Review of TLS's ECH HTTP-related I-Ds

Sean Turner <sean@sn3rd.com> Mon, 01 April 2024 17:03 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CFDEC14CE51 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 1 Apr 2024 10:03:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.848
X-Spam-Level:
X-Spam-Status: No, score=-2.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org header.b="XiKiSHst"; dkim=pass (2048-bit key) header.d=w3.org header.b="OeM/eGaV"; dkim=pass (1024-bit key) header.d=sn3rd.com header.b="Qr203aVy"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fjeK3NrHDCdO for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 1 Apr 2024 10:03:52 -0700 (PDT)
Received: from mab.w3.org (mab.w3.org [IPv6:2600:1f18:7d7a:2700:d091:4b25:8566:8113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 956E9C14CE55 for <httpbisa-archive-bis2Juki@ietf.org>; Mon, 1 Apr 2024 10:03:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:To:Cc:Date:Message-Id:Mime-Version:Content-Type:From:Reply-To :In-Reply-To:References; bh=wWmVH84JYXsGG3yJDzHbD8QPs73vz3UhXLJyp8Vjmpo=; b=X iKiSHstf/dY7WZ9CgluZkKaNKLsH0eSJXVUw/B9YaHsNlFYD6JvwoLxe2KVTpJzYxx4bv1wi1aE3I pg7FPoYos+EwuwUUhQpawliHdO24N9k9tb0e/vKyjWfcaCmyblYwoxXbThnUsvXax0WUtP70mQjp4 0r0qTK6/9PEKBrDAZicpF+7Z32e3gqdDyU67okOeK7h8Jzq11pmXXYLyCLjz+O7ztAIOpZcDggEzD VmiYZ0TahMWQnrVvsJ8THYTctzkQjYX2tvUsiKuD7rHRJiWK1vnx8HoCh9pYLLYCoMzwFneVhRHxk A/eDQC5kazSEYfFLwb97BJy9V1Sp0paPA==;
Received: from lists by mab.w3.org with local (Exim 4.96) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1rrL3Y-00DKL2-2m for ietf-http-wg-dist@listhub.w3.org; Mon, 01 Apr 2024 17:02:48 +0000
Resent-Date: Mon, 01 Apr 2024 17:02:48 +0000
Resent-Message-Id: <E1rrL3Y-00DKL2-2m@mab.w3.org>
Received: from www-data by mab.w3.org with local (Exim 4.96) (envelope-from <sean@sn3rd.com>) id 1rrL3W-00DKKC-2I for ietf-http-wg@listhub.w3.org; Mon, 01 Apr 2024 17:02:46 +0000
Received: from ip-10-0-0-224.ec2.internal ([10.0.0.224] helo=puck.w3.org) by mab.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <sean@sn3rd.com>) id 1rrL2Z-00DK99-2Y for ietf-http-wg@listhub.w3.org; Mon, 01 Apr 2024 17:01:47 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=To:Cc:Date:Message-Id:Subject:Mime-Version:Content-Type:From:Reply-To :In-Reply-To:References; bh=wWmVH84JYXsGG3yJDzHbD8QPs73vz3UhXLJyp8Vjmpo=; t=1711990907; x=1712854907; b=OeM/eGaVYyW35Ej39g8jrAqD/uBNarsAG1bXSdo7LCKDWDy AjZnwGicqsvfNN9WK4a8oMCzPjpKFi+dc2OudfEtzwJKwKQ6tKb0tKLiWrFGN/FH0kI0+P645UbvH e86NNYUobE/TsNH0MblJ/Kcj51vbRJy2U/1yXmU/lz5sg1MtmtsTjNDFYCkIckEPNM5EY9211ou0L W6HqNm7tlFZW1joHQEU0idRcLyanmKJa63jZbys/HfFV9YiBXI1yRRsANbdaJIF2a77s4C+pL4mP+ a1TpY9RmF20difI7ndvqYTB6Cl7VTxwx0GbFagbK0301DaeSoq53kkiqjtN9O/KQ==;
Received-SPF: pass (puck.w3.org: domain of sn3rd.com designates 2607:f8b0:4864:20::72c as permitted sender) client-ip=2607:f8b0:4864:20::72c; envelope-from=sean@sn3rd.com; helo=mail-qk1-x72c.google.com;
Received: from mail-qk1-x72c.google.com ([2607:f8b0:4864:20::72c]) by puck.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from <sean@sn3rd.com>) id 1rrL2X-00Fwze-35 for ietf-http-wg@w3.org; Mon, 01 Apr 2024 17:01:47 +0000
Received: by mail-qk1-x72c.google.com with SMTP id af79cd13be357-78a5580333bso305466285a.2 for <ietf-http-wg@w3.org>; Mon, 01 Apr 2024 10:01:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1711990902; x=1712595702; darn=w3.org; h=to:cc:date:message-id:subject:mime-version :content-transfer-encoding:from:from:to:cc:subject:date:message-id :reply-to; bh=wWmVH84JYXsGG3yJDzHbD8QPs73vz3UhXLJyp8Vjmpo=; b=Qr203aVyWOcdooDMocGA06W3zzISDpRIWuB11HILTvktXaVa+Gn4lM9AsAlxvs+UTS ih03wjPZFqZADxEZN4I2ikDjMt7AysHC9r+yPpotZLaL8xDi0IurIBHfx37rqnTLEMWo LPs6c/mvoq8wpM5UKO0ZGgOUBPtyU9wM9vJbM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1711990902; x=1712595702; h=to:cc:date:message-id:subject:mime-version :content-transfer-encoding:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=wWmVH84JYXsGG3yJDzHbD8QPs73vz3UhXLJyp8Vjmpo=; b=k1w9vuGzekMsbbYk36DwmlA4gcRYlRX0ioWthTSLNIHOzFoPxarWCsQNKP5klOVVJm jjF1mDg8RVTZHcZWzutnQdwaodq2DLA+69in6jJJDZ7bfLVzVLFYfyUZ03qKcEnGKnvO SeObax77ryo9+7NBpOAcNSM9m/5R6Qe+oigngjxBzoCk4HIdtq3qC4z4VVi2/1jADdV/ 1BoS0CNRjh0rTEDrRsnx2TGLZLnzdD/cWfansy1bGXPLucTzANsS6JGvkLfdEVUEphDH dYqqs7zUsmcQlhln88lbfngJvRRsmZK3h1U2uEOfK+1TEOGWI8x3ZkgtKpK1z0Q0jP2Q EKSw==
X-Gm-Message-State: AOJu0Yxw8o747i0jZV6rDkwH2zZ1WLFp0TzwP2HOHQioaK0Vmv0fK9Ml rOzFlobe0d6+s9SsRV56rZSmetU0W1+YS2hIQ+wxjTn9aQgSXp45MnyJHrqKlNnITnRBEJCiPnm x
X-Google-Smtp-Source: AGHT+IHoRWpdnRp3NpPbLrUr+eg7QKzObN0IP4svO8sZAvksaq2qkkkIsZ0i3cjhjQIDIrNbZpUmmA==
X-Received: by 2002:a05:620a:1653:b0:788:26bb:1378 with SMTP id c19-20020a05620a165300b0078826bb1378mr11355492qko.73.1711990902211; Mon, 01 Apr 2024 10:01:42 -0700 (PDT)
Received: from smtpclient.apple (pool-68-238-162-47.washdc.fios.verizon.net. [68.238.162.47]) by smtp.gmail.com with ESMTPSA id i22-20020a05620a27d600b0078be83fc34asm500610qkp.125.2024.04.01.10.01.41 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 01 Apr 2024 10:01:41 -0700 (PDT)
From: Sean Turner <sean@sn3rd.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.15\))
Message-Id: <1D98A453-4782-47C0-8C3F-F0C2DB1970DD@sn3rd.com>
Date: Mon, 01 Apr 2024 13:01:40 -0400
Cc: draft-ietf-tls-wkech@ietf.org, draft-ietf-tls-svcb-ech@ietf.org
To: HTTP Working Group <ietf-http-wg@w3.org>
X-Mailer: Apple Mail (2.3654.120.0.1.15)
X-W3C-Hub-DKIM-Status: validation passed: (address=sean@sn3rd.com domain=sn3rd.com), signature is good
X-W3C-Hub-Spam-Status: No, score=-9.1
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, DMARC_MISSING=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: puck.w3.org 1rrL2X-00Fwze-35 5e32b329a11b6b7824902636f6cd6d05
X-caa-id: 4412da8e2e
X-Original-To: ietf-http-wg@w3.org
Subject: Review of TLS's ECH HTTP-related I-Ds
Archived-At: <https://www.w3.org/mid/1D98A453-4782-47C0-8C3F-F0C2DB1970DD@sn3rd.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/51912
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Hi!

We are in the process of closing out the WGLC on TLS Encrypted Client Hello [0] over in the TLS WG. There are two other ECH-related documents that are HTTP-related that I would like to get wider review of:

- Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings [1]
- A well-known URI for publishing ECHConfigList values [2]

Cheers,
spt

[0] https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
[1] https://datatracker.ietf.org/doc/draft-ietf-tls-svcb-ech/
[2] https://datatracker.ietf.org/doc/draft-ietf-tls-wkech/