[radext] Re: I-D Action: draft-ietf-radext-tls-psk-10.txt

Alan DeKok <aland@deployingradius.com> Thu, 01 August 2024 13:41 UTC

Return-Path: <aland@deployingradius.com>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88AF1C14F6BC for <radext@ietfa.amsl.com>; Thu, 1 Aug 2024 06:41:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.907
X-Spam-Level:
X-Spam-Status: No, score=-6.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PmpsCUDQUy39 for <radext@ietfa.amsl.com>; Thu, 1 Aug 2024 06:40:56 -0700 (PDT)
Received: from mail.networkradius.com (mail.networkradius.com [62.210.147.122]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72CF9C14F681 for <radext@ietf.org>; Thu, 1 Aug 2024 06:40:55 -0700 (PDT)
Received: from smtpclient.apple (135-23-95-232.cpe.pppoe.ca [135.23.95.232]) by mail.networkradius.com (Postfix) with ESMTPSA id 38D8643F for <radext@ietf.org>; Thu, 1 Aug 2024 13:40:53 +0000 (UTC)
Authentication-Results: NetworkRADIUS; dmarc=none (p=none dis=none) header.from=deployingradius.com
From: Alan DeKok <aland@deployingradius.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
Date: Thu, 01 Aug 2024 09:40:51 -0400
References: <172251928752.2349928.10687788010005883004@dt-datatracker-659f84ff76-9wqgv>
To: radext@ietf.org
In-Reply-To: <172251928752.2349928.10687788010005883004@dt-datatracker-659f84ff76-9wqgv>
Message-Id: <3B1E6326-64CD-4BDB-9696-5D173168F8C2@deployingradius.com>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Message-ID-Hash: S3NIOG2KIWVPDQ2D33CZFYSBLDRNJ67Y
X-Message-ID-Hash: S3NIOG2KIWVPDQ2D33CZFYSBLDRNJ67Y
X-MailFrom: aland@deployingradius.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-radext.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [radext] Re: I-D Action: draft-ietf-radext-tls-psk-10.txt
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/XCwDZBo9Ug6QOhlreOVDDBfI5Vg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Owner: <mailto:radext-owner@ietf.org>
List-Post: <mailto:radext@ietf.org>
List-Subscribe: <mailto:radext-join@ietf.org>
List-Unsubscribe: <mailto:radext-leave@ietf.org>

  This version addresses issues raised in the mailing list, including the Selfie attack.  

> On Aug 1, 2024, at 9:34 AM, internet-drafts@ietf.org wrote:
> 
> Internet-Draft draft-ietf-radext-tls-psk-10.txt is now available. It is a work
> item of the RADIUS EXTensions (RADEXT) WG of the IETF.
> 
>   Title:   RADIUS and TLS-PSK
>   Author:  Alan DeKok
>   Name:    draft-ietf-radext-tls-psk-10.txt
>   Pages:   21
>   Dates:   2024-08-01
> 
> Abstract:
> 
>   This document gives implementation and operational considerations for
>   using TLS-PSK with RADIUS/TLS (RFC6614) and RADIUS/DTLS (RFC7360).
>   The purpose of the document is to help smooth the operational
>   transition from the use of the insecure RADIUS/UDP to the use of the
>   much more secure RADIUS/TLS.
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-radext-tls-psk/
> 
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-radext-tls-psk-10.html
> 
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-radext-tls-psk-10
> 
> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts
> 
> 
> _______________________________________________
> radext mailing list -- radext@ietf.org
> To unsubscribe send an email to radext-leave@ietf.org