Re: [saag] AD review of draft-iab-crypto-alg-agility-06

"Salz, Rich" <rsalz@akamai.com> Tue, 25 August 2015 15:44 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A43811B2F65 for <saag@ietfa.amsl.com>; Tue, 25 Aug 2015 08:44:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.711
X-Spam-Level:
X-Spam-Status: No, score=-2.711 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1r30mwn1YLfq for <saag@ietfa.amsl.com>; Tue, 25 Aug 2015 08:44:14 -0700 (PDT)
Received: from prod-mail-xrelay08.akamai.com (prod-mail-xrelay08.akamai.com [96.6.114.112]) by ietfa.amsl.com (Postfix) with ESMTP id 46B901B2F49 for <saag@ietf.org>; Tue, 25 Aug 2015 08:44:14 -0700 (PDT)
Received: from prod-mail-xrelay08.akamai.com (localhost.localdomain [127.0.0.1]) by postfix.imss70 (Postfix) with ESMTP id 560FD74001B for <saag@ietf.org>; Tue, 25 Aug 2015 15:44:13 +0000 (GMT)
Received: from prod-mail-relay08.akamai.com (prod-mail-relay08.akamai.com [172.27.22.71]) by prod-mail-xrelay08.akamai.com (Postfix) with ESMTP id 3B533740018 for <saag@ietf.org>; Tue, 25 Aug 2015 15:44:13 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=akamai.com; s=a1; t=1440517453; bh=HsVkRQiJUz3UM9MiDo5fsD+DijG7cnNOwXdc0ptWTl8=; l=693; h=From:To:Date:References:In-Reply-To:From; b=VEEgFx+GssBLAHjBxpvprIwDa5wqOBXSODktZxeZvyxkZ79yP/lgUF/erAUawhaee ybh0JyL4L5nGsJkgxtTAkKG4AhT/hM5nJNxlhcFckZWTSCWkrd98e4dv89tQA4Poew EkNxwtja8tSAawJcJPbDyBqzG4L5jrpdpNbXUCrQ=
Received: from email.msg.corp.akamai.com (ustx2ex-cas1.msg.corp.akamai.com [172.27.25.30]) by prod-mail-relay08.akamai.com (Postfix) with ESMTP id 395E998082 for <saag@ietf.org>; Tue, 25 Aug 2015 15:44:13 +0000 (GMT)
Received: from USTX2EX-DAG1MB2.msg.corp.akamai.com (172.27.27.102) by ustx2ex-dag1mb3.msg.corp.akamai.com (172.27.27.103) with Microsoft SMTP Server (TLS) id 15.0.1076.9; Tue, 25 Aug 2015 10:44:12 -0500
Received: from USTX2EX-DAG1MB2.msg.corp.akamai.com ([172.27.6.132]) by ustx2ex-dag1mb2.msg.corp.akamai.com ([172.27.6.132]) with mapi id 15.00.1076.000; Tue, 25 Aug 2015 10:44:12 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "saag@ietf.org" <saag@ietf.org>
Thread-Topic: [saag] AD review of draft-iab-crypto-alg-agility-06
Thread-Index: AQHQ3qvj021A7RxjOEahYRWcAOaGUp4b/kqA//+syqCAAFk4gIAAoQGAgABpPoD//8v60A==
Date: Tue, 25 Aug 2015 15:44:12 +0000
Message-ID: <6b5167f3d0684a8a91caa6d37dec65e3@ustx2ex-dag1mb2.msg.corp.akamai.com>
References: <20150727194020.GD15860@localhost> <55B6D36C.70105@iang.org> <20150728013020.GO4347@mournblade.imrryr.org> <DM2PR0301MB0655CF099FA7C56E9B9D24A9A88D0@DM2PR0301MB0655.namprd03.prod.outlook.com> <20150728053035.GR4347@mournblade.imrryr.org> <CAHbuEH7B3_G9vAhw=U2tuz-Uh8mKMUfL6s=H+BOG96FDZaACig@mail.gmail.com> <20150824212907.GN9021@mournblade.imrryr.org> <619ffebb05ba4e2a9af03a6dcc768d6e@ustx2ex-dag1mb2.msg.corp.akamai.com> <20150824215037.GO9021@mournblade.imrryr.org> <9A043F3CF02CD34C8E74AC1594475C73F4AE62A1@uxcn10-5.UoA.auckland.ac.nz> <20150825134333.GX9021@mournblade.imrryr.org>
In-Reply-To: <20150825134333.GX9021@mournblade.imrryr.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.44.72]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/3SoqG3buFpHOzhb53MMs7ArSVlQ>
Subject: Re: [saag] AD review of draft-iab-crypto-alg-agility-06
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Aug 2015 15:44:15 -0000

> Opportunistic TLS is supported in at least Exchange 2007 and later.
> I don't recall what Exchange 2003 did outbound, I only recall helping
> Microsoft to design fixes for various issues prior to the release of Exchange
> 2007.  Some flaws remain, but it is largely workable without a CA tax.

This is important.  It means that for SMTP, OS really started in 2005 with Postfix and 2007 for Exchange?   If so, then there is really no need to support RC4.  STARTTLS, as Peter was saying, can imply more than just OS, as MS really wants a CA to be involved.  Since a principle tenet of OS is *unauthenticated* privacy, it appears that the discussion has conflated the two.