Re: [Last-Call] Secdir last call review of draft-ietf-tls-exported-authenticator-13
Martin Thomson <mt@lowentropy.net> Thu, 10 December 2020 03:43 UTC
Return-Path: <mt@lowentropy.net>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A42FE3A0982 for <last-call@ietfa.amsl.com>; Wed, 9 Dec 2020 19:43:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.12
X-Spam-Level:
X-Spam-Status: No, score=-2.12 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b=EJt7fnF1; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=D9vk3JdP
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nYKZXNIq2cqs for <last-call@ietfa.amsl.com>; Wed, 9 Dec 2020 19:43:22 -0800 (PST)
Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5931E3A095F for <last-call@ietf.org>; Wed, 9 Dec 2020 19:43:22 -0800 (PST)
Received: from compute1.internal (compute1.nyi.internal [10.202.2.41]) by mailout.nyi.internal (Postfix) with ESMTP id 622D65C016C for <last-call@ietf.org>; Wed, 9 Dec 2020 22:43:21 -0500 (EST)
Received: from imap10 ([10.202.2.60]) by compute1.internal (MEProxy); Wed, 09 Dec 2020 22:43:21 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type; s=fm1; bh=GZR2eiO5Vq87XJb3vfEKdDXJrkLkbQr /L3e+I2yJDzk=; b=EJt7fnF12vV0+5SYF589RKGXy8L5tXc4381uYWLKOYQHbWV V+usbt/L9fmh/0QIyf7rrA0h31d+FsboZiY5Eh0Es9v0NwEU1Edi72pm4zeUnYds XgWHoSyhAVNkk4kSaHt0T3lX+Jt7q22OcaAa0rGGC7JgjnD3bHVdbi6Mhd17Om/g f6k7ONQwridTHK45bLDqRv5XcyDsbtLnpiy5qxgG/trF1ETbA0Frb37N78sRnimI HveR/bT0IYmCYZoEjzCafQXwUJFWjL34ZzVyxHPqQ/8EvgkYuljhvJ1gk0fUFW93 JAysA92tKVIh8NDQGcikLvXUkB70zhw5E3qlEOA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=GZR2ei O5Vq87XJb3vfEKdDXJrkLkbQr/L3e+I2yJDzk=; b=D9vk3JdPaFEyMxL/koWfyq H/QE6Vzkmyg4UDLyhiWnSd9bMBZZo7jcXAZwDBn12TLcIJERX5iTCEj2NzrcTqB3 C13tqWauPpeIA29qnKdBWQ95a3fZm7BqsCXKRsTsPN8GczwRBsxxxjqlzCg4tWe+ 4DV+GynRIsX1vcAWeH4u+6OYlWWXFuZhvq5sWYbchRUqzParTM6sr2ZhdgFe4TXf gejZ3CBE5MkrQ7EDXhJBy8Go2l86B1lFMN9EHyBuOWFcM8EOOidNFAurgKOrmkUE LR3ZAjGp05EJxR0fIhhtLcymXO1OA1MH5kyRUC7wOJ+NS72Al9iuvTk7l7JCB9Pw ==
X-ME-Sender: <xms:WZnRX0o1dgxkyPZhHSevfe_WrKDDxiZehgIkuP4Q2E_-1dTar6s2pw> <xme:WZnRX6pIYxb0Fu6sw9C_UCqFI_IZ1acnTEZdgr8E0twPrI3AyEoByJm4sOVPa0Hzt hkZCF3K4tnzu2Lcemg>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedujedrudejledgieduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtsehttd ertderreejnecuhfhrohhmpedfofgrrhhtihhnucfvhhhomhhsohhnfdcuoehmtheslhho figvnhhtrhhophihrdhnvghtqeenucggtffrrghtthgvrhhnpeehfeetudduudehtdekhf dvhfetleffudejgeejffehffevkeduiefgueevkeefleenucevlhhushhtvghrufhiiigv pedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehmtheslhhofigvnhhtrhhophihrdhnvg ht
X-ME-Proxy: <xmx:WZnRX5MEpxvoWLG1FvpA1HXC9S9ozbAGuOI2NF67K_Ha2qlfcjPx1g> <xmx:WZnRX75woMpHC4-DRTdSfYt0JfNsAqExkIlTevWXhXSex9VyxD9kEg> <xmx:WZnRXz55BlvxYZCrNoJVjwxLfzKVWqoFPLL9aaeUf8xdOK5nc2xUug> <xmx:WZnRX1E_WDw_m1-lpOlQjjtBkVUE6aRGepuGaJQZ85l9RTSlTbFycg>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id E8A71200EC; Wed, 9 Dec 2020 22:43:20 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.3.0-622-g4a97c0b-fm-20201115.001-g4a97c0b3
Mime-Version: 1.0
Message-Id: <8a38b8be-6ca2-4cf7-8272-5bed3ec31aa8@www.fastmail.com>
In-Reply-To: <BBD7F57A-AE08-4B1D-9BBA-84A8E125AEDC@sn3rd.com>
References: <160458838575.14807.16400082227129460453@ietfa.amsl.com> <BBD7F57A-AE08-4B1D-9BBA-84A8E125AEDC@sn3rd.com>
Date: Thu, 10 Dec 2020 14:43:00 +1100
From: Martin Thomson <mt@lowentropy.net>
To: last-call@ietf.org
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/r7xBGP_L26VWOeUb-EAXyBKcQOY>
Subject: Re: [Last-Call] Secdir last call review of draft-ietf-tls-exported-authenticator-13
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Dec 2020 03:43:24 -0000
On Thu, Dec 10, 2020, at 14:30, Sean Turner wrote: > OLD: > > The application layer protocol > used to send the authenticator request SHOULD use TLS as its > underlying transport to keep the request confidential > > NEW: > > The application layer protocol > used to send the authenticator request SHOULD use a secure > channel with equivalent security to TLS, such as > QUIC [ID.draft-ietf-quic-tls], as its underlying transport > to keep the request confidential Hi Sean, Any reason this can't become a MUST now? Once you require comparable channel security, a stronger requirement seems pretty reasonable.
- [Last-Call] Secdir last call review of draft-ietf… Yaron Sheffer via Datatracker
- Re: [Last-Call] Secdir last call review of draft-… Sean Turner
- Re: [Last-Call] Secdir last call review of draft-… Martin Thomson
- Re: [Last-Call] Secdir last call review of draft-… Nick Sullivan
- Re: [Last-Call] Secdir last call review of draft-… Martin Thomson