[TLS] Re: Adoption call for TLS 1.2 Update for Long-term Support

Andrew Campling <andrew.campling@419.consulting> Fri, 22 November 2024 17:01 UTC

Return-Path: <andrew.campling@419.consulting>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DE66C1E0D7A for <tls@ietfa.amsl.com>; Fri, 22 Nov 2024 09:01:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.908
X-Spam-Level:
X-Spam-Status: No, score=-1.908 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=netorgft5189650.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZkHjbo3XJI5b for <tls@ietfa.amsl.com>; Fri, 22 Nov 2024 09:01:51 -0800 (PST)
Received: from LO3P265CU004.outbound.protection.outlook.com (mail-uksouthazon11020108.outbound.protection.outlook.com [52.101.196.108]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 89767C1D6FAA for <tls@ietf.org>; Fri, 22 Nov 2024 09:01:51 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Flxs5EjwWZDbK99EOJXWNPguWNvwSERxV48LmYVC9cDywLgA/WX7G37pNx7ej088v2BYibbxLHkxvPwfW60flSMHQm6RI7MlfG9MMYdIdrhRVJT+mWpjnYx/DZpwllwek0e7BBLXlj5Yd1Lta7bBoe5l1rOIigk+39eU6Q8BBeMmX0JxaloN5E3tJpYfRyIXfsPn52UizaVHYLDqwXj4zXhauKB1lbz4uxD/X7ZlECmmhszP3/PHQdvRPSU1GC21XnVFf82aXtONJq9ZA5ePpX3NUv+ODg4hOsunEJ6Bt4N+vmW6GEzjzGu54oF9Yyh8axIKwaL+QU8OL+1JGPybRQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=C8xirIPGdttrSJIbU5abcxsBHHXnHbED0PLVMXpd8/o=; b=Ea8p1cbm/5Ry3PM96Eik57EF7iNz3LzBZU6hyghLD2DpEew3Cuy2GdgWkZJkQIDaA8F5FVjPqczvHE04k/w6yOVM5lFQfMtSt8qS0CQjxMngL4wyJdE4DItpHkLLqdf+E3J8RPOWotEscQPPByeDdXIBqvIf5f7iRmZVXEURl04LB1zeJ+PJFBi6ztjGiBdfeXcCpWOm0BrxWEgDb0AHf1j89usJYj5hEGuVZbL/Vqz6EVssk1pHL3gf1Y+1qUCA2m8Qnn48taDH2jOCk/FYsLx1BvBHsmkSaVuS91AuH6VbRT9Q7w4XEr4gOQGnvXm3ko1sP9pNaInpydFHuD2GtA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=419.consulting; dmarc=pass action=none header.from=419.consulting; dkim=pass header.d=419.consulting; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=NETORGFT5189650.onmicrosoft.com; s=selector1-NETORGFT5189650-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=C8xirIPGdttrSJIbU5abcxsBHHXnHbED0PLVMXpd8/o=; b=So1/FEoJj5RIpnPAMSEymBD0+hwp70ixLtSQnvAsklmyhiGGTihboGFLqc9HwpYQGcefAL3t6rhGmT2Wl8q5Y/xvm631PIt0xO7yFSRx3wdDAUuatiGA8p9iaGKExD+dNSuDLjuqYedcY07L1cNyNCbgcpzam7yBaLvIH5sHCy8=
Received: from LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:253::13) by LO0P265MB6535.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:2d0::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8182.18; Fri, 22 Nov 2024 17:01:49 +0000
Received: from LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM ([fe80::aa2:215:563:824c]) by LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM ([fe80::aa2:215:563:824c%6]) with mapi id 15.20.8182.018; Fri, 22 Nov 2024 17:01:48 +0000
From: Andrew Campling <andrew.campling@419.consulting>
To: Watson Ladd <watsonbladd@gmail.com>
Thread-Topic: [TLS] Re: Adoption call for TLS 1.2 Update for Long-term Support
Thread-Index: AQHbO3F1/EPy4KodgE294dFXeYuzC7LAhS2AgAKQb4CAADrOgIAADjhAgAAmlICAAABBAA==
Date: Fri, 22 Nov 2024 17:01:48 +0000
Message-ID: <LO2P265MB516030CFA96A53D211613157C2232@LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM>
References: <278163DF-0CB8-472F-84CB-0B8236FEC7C1@sn3rd.com> <231D5F24-E1AE-4F7C-9860-F6B0FF79D6FF@akamai.com> <CWXP265MB5153A14B88F7E5CC94E9BF9AC2212@CWXP265MB5153.GBRP265.PROD.OUTLOOK.COM> <67DD955A-3D13-E04F-9398-F5B37786F79A@hxcore.ol> <ME0P300MB0713FDE4AAA6BB169D676391EE232@ME0P300MB0713.AUSP300.PROD.OUTLOOK.COM> <1A650921-0180-864F-A50B-E385FAC59653@hxcore.ol> <LO2P265MB5160EA88E5389CDE7036F465C2232@LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM> <CACsn0cnysjWfdftcEF263C=veVgCz7Z7-ejMBXFLC5HhKnurBw@mail.gmail.com>
In-Reply-To: <CACsn0cnysjWfdftcEF263C=veVgCz7Z7-ejMBXFLC5HhKnurBw@mail.gmail.com>
Accept-Language: en-US, en-GB
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=419.consulting;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LO2P265MB5160:EE_|LO0P265MB6535:EE_
x-ms-office365-filtering-correlation-id: c1ddd86c-4678-469e-7a21-08dd0b175aa2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|8096899003|7053199007|38070700018;
x-microsoft-antispam-message-info: HoqfInwfCWsZysKrUCvtLG6vt7m6REVG4MgAbbucnPzCA25hvRrV4QJnXb89jiXDO/WVU0G7eZWSY7VAqG5FdkMyH/Pi68kZqJ4yxBEd1SuvXvLxi5tllH3ywrtj6fUwEPU682VQKd80ZRW6PXjCAreq1X0kEaPgQ2X9VazdohtTOo6YR6fA2K4n1eqMMfsNWC6Vo9j/heQgMk2Bz5UAP8KazTxH9qfbNLq4gcBwDGGE/b7CiD7YnABNoldmSZYpk5A4TI0/k7byGgY3BcKQuFwVu9383hashZ6wLARq3XCYmghUugzp8PBik+m1X34wrrbw7F7rpPfOjsy8LuXuek0WKj2gvD1ScScezIZUc0Imm6CrBwtwtUSaN0V6kI6Pc0qMSNt5mUESoYgROEY7KDDcliKHG6SLqOqAiUNOv9piHIAFcktJfSFyPBrOMXYd2yIjRs3ROwC5hwv2uvLkU2Xu6LI+wsvd9zUlKREgEpiMshVCfKtvkDp8YE00o2NyXr9Z43Ay1XoVyA0Ce6b2svWXF4f6ixejFQQTgpB8qKjgwqFXAQSM9mTiGvzi+3FpR0UrQxuH8glkrVsG4D24BIfmO+9sswYsZXK4ViR3PBqChHvb+rLvvT59BtcEEKXr+isD14z8EOmCujzM0ZCbM7mPEg3Wggw09yQy4NFMFDfChh5JzLr9Ke5HoI+xE2jq1sKCziaA7HnagLyf7D3v9I3H80BJMCIpPUMUzEj6Odv8Sd+fKsy40pBop9BOP8mkWbBgufvuXukT3Tz+sHbjN4e0HDfzbuaQolp8NxAOwPK3+WV4Ec40Us5L2s77EpxKqpsaAEDgEdh3K64IGyj39d2Tlu5pjS2QS32rJW1WsoTuTp71G914kJN6X1z44ReQchG4xnPpdA5IW9RCdbPqRvbzrrn4meg6oMqgad0yLQrZZ3wW/ChQzbXLr9YliftSajEQI8dM8pXjm21mDZVIu1R5+hwm5Xsowew+ffmBF+FZpSh7tFxYf8HzPBd5WFbtu84r/dWWIfuBivmBAZAkZTZ3GemD9x9mvnRmfpgLosN4daiIz+E5gIj+/dQ3beDgKVQze6//0+kp9VPHKBIB0W7MCvvThF3OaoRLGkX5t1pio7g1nSMw+9Lj5gIe5vZkEjpp0uVEi8q+YGHy1NyBt1b4xhW2IbTRka35CGx9OcRKDgk3M4HEDW8vP6jRT7CGLjyaTAc8HWW9ybN3r+g8QYJyzL1JpiwFbefkE+y6geQ1GoPQ2DA/KcK0vDaBDfZMn9n9vTeyjWOxh4/6DLSpn0/Kj/zBKrv/SEItYhxwge7iwO/uQbFYBphkzQDNjMHza9x8kvDuGHEsO1WxrKhbuppx5J0rfqpLib4wx5XV36Vf1rwlUGgMGpBfG5Sa5toF5jBigxE4C5F36j4pLm4w6A==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(8096899003)(7053199007)(38070700018);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ec33T7Ou+V7pV68IQYmgy8Ys7+W44EVwnQBTkGUi7BY/CKY2xqWrDgT/fzVukF026V1WypA3tCItjzroH1VW5E4rXIf3sl7KoJTXodSU23U/f4+312RrTNzv3qjoz+ao4kKYU+MmMkOhFe6HxXxr6bfknyKkGu9a1PuYYyeafDOcb4KERV8QT4E0mCIGSZRRTw5PYVHqLU05dAruJp2oPPAUMYVbyWzNEMJtNntRvqiU3N/07mDzKOvt2dFIqchmUd3P2Iie/ZPcyT4W9dOSEXXhUPafxDOImHfJsHYTfsXqibetJtEOC6DSGVzvAUu0317ntryOUuE57v6K9CTSFXZcM+737vyZ9E3jRsrsJLirXA1tHobYOaEgLtvPVPrAWQkCqEupC9Q06PtP9jyJHmcQTJDWdWwcOMbrf5aqczA/vafZyMi1RerBcqjU5Ycqjv6FszDI2KcZH/j1aRvhbwxVaC3bMmRTqV6h/E7MGH0PPECcJQXtCP53a12pIhK31CDY7lt9+ymx1JxCzuPh+5ngc5nwGxliZKBVvEmPMw6s/398j4UH+eU++Itdfe6uU005AzwoyIvSl6A+aq0dCOHcxkle8BwjMMI6wG7KlRFDOEKPkfBd8XoRO2EX3Kk24dwvBoae1hp633+Q0BEpR5wbZ9wBdWG/RhTMhVwlUqV92jAjlvjBMYWI81CNT10dkOTmjjDvLkYdB2Bf19LR8crUsgAu3V2OvNV5hkcstKUPpLySwZ2F37BoGfSMxSjBDPr4jt0u6WbrIMfaa+uDL+hafYvaxSpB4J1pP9GgXh0qYywENaIC7eiyc4EpdvEV0KzNlUrMRduneFGcW4UDACfBcWDDZLwDob6+AEUF+SfAMqiFrqcWk31DrjAUJ9MMi5mFDlfGGi2wBrktacoSfuFvTde/qXE/xmF+7K+HBmYlz1chaQiv+WFbRMmeXAXGtKEA5CqHb1nCfykiR03AkmhTpsRwtZ0WHFftmhkV8YZtvOjy5B5s4gkV/htTKqBi/u89sJp+0/pEpw3f1W3CjlEeiHBYj0cflgBVZqWkHwURyr6jxOXZj4RQl01yQ16MMBaWBvYltUzg7znlRe4PvD/XYU5VZ4XywXkTI8NZVXsOr7gutrYQ5AKAqJ9uCnbZFZIFiNoj5fnyzCE/KtEFxiAHxX02PfwGFDJeM4lWsRHG0/VnyaqUOy7qq0b8ZjL2pIK/rYQHpzZiYwUps8m+yYEuTzdXqaO55kJISaNjhrKJL1f1XqOw49npROpDBJznjusTo7R+DhL89oditAJ2yO/UoMYVyCan8XEBiwJ8r76ryVDsAQ4wCSfNCFq1H2Y3v7kLr0iGGa3/ELNF2G0DbufC00qHUyUl4ru3VxFgahKns4H48KXF4/maldZxi7sAAnEE/3d777T8J7ImfC7BtYxpzf/BGUXZhlWL7iW5isWqVGNwqH/zeuu/kNrnbB4nWMhxrr95DIyD9XY5/U6FxeTNIBcyLudFGF0CG/TNfVUksjm84yAZeJGZ1azePbXsAnTjQ9HPIi773OHmbfl15+wt/PRmx9+YxOrzqEA7dCRHws9sPNTESoEPra35V/5liA06g8IOs5WSPzl2IfeSmw==
Content-Type: multipart/alternative; boundary="_000_LO2P265MB516030CFA96A53D211613157C2232LO2P265MB5160GBRP_"
MIME-Version: 1.0
X-OriginatorOrg: 419.consulting
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LO2P265MB5160.GBRP265.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: c1ddd86c-4678-469e-7a21-08dd0b175aa2
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Nov 2024 17:01:48.9000 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9c2ced3e-7522-4755-87dc-f983abc66ec3
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: qK5GDTw/4uqNJcr8lfzpc1UwGx8dE90AaY4SILb5YBBwf9WVUNqzz4XVMtnOvEf50vI2IMdvhyVclfsZXFpWWehylhwNhY0z3Y9B36oPlE0=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LO0P265MB6535
Message-ID-Hash: PKTRQGAAJARQNWUJNJDZKAMJ5VDGI7BF
X-Message-ID-Hash: PKTRQGAAJARQNWUJNJDZKAMJ5VDGI7BF
X-MailFrom: andrew.campling@419.consulting
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Adoption call for TLS 1.2 Update for Long-term Support
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/4tM-P6FBZgptOki3RyihbnUau8I>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Fri, Nov 22, 2024 at 16:46 Watson Ladd <watsonbladd@gmail.com<mailto:watsonbladd@gmail.com>> wrote:



> How on earth would providing another incompatible set of suggestions help? No matter what text was in there it would still raise the question of what people should be doing.



Hi Watson
You may of course not believe that this is a problem or that it is not something that the working group needs to solve.  I wouldn’t suggest starting with “another incompatible set of suggestions” unless you believe that the previous efforts were not useful(?).

If you agree with the previous post from Yaron that there is a problem then it seems reasonable to come up with a proposal on how best to address the current lack of clarity.  One way to do that is to incorporate updated text into the TLS-LTS draft, and any others that touch on TLS 1.2, making sure that it communicates clearly to implementers and others the relative positions of TLS 1.2, TLS-LTS and TLS 1.3 with reference RFC 9325 and any other relevant documents etc.  Using this consistently from now on ought to help.



There are other ways to address this problem if you agree that it needs to be addressed.





Andrew