[TLS] Re: Publication has been requested for draft-ietf-tls-keylogfile-03
Sean Turner <sean@sn3rd.com> Fri, 11 April 2025 16:07 UTC
Return-Path: <sean@sn3rd.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D3D291AC2BFC for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 09:07:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SVrimXKKu1u1 for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 09:07:44 -0700 (PDT)
Received: from mail-qv1-xf2c.google.com (mail-qv1-xf2c.google.com [IPv6:2607:f8b0:4864:20::f2c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 408FC1AC2BE9 for <tls@ietf.org>; Fri, 11 Apr 2025 09:07:44 -0700 (PDT)
Received: by mail-qv1-xf2c.google.com with SMTP id 6a1803df08f44-6f0c30a1cf8so22567016d6.2 for <tls@ietf.org>; Fri, 11 Apr 2025 09:07:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1744387664; x=1744992464; darn=ietf.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=OH2Bv9jvpcuJ/+OYYMqdP2TyVYXuweWS8TcP38+mf7E=; b=RlXCa4MurtRPLNMvw05z0zaCaq+BcFuczv/dkNGJGHX1NZdmKLwEkQ/x29zTenb7mc sIwGd/XfYmiGhHnPIrx1XTMAMsTnmOSScaBJYS003206U8wDkDCLgn6WjjK2DAm40da8 SGT+tmufpjnWbdhcHhAtNyCxAzgDEW/F6Jjyk=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744387664; x=1744992464; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=OH2Bv9jvpcuJ/+OYYMqdP2TyVYXuweWS8TcP38+mf7E=; b=lnhxAHaCVPlHdH9ucjxnMTwEbo2M0ehL6UnFoVxpIUNZHEvZXu3Lvp7Cyeu4g7Yu2y DxvDmvMT41NUqDAthk0bFZ08xln1fb06CNYszO8IhOtsjgrMyGHCd5FK+ADDi5kjkPJ0 tuazwxu8qCZwEfI07DlUsgB7AQhaN0MovswxSwP0A4MibIyJCuaUn/b+xN0Gb9ZkFd88 5PyN/sI1FgkDSClZbfTnush1cUsgwmOcinXXnXUhdh37+yEQpcquJkOs9ePewjYnyvyl Wl5fTXUkpYqyWeN9x3aLw/3Wd9Nc6XI7O/LaaUm89SoanQH1tCJA4U19975KiERf+qM6 U4hw==
X-Gm-Message-State: AOJu0Yz8jpgU3Bn2ZouOtfzp/fvOqJwfIdGFb2458Ov/MNaWIx2IHXb9 TYFVK4CX2WiY1uMCM+Rm96I6e5CrXJE3bh3R6gcoLnmqc8JxRU/U0Czg6aRP7CFAWOANEHoq63r C
X-Gm-Gg: ASbGncsxA0U856D4DWSMLX7uYKY52nNxWrQXb70fGmhXLn7e8vaR06SoN1qXPIayKIx c9+4zeXM9idfeWMVCP7afHK6XYuWBHJZacLhwrjwmgp4li6Qk7vFIRqWY/slARZ4SvIhD3ke8vx /SWPgZHbxZ1bmcOlPGoArChchjKjWeY1ljnzh4yX5TQMdWTGtKMb0WRWqr1zM6pCmrOefGDkyfW SJe7tLqWm3ZPnC8jlXWPwuik4Wrteqk+JgxiP4mv6up3NJ30fa3LP2oLDoGSLhNV8le+pIiZfw3 XAuzFIT2bhm5p2XM7bL4iA/E4JL3bwNSMMhyVr4rzyBKB/6mbjxKcM6+F1ffE86ZmJjSj+U=
X-Google-Smtp-Source: AGHT+IHpZsGfzvPWJNJryZGZnPvnWyTxbO5wuH3LEueJ+Ui2TEaaNY6mlI+0d5iFnTkfFaUg0r18Tw==
X-Received: by 2002:a05:6214:21ed:b0:6e6:5efa:4e01 with SMTP id 6a1803df08f44-6f230d67bd2mr45472026d6.20.1744387663615; Fri, 11 Apr 2025 09:07:43 -0700 (PDT)
Received: from smtpclient.apple ([2600:4040:252a:8d00:2d4e:e8d3:9638:df7]) by smtp.gmail.com with ESMTPSA id af79cd13be357-7c7a8a0cfb0sm280029385a.94.2025.04.11.09.07.42 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 11 Apr 2025 09:07:42 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.500.181.1.5\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <a8b8667a-86bc-47b2-bbfc-e59a554c0f4e@cs.tcd.ie>
Date: Fri, 11 Apr 2025 12:07:22 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <1415986C-125E-4D84-919F-CC5D7CCEBC33@sn3rd.com>
References: <174368734611.2714005.3310313743466251329@dt-datatracker-5b9b68c5b6-zxk6z> <d334a79a-2c49-40d5-9567-b5878c040df9@cs.tcd.ie> <492e3391-ce13-4bfb-a640-caa61fcca743@cs.tcd.ie> <574BA3CD-8302-4E91-B42B-68FB0EBD43C9@sn3rd.com> <a8b8667a-86bc-47b2-bbfc-e59a554c0f4e@cs.tcd.ie>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
X-Mailer: Apple Mail (2.3826.500.181.1.5)
Message-ID-Hash: E4CW2RZIQTGKRTSMGL3D6DJHLGBI4AIV
X-Message-ID-Hash: E4CW2RZIQTGKRTSMGL3D6DJHLGBI4AIV
X-MailFrom: sean@sn3rd.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>, TLS Chairs <tls-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Publication has been requested for draft-ietf-tls-keylogfile-03
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/-n3CjkgATj7rUSqOrhSt72WR51Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
> On Apr 11, 2025, at 11:50 AM, Stephen Farrell <stephen.farrell@cs.tcd.ie> wrote: > > > Hiya, > > On 11/04/2025 16:40, Sean Turner wrote: >>> On Apr 9, 2025, at 8:00 PM, Stephen Farrell >>> <stephen.farrell@cs.tcd.ie> wrote: On 03/04/2025 14:42, Stephen >>> Farrell wrote: >>>> On 03/04/2025 14:35, Sean Turner via Datatracker wrote: >>>>> Sean Turner has requested publication of draft-ietf-tls- keylogfile-03 as Informational on behalf of the TLS working >>>>> group. >>>>> Please verify the document's state at https:// >>>>> datatracker.ietf.org/ doc/draft-ietf-tls-keylogfile/ >>>> Hang on - where was the outcome of the WGLC declared or summarised by the chairs? Where are the minutes for the IETF-122 >>>> meeting? I think you're skipping process steps here in a way >>>> that ought not be done, esp when there have been objections to this draft. (And I think I already asked that the poll at the >>>> meeting not be used as a declaration of consensus.) Please >>>> correct. I object to decisions not being made on the list when >>>> there is contention. >>> I got no response from chairs or AD on or off list to the above. >>> Seems like bad form to me but maybe people were too busy. >>> I note that despite my request/objection, the IETF LC for this has >>> now been issued. I've objected there too. [1]. I see that SM also >>> had process comments on this too. [2] >>> I do plan to appeal should this document not be sent back to the >>> WG to confirm whether or not there is WG consensus to publish. >>> (And publishing as-is is wrong of course:-) >>> Cheers, S. >>> [1] https://mailarchive.ietf.org/arch/msg/last-call/ >>> KFXyZbe_hi-0OjCtvORwyJm_wpo/ [2] https://mailarchive.ietf.org/arch/ >>> msg/last-call/fLGvbWNGBhux9c6crFJ1ZioKmLg/ >> Stephen, >> The minutes have now been posted; see [0]. Joe posted them for >> internal review, and I got my wires crossed that the minutes were >> not also published to the datatracker. > > Ack. > >> I have updated the Shepherd Write-Up and brought your (and others) >> continued objections to progressing this draft. Likewise, I have >> discussed this with our AD at length. The points I believe you have >> made align the way (beyond don’t publish, this is a bad idea) are: >> 1. Strong Caveats/Warnings: When draft-thomson-tls-keylogfile was up >> for adoption, you were okay adopting it as long as there were >> sufficient warnings. The Security Considerations section includes >> much more text and an Applicability Statement section was added, >> which in particular notes this mechanism “MUST NOT” be used in >> production systems. When -ech-keylogfile, I believe there were more >> objections, but not a lot of support for more text. Now the drafts >> are combined, the text in the Security Considerations has been >> expanded to also include ECH and the Applicability Statement >> remains. Likewise, a PR has been landed and will appear when -04 is >> published that adds words specifically about the compilation issue >> [1]. As both drafts completed WGLC independently and now the draft >> is a combo, this point seems settled. >> 2. -ech-keylogfile is not needed because ECH is new. There were >> people who implemented ECH at scale who spoke in support of -ech- >> keylogfile. Also, -ech-keylogfile made it through WGLC; the only new >> comment beyond “make the warnings stronger and bigger” was to merge >> the draft together because it was odd that -ech-keylogfile was >> creating a registry for a draft so newly in the RFC editor’s queue. >> 3. Merging: During -ech-keylogfile, Rich suggested we merge it. I >> noted that that was going to happen when I closed out that WGLC. >> There were no objections. I noted that that merge had completed when >> -tls-keylogfile-03 was published; again, no objections to the >> initial note. >> 4. Specification Required vs IETF Review: This WG published RFC 8447 >> and -rfc8447bis is nearing completion. As you know, these documents >> set the registration requirements for almost all of the registries >> to Specification Required, which also implies expert review. This is >> true for the Cipher Suite & Support Groups. If the concern is about >> something slipping by the DEs, then we have bigger problems. The >> registration list is public [2], the DEs are known (Yoav, Rich, and >> Nick), and the DEs can raise registrations with the WG and have >> previously reported on registrations [3]. > > The above is a pretty fair summary, but not quite 100% (which is > natural enough) - IMO item #4 is by far the worst aspect of > publishing as-is; this does differ from other registries as every > new thing added to this one is a new way to exfiltrate (a bad > thing when done outside debugging which we know will happen), > whereas with other registries adding a bad thing is very much > the exception (e.g. NULL ciphers are very rare). I think we would > be far better off with IETF review if we do have to hold our > noses and create this registry. > >> As you note I did not close out that WGLC; I should have, I will >> send a message in response to the WGLC thread referring to this >> message. >> While I know you would prefer to not use the informal poll we took >> at the IETF 122 session because it does not support your position it >> is nonetheless telling. But because I forgot about the change to add >> more compilation constraints in the Applicability Statement and we >> should confirm the discussions at IETF on list, we will get a new >> version posted and re-run the confirmation about progressing the >> draft call noting that there was strong consensus with some vocal >> opposition. Stay tuned. > > That plan should fix the process glitches, thanks. (Mind you, > having 4 people, one of whom was up at 4am local, indicate a > preference for something like do-not-publish might well be argued > to indicate that there is not a strong consensus.) > > Thanks, > S. Yep that’s the plan fix ‘em. And, we are waiting on the -04 version. I mean technically I can submit a new version, but I will let the authors do so. spt >> I have replied to S. Moonesmay. >> Cheers, spt >> [0] https://datatracker.ietf.org/doc/minutes-122-tls-202503200230/ [1] https://author-tools.ietf.org/api/iddiff?doc_1=draft-ietf-tls- >> keylogfile&url_2=https://tlswg.github.io/sslkeylogfile/draft-ietf- >> tls-keylogfile.txt [2] https://mailarchive.ietf.org/arch/browse/tls- >> reg-review/ [3] https://datatracker.ietf.org/doc/minutes-119- >> tls-202403182330/ >
- [TLS] Re: Publication has been requested for draf… Stephen Farrell
- [TLS] Publication has been requested for draft-ie… Sean Turner via Datatracker
- [TLS] Re: Publication has been requested for draf… Stephen Farrell
- [TLS] Re: Publication has been requested for draf… Sean Turner
- [TLS] Re: Publication has been requested for draf… Stephen Farrell
- [TLS] Re: Publication has been requested for draf… Sean Turner