Re: [kitten] Review of draft-ietf-kitten-tls-channel-bindings-for-tls13-01

Sam Whited <sam@samwhited.com> Fri, 26 February 2021 21:15 UTC

Return-Path: <sam@samwhited.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CF533A0ADB for <kitten@ietfa.amsl.com>; Fri, 26 Feb 2021 13:15:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=samwhited.com header.b=nyLSlp2m; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=gYPRJ05x
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tGSouqFiiXs2 for <kitten@ietfa.amsl.com>; Fri, 26 Feb 2021 13:15:24 -0800 (PST)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8DA463A0AD6 for <kitten@ietf.org>; Fri, 26 Feb 2021 13:15:24 -0800 (PST)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id 094F5AED for <kitten@ietf.org>; Fri, 26 Feb 2021 16:15:22 -0500 (EST)
Received: from imap34 ([10.202.2.84]) by compute4.internal (MEProxy); Fri, 26 Feb 2021 16:15:23 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samwhited.com; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm2; bh=uHGML ltlX6LZ+aWjsBkF6YhAmZN9iztA2jTuXjcN5mY=; b=nyLSlp2m9qiNDpqVMitfS MHe+udrlYyYXwDZgT3uDr3zD+Ndwft/0ovd1K3SufDpFrodJH0sQGo6whwOe2sWr r7506ZkGktm7tU4sfRX91PPo54na71ImCNw60lMLnDAkO6aTClLRVAO1zvWHM5Zg 4LX0u3/5oOrwN91NaN8WSNt6Gi3f+RUctoYDqtoVJonSOZGQm7iT3bw5zMIwcYiI BpX2qpUgoVIwV/x2uu+GSvFch5H0OTlBQh5w3+UGZJBNtmZ2pVB8CMMU42OOOYfy L5Eb6eQTFSk+5Bu3zKHifBnbGnHBJqjIjJq7fsKi3sTM8qj5tsy2v4G3dev0Kzul g==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=uHGMLltlX6LZ+aWjsBkF6YhAmZN9iztA2jTuXjcN5 mY=; b=gYPRJ05x+ti7X2zoGsekvCn6SJcwAIfTHZx5dqFC46GMi5hfnPSn16Eyu atuRk3kemgfShYMbMqLSxFEFO3/gnkAUS/4X4LDIpyFsNvC/35XjFQxtCucPtoGP Xk+qhR8dfnzDiqCwHEim7jPE3pqQurm9J01iN83QcgCoiLMko97GVa6GCSjb4SzA zy/1utGpYhgLuLkXt9XvvZtSSNX0Y6HgkkPKYXL1121CtLM/7hS2ukO5L40X+04W XSV4nqIoOAlYoHnTcv9hbRpKLSfWZBlrhTDvABt/FIWYnB1iFKZuEwwG8fsH/tP9 dDYA813ilGU8rijY+uNcOk+VrYovw==
X-ME-Sender: <xms:6mQ5YNuLyod6687eMXKmk-_223PnuQ4CqSWkmRIn0Q4vaa8f_F1QXA> <xme:6mQ5YGdqvuqXCemkdwx6OX65oecnBxCvZYk7XzpjxmvyKXiwLWMZZByBRnlHQTwBa 0-2X5nB0jJcpOnd1Q>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrledugddugeelucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvffutgfgsehtqhertderreejnecuhfhrohhmpedfufgr mhcuhghhihhtvggufdcuoehsrghmsehsrghmfihhihhtvggurdgtohhmqeenucggtffrrg htthgvrhhnpeefuddukeekueetueelfeeguedvuedvffehvdevieffgeehhfejffdtveev uedvffenucffohhmrghinhepihgvthhfrdhorhhgnecuvehluhhsthgvrhfuihiivgeptd enucfrrghrrghmpehmrghilhhfrhhomhepshgrmhesshgrmhifhhhithgvugdrtghomh
X-ME-Proxy: <xmx:6mQ5YAwwAGeak5EB1f2E8SzFvptFW0IB5GJ56bfH-VY4AShrfBZ2Cg> <xmx:6mQ5YEOpMv4pGEgIIdSdYYHFU_IilYd-1tri3TXn2oDC6mee_Of3jQ> <xmx:6mQ5YN8HrB_EqxKILaoUZPnv22m8mzBRHtZHHT_AbqLzLIFD5xZ7Dg> <xmx:6mQ5YAJ38BXfWTzEiwkVCRrb87uTHkhyoDjQ-WMHJ84vA-HNqJEQ2w>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 3F202280073; Fri, 26 Feb 2021 16:15:22 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-141-gf094924a34-fm-20210210.001-gf094924a
Mime-Version: 1.0
Message-Id: <31529fef-f768-4b39-ba0a-9d6a186549c8@www.fastmail.com>
In-Reply-To: <20210226210401.GA13511@localhost>
References: <20210226210401.GA13511@localhost>
Date: Fri, 26 Feb 2021 16:15:00 -0500
From: Sam Whited <sam@samwhited.com>
To: KITTEN Working Group <kitten@ietf.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/bYTGgKJ__DAxLmNlLxPirAU5DIY>
Subject: Re: [kitten] Review of draft-ietf-kitten-tls-channel-bindings-for-tls13-01
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Feb 2021 21:15:27 -0000

Thank you; would something as simple as "Some of the channel binding
types defined in…" work for you?

—Sam

On Fri, Feb 26, 2021, at 16:04, Nico Williams wrote:
> I have reviewed draft-ietf-kitten-tls-channel-bindings-for-tls13-01.
>
> My only comment, besides a thank you, is this:
>
>  - Section 1, first sentence
>
>    | The channel binding types defined in [RFC5929] were found to be
>    | vulnerable to the "triple handshake vulnerability" ...
>
>    I believe that's specifically about tls-unique and tls-unique-for-
>    telnet, but not tls-server-end-point.
>
>    A slight rephrasing would be useful, as there is no need to give
>    the wrong impression about tls-server-end-point.
>
> Thanks,
>
> Nico
> --
>
> _______________________________________________
> Kitten mailing list Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>

-- 
Sam Whited