RE: FW: New Version Notification for draft-thomson-http2-client-certs-01.txt

Mike Bishop <Michael.Bishop@microsoft.com> Thu, 28 January 2016 23:35 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 875131B2A5A for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Thu, 28 Jan 2016 15:35:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.003
X-Spam-Level:
X-Spam-Status: No, score=-7.003 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LzoSuccmS_Ya for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Thu, 28 Jan 2016 15:35:36 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9878F1B2A59 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Thu, 28 Jan 2016 15:35:36 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1aOw2u-000814-8H for ietf-http-wg-dist@listhub.w3.org; Thu, 28 Jan 2016 23:32:12 +0000
Resent-Date: Thu, 28 Jan 2016 23:32:12 +0000
Resent-Message-Id: <E1aOw2u-000814-8H@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtps (TLS1.2:DHE_RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <Michael.Bishop@microsoft.com>) id 1aOw2q-00080L-1E for ietf-http-wg@listhub.w3.org; Thu, 28 Jan 2016 23:32:08 +0000
Received: from mail-bn1bbn0102.outbound.protection.outlook.com ([157.56.111.102] helo=na01-bn1-obe.outbound.protection.outlook.com) by lisa.w3.org with esmtps (TLS1.2:RSA_AES_256_CBC_SHA256:256) (Exim 4.80) (envelope-from <Michael.Bishop@microsoft.com>) id 1aOw2o-0004fT-Pr for ietf-http-wg@w3.org; Thu, 28 Jan 2016 23:32:07 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=oU+a/NvkYqIJhVq6k/MJaLJto1XwFQYqEljEhRSeQhk=; b=NLGwZ+jPjQ0v0YVkTTvL3eSeY8jG954iheyIXc8gRjDa1lFEe5SZCbp188DqeycU0wrGgkYV0DAFZ/aqOnnyE+d6Uhf67abpPQ3ESkzZvkMWWVXLb0z0628eXxFiB4R5POzy8C3oOMrTZS/HScUZKASLs7tZmaqNhdSd7k3qEIc=
Received: from CY1PR03MB1374.namprd03.prod.outlook.com (10.163.16.28) by CY1PR03MB1375.namprd03.prod.outlook.com (10.163.16.29) with Microsoft SMTP Server (TLS) id 15.1.390.13; Thu, 28 Jan 2016 23:31:31 +0000
Received: from CY1PR03MB1374.namprd03.prod.outlook.com ([10.163.16.28]) by CY1PR03MB1374.namprd03.prod.outlook.com ([10.163.16.28]) with mapi id 15.01.0390.016; Thu, 28 Jan 2016 23:31:31 +0000
From: Mike Bishop <Michael.Bishop@microsoft.com>
To: "ilariliusvaara@welho.com" <ilariliusvaara@welho.com>, Martin Thomson <martin.thomson@gmail.com>
CC: HTTP Working Group <ietf-http-wg@w3.org>
Thread-Topic: FW: New Version Notification for draft-thomson-http2-client-certs-01.txt
Thread-Index: AQHRVWOAcftGZF4T1UaJdSueCSI/S58OO4GAgAAdb4CAAAc/gIAAHimggACVuYCAAO3uAIAAIiuAgABsZACAAQys4A==
Date: Thu, 28 Jan 2016 23:31:31 +0000
Message-ID: <CY1PR03MB13744FAAD254D1164EF0BD2887DA0@CY1PR03MB1374.namprd03.prod.outlook.com>
References: <20160122222315.28781.93913.idtracker@ietfa.amsl.com> <CY1PR03MB1374890E32B6F6CA2AB78D8D87D80@CY1PR03MB1374.namprd03.prod.outlook.com> <20160126213813.GA5528@LK-Perkele-V2.elisa-laajakaista.fi> <CABkgnnVXvdLr7fh=Dc2HswE=hAmq30k2aXMvdi7u18=jj2iv9w@mail.gmail.com> <CY1PR03MB13742153C8F4DF64EEA67D8687D90@CY1PR03MB1374.namprd03.prod.outlook.com> <20160127084759.GA8247@LK-Perkele-V2.elisa-laajakaista.fi> <CY1PR03MB1374BE68A92BACD8FA24A70087D90@CY1PR03MB1374.namprd03.prod.outlook.com> <CABkgnnWEkDYDqg+1zm3=1gMHHnLGGoau8ncaWi5m7UYsGMvjbw@mail.gmail.com> <20160128072948.GA11013@LK-Perkele-V2.elisa-laajakaista.fi>
In-Reply-To: <20160128072948.GA11013@LK-Perkele-V2.elisa-laajakaista.fi>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Michael.Bishop@microsoft.com;
x-originating-ip: [2001:4898:80e8::5b3]
x-ms-office365-filtering-correlation-id: b60a76c8-e592-44ab-ba58-08d3283b2737
x-microsoft-exchange-diagnostics: 1; CY1PR03MB1375; 5:wNtNaVyrFQdlpjDV7xVonPPGLVTc4n7KBJ+25kwXsvBw8PGigohrDKc6/v7uaHg2yBetKjXWV/VjNrxsP4vYUie5RB22gAIs83k2FdtCAyzT/Hmh3+jWqIxORQgVD3yXoe3PXiplpEsi1fJZprGTLA==; 24:WVAt+D5cBiJCStBDgQyyGOjSUG8OF1Ok2X+aYc5x/eUunXgWwtedGSyyF0YfTfjllOAFBnXxGjZj9EHhvt0PmJCxyrF6l7hI4uRYVOsy8yI=
x-exchange-antispam-report-test: UriScan:; BCL:0; PCL:0; RULEID:; SRVR:CY1PR03MB1375; UriScan:;
x-microsoft-antispam-prvs: <CY1PR03MB137575748EA9D7D2C9568BA087DA0@CY1PR03MB1375.namprd03.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(601004)(2401047)(5005006)(8121501046)(10201501046)(3002001)(61426038)(61427038); SRVR:CY1PR03MB1375; BCL:0; PCL:0; RULEID:; SRVR:CY1PR03MB1375;
x-forefront-prvs: 083526BF8A
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(979002)(6009001)(189002)(24454002)(13464003)(199003)(51444003)(377454003)(77096005)(106356001)(102836003)(6116002)(15975445007)(586003)(86362001)(106116001)(93886004)(2501003)(74316001)(81156007)(2906002)(19580395003)(87936001)(5008740100001)(19580405001)(40100003)(2900100001)(10290500002)(97736004)(2950100001)(5005710100001)(33656002)(92566002)(10400500002)(76576001)(86612001)(5001770100001)(105586002)(50986999)(76176999)(54356999)(101416001)(122556002)(4326007)(5002640100001)(8990500004)(189998001)(5001960100002)(10090500001)(230783001)(5003600100002)(3470700001)(1096002)(11100500001)(3660700001)(99286002)(1220700001)(5004730100002)(3280700002)(3826002)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR03MB1375; H:CY1PR03MB1374.namprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Jan 2016 23:31:31.4579 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR03MB1375
Received-SPF: pass client-ip=157.56.111.102; envelope-from=Michael.Bishop@microsoft.com; helo=na01-bn1-obe.outbound.protection.outlook.com
X-W3C-Hub-Spam-Status: No, score=-3.9
X-W3C-Hub-Spam-Report: AWL=-2.397, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_NW=0.5
X-W3C-Scan-Sig: lisa.w3.org 1aOw2o-0004fT-Pr 8517921c26c2437a5d8195f104906e88
X-Original-To: ietf-http-wg@w3.org
Subject: RE: FW: New Version Notification for draft-thomson-http2-client-certs-01.txt
Archived-At: <http://www.w3.org/mid/CY1PR03MB13744FAAD254D1164EF0BD2887DA0@CY1PR03MB1374.namprd03.prod.outlook.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/31027
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

https://github.com/MikeBishop/http2-client-certs/commit/33262d527e88948a9fb3b9f10cbb2988c4cc50dc

-----Original Message-----
From: ilariliusvaara@welho.com [mailto:ilariliusvaara@welho.com] 
Sent: Wednesday, January 27, 2016 11:30 PM
To: Martin Thomson <martin.thomson@gmail.com>
Cc: Mike Bishop <Michael.Bishop@microsoft.com>; HTTP Working Group <ietf-http-wg@w3.org>
Subject: Re: FW: New Version Notification for draft-thomson-http2-client-certs-01.txt

On Thu, Jan 28, 2016 at 12:01:51PM +1100, Martin Thomson wrote:
> GIthub is unicorny again [1], so I'm going to dump this into email for 
> later action.
> 
> This should say that only the signature algorithms supported in the 
> negotiated version of TLS can be used.  Plus the following MUST NOT be
> used:
>  - MD5
>  - SHA1
>  - SHA224
>  - DSA
>  - ECDSA with curves on prime fields that are less than 240 bits wide
>  - RSA with a prime modulus less than 2048 bits
> 
> I think that's about as aggressive without starting to prohibit some 
> things that are in common use.  Would that work for you Ilari?

Sure, seems reasonable.


-Ilari