tJTrv4E4vltDCk=
X-Gm-Gg: AZuq6aJRl+aZrGBkkjGKE83uq4Elf4c8H8PztJsNku6fnDWx53/K55FoSXjJFJTWnER u5FKcqIe69sE7KW0dTwgQhAd1QEmkZ8Kbcs8OBUT2m4Z4/fHmEbQnoLGdyfMlwAn96U1cWu4IzL sG459Q34xosqlQgKP21FAOmMfYS32lvF/iab7MCsVu1OoxMyQSfdaJbN5lQql8cntmrlciCdafs /TAca0dpvQfP+T2s/+qTtVVat/4ucnahMf6t8e9PlKdNKw/DfKAgtWTwd2nkGxkU0+W11w=
X-Received: by 2002:a05:6870:16f1:b0:3ec:8851:54d2 with SMTP id 586e51a60fabf-408f7f81dc7mr2433034fac.21.1769442503194; Mon, 26 Jan 2026 07:48:23 -0800 (PST)
MIME-Version: 1.0
References: <176590748955.656684.2236400968307216716@dt-datatracker-5bd94c585b-pvtsm> <CAHPuVdXRT4COLoiJ_1uHwgmQ7OpndhVmKmGR9wNoT4SPdEz68g@mail.gmail.com> <MN2PR17MB403116FA633AA9E0A5ED4460CD93A@MN2PR17MB4031.namprd17.prod.outlook.com>
In-Reply-To: <MN2PR17MB403116FA633AA9E0A5ED4460CD93A@MN2PR17MB4031.namprd17.prod.outlook.com>
From: Shumon Huque <shuque@gmail.com>
Date: Mon, 26 Jan 2026 10:48:11 -0500
X-Gm-Features: AZwV_QhmTQ5lCt-HZhHzFw2FvhRtjJSopGW2eZ-Wk3ZtlmnOWnNRiVnJSnZDRco
Message-ID: <CAHPuVdXQjzMvBa2f+b5zk5fK0BjbZ633OLrjTQae2s-++Q0aBg@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: multipart/alternative; boundary="000000000000da7cdf06494c6fe3"
Message-ID-Hash: 54PHM5Q7NDIT5UAHQYEMEKWAC3ZYV5PQ
X-Message-ID-Hash: 54PHM5Q7NDIT5UAHQYEMEKWAC3ZYV5PQ
X-MailFrom: shuque@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "secdir@ietf.org" <secdir@ietf.org>, "dance@ietf.org" <dance@ietf.org>, "draft-ietf-dance-client-auth.all@ietf.org" <draft-ietf-dance-client-auth.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Dance] Re: [secdir] Re: draft-ietf-dance-client-auth-09 ietf last call Secdir review
List-Id: DANE Authentication for Network Clients Everywhere <dance.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dance/uxl3EkZ30TbDYP0LPAfjf_7v8w0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dance>
List-Help: <mailto:dance-request@ietf.org?subject=help>
List-Owner: <mailto:dance-owner@ietf.org>
List-Post: <mailto:dance@ietf.org>
List-Subscribe: <mailto:dance-join@ietf.org>
List-Unsubscribe: <mailto:dance-leave@ietf.org>
Yes, I answered Eric's email this morning too in a separate message. My proposal is to just remove TLS 1.2 from this spec, and am waiting to hear feedback from other DANCE working group participants. Shumon. On Mon, Jan 26, 2026 at 10:44 AM Salz, Rich <rsalz@akamai.com> wrote: > Was there a response to EKR’s that adding new extensions to TLS 1.2 is now > disallowed? (He wasn’t the only one.). If so, please post a link as I > missed it. And his other concerns, too. > > (Posting on this thread since it seems likely the clientID draft will be > merged into this one.) > > >
- [Dance] draft-ietf-dance-client-auth-09 ietf last… Mike Ounsworth via Datatracker
- [Dance] Re: [secdir] draft-ietf-dance-client-auth… Eric Rescorla
- [Dance] Re: draft-ietf-dance-client-auth-09 ietf … Shumon Huque
- [Dance] Re: [secdir] Re: draft-ietf-dance-client-… Salz, Rich
- [Dance] Re: [secdir] Re: draft-ietf-dance-client-… Shumon Huque
- [Dance] Re: [secdir] Re: draft-ietf-dance-client-… Paul Wouters
- [Dance] Re: [secdir] Re: draft-ietf-dance-client-… Shumon Huque