[radext] Re: Final update to RADIUS/(D)TLS-bis
Alan DeKok <alan.dekok@inkbridge.io> Sun, 02 August 2026 22:31 UTC
Return-Path: <alan.dekok@inkbridge.io>
X-Original-To: radext@mail2.ietf.org
Delivered-To: radext@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 848AF1226B0B9 for <radext@mail2.ietf.org>; Sun, 2 Aug 2026 15:31:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785709877; bh=J3OC2dxZ4Mwq1asxROBsdEQ8IgDkjNvNFK2esgwXJA4=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=j4KxDAXJYQNAXFsNr1KCzfnGr481h2jWrU91b6qBy82ivJYA9W6YsRQJanm2TYmQj JPjO/sOX5Tu/pJSYk4+jUVoUEZWSKMSms25D0SHghcoEp2YhQkiE/IiRv9qKpopM/+ ZkXbRdrPxG1kXrBVl7MC8NxiE08uRjZJOXhxfGm4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=inkbridge.io
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wXDqI4SMMzFc for <radext@mail2.ietf.org>; Sun, 2 Aug 2026 15:31:16 -0700 (PDT)
Received: from mail.networkradius.com (mx1-ca.networkradius.com [199.66.222.134]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4D3A01226B0AE for <radext@ietf.org>; Sun, 2 Aug 2026 15:31:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=inkbridge.io; s=sep2024; t=1785709869; bh=2W30atA/Q6O6xBIKwrEiO1Hr0lUve7Kq5mOxhGv7Y5g=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=SDQSbn6QmuzLHPlII0rmdrERbFh4A7AeNyYb9Wb+CZiXq8nTGrefYQj6I56gjHw5L 1e+AmJFN982C7CNSMdE1sgqGz/dwygeHLWA8ACedN4/YCflXoSHtqmRXeQbWMK2S7+ 6ah/ToEpi8kskGrXFvShJ7S6tItTs/1DxeILN7VbzW1Qb4e/v/d1IMQ/ZgsZ9NhzGj maAnEvThnkaCXUELk6OwCxtRNNP7lQJONESPN3lI/KTkNXYml/7evw9FiN18CKdVPa JTGOAHtoEXqiqlUxlOxW3UuVb+ZEFlqoplJmas6XS3RGANjvq0ppNDjdn3zxrAV0wC a8WN7/1T03o9w==
Received: from smtpclient.apple (24-246-4-149.cable.teksavvy.com [24.246.4.149]) by mail.networkradius.com (Postfix) with ESMTPSA id 46B371340097; Sun, 02 Aug 2026 22:31:09 +0000 (UTC)
Content-Type: multipart/signed; boundary="Apple-Mail=_4AA2D95A-8541-4F62-8849-C1E138A2CF53"; protocol="application/pgp-signature"; micalg="pgp-sha256"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\))
From: Alan DeKok <alan.dekok@inkbridge.io>
In-Reply-To: <4be6b9ec-3432-441f-a1f2-689261d94571@dfn.de>
Date: Sun, 02 Aug 2026 18:30:58 -0400
Message-Id: <FC79EC33-0C8E-4EFA-8E98-5D4721F484D4@inkbridge.io>
References: <4be6b9ec-3432-441f-a1f2-689261d94571@dfn.de>
To: Jan-Frederik Rieckers <rieckers@dfn.de>
X-Mailer: Apple Mail (2.3826.700.81.1.4)
Message-ID-Hash: IYTDXOMUOPSK3I6RNRANUIPJJRUST4VS
X-Message-ID-Hash: IYTDXOMUOPSK3I6RNRANUIPJJRUST4VS
X-MailFrom: alan.dekok@inkbridge.io
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-radext.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "radext@ietf.org" <radext@ietf.org>, stndrds-inacio@andrew.cmu.edu
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [radext] Re: Final update to RADIUS/(D)TLS-bis
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/X_eW_6DdhWXZBv8fPHn9qjlbdqM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Owner: <mailto:radext-owner@ietf.org>
List-Post: <mailto:radext@ietf.org>
List-Subscribe: <mailto:radext-join@ietf.org>
List-Unsubscribe: <mailto:radext-leave@ietf.org>
On Aug 1, 2026, at 4:43 AM, Jan-Frederik Rieckers <rieckers@dfn.de> wrote: > I've put them in this PR: > https://github.com/radext-wg/draft-ietf-radext-radiusdtls-bis/pull/172 > > The changes are: > > * Explicitly state that a connection attempt must be rejected if the peer certificate is not accepted. (for the client side we reference RFC9525, Section 6.6) > * Servers should send a TLS alert of access denied in this case. > * A connection is treated as "failed" if it has not received valid packets within the reconnect window (e.g., closed immediately after the TLS handshake) > * Remove paragraph about retries on different protocol/connection. (This most likely is an artifact from the old "Server Identity" discussion, I've clarified things more in the retransmit/retry section) That looks good, thanks. > The following non-editorial changes have been made: > > * Clients MAY open multiple connections, servers MUST be able to accept multiple connections per client > * Forbid usage of 0-RTT > * Implementations MUST reassess validity if the trusted CAs/revocation information changes (previously SHOULD) > * Added ALPN of "radius/1.0" as SHOULD (with a whole paragraph) > * Add (short) discussion of Connection IDs for DTLS > * Remove text around Path-MTU Discovery > * Add ALPN "radius/1.0" to IANA section > * Add Appendix explaining the congestive collapse for Acct-Delay-Time vs. Event-Timestamp That looks good too, thanks. Alan DeKok.
- [radext] Final update to RADIUS/(D)TLS-bis Jan-Frederik Rieckers
- [radext] Re: Final update to RADIUS/(D)TLS-bis Margaret Cullen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Heikki Vatiainen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Jan-Frederik Rieckers
- [radext] Re: Final update to RADIUS/(D)TLS-bis Margaret Cullen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Alan DeKok
- [radext] Re: Final update to RADIUS/(D)TLS-bis Heikki Vatiainen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Alan DeKok
- [radext] Re: Final update to RADIUS/(D)TLS-bis Heikki Vatiainen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Jan-Frederik Rieckers
- [radext] Re: Final update to RADIUS/(D)TLS-bis Heikki Vatiainen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Alan DeKok
- [radext] Re: Final update to RADIUS/(D)TLS-bis Heikki Vatiainen
- [radext] Re: Final update to RADIUS/(D)TLS-bis Alan DeKok
- [radext] Re: Final update to RADIUS/(D)TLS-bis Peter Deacon
- [radext] Re: Final update to RADIUS/(D)TLS-bis Fabian Mauchle
- [radext] Re: Final update to RADIUS/(D)TLS-bis Michael Richardson