Re: [TLS] TLSrenego - possibilities, suggestion for SSLv3

Peter Gutmann <pgut001@cs.auckland.ac.nz> Thu, 12 November 2009 01:44 UTC

Return-Path: <pgut001@wintermute01.cs.auckland.ac.nz>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BFCDE28C178 for <tls@core3.amsl.com>; Wed, 11 Nov 2009 17:44:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.909
X-Spam-Level:
X-Spam-Status: No, score=-5.909 tagged_above=-999 required=5 tests=[AWL=0.690, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tbSVO19TvA9h for <tls@core3.amsl.com>; Wed, 11 Nov 2009 17:44:14 -0800 (PST)
Received: from mailhost.auckland.ac.nz (larry.its.auckland.ac.nz [130.216.12.34]) by core3.amsl.com (Postfix) with ESMTP id 0C7CA28C17B for <tls@ietf.org>; Wed, 11 Nov 2009 17:44:13 -0800 (PST)
Received: from localhost (localhost.localdomain [127.0.0.1]) by mailhost.auckland.ac.nz (Postfix) with ESMTP id F2A8441416E; Thu, 12 Nov 2009 14:44:39 +1300 (NZDT)
X-Virus-Scanned: by amavisd-new at mailhost.auckland.ac.nz
Received: from mailhost.auckland.ac.nz ([127.0.0.1]) by localhost (larry.its.auckland.ac.nz [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9JtlzcvTLPie; Thu, 12 Nov 2009 14:44:39 +1300 (NZDT)
Received: from mf1.fos.auckland.ac.nz (mf1.fos.auckland.ac.nz [130.216.33.150]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mailhost.auckland.ac.nz (Postfix) with ESMTP id D1FC9414164; Thu, 12 Nov 2009 14:44:39 +1300 (NZDT)
Received: from wintermute01.cs.auckland.ac.nz ([130.216.34.38]) by mf1.fos.auckland.ac.nz with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from <pgut001@wintermute01.cs.auckland.ac.nz>) id 1N8Ojn-0002qT-IB; Thu, 12 Nov 2009 14:44:39 +1300
Received: from pgut001 by wintermute01.cs.auckland.ac.nz with local (Exim 4.63) (envelope-from <pgut001@wintermute01.cs.auckland.ac.nz>) id 1N8Ojn-0008Fe-Hb; Thu, 12 Nov 2009 14:44:39 +1300
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: marsh@extendedsubset.com, mrex@sap.com, pgut001@cs.auckland.ac.nz, ynir@checkpoint.com
In-Reply-To: <006FEB08D9C6444AB014105C9AEB133FB36A4EBFB5@il-ex01.ad.checkpoint.com>
Message-Id: <E1N8Ojn-0008Fe-Hb@wintermute01.cs.auckland.ac.nz>
Sender: pgut001 <pgut001@wintermute01.cs.auckland.ac.nz>
Date: Thu, 12 Nov 2009 14:44:39 +1300
Cc: tls@ietf.org
Subject: Re: [TLS] TLSrenego - possibilities, suggestion for SSLv3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Nov 2009 01:44:14 -0000

Yoav Nir <ynir@checkpoint.com> writes:

>Implementations actually do that?

I know of at least two that do, so it's at least a nonzero result :-).  There
may be a lot more, since no-one checks the time and there's no obvious reason
to include it in the nonce it's quicker and easier for an implementation not
to bother (quite apart from any security concerns).

Peter.