[TLS] Adoption call for TLS 1.2 Update for Long-term Support
Sean Turner <sean@sn3rd.com> Tue, 05 November 2024 16:25 UTC
Return-Path: <sean@sn3rd.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3BAFC1930D8 for <tls@ietfa.amsl.com>; Tue, 5 Nov 2024 08:25:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RU61SyUp5rmp for <tls@ietfa.amsl.com>; Tue, 5 Nov 2024 08:25:18 -0800 (PST)
Received: from mail-pf1-x42b.google.com (mail-pf1-x42b.google.com [IPv6:2607:f8b0:4864:20::42b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AAF34C090381 for <tls@ietf.org>; Tue, 5 Nov 2024 08:25:18 -0800 (PST)
Received: by mail-pf1-x42b.google.com with SMTP id d2e1a72fcca58-71e52582cf8so4883631b3a.2 for <tls@ietf.org>; Tue, 05 Nov 2024 08:25:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1730823917; x=1731428717; darn=ietf.org; h=to:date:message-id:subject:mime-version:content-transfer-encoding :from:from:to:cc:subject:date:message-id:reply-to; bh=GM5oVmRi3PoR5BmJpjLg3CQZnzXrJO8g2WwRwJNVlik=; b=JaUhZ4P4TZxW+h3sE/m2jHu6oZIe9RPG6OB0xgaIJgkUVSokq5fiAmEygCtcdkS2ow 1hVpo1/3hJznZwyL0/JbFrG5vuxV/wUpuQjZJoGCdBkA6nbKS3Ki7Bi/wraaR/vXpPYP inpzSPagK+MoyGes8KtsXz93taAEtdrC2B4g4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1730823917; x=1731428717; h=to:date:message-id:subject:mime-version:content-transfer-encoding :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=GM5oVmRi3PoR5BmJpjLg3CQZnzXrJO8g2WwRwJNVlik=; b=ejzeMRe9lezlUz6L3ZG6BMr2+tmMDA8myaCgRRMaN9b5u+FXi/1cA2IE/mz/Za7gF6 3rwJZN+FmfODN6AvtVeovwHS79/EuPE+WWsLcUSg0WOrtrYfgFB5SPt6wMVrVp0o8xlb r2FC1CThEt3mVW/EZrdHTQDRLB6n2GZAKMYr99BmVfwGWPQ5XEwQnrfmo2npwNhLG20/ W+jWHjm0FM5tGBs9SsVqsdzTZP3bBas0IxWNL6tIBpX+NYHA1dze5iDpAaFdUu4hK5L2 o2xlFIEryAHpcXp71wkcJAuULux47tPktU9P9TaZWsOcnCWl78PB2y+0oiRvLqPvRibH 9E4g==
X-Gm-Message-State: AOJu0YxzT2J98SgzHNWgvfCtIkT7cPi4SniZLAPv1+cB8GZouTUhKfId 7xohX4vLoPxGN2tJOkUlS2vgXZK2VSp+CA9PwaJjqFeJvikRMFMBBxMb1IzXhMR/aO1VYXMPjPm GDOJTv3Xz
X-Google-Smtp-Source: AGHT+IFt8IUISwjGnZagIPS2j+DEU+myECQGoe5Ld/DxWXquDCECbdPzrdRchPdpube7Zv75QilTdQ==
X-Received: by 2002:a05:6a20:244e:b0:1db:e4c8:3437 with SMTP id adf61e73a8af0-1dbe4c86583mr8470622637.20.1730823917375; Tue, 05 Nov 2024 08:25:17 -0800 (PST)
Received: from smtpclient.apple ([2001:67c:370:128:5ce0:907:16ac:720f]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-720bc205582sm9882056b3a.88.2024.11.05.08.25.16 for <tls@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 05 Nov 2024 08:25:17 -0800 (PST)
From: Sean Turner <sean@sn3rd.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.15\))
Message-Id: <278163DF-0CB8-472F-84CB-0B8236FEC7C1@sn3rd.com>
Date: Tue, 05 Nov 2024 16:25:16 +0000
To: TLS List <tls@ietf.org>
X-Mailer: Apple Mail (2.3654.120.0.1.15)
Message-ID-Hash: XFJYWBNAWAYQQHACNGHXOBGHYJ2YCZSA
X-Message-ID-Hash: XFJYWBNAWAYQQHACNGHXOBGHYJ2YCZSA
X-MailFrom: sean@sn3rd.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Adoption call for TLS 1.2 Update for Long-term Support
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/3inaOlIShATLhdKmzfn84igPP_k>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
REQUEST: Let’s not rehash all the context. It is provided for those who might not remember or those that were not around for the duration. CONTEXT: Way back in 2016 after the WG had embarked on developing TLS 1.3, Peter Gutmann suggested that another way to “fix” TLS was to specify a version of TLS that indicates a “known-good config drawn from the maybe 10 extension-RFCs”; see [0]. Peter submitted his “TLS 1.2 Update for Long-term Support”; see [1]. There was some list discussion; see [2]. Peter asked us about adopting the I-D; see [3]. He made changes based on that feedback; see [4]. At IETF 98, the WG discussed adopting this I-D and the sense of the room was to not adopt the I-D; see [5]. Progress on this document was paused while the WG worked on TLS 1.3. Once RFC 8447 was published, a code point was assigned for the “tls-lts” extensions; see [6] and [7]. Now that we are looking to publish Feature Freeze for TLS 1.2 [8][9] we want to make sure that the working group sentiment has not changed over time so we are running an adoption call for TLS-LTS. MESSAGE: This message is to judge consensus on whether there is support to adopt TLS 1.2 Update for Long-term Support; see [1]. If you support adoption and are willing to review and contribute text, please send a message to the list. If you do not support adoption of this draft, please send a message to the list and indicate why. This call will close on November X, 2024. Thanks, spt [0] https://mailarchive.ietf.org/arch/msg/tls/Lr7VwcPCjzDJelUTRTIUJf_8-ww/ [1] https://datatracker.ietf.org/doc/draft-gutmann-tls-lts/ [2] https://mailarchive.ietf.org/arch/msg/tls/r4w75rooy-r8Ky-xXAUoslYTL_U/ [3] https://mailarchive.ietf.org/arch/msg/tls/6tBftKBmxYz_wUcq79_zH8yDTQk/ [4] https://mailarchive.ietf.org/arch/msg/tls/aw9BOS4HJ9uum0snEZqSuKA4BYw/ [5] https://datatracker.ietf.org/meeting/98/materials/minutes-98-tls-00 [6] https://mailarchive.ietf.org/arch/msg/tls-reg-review/bP84S3tHSG9gAmc45CLTjpiA0z8/ [7] https://mailarchive.ietf.org/arch/msg/tls/xmhnVQTckDmUkoxhx4wx1bfpYXM/ Thanks to Peter because he helped us iron out the wrinkles in the tls-reg-review process. [8] https://datatracker.ietf.org/doc/draft-ietf-tls-tls12-frozen/ [9] https://mailarchive.ietf.org/arch/msg/tls/f62yvLL_4mDEsRzAY46L4QLjakU/
- [TLS] Adoption call for TLS 1.2 Update for Long-t… Sean Turner
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Sean Turner
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Rob Sayre
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Alicja Kario
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Thom Wiggers
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Viktor Dukhovni
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Christopher Wood
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Richard Barnes
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Martin Thomson
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Alicja Kario
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Sean Turner
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Nick Harper
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Arnaud Taddei
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Eric Rescorla
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… David A. Cooper
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Andrew Campling
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Yaron Sheffer
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… David Benjamin
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Yaron Sheffer
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Andrew Campling
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Andrew Campling
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Rob Sayre
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Rob Sayre
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Alicja Kario
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Salz, Rich
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Rob Sayre
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Pascal Urien
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Sean Turner
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Stephen Farrell
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Muhammad Usama Sardar
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Yaron Sheffer
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… David A. Cooper
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Bas Westerbaan
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… David A. Cooper
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Watson Ladd
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… David Benjamin
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Peter Gutmann
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Sean Turner
- [TLS] Re: Adoption call for TLS 1.2 Update for Lo… Rob Sayre