Re: [TLS] Adoption call for Deprecating FFDH(E) Ciphersuites in TLS

Carrick Bartle <cbartle891@icloud.com> Sun, 29 August 2021 00:29 UTC

Return-Path: <cbartle891@icloud.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3934F3A2818 for <tls@ietfa.amsl.com>; Sat, 28 Aug 2021 17:29:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=icloud.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k7787xc8L6TW for <tls@ietfa.amsl.com>; Sat, 28 Aug 2021 17:29:38 -0700 (PDT)
Received: from mr85p00im-hyfv06021301.me.com (mr85p00im-hyfv06021301.me.com [17.58.23.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A68293A2816 for <tls@ietf.org>; Sat, 28 Aug 2021 17:29:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1630196978; bh=WoiRY35lQxn08r13rvtTx9JMCVSt2VRrx289dsi31ns=; h=From:Message-Id:Content-Type:Mime-Version:Subject:Date:To; b=bDF4LVyt9R6YWXhCPcEzvJRjq31fOKn9WpXjQXQMEMu+Dq5wKZZRJcXP1dcNnq08H 8EvTZct+0GPFZZxtjUrdwmd4tScE+66qgeDqkf97cDm70gk93xYC4msEVQZs35UC/g wAAyrYf1GwKJPoGYGFgSzjwcnOKbmXLiFl1YB7532NBEgaaGPQ9hj3hk3+nFGGx3fY Ulbs4fklkPOhWpE/60T8mLSOXerAYRWuY+z8hdLihWMXo1k1UZvYCw9OlCRnmuwZvv FY5pj99rgwbJX1AQMEfVUrxAqmugyefkZd7aUWRqvGfnlvwglzpnxSVnChfuDJtuHm BYGYPZ4l5/NXg==
Received: from smtpclient.apple (unknown [17.11.79.97]) by mr85p00im-hyfv06021301.me.com (Postfix) with ESMTPSA id 330AB40518; Sun, 29 Aug 2021 00:29:38 +0000 (UTC)
From: Carrick Bartle <cbartle891@icloud.com>
Message-Id: <4D0CEB0B-2134-4DE8-88D1-0A1B87444E64@icloud.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_7CED1536-1E97-45A7-895E-2EEE658101F8"
Mime-Version: 1.0 (Mac OS X Mail 15.0 \(3689.0.4\))
Date: Sat, 28 Aug 2021 17:29:37 -0700
In-Reply-To: <CAChr6Sz-tpipLTg_-cGYSoHmWz-VYK=ZT5W-3_cHQmSVnK-Kmg@mail.gmail.com>
Cc: Filippo Valsorda <filippo@ml.filippo.io>, "tls@ietf.org" <tls@ietf.org>
To: Rob Sayre <sayrer@gmail.com>
References: <CAOgPGoC4C0bWz0h0iyzGzMPEoDKAPv4euoOkmS+6Uuxncux4Zg@mail.gmail.com> <cc9c9d9f-d6b1-3b93-1231-a9a9c34a7fcd@gmail.com> <67533325-2983-47B7-871C-D90799D09532@ll.mit.edu> <CAOgPGoDAvnFic3VmEsge3i8C2FEfWp74ac_ievtfNo=MQB+C8g@mail.gmail.com> <C8E91D9B-2326-4AAF-9952-69481081E337@ll.mit.edu> <BD109A95-129A-4995-AFCA-FEF10DBD6440@icloud.com> <CAOgPGoBMhhsTupXuWF__zkLuy-4qQhha_Kp1_+ToZrNoaFUsgQ@mail.gmail.com> <13b9e674-9e0b-46aa-b5d6-49798c310d85@www.fastmail.com> <5D5FB49A-7D18-4EC9-B572-BD860479CD5E@ll.mit.edu> <bc91502a-471e-484e-ae5f-d843b703edd6@www.fastmail.com> <64c6ca0a-b3cf-cbdf-c1be-7cc4cc050a52@gmail.com> <0ba2ed9a-3128-4956-bd9d-2b961cbcb6d0@www.fastmail.com> <CAChr6Sz-tpipLTg_-cGYSoHmWz-VYK=ZT5W-3_cHQmSVnK-Kmg@mail.gmail.com>
X-Mailer: Apple Mail (2.3689.0.4)
X-Proofpoint-Virus-Version: vendor=fsecure engine=1.1.170-22c6f66c430a71ce266a39bfe25bc2903e8d5c8f:6.0.391,18.0.790,17.0.607.475.0000000 definitions=2021-08-28_08:2021-08-26_02,2021-08-28_08,2020-04-07_01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 spamscore=0 clxscore=1011 mlxlogscore=999 bulkscore=0 suspectscore=0 malwarescore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2108290000
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/-awRu75CIKtnzg6_QQD3ASwEXtw>
Subject: Re: [TLS] Adoption call for Deprecating FFDH(E) Ciphersuites in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Aug 2021 00:29:44 -0000

All the ciphersuites mentioned in the draft under discussion are already listed as not recommended because they don't offer forward secrecy.

> On Aug 27, 2021, at 11:01 AM, Rob Sayre <sayrer@gmail.com> wrote:
> 
> On Fri, Aug 27, 2021 at 9:42 AM Filippo Valsorda <filippo@ml.filippo.io <mailto:filippo@ml.filippo.io>> wrote:
> 
> If a consistent history of directly linked vulnerabilities across major implementations doesn't show something is unsafe, I don't think there is progress to be made in the discussion. Blaming the implementers is not particularly interesting to me.
> 
> Anyway, I don't have an opinion on SHOULD NOT vs MUST NOT, as long as it leads to Recommended: N in the registry.
> 
> I agree. I can't think of a reason to list it as " Recommended: Y".
> 
> thanks,
> Rob
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls