RE: FW: New Version Notification for draft-bishop-httpbis-http2-additional-certs-05.txt

Mike Bishop <mbishop@evequefou.be> Mon, 13 November 2017 16:45 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E06F7129B04 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 13 Nov 2017 08:45:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level:
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=evequefou.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rLCpLvo0tQ3E for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 13 Nov 2017 08:45:51 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F82212945A for <httpbisa-archive-bis2Juki@lists.ietf.org>; Mon, 13 Nov 2017 08:45:51 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.89) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1eEHk9-0008CD-82 for ietf-http-wg-dist@listhub.w3.org; Mon, 13 Nov 2017 16:37:53 +0000
Resent-Date: Mon, 13 Nov 2017 16:37:53 +0000
Resent-Message-Id: <E1eEHk9-0008CD-82@frink.w3.org>
Received: from titan.w3.org ([128.30.52.76]) by frink.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <mbishop@evequefou.be>) id 1eEHk2-0008BE-54 for ietf-http-wg@listhub.w3.org; Mon, 13 Nov 2017 16:37:46 +0000
Received: from mail-cys01nam02on0093.outbound.protection.outlook.com ([104.47.37.93] helo=NAM02-CY1-obe.outbound.protection.outlook.com) by titan.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA384:256) (Exim 4.89) (envelope-from <mbishop@evequefou.be>) id 1eEHk0-0007n5-Qf for ietf-http-wg@w3.org; Mon, 13 Nov 2017 16:37:46 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=evequefou.onmicrosoft.com; s=selector1-evequefou-be; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=t9HiJMfQIyA3UpkVe1SZBLVZqMTThm7szDFzb4DqO4I=; b=QETYaZHKsQxlnEi1C21B5s82x/xdeYOxnEDG/HqkDk/VqjaIKvU6ZG+iSNjjfL+I/chskxCmnC18LvqOWx2jwNXVgQ3XoVBsqJ4THuYUKIBMbBSmcguRRqW8u9GbTRD1JDa2gj6HcJ+res1ywupMgMgnLz0namTpD5Kab0b1ikg=
Received: from MWHPR08MB2432.namprd08.prod.outlook.com (10.169.203.136) by MWHPR08MB2430.namprd08.prod.outlook.com (10.169.203.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.218.12; Mon, 13 Nov 2017 16:37:18 +0000
Received: from MWHPR08MB2432.namprd08.prod.outlook.com ([10.169.203.136]) by MWHPR08MB2432.namprd08.prod.outlook.com ([10.169.203.136]) with mapi id 15.20.0218.015; Mon, 13 Nov 2017 16:37:18 +0000
From: Mike Bishop <mbishop@evequefou.be>
To: "ilariliusvaara@welho.com" <ilariliusvaara@welho.com>, Nick Sullivan <nicholas.sullivan@gmail.com>
CC: Kazuho Oku <kazuhooku@gmail.com>, HTTP Working Group <ietf-http-wg@w3.org>
Thread-Topic: FW: New Version Notification for draft-bishop-httpbis-http2-additional-certs-05.txt
Thread-Index: AQHTUcemM1buscySTEG+TflIqHjEJKL9FgQggBTjHwCAACcQgIAAGsyAgABXFFA=
Date: Mon, 13 Nov 2017 16:37:18 +0000
Message-ID: <MWHPR08MB2432294E29EAAB98474F2A1FDA2B0@MWHPR08MB2432.namprd08.prod.outlook.com>
References: <150939960176.7740.5723475746682417243.idtracker@ietfa.amsl.com> <MWHPR08MB347212B6F2F9DDD092728354DA5E0@MWHPR08MB3472.namprd08.prod.outlook.com> <CANatvzzO0gsuvjBjCuGuvxenubnVt4G==qw1huzjSd57V+8A9Q@mail.gmail.com> <CAOjisRyTn4UR0oV7si93da2G4gbzZZXU4LO-NW2PZWSLosFOLg@mail.gmail.com> <20171113110513.ck2nm3wlynzpaxog@LK-Perkele-VII>
In-Reply-To: <20171113110513.ck2nm3wlynzpaxog@LK-Perkele-VII>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=mbishop@evequefou.be;
x-originating-ip: [2001:67c:1232:144:e9b4:7a6:ab69:5d8c]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR08MB2430; 6:e2Gt58btgQCWLXjHB8H92gJBom9yYU/0HYr+GYbVurMLQ1vdM+o3dsF4V6j/Gm7KEO93uc0hRsuTO2J7ndM1n7fFqDmFCC/Xsvs0k/+LMXjTBSLmA+S/ldV90Rgr/yrgsXKOkJDdrMUNU47iRSNCqBN5zTmDgLr/L59rm51HDA/eX6qhPeD5Y/pFg88fHFm4BmXQJwxRKJMeVI3CYg+JrYv0wJWDEqRP9R38Gxh4WAkEgTWKN/mrTtyawPFp0TaFlQw0wGALOPmIlyPkv/5VHfvUx4mcatFIHXaSyEgFvQXZDL+I+5RVnoHJaVrTfUZyID/GC1w5n2Z/aOpyFzKx6MrX05r7eE6d5P5JOK1LCxE=; 5:k8BDacXiX3LRkeeQ9yx6eHzMlo6vpMwzoruvHVu+vT91d28AvrhDCp6GXmyYAS/hVONB6+2BCsY7u0EErkfkJhDCuxsxL7qMwRzChSOA+D0Y7IL135zCIPybAMyNNmzuZhvJAcoj7mOLGqx9nG3aJ3XLln3eswBkDM0LWrbs2Ec=; 24:wuzt4sBHAyslLYpYZvU1vK2JcP6J5PplxK91SVtMn7P+I4qJPrJ3C90AOToAbOJnwn6Itdqk1xe106r0lJP8IkmbCKvGEXZNEEdb+DEJYlM=; 7:5Eq+8TBGrqSa+EEpXSR5xIGuHbc/0PuPuj28TrL494BR9TUn8dc2dyt2yd2SipGwJnQ+nXHD4gcJCT/tcgCtwrJaKIcN3417PmRXsXXKBoqpGwJuo5jX3hvGbhs6RnkLWjS+tNFxcJn5j3L47Tl2xE/zO5+oGoRxsah8A0UeDNG0rW1XOCv8OWVzKB1LiHDvChgh89DrXaHkig43xdFZqRPvZkcj6UNNpwdlTq4iqtLjEKOvVYNW5oEUq6KhWhsV
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 23852f97-6717-42a0-0891-08d52ab4ce4d
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603199); SRVR:MWHPR08MB2430;
x-ms-traffictypediagnostic: MWHPR08MB2430:
x-microsoft-antispam-prvs: <MWHPR08MB24303FF79F1F8C890F6A70E7DA2B0@MWHPR08MB2430.namprd08.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(3002001)(3231022)(10201501046)(100000703101)(100105400095)(93006095)(93001095)(6041248)(20161123564025)(20161123555025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(2016111802025)(20161123558100)(20161123560025)(6043046)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:MWHPR08MB2430; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:MWHPR08MB2430;
x-forefront-prvs: 0490BBA1F0
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(39830400002)(346002)(376002)(199003)(13464003)(24454002)(189002)(39060400002)(2950100002)(15650500001)(55016002)(6246003)(74316002)(7736002)(5660300001)(4326008)(54356999)(76176999)(53936002)(6506006)(6436002)(97736004)(77096006)(229853002)(53546010)(2501003)(50986999)(7696004)(9686003)(230783001)(305945005)(101416001)(189998001)(14454004)(74482002)(2900100001)(106356001)(105586002)(3660700001)(110136005)(68736007)(25786009)(2906002)(99286004)(54906003)(8936002)(6116002)(102836003)(33656002)(86362001)(8676002)(3280700002)(93886005)(478600001)(316002)(81156014)(81166006); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR08MB2430; H:MWHPR08MB2432.namprd08.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: evequefou.be does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: evequefou.be
X-MS-Exchange-CrossTenant-Network-Message-Id: 23852f97-6717-42a0-0891-08d52ab4ce4d
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Nov 2017 16:37:18.1271 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 41eaf50b-882d-47eb-8c4c-0b5b76a9da8f
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR08MB2430
Received-SPF: pass client-ip=104.47.37.93; envelope-from=mbishop@evequefou.be; helo=NAM02-CY1-obe.outbound.protection.outlook.com
X-W3C-Hub-Spam-Status: No, score=-3.9
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: titan.w3.org 1eEHk0-0007n5-Qf f2f445a721302a23c8845d3527de980b
X-Original-To: ietf-http-wg@w3.org
Subject: RE: FW: New Version Notification for draft-bishop-httpbis-http2-additional-certs-05.txt
Archived-At: <https://www.w3.org/mid/MWHPR08MB2432294E29EAAB98474F2A1FDA2B0@MWHPR08MB2432.namprd08.prod.outlook.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/34785
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

It might also be an option to remove AUTOMATIC_USE; clients that want a certificate applied to all requests generate the extra frame for each stream, but that's fairly small overhead.

I think for legacy reasons, it makes sense to restrict sending USE_CERTIFICATE 0-1 times *unless* the server sends multiple CERTIFICATE_REQUIRED messages.  This support was added to parallel TLS 1.3, which permits multiple simultaneous demands for (presumably different) certificates.

-----Original Message-----
From: ilariliusvaara@welho.com [mailto:ilariliusvaara@welho.com] 
Sent: Monday, November 13, 2017 7:05 PM
To: Nick Sullivan <nicholas.sullivan@gmail.com>
Cc: Kazuho Oku <kazuhooku@gmail.com>; Mike Bishop <mbishop@evequefou.be>; HTTP Working Group <ietf-http-wg@w3.org>
Subject: Re: FW: New Version Notification for draft-bishop-httpbis-http2-additional-certs-05.txt

On Mon, Nov 13, 2017 at 09:29:19AM +0000, Nick Sullivan wrote:
> Hi Kazuho,
> 
> Thanks for this. I think you found an issue that we did not consider: 
> the fact that server support for setting AUTOMATIC_USE in client 
> certificates may not be desirable for all servers. The CGI case you 
> describe would work find as long as the client doesn't use AUTOMATIC_USE.

I think it is more multiple certificates that causes problems here than AUTOMATIC_USE.

(AUTOMATIC_USE has its problems, but those seem to be mostly related to the server becoming confused about what the client actually meant).


-Ilari