Re: [quicwg/base-drafts] Initial secrets change after Retry (#2870)

Nick Harper <> Wed, 03 July 2019 17:53 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id E519012038E for <>; Wed, 3 Jul 2019 10:53:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -6.382
X-Spam-Status: No, score=-6.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id XXBNpwwbxu0g for <>; Wed, 3 Jul 2019 10:53:10 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id E28071202F9 for <>; Wed, 3 Jul 2019 10:53:09 -0700 (PDT)
Date: Wed, 03 Jul 2019 10:53:08 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=pf2014; t=1562176388; bh=1JKuJegUrFZDVSKgA7Q4cLraYGO1hPkktm28jIBMksU=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=jAKe0CRI6YtsaJF2ZR0pjH2DV1g4MXcecdDcp8yK9aqDcNduQkxmsaLqzsKVyLb/E LMZHidEq76pv1v/MZyhxxqQCpRY3Bn362jl0iLCb90EJ3AacSNMaf45fy/KggKmUu8 85KfAsZKndENoR1TEOreDzgiCo2M/0xKDM8gPPdQ=
From: Nick Harper <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/pull/2870/>
In-Reply-To: <quicwg/base-drafts/pull/>
References: <quicwg/base-drafts/pull/>
Subject: Re: [quicwg/base-drafts] Initial secrets change after Retry (#2870)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5d1ceb84cb67f_4e913fdd7c0cd96c116243"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: nharper
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 03 Jul 2019 17:53:12 -0000

I think this also needs to change the first sentence that currently says "Initial packets are protected with a secret derived from the Destination Connection ID field from the client’s first Initial packet of the connection."

If we're attempting to describe the behavior that people currently have implemented (where Initial keys change on a Retry packet but nothing else), the sentence I've quoted above is false.

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: