Re: [Emu] I-D Action: draft-ietf-emu-eap-tls13-09.txt

John Mattsson <john.mattsson@ericsson.com> Tue, 10 March 2020 06:01 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD85C3A079F for <emu@ietfa.amsl.com>; Mon, 9 Mar 2020 23:01:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AZGFqn69eVjx for <emu@ietfa.amsl.com>; Mon, 9 Mar 2020 23:01:53 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-eopbgr70057.outbound.protection.outlook.com [40.107.7.57]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B0C83A07A4 for <emu@ietf.org>; Mon, 9 Mar 2020 23:01:52 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EaajeZsFxrgnQtwY95uGayHQ8mprLekrIzex1joXM+rRZidOCea4KQwR6yq2YQpjTetg3V11huiVKIeKIKHnZdji++btTSL5j0fpZYFWE3bo19KQq24Ke1XCxes56MRsk8goZNnXP7KQmbYNzuxASrPsPgLKnb2VLXB4mI/mMBykBM2O5TZQv0ZOAbYdmm5MqHBSe+tXi73/dOx9+guwoRnOEc3vPE7QJfzot/G+lEqvAsGNHF7qGEL5X6gfljV/I4ZaU0zsE1eClKHk2eYJn2BkhWCT4nKS/GhxTC9LVrgU0Qwaq8u+jwzw/xhEAGn6HmkANjKCN0iEPGoK42qbSw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=JYr9clDc497R1S5h7HYLMFwU5Nwp880BhZ1sA6o4TAY=; b=ULc9aA6FHep1kUSp/vi67xnnz9Pdm7EVl+pQOL1Z3znEjKOehGo50Ow4HibaGnZUovSpik0GwmDcmPx9Z+xLHk9mG8pYapalp+KBJrIq7EMBNoDPunFDJz5N43IqOnQkXA38i7D0VQjhqZ5HihtecIsk5zO4P9Ca9EW8vyX+vNPszdg9qbIo+bkv7Z7PoF/9LnVZnu3IOVlcCWoK0HL5HtlBSzaXuLyWGUbZTFxa4dfYFCyc/u+QjVpm4uCp4w3hOF5J434l5N8CeFZ9t/JIJl0Vr76FSCOpRGhPTok69R6Eew5N907Zv2wlNPCsHIptu2Poab/pB1fukO/L7YrD7A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=JYr9clDc497R1S5h7HYLMFwU5Nwp880BhZ1sA6o4TAY=; b=IjRgWSOObIvq++2iUwf7ZfNap6ljOsX4FEQJR/FN39tabOJttpbwC2XS9cFFj4zlW1HSnBrWvuEls1cqURWlfIwFgoCXi/zUOYQt33akj1Fd2dwHwIxwZ/WRyXMzN8tSPmt/rz5JBmMAT3zDsl2CY1HiRuSBK+IRXvXCKHweb5k=
Received: from AM6PR07MB4134.eurprd07.prod.outlook.com (52.134.114.155) by AM6PR07MB3861.eurprd07.prod.outlook.com (52.134.112.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2814.9; Tue, 10 Mar 2020 06:01:50 +0000
Received: from AM6PR07MB4134.eurprd07.prod.outlook.com ([fe80::501f:822f:f9b5:eb71]) by AM6PR07MB4134.eurprd07.prod.outlook.com ([fe80::501f:822f:f9b5:eb71%7]) with mapi id 15.20.2814.007; Tue, 10 Mar 2020 06:01:50 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "emu@ietf.org" <emu@ietf.org>
Thread-Topic: [Emu] I-D Action: draft-ietf-emu-eap-tls13-09.txt
Thread-Index: AQHV9jv2NaNJBzOwSEyO/AoztQ3Jj6hBZxIA
Date: Tue, 10 Mar 2020 06:01:50 +0000
Message-ID: <7B6205E6-C9E6-49A9-9187-50966959B698@ericsson.com>
References: <158377649511.5537.12802310754221134462@ietfa.amsl.com>
In-Reply-To: <158377649511.5537.12802310754221134462@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.22.0.200209
authentication-results: spf=none (sender IP is ) smtp.mailfrom=john.mattsson@ericsson.com;
x-originating-ip: [82.214.46.143]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: ccdb8b06-ed75-4d2e-0404-08d7c4b88673
x-ms-traffictypediagnostic: AM6PR07MB3861:
x-microsoft-antispam-prvs: <AM6PR07MB38617EE0D06A8231126B294E89FF0@AM6PR07MB3861.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 033857D0BD
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(376002)(136003)(346002)(396003)(39860400002)(366004)(189003)(199004)(6916009)(86362001)(966005)(91956017)(478600001)(2906002)(316002)(8676002)(66946007)(81156014)(64756008)(76116006)(8936002)(66476007)(66446008)(71200400001)(81166006)(5660300002)(6506007)(66556008)(66574012)(36756003)(6512007)(26005)(6486002)(186003)(33656002)(2616005)(44832011); DIR:OUT; SFP:1101; SCL:1; SRVR:AM6PR07MB3861; H:AM6PR07MB4134.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: fSaOjFjhmgJRQNRX+EOkAMAuUWbVJoFzu4wteCqiYX8WgOqeR2kdBCJJa738IjeBllqCd0XLNGOMGhO3QLUKJhImnoCEBd17diHEmf0XGd1l/5UPcAZzvnqjnWE2Xt3FJtnuO3rcMzeFb1U1vE0IUxaB7QIwI27P+a/Mvdmz8Of1ypLDvI/lzOpOwdHUPeDca+D7mfIo3lSibaYiEQIZmhR1Tya1brRstA8dfcLCQrZmcRueX2SHTSQ7U4u5yrG2j4oV/Euzbr/Fe6uorGMuSm+glueZVY/hMGJa69FKqpDfoJHUhPdHrRwdMP1l3uOidm+gqb/l2thOC1i/jv8QkPdrQzd74PGSAjfDGOO+Iw1RtiE7Sqs9micAgssUom1axSqdzfPLU/VjuRnNJaTTYpUFHm9KTQBifiiZnqU2q9ITFVzA+PzfPuDNXYbFRrw/FLCHMNsYlms0Am43dsgH9nyz7symJ58wZ37WxhaYm81oJqoBgVlpTy/Nx9KibKT0w/HqFebEo6dYqnCcbgHtnA==
x-ms-exchange-antispam-messagedata: nkAiX/3Kss8Vg/brKZcvbpM/KDgFFdQ87erUTIY7KQHBKeYUNBXw3ebEJvVte+pBgOqCQ81RBMwDyhOulkNM4WbWv0KqiXtlUpupEqST5EQVjViK7fCbpDuFyv88Nap1ch2w6QlDbDXgdSPWsQpPGw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <4933BCC6D8662540A7EFB49DAD99E34D@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ccdb8b06-ed75-4d2e-0404-08d7c4b88673
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Mar 2020 06:01:50.4336 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ypt7XY28guawC51QdZLkxrnV5O8ZR9pi15IHyJyGbpQBdJOXqJDNDgtOL/S/zI7db3CJzjzmYgcp1Ty5VyIzbOsqeCRGXNxO/gX4E8Si6EI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR07MB3861
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/1S4d5mKilGtotvzn1uAIWgfJ2yI>
Subject: Re: [Emu] I-D Action: draft-ietf-emu-eap-tls13-09.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Mar 2020 06:01:56 -0000

Hi,

- The new version should address all the received comments from Alan and Russ regarding EAP, TLS, and Certificate identities.
  - New section on identities early in the document discussing identities and pointing to other sections discussing identities.
  - More information given on why some identities are prefered over other (routing)
  - More guidance on how to contruct a NAI to use use in EAP-TLS

- I did not include draft-ietf-tls-tls13-cert-with-extern-psk as there at this point is no consencus to do so with Russ suggesting to include it and Bernard previous being stongly against such inclusion.

Cheers,
John

-----Original Message-----
From: Emu <emu-bounces@ietf.org> on behalf of "internet-drafts@ietf.org" <internet-drafts@ietf.org>
Reply to: "emu@ietf.org" <emu@ietf.org>
Date: Monday, 9 March 2020 at 18:55
To: "i-d-announce@ietf.org" <i-d-announce@ietf.org>
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: [Emu] I-D Action: draft-ietf-emu-eap-tls13-09.txt

    
    A New Internet-Draft is available from the on-line Internet-Drafts directories.
    This draft is a work item of the EAP Method Update WG of the IETF.
    
            Title           : Using EAP-TLS with TLS 1.3
            Authors         : John Preuß Mattsson
                              Mohit Sethi
    	Filename        : draft-ietf-emu-eap-tls13-09.txt
    	Pages           : 29
    	Date            : 2020-03-09
    
    Abstract:
       This document specifies the use of EAP-TLS with TLS 1.3 while
       remaining backwards compatible with existing implementations of EAP-
       TLS.  TLS 1.3 provides significantly improved security, privacy, and
       reduced latency when compared to earlier versions of TLS.  EAP-TLS
       with TLS 1.3 further improves security and privacy by mandating use
       of privacy and revocation checking.  This document updates RFC 5216.
    
    
    The IETF datatracker status page for this draft is:
    https://datatracker.ietf.org/doc/draft-ietf-emu-eap-tls13/
    
    There are also htmlized versions available at:
    https://tools.ietf.org/html/draft-ietf-emu-eap-tls13-09
    https://datatracker.ietf.org/doc/html/draft-ietf-emu-eap-tls13-09
    
    A diff from the previous version is available at:
    https://www.ietf.org/rfcdiff?url2=draft-ietf-emu-eap-tls13-09
    
    
    Please note that it may take a couple of minutes from the time of submission
    until the htmlized version and diff are available at tools.ietf.org.
    
    Internet-Drafts are also available by anonymous FTP at:
    ftp://ftp.ietf.org/internet-drafts/
    
    
    _______________________________________________
    Emu mailing list
    Emu@ietf.org
    https://www.ietf.org/mailman/listinfo/emu