Re: [quicwg/base-drafts] forbid key discarding before receiving a packet protected with new keys (#4079)
Martin Thomson <notifications@github.com> Wed, 09 September 2020 03:54 UTC
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B6923A0C1D for <quic-issues@ietfa.amsl.com>; Tue, 8 Sep 2020 20:54:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.1
X-Spam-Level:
X-Spam-Status: No, score=-3.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Ju-tpfwbJLv for <quic-issues@ietfa.amsl.com>; Tue, 8 Sep 2020 20:54:31 -0700 (PDT)
Received: from out-26.smtp.github.com (out-26.smtp.github.com [192.30.252.209]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D430A3A0BFD for <quic-issues@ietf.org>; Tue, 8 Sep 2020 20:54:30 -0700 (PDT)
Received: from github-lowworker-c5134a3.ac4-iad.github.net (github-lowworker-c5134a3.ac4-iad.github.net [10.52.23.55]) by smtp.github.com (Postfix) with ESMTP id 15BBA5E0080 for <quic-issues@ietf.org>; Tue, 8 Sep 2020 20:54:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1599623670; bh=uYif4LenSeHUxyFZCXoySbCZ2LDxx+Z42OuyifZKkBI=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=dSlw5kurKV2Ug82aSh9iLmasM+vG8lolAVoGiz9ZzjK/WUKT6I37hb6ZJgrMeTGFP Kt2zABC5xUtgzMkyv+nMS7dAEXHYBxAa2un79rbFgTe0pRxs6xmYw8KkLWD2cVsfij JiLWehkeIgLjyYpTtC1bR6irIyCaXpm8Vw/ERGjU=
Date: Tue, 08 Sep 2020 20:54:30 -0700
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+AFTOJK4O5FOGFGCJRJYPKEV5MQZPNEVBNHHCS6GFAM@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/4079/review/484642921@github.com>
In-Reply-To: <quicwg/base-drafts/pull/4079@github.com>
References: <quicwg/base-drafts/pull/4079@github.com>
Subject: Re: [quicwg/base-drafts] forbid key discarding before receiving a packet protected with new keys (#4079)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5f5851f658a4_372019f0590d0"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/U_AoIFDofJfnvrLGdHxmRCmknUo>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Sep 2020 03:54:33 -0000
@martinthomson commented on this pull request. > @@ -1496,10 +1496,11 @@ The endpoint that initiates a key update also updates the keys that it uses for receiving packets. These keys will be needed to process packets the peer sends after updating. -An endpoint SHOULD retain old keys so that packets sent by its peer prior to -receiving the key update can be processed. Discarding old keys too early can -cause delayed packets to be discarded. Discarding packets will be interpreted -as packet loss by the peer and could adversely affect performance. +An endpoint MUST retain old keys until it has successfully unprotected a packet +sent using the new keys. An endpoint SHOULD NOT discard old keys immediately +after unprotecting a packet sent using the new keys. Discarding old keys too +early can cause delayed packets to be discarded. Discarding packets will be +interpreted as packet loss by the peer and could adversely affect performance. Yes, it's safe to drop key N when you receive packets protected with key N+1. And it's true that keeping keys for a short while helps avoid dropping reordered packets. However, it it generally safer to only drop key N when you receive an acknowledgment for a packet sent with N+1 keys. Because the other side might have updated on its own. That means that the N+1 packet you received isn't any indication that they received your key update. This distinction doesn't matter for dropping keys, but it does matter for determining whether you can initiate an update to N+2 keys later. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/pull/4079#discussion_r485321502
- [quicwg/base-drafts] forbid key discarding before… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Kazuho Oku
- Re: [quicwg/base-drafts] forbid key discarding be… Mike Bishop
- Re: [quicwg/base-drafts] forbid key discarding be… ianswett
- Re: [quicwg/base-drafts] forbid key discarding be… Kazuho Oku
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… ianswett
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson