[Seat] Re: Fwd: New Version Notification for draft-usama-seat-intra-vs-post-00.txt
Ayoub Benaissa <ayoub.benaissa@zama.ai> Fri, 16 January 2026 08:24 UTC
Return-Path: <ayoub.benaissa@zama.ai>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E48DFA8798A2 for <seat@mail2.ietf.org>; Fri, 16 Jan 2026 00:24:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=zama.ai
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mSACThu7jmLp for <seat@mail2.ietf.org>; Fri, 16 Jan 2026 00:24:03 -0800 (PST)
Received: from mail-ed1-x530.google.com (mail-ed1-x530.google.com [IPv6:2a00:1450:4864:20::530]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2A183A879897 for <seat@ietf.org>; Fri, 16 Jan 2026 00:24:01 -0800 (PST)
Received: by mail-ed1-x530.google.com with SMTP id 4fb4d7f45d1cf-64d02c01865so2931740a12.1 for <seat@ietf.org>; Fri, 16 Jan 2026 00:24:01 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1768551840; cv=none; d=google.com; s=arc-20240605; b=kuvqTDMiFvkigKvBJ8EMqxy6XI9JhCQwtC5eQU5FcOwKCqBkovOmhCsXExQhxiSoSF E/d7YhEDFXYcmX/9QpFfkf1sudIYWmVnVL2HFanOpdGNo/6oh4Bn1YcHcJFHFbG3kXqd J6yqbWgGpzajRzsVBtEIicINegS4lOb40gfpp5gG8Ow1gXpQrmSZ6J1Kw43ySKXYFkkK V3qOfFbr4Ch7wma+DQ/mdD6BAmNs92bnUIbXNPe+kccD1yEcoYywFvEWkCcnBc8+HZRo Nr0ToOrvJ2sPhTIPzbzBKHKTTeYjGmyftOPAAa9ueefOmEUWhohHRF5hQLMNXLw37/65 Wglw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=cAgk2A4rYCPitI4cIMg/OfCwZIYgT1RX6fK2dV9f5xQ=; fh=nonanup7af3odSacD+avaZXzPkTQ1Kb/ongJHX+6ikI=; b=UMeWz1Ykqs+LOAl5Lo5deLcdr6Htf/4r7TaqRlMQ3v2sltmQeS+akKwsn+kB+lLAiG /VC+fr/Yk4gmkc1tqnyvlOM6YMKNJUMxQh7r+2lVdXU4lSBQRI/CzoVBYxaOFgVtdbnE 8Jgn/O8IgXpDMwjgq3SARfLTGDuE/W3EPv+mKj2tvzHEhBu+jtqbWuSE8B7Usj5tkbMn HhG7+l4Rg29tYubfoKfbLOjnxCT3qH1G7QojZfg5vSypiqegQ4qjunFKQLW4kTv2hmIp mxCvpTCe1FNalEfPEt2z1R+bizwBqwlNTg+KVKl3U5hGo0/71UYdwiVRaJPZ9EYlBqKg Buyw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zama.ai; s=google; t=1768551840; x=1769156640; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=cAgk2A4rYCPitI4cIMg/OfCwZIYgT1RX6fK2dV9f5xQ=; b=OY1wxBsRFgfGpM1XPhbi/3x/G1I36APYh/vT37Ecp0PqlgXeuVRgFpSj7YotrjsdO/ ZWGJUsoa+fJblxSB49WGc9kGP/XaSYBDILr1HZblb1U6a37xmdLZhiz1XmYI4H7fquXi kFvxSrUp0M0b/y7yuMQPDfXZuMuYmZoLevZIDRNi8qErVdIBCp8Y4or9z4/Kv3v2HA3R vrlt9EPWg1wQOc1vyBVv6ZnvrngVetTwAvUPMLVltmAByiXy1S8E5NXX8JHkNqpTyDMH PdM1/WSuQWKwnMaj3XxQP85S7L+VDyfuiziv3mqSA+LQ1SN7fIGdnM06ea5V/tZF5It3 GdJg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768551840; x=1769156640; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=cAgk2A4rYCPitI4cIMg/OfCwZIYgT1RX6fK2dV9f5xQ=; b=fMA52WuosCxrqrFyQkVr7HFf94kjXLcttlONzyDVH7rjwbmcGehmmTq6nWtZQFNGFp 4hSbLOb+qX/D5jhFknLvoxJATl2293pkBC0qZ5sQjAqHatExPACC8e/3cppuxjFzclmG rzm6djYbhJmk2rJGOiyMf2hKB/y743pOrv8X/bQcn8jAnyWhuVovlIu/KEDyI9OB69yr oRzvKDxr+IqMS3Bacv9s7c7bCTTGgcpjQNsFBS5duDLjuv4F5PS8VXoEFAnwng2mZgy4 2Fzj/kWixKq7rg899LUJyKWB5jCHijBOOQJg/2bdpq3T8riRNmzy2WLmZeNhKV7URzkx Mzqw==
X-Gm-Message-State: AOJu0YwQHq+m9sWEz2XDz2fPvKlSJmifXicaBAHv+yRnBTS6bDqV+HCE sEtjcHQ09JO3WhceKJst+5bvLGpKtev4AwrhOd1GKxveEHCAO5IxX4Us5tC6bb/nD/OgoxYhfyr JAC8JWNd0MaOjeP9daiLSB+f8ARliIVJW6G36XZvf/KO6JFPLHmQSZ7lwBQ==
X-Gm-Gg: AY/fxX5N3M2dbsLgIZB5wCM8RhGHshsUiOe5K0gdLL1GCz9rCL6na+IqlyIFBLVFcDq zAfNh2swmJ0pj6ZSueJ4HV/38TNPqhEXS0JBv2ipPMJ5bzPk0jisCeVa+v3cZhOyyDNNp76atlG B+V3mTl60izLw89jI50VSa/CQGvDHOZb9mZd53kqeLqa3y1TwIXy1jZyntedXqqfV+08cYYwcVZ MobWcNKNR602gzVT7x7P3xCuEoaLdAqLKveE+0MqL+OYYhGSHrw2+qxttkgM7uvro1AXEGIkfSP zZmb+fU=
X-Received: by 2002:a05:6402:4404:b0:649:cb6e:61ea with SMTP id 4fb4d7f45d1cf-654ba3be113mr1451779a12.15.1768551839635; Fri, 16 Jan 2026 00:23:59 -0800 (PST)
MIME-Version: 1.0
References: <CAD_oqtdC-aerstGEfJpLoPDexUZmihehSwQgQvFpdJ2tZmYuow@mail.gmail.com> <bd17ac4f-e5ab-4853-870b-f05bc37eb2d4@tu-dresden.de>
In-Reply-To: <bd17ac4f-e5ab-4853-870b-f05bc37eb2d4@tu-dresden.de>
From: Ayoub Benaissa <ayoub.benaissa@zama.ai>
Date: Fri, 16 Jan 2026 09:23:48 +0100
X-Gm-Features: AZwV_QhOQa9ZOcWOBVByAPKd_f5wYzkQepI-KB4qLssyNEqbRImIlOPDP7MzPcA
Message-ID: <CAD_oqtf=b87O+G=X5XX0H_=AoUsOQRLLhadO6BScyi_3QAMt1w@mail.gmail.com>
To: seat@ietf.org
Content-Type: multipart/alternative; boundary="0000000000002b26ad06487d1021"
X-MailFrom: ayoub.benaissa@zama.ai
X-Mailman-Rule-Hits: nonmember-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation
Message-ID-Hash: TU6JKOZ3BMQNTA5OU7NJBM2YRECMZKOV
X-Message-ID-Hash: TU6JKOZ3BMQNTA5OU7NJBM2YRECMZKOV
X-Mailman-Approved-At: Fri, 16 Jan 2026 01:08:21 -0800
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Fwd: New Version Notification for draft-usama-seat-intra-vs-post-00.txt
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/8eynK9ky5F-TcnL_UPbSRDKuK1E>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
On Fri, Jan 16, 2026 at 3:26 AM Muhammad Usama Sardar < muhammad_usama.sardar@tu-dresden.de> wrote: > Hi Ayoub, > > On 15.01.26 16:59, Ayoub Benaissa wrote: > > From a practical perspective, I think a post-handshake implementation > > makes more sense. We have been building an Attested TLS protocol for a > > web-based application, and we had to do a post-handshake > > implementation. Intra-handshake requires too much change. For example, > > you have to reimplement or customize how Nginx (or other) servers > > speak TLS. This would take months and more to have a standard > > implementation that is somehow safe to use. It's different in a > > post-handshake implementation where you can have a full working > > example in a matter of weeks. > > Could you possibly share more details? > > Also, we are collecting use cases of attested TLS [0]. Would you be > willing to share your use case and co-author the use cases draft [0], as > in write goal, use case and requirement? Thanks. > > -Usama > > [0] > > https://tls-attestation.github.io/use-cases-and-properties/draft-mihalcea-seat-use-cases.html#section-3 > > I will gladly share our use case. How should I do that? For what I said about post-handshake vs intra-handshake, I will try to elaborate with a few points: - TLS might not be well suited to include this in its protocol. Not sure TEEs are even as mature for the people to see that it should be included right now. The plan to make it a post-handshake protocol makes more sense right now. A future where it's incorporated into TLS might exist, but I don't think there is enough motivation right now. - An intra-handshake requires much more work compared to a post-handshake. People need to agree on how to add this as optional in TLS (we can't force everyone to use it of course), the standard needs to be implemented by major libraries, and then it will be available in major client/server applications. If any of the prior steps doesn't go through, it means you have to patch your components to make it work, which is not convenient / less secure. - We already implemented a post-handshake protocol and have a full demo working. We were able to do this in a matter of weeks. That's because you don't need to modify any TLS implementation, but only add a few verification steps after the usual TLS handshake. This is almost the same on the client and server side. I also want to point out that the need for such a protocol is high. I can talk about how LLMs are being served with TEEs, and everyone is doing the attested TLS differently. A standard leading to a major and secure implementation that can be used in browsers and so on would really benefit the people.
- [Seat] Fwd: New Version Notification for draft-us… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Paul Wouters
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Paul Wouters
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Paul Wouters
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Ayoub Benaissa
- [Seat] Re: Fwd: New Version Notification for draf… Ayoub Benaissa
- [Seat] Re: Fwd: New Version Notification for draf… Markus Rudy
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Ayoub Benaissa
- [Seat] Re: Fwd: New Version Notification for draf… Markus Rudy
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar
- [Seat] Re: Fwd: New Version Notification for draf… Muhammad Usama Sardar