Re: [quicwg/base-drafts] TLS alert no_application_protocol is not always possible (#3580)

Martin Thomson <> Wed, 15 April 2020 00:41 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id EED293A13C1 for <>; Tue, 14 Apr 2020 17:41:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.175
X-Spam-Status: No, score=-2.175 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.168, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_IMAGE_ONLY_16=1.092, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id Zw4wQtMBoxMK for <>; Tue, 14 Apr 2020 17:41:46 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 685BF3A13B2 for <>; Tue, 14 Apr 2020 17:41:46 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 1B526660A92 for <>; Tue, 14 Apr 2020 17:41:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=pf2014; t=1586911305; bh=eMtO5bosq7GjXSH256eOwJ5rce//f8BJtFHqVIIH37Q=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=GPIuT8P4qxj7s98cikNjVVLLa/i8s41fKz5DBNrwTknw8MLPq9j/hpVcS2H49aexe gyjsD9Z3QkcitiLoMHcivizCDEtXlETTpTyjdU+mgWkplvcRZ/0aiuhDCAYG5cASZY dn8r5PhfTQn06DQ5VfWoaEjrMc2GceiS0FPi88R4=
Date: Tue, 14 Apr 2020 17:41:45 -0700
From: Martin Thomson <>
Reply-To: quicwg/base-drafts <>
To: quicwg/base-drafts <>
Cc: Subscribed <>
Message-ID: <quicwg/base-drafts/issues/3580/>
In-Reply-To: <quicwg/base-drafts/issues/>
References: <quicwg/base-drafts/issues/>
Subject: Re: [quicwg/base-drafts] TLS alert no_application_protocol is not always possible (#3580)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5e965849baeb_22fb3fcbcdacd964153171"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
Archived-At: <>
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 15 Apr 2020 00:41:54 -0000

This is probably fine as the reason is observable.  It is true that some TLS alerts are hidden, but that is generally because that leaks private information.  But here the information is public, or at least shared by client and server.

Is the concern that this is potentially sent in an Initial frame?  Because that shouldn't be necessary, or even possible.

You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub: