Re: [quicwg/base-drafts] Key Diversity (#2175)

martinduke <notifications@github.com> Sat, 09 February 2019 04:20 UTC

Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A60713112D for <quic-issues@ietfa.amsl.com>; Fri, 8 Feb 2019 20:20:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.001
X-Spam-Level:
X-Spam-Status: No, score=-8.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1xmlSdrofC24 for <quic-issues@ietfa.amsl.com>; Fri, 8 Feb 2019 20:20:05 -0800 (PST)
Received: from out-7.smtp.github.com (out-7.smtp.github.com [192.30.252.198]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 086A41274D0 for <quic-issues@ietf.org>; Fri, 8 Feb 2019 20:20:04 -0800 (PST)
Date: Fri, 08 Feb 2019 20:20:03 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1549686003; bh=YOSOlbzE8FsWZTLbAinfgBJ78mc9bA1xEMC0zGX6R/s=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=18PmgbpETUAtDrbUteIRJP12F49/1rspqQvWbfnoudD6ws+IBIY+QzqLmjMaHHQOl QFisXNyGAUHsWwpRXtvGEJFcICsWhVC6UQ0Oa36MIGc5/OL9PUtTplQqpdODKeIbsY 7rIGdY8QSZIvfqOQ3hmH8bUEjGi/VOBTA+VSeRbE=
From: martinduke <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab9fe9038e6656ea73405ba066c411e7592fce296e92cf00000001187616f392a169ce174cebde@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/2175/462012088@github.com>
In-Reply-To: <quicwg/base-drafts/issues/2175@github.com>
References: <quicwg/base-drafts/issues/2175@github.com>
Subject: Re: [quicwg/base-drafts] Key Diversity (#2175)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5c5e54f3e5a83_7c133ff86ced45b47674e"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinduke
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/H-wms1jPQgfsNmz-VDF2wlfoO3Y>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Feb 2019 04:20:08 -0000

I agree with @ekr. The key separation design is fine, but the sentence about 0-RTT doesn't make any sense. I would delete the sentence about 0-RTT, so it would read thus:

In using TLS, the central key schedule of TLS is used.  As a result of the TLS
handshake messages being integrated into the calculation of secrets, the
inclusion of the QUIC transport parameters extension ensures that keys are
not the same as those that might be produced by a server running
TLS over TCP.  To further diminish the possibility of cross-protocol key
synchronization, additional measures are provided to improve key separation.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/2175#issuecomment-462012088