[km-fs-pcs] Re: No ciphersuite negotiation in MLS-TLS with 2-party profile

Konrad Kohbrok <konrad.kohbrok@datashrine.de> Tue, 30 June 2026 07:14 UTC

Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: km-fs-pcs@mail2.ietf.org
Delivered-To: km-fs-pcs@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1027510A83DDE for <km-fs-pcs@mail2.ietf.org>; Tue, 30 Jun 2026 00:14:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782803683; bh=mg6t2zBiPpNuctdA8Ra4xcAZ5Q8qnsQpORsp89wb21g=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=TKpMokzfSWAdK3hs7Xw5BFNEtnvsbEJAYpwHQ/9q0m0nZps333Q59zRSZ9wR3tYxQ LwRztfS2zOsa1zuOMtgoBp+n8y78mV04PO1s8zG3z2b2q+NCqDhUavuwithcGM6N/P aCh1x2oouknHjaGTGFjctIuqWMT18bIkkp/6pVys=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=datashrine.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PJdvFIzisaPW for <km-fs-pcs@mail2.ietf.org>; Tue, 30 Jun 2026 00:14:41 -0700 (PDT)
Received: from mout-p-201.mailbox.org (mout-p-201.mailbox.org [80.241.56.171]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D9BA110A83DD4 for <km-fs-pcs@ietf.org>; Tue, 30 Jun 2026 00:14:41 -0700 (PDT)
Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-201.mailbox.org (Postfix) with ESMTPS id 4gqDt10VHZz9tp3; Tue, 30 Jun 2026 09:14:33 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=datashrine.de; s=MBO0001; t=1782803673; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=52z8b+VcaIM+T0ULvLzl9yr7NwyqsK0xiCZ//KOkiVY=; b=ezN3Iy3FxTrmUdyrVIhlPQ3jl2gg3rBpS9clr7AEDboBJJW0HB3CPPwEAmTKqCHwJvMojN pCrQ3s5Rx/USgCmOlRx8YO4DSy3tPuDfxI7z3zWQ/2bdLcdrI/icepMPpuGQGYDnwlRoK9 KCjliuQPEfi9pERw8CApqySTV2TYhof/qML5IExP8naWeJxvMH51Uj5AjRDiFaKBdrnVb7 M4JfQ8GNI90UHVs2baN8jaRlV8cHVE7AROiasAyT0zMqYNdiNSS8Hh/oh38dfZAf67M7CM ZHabwWKebINpWGG8sApZuwXYvnsC8sjEulu8Nq5qsYgxwqc05sKMACtWizUYxQ==
Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of konrad.kohbrok@datashrine.de designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=konrad.kohbrok@datashrine.de
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
In-Reply-To: <UcOlvPpSFMK9IEowELPzi7VefjUZwp17PIosXmALED_sZeUzt3z_kThr0L0NUCJ1eIuSNBcfEilE2RJK5r5__7cYOw0Fp_Fn_YW3QAE7yoA=@proton.me>
Date: Tue, 30 Jun 2026 09:14:21 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <EFF046FB-5CCA-45F9-8F07-3B04D8D338A5@datashrine.de>
References: <UcOlvPpSFMK9IEowELPzi7VefjUZwp17PIosXmALED_sZeUzt3z_kThr0L0NUCJ1eIuSNBcfEilE2RJK5r5__7cYOw0Fp_Fn_YW3QAE7yoA=@proton.me>
To: Gaëtan Wattiau <gaetan.wattiau=40proton.me@dmarc.ietf.org>
X-Rspamd-Queue-Id: 4gqDt10VHZz9tp3
Message-ID-Hash: U4JMIGDHCEA2EUR77XNFVX34MHHV2ULY
X-Message-ID-Hash: U4JMIGDHCEA2EUR77XNFVX34MHHV2ULY
X-MailFrom: konrad.kohbrok@datashrine.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "km-fs-pcs@ietf.org" <km-fs-pcs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [km-fs-pcs] Re: No ciphersuite negotiation in MLS-TLS with 2-party profile
List-Id: Key management that provides forward security and post compromise security <km-fs-pcs.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/km-fs-pcs/-f0J7YHXhimcLxFBAgSPVQMIh3o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/km-fs-pcs>
List-Help: <mailto:km-fs-pcs-request@ietf.org?subject=help>
List-Owner: <mailto:km-fs-pcs-owner@ietf.org>
List-Post: <mailto:km-fs-pcs@ietf.org>
List-Subscribe: <mailto:km-fs-pcs-join@ietf.org>
List-Unsubscribe: <mailto:km-fs-pcs-leave@ietf.org>

Hi Gaëtan,

Thanks for pointing those out! I expect that we’ll spec out more details around the handshake after the BoF in Vienna. There are multiple ways to solve these problems and I think we should have a discussion in the working group (once it exists) on where we want the protocol to go.

Cheers,
Konrad


> On 25. Jun 2026, at 15:37, Gaëtan Wattiau <gaetan.wattiau=40proton.me@dmarc.ietf.org> wrote:
> 
> The 2-party profile or MLS-TLS drafts don't support ciphersuite negotiation.
> 
> The only mention of it is in §3:
> 
> > The responder inspects the KeyPackage and checks whether it supports
> > the offered ciphersuite and whether the initiator has sufficient
> > capabilities to support the connection.
> Problems:
>     • It doesn't define an error path if the ciphersuite isn't supported by the server.
>     • It doesn't offer any indication of what to do when there is an error.
>     • It doesn't define any efficient negotiation system.
> 
> Best,
> 
> Gaëtan Wattiau
> 
> _______________________________________________
> km-fs-pcs mailing list -- km-fs-pcs@ietf.org
> To unsubscribe send an email to km-fs-pcs-leave@ietf.org