[TLS] IANA Recommendations for Obsolete Key Exchange

Joseph Salowey <joe@salowey.net> Mon, 15 April 2024 17:30 UTC

Return-Path: <joe@salowey.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 021BCC14F747 for <tls@ietfa.amsl.com>; Mon, 15 Apr 2024 10:30:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=salowey-net.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pNYoqebsfVfE for <tls@ietfa.amsl.com>; Mon, 15 Apr 2024 10:30:43 -0700 (PDT)
Received: from mail-lj1-x232.google.com (mail-lj1-x232.google.com [IPv6:2a00:1450:4864:20::232]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77CA7C14F726 for <tls@ietf.org>; Mon, 15 Apr 2024 10:30:43 -0700 (PDT)
Received: by mail-lj1-x232.google.com with SMTP id 38308e7fff4ca-2d6c9678cbdso43938861fa.2 for <tls@ietf.org>; Mon, 15 Apr 2024 10:30:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=salowey-net.20230601.gappssmtp.com; s=20230601; t=1713202241; x=1713807041; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=0gfsHd34qK6oKXwmF6jkX/r+tsHZTbVTMNCvD1CTdW8=; b=AsLPwnMFz2Tv7IVMoGCONvHqs/O9dV/ln5TTKXw40BZ0rQ/PmH4tnC8MaosCLwULH5 mtX97KiRoUKfHKiFISboyxh2oN4Dj++ExdkpxAzKNrQk7IauJl/2vRJBx2ZZdLNFjRrP WSOQ1ZSOD41MyjTdqx/g9wzOhK3roTMfT0bf9cgA8JHmUocPhUjXjNiHFXFTvd8deKqR 5MIKUgBwAetbTExa9+PRRV9h9imwH97ZTaD4EtqvKHkqjzf8repHeBiaVCd0Ko3aA05l //IhgqVPJ4kgxQ+BO4SLManXMFxxkDsVGRCgwnwLPMd0ayfCFgs3iOzo0tgOoUNJ2RAq pPsw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713202241; x=1713807041; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=0gfsHd34qK6oKXwmF6jkX/r+tsHZTbVTMNCvD1CTdW8=; b=r8bFRwuflxskfJNabKkRHNrbJkSMxw+psj4oMqidEz30YgUo3R0KDNyaYT3T9pGSlO RDv1aMGek1VWckopYXcuURj4ZIgPqIK930YoN7MeOB9ZsFW/ZmvX+WHygYFx/eim4gfu qx4fbjb6frpzHuO3KMGBxJhVpDcT11KWZb4h8so1v5jH8MmiMf+v+3BcUNG1Jio75W0S 00Adxa6sGU5Z+F1eSZ3uMlNMuQJGZPVSgf07r6QNdfMBegYlhEOhMdC4G3E8fVisMOog /cPhjEuXI55InTA77SRyqQ59o/98kTXsHxXPgyMz5UchM8J9WC+7a/xBHSQQOir4EHdT M+ig==
X-Gm-Message-State: AOJu0YwU0qkix+0WzeUoDEQu30iT+wsJ3AZGGz9p+35/onB0om7aUb9t fLsnYrKK+lXcAP6vrPSpLsjXvrpQUf9evLmbj9Phy0kmhDRf4z20KGFwJafd6jY6Y6OmUAtr+// WYS70YSUQCC4oBJvJ4bq/R0wAzVUC3ScFfFtgdDW2QBFZTQ95W64=
X-Google-Smtp-Source: AGHT+IGudwnQ2FvCdg69n75lvvE5kOfPEHT+KzE/+C37VaVxCxXitLy206r9ICCC8apQ+E2fdENValYjDrWnVNj9YwA=
X-Received: by 2002:a05:651c:1994:b0:2d8:59cb:89ef with SMTP id bx20-20020a05651c199400b002d859cb89efmr7108116ljb.24.1713202240728; Mon, 15 Apr 2024 10:30:40 -0700 (PDT)
MIME-Version: 1.0
From: Joseph Salowey <joe@salowey.net>
Date: Mon, 15 Apr 2024 10:30:29 -0700
Message-ID: <CAOgPGoDZbdQD_i+u4=XQ7gRmJPOHM-T+Q-=dzRQh-+cs3ZLEkg@mail.gmail.com>
To: "<tls@ietf.org>" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fcce60061625faa6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/4n0EFQg0FtMKDptGnTkzMbmPxpk>
Subject: [TLS] IANA Recommendations for Obsolete Key Exchange
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Apr 2024 17:30:44 -0000

At IETF 119 we had discussion on how to mark the ciphersuites deprecated by
draft-ietf-tls-deprecate-obsolete-kex in the IANA Registry. At the meeting
there was support for ('D' means discouraged):

RSA ciphersuites should be marked with a "D"
FFDH ciphersuites should be marked with a "D"
FFDHE ciphersuites should be marked with a "D"
ECDH ciphersuites should be marked with a "D"

This aligns with the deprecation intent of the draft. The draft states ECDH
are a SHOULD NOT instead of a MUST NOT, but the sentiment was they should
be generally discouraged.

Please respond with any comments on this proposal by April 30,2024.

Thanks,

Sean, Deirdre and Joe