Re: [saag] new terminology ID posted
Stephen Kent <kent@bbn.com> Mon, 14 April 2014 13:57 UTC
Return-Path: <kent@bbn.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A2E11A0489 for <saag@ietfa.amsl.com>; Mon, 14 Apr 2014 06:57:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.473
X-Spam-Level:
X-Spam-Status: No, score=-4.473 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.272, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qHBt0Fh2_Ody for <saag@ietfa.amsl.com>; Mon, 14 Apr 2014 06:57:39 -0700 (PDT)
Received: from smtp.bbn.com (smtp.bbn.com [128.33.0.80]) by ietfa.amsl.com (Postfix) with ESMTP id 7B6351A0466 for <saag@ietf.org>; Mon, 14 Apr 2014 06:57:39 -0700 (PDT)
Received: from dommiel.bbn.com ([192.1.122.15]:38177 helo=comsec.home) by smtp.bbn.com with esmtp (Exim 4.77 (FreeBSD)) (envelope-from <kent@bbn.com>) id 1WZhOC-0007bf-W2 for saag@ietf.org; Mon, 14 Apr 2014 09:57:37 -0400
Message-ID: <534BE950.3070809@bbn.com>
Date: Mon, 14 Apr 2014 09:57:36 -0400
From: Stephen Kent <kent@bbn.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: saag@ietf.org
References: <533AE246.9080806@bbn.com> <20140401163654.GD12559@mournblade.imrryr.org> <533B0993.80001@bbn.com> <20140405212023.GF2727@localhost> <20140406033929.GQ12559@mournblade.imrryr.org> <5342B454.1050607@bbn.com> <20140407150834.GW12559@mournblade.imrryr.org> <5342EF73.5070903@bbn.com> <20140407203658.GE12559@mournblade.imrryr.org> <53444C89.4040502@bbn.com> <20140408212304.GO12559@mournblade.imrryr.org>
In-Reply-To: <20140408212304.GO12559@mournblade.imrryr.org>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/saag/iPplNNLxcwqVTcksgBGYFiXpgUo
Subject: Re: [saag] new terminology ID posted
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Apr 2014 13:57:41 -0000
Viktor, > ... > I am not asking you to classify RFC 6698 DANE as OS. Rather, I'm > asking you leave room for opportunistic variants of RFC 6698 such > as: > > http://tools.ietf.org/html/draft-ietf-dane-smtp-with-dane > > Opportunistic DANE TLS is a protocol in which (for now SMTP) clients > employ as strong as possible security with each (SMTP) server. > This subsumes cleartext for servers that neither publish TLSA > records nor offer STARTTLS (or some MITM downgraded their EHLO > response). It also subsumes opportunitic unauthenticated TLS when > no TLSA records are found, but STARTTLS is available. It also > subsumes mandatory unauthenticated TLS when TLSA records exist, > but none are usable, ... I understand, now. Sorry for the confusion. > >> But, as you noted, if one employs authenticated cipher suites plus >> DH (ECDH) one can still achieve PFS. > Across all TLSA record types, the TLSA record does not select the > TLS key exchange mechanism. It can be PFS or RSA key transport if > the keys happen to be RSA keys, but even RSA keys work with PFS. You are correct. But, I suspect that most folks reading 6698 interpret it relative to the most common practice for TLS, in which RSA is used for key transport. If one conveys an EE cert via a TLSA record, I think most folks would not expect that cert to be used for auth and NOT key transport, even though that use case is covered by TLS. Anyway, I was confused by which doc we were debating. My bad. And, you are correct that TLSA records do not, strictly speaking, dictate the cipher suite used with TLS, so PFS is not incompatible with use of DANE. Steve
- [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Farrell
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Salz, Rich
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Tero Kivinen
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Nico Williams
- Re: [saag] new terminology ID posted Nico Williams
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Paul Hoffman
- Re: [saag] new terminology ID posted Nico Williams
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Eliot Lear
- Re: [saag] new terminology ID posted Paul Hoffman
- Re: [saag] new terminology ID posted Nico Williams
- Re: [saag] new terminology ID posted Stephen Farrell
- [saag] area WGs (was: Re: new terminology ID post… Stephen Farrell
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Paul Hoffman
- Re: [saag] new terminology ID posted Olle E. Johansson
- Re: [saag] new terminology ID posted Nico Williams
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent
- Re: [saag] new terminology ID posted Viktor Dukhovni
- Re: [saag] new terminology ID posted Stephen Kent