Re: [tcpinc] Review of draft-bittau-tcpinc-tcpeno-01

Mirja Kühlewind <mirja.kuehlewind@tik.ee.ethz.ch> Wed, 26 August 2015 15:47 UTC

Return-Path: <mirja.kuehlewind@tik.ee.ethz.ch>
X-Original-To: tcpinc@ietfa.amsl.com
Delivered-To: tcpinc@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D47F61A8BC4 for <tcpinc@ietfa.amsl.com>; Wed, 26 Aug 2015 08:47:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.91
X-Spam-Level:
X-Spam-Status: No, score=-3.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oOcivni9tnTs for <tcpinc@ietfa.amsl.com>; Wed, 26 Aug 2015 08:47:20 -0700 (PDT)
Received: from smtp.ee.ethz.ch (smtp.ee.ethz.ch [129.132.2.219]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3EE7D1A883E for <tcpinc@ietf.org>; Wed, 26 Aug 2015 08:47:19 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.ee.ethz.ch (Postfix) with ESMTP id 47AF8D9316; Wed, 26 Aug 2015 17:47:18 +0200 (MEST)
X-Virus-Scanned: by amavisd-new on smtp.ee.ethz.ch
Received: from smtp.ee.ethz.ch ([127.0.0.1]) by localhost (.ee.ethz.ch [127.0.0.1]) (amavisd-new, port 10024) with LMTP id In4rWppZD46X; Wed, 26 Aug 2015 17:47:18 +0200 (MEST)
Received: from [10.2.124.145] (public-docking-etx-3215.ethz.ch [10.2.124.145]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: mirjak) by smtp.ee.ethz.ch (Postfix) with ESMTPSA id 0B30ED9307; Wed, 26 Aug 2015 17:47:18 +0200 (MEST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2102\))
From: Mirja Kühlewind <mirja.kuehlewind@tik.ee.ethz.ch>
In-Reply-To: <55DCCA26.1040803@cs.tcd.ie>
Date: Wed, 26 Aug 2015 17:47:20 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <E93F1869-ACC3-4490-8280-94176227ECC4@tik.ee.ethz.ch>
References: <CABcZeBNEFVkDi38y3G-C2nQF=dzW2mGDsj5DVK_OKVkPwK=G0g@mail.gmail.com> <871teuo7nu.fsf@ta.scs.stanford.edu> <CACsn0ckn-QdoXmTgjW8gYQyVqZ0x9JHEYvZO5VHQkG9nKA3-Ew@mail.gmail.com> <87wpwmnenv.fsf@ta.scs.stanford.edu> <CACsn0cnq9cZdkn=yp8-GJfXDGMP8r1sib3qrQQEQYhF25kYZPg@mail.gmail.com> <87twrpokpz.fsf@ta.scs.stanford.edu> <CACsn0ck2PfKQ8pkDLiSmuLH+81s2GzsBnKYH7e=5ga5nSJvo1Q@mail.gmail.com> <87io85ofkl.fsf@ta.scs.stanford.edu> <CACsn0cmna07KzCZme7pxRgCcAOJLXzup3KPJ+bRimL=n3mpPXg@mail.gmail.com> <87vbc5l8si.fsf@ta.scs.stanford.edu> <CACsn0c=cLj2F6JyFX848D1TuDt0A=kT7UMm8ZPRRu-X6ow4oTQ@mail.gmail.com> <55DB79BC.8040309@bbn.com> <55DB8338.4060403@cs.tcd.ie> <877foke4yx.fsf@ta.scs.stanford.edu> <55DB93CD.4000701@cs.tcd.ie> <87zj1gcng8.fsf@ta.scs.stanford.edu> <55DC4A97.3000602@cs.tcd.ie> <877foje94q.fsf@ta.scs.stanford.edu> <55DC81F3.9090904@cs.tcd.ie> <871tere2b5.fsf@ta.scs.stanford.edu> <55DCCA26.1040803@cs.tcd.ie>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, David Mazieres expires 2015-11-23 PST <mazieres-kag7pprthcqzjsh5ew583fg4jn@temporary-address.scs.stanford.edu>, tcpinc@ietf.org
X-Mailer: Apple Mail (2.2102)
Archived-At: <http://mailarchive.ietf.org/arch/msg/tcpinc/Sey0FcsfyV-5gSSwinOijQEqoSE>
Subject: Re: [tcpinc] Review of draft-bittau-tcpinc-tcpeno-01
X-BeenThere: tcpinc@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussion list for adding encryption to TCP." <tcpinc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tcpinc>, <mailto:tcpinc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tcpinc/>
List-Post: <mailto:tcpinc@ietf.org>
List-Help: <mailto:tcpinc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tcpinc>, <mailto:tcpinc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2015 15:47:23 -0000

Hi Stephen,

just to double-check if I understand correctly what you are saying:

You basically say that you would not support the tcp-eno approach because you would like to have for any tcpinc protocol (not matter if tcp-use-tls or tcpcrypt) only a very simple negotiation in a TCP option where both ends confirm that they support tcpinc and then all additional negotiation is done in the payload data space (and therefore an own document is not needed)?

What’s about the argument, that I believe you’ve stated earlier yourself, that one could use tcp-eno to update to a new protocol version (not only a new cipher) in case we detect flaws in the general protocol design…? If you think this is useful to have, would it then make then to have an own document for it (and potentially take the tcp-eno proposal as a starting point)?

Mirja



On 25.08.2015 22:03, Stephen Farrell wrote:
> 
> On 25/08/15 17:54, David Mazieres wrote:
>> TCP-ENO is an
>> effort A) to make progress on common elements of TCP-use-TLS and
>> tcpcrypt,
> 
> The above is reasonable.
> 
> ...
>> Well, in order to make the choice between tcpcrypt and TCP-use-TLS the
>> most salient, it seems worth maximizing the advantages of the two
>> protocols.
> 
> I think your goal (A) and "maximising the advantages" of tcpcrypt
> (or of TLS) are incompatible goals at this point in time.
> 
> If/when the WG adopt tcpcrypt optimisations relating to algorithm
> agility will inevitably be explored. If/when the WG adopt TLS that
> kind of change wouldn't make sense.
> 
> In the meantime trying to squeeze discussion of loads of different
> things into discussion about TCP-ENO seems mostly a distraction.
> 
> S.
> 
> _______________________________________________
> Tcpinc mailing list
> Tcpinc@ietf.org
> https://www.ietf.org/mailman/listinfo/tcpinc
> 

-- 
------------------------------------------
Dipl.-Ing. Mirja Kühlewind
Communication Systems Group
Institute TIK, ETH Zürich
Gloriastrasse 35, 8092 Zürich, Switzerland

Room ETZ G93
phone: +41 44 63 26932
email: mirja.kuehlewind@tik.ee.ethz.ch
------------------------------------------