[TLS] Re: Question to draft-ietf-tls-esni 6.2.1.

Stephen Farrell <stephen.farrell@cs.tcd.ie> Thu, 13 March 2025 00:44 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C4235AA052A for <tls@mail2.ietf.org>; Wed, 12 Mar 2025 17:44:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZoqZNabosEVb for <tls@mail2.ietf.org>; Wed, 12 Mar 2025 17:44:09 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2092.outbound.protection.outlook.com [40.107.20.92]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 634FDAA051A for <tls@ietf.org>; Wed, 12 Mar 2025 17:44:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=n0yRpDHeRWPyuxCvDVD+FYBcBgR02vWXzZtzqYWu5v+zumh2dOIVdYXYF4AoXdW3UQKbpZykaKeYNpxtaoYdGwopuMH/cPeHovdVnKtLilIIUWeAlCgeCcgLrCBzpN1CAWoW5EVrjxrQ9YkMdSizmq8DOu61RQBupqVP9ArixEqDB1OeFUCL/DaIL0y44Pw1P47KwpEWgZ6B57JCaU8UvO0R3jHGOumJAKNxw/Kgs4bIJs7DFB7wGE+1MSc+ohq50mKVzUXYcYpmsVLY2fuGkL8dj5AXJg2tRuXiRZ0PZD3Bd1rZAojAnK9gAoijPOwIpPqFpDUdRY2pnebH2oRR2g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ZfkqQo38XUbWNOwSxl4nDxiFP0dY9frk3nDSSbRn+Q4=; b=liXBGemLirHkGz3LEuksSaKZ9Ps8+mRVflWWp+nWnjW7GwTvJNmqg4HPNwXJZaxQrN76HWZj1HNpNDcAPAMeNaupBWM0vaNpCi+vBBMusdWFljbujr2f+CvvuF9WqHZAuQP/arQX2Xg30iZ+Gdjgnxc9ibBcwihnU1qDnu6zfH5q89uXogyWJMWoiVL77T/cYNOEvBEA4CkYowpkzl3iIgwKOwkF72VyORz9I4ucqBmbU4dsbGsAzXvaswDh6qs/nPXXTCbk8ywszBeRDAhyI/WRSQVkukKqpxHcOV15kE8pfL1+wI9UL8iJ/2zSB+0bLoMTzP3M0zMIbfP/ICeJFQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ZfkqQo38XUbWNOwSxl4nDxiFP0dY9frk3nDSSbRn+Q4=; b=ZGthzOhlWl4HJqydGRv7jOdVZA1T92BlhWWCTX0y/q77si3NGKR/EyaqJdmlyANRMOpaNt2oUOg1De+XdHqM5XM+MZ9N4cpUPxLknWGZs6K5NWX3D+BBHVSH30EY6N5ujIOzbRVJ8vPW/WhYegWKwCzv/O1u9eUvSaD3/eI+Faqsbn8JGRbkyXoos/R6mM7kB3hzt1EI0CLwkBzp5GlJ2G8FjKuP3TrfR373JZjsucnfFd86LGKHfaZRNPw3EhUqImUj6neervoVUGKYfNR6QdOamSWEjYW6xLCmwgI7L5nXOvKUoTdwhjcxR3NTNdWWEH1T4HHqnPWYF88CVuxhmg==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB8PR02MB5946.eurprd02.prod.outlook.com (2603:10a6:10:11c::16) by AM7PR02MB6209.eurprd02.prod.outlook.com (2603:10a6:20b:1be::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8511.28; Thu, 13 Mar 2025 00:44:07 +0000
Received: from DB8PR02MB5946.eurprd02.prod.outlook.com ([fe80::e0d3:772e:a68d:d54a]) by DB8PR02MB5946.eurprd02.prod.outlook.com ([fe80::e0d3:772e:a68d:d54a%3]) with mapi id 15.20.8534.024; Thu, 13 Mar 2025 00:44:07 +0000
Message-ID: <6ef5087c-4aa3-476f-a65d-c45e018bf130@cs.tcd.ie>
Date: Thu, 13 Mar 2025 00:44:06 +0000
User-Agent: Mozilla Thunderbird
To: Christopher Patton <cpatton=40cloudflare.com@dmarc.ietf.org>, 风扇 滑翔翼 <Fangliding@outlook.sg>
References: <OSZPR01MB69530987F781FAB8C82DE6FD81D12@OSZPR01MB6953.jpnprd01.prod.outlook.com> <CAG2Zi20ftTgxva4xT9rNZwb90SXThWEG9NX00yMwcbYC2Ps0pg@mail.gmail.com>
Content-Language: en-US
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Autocrypt: addr=stephen.farrell@cs.tcd.ie; keydata= xjMEY9GzphYJKwYBBAHaRw8BAQdAo6JvjmSbxHdQWPZdvciQYsHhM1NxQBU398Mmimoy4p7N M1N0ZXBoZW4gRmFycmVsbCAoMjU1MTkpIDxzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllPsKQ BBMWCAA4FiEEMG54R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQ5Njp+ZeoM93bogEA25ElRyX0wwg+kGEN1AoL60MoZfvQZ/VtmXY6IC5j +csBAIBpkL5ySuzJK2zLNZn9qQGht8IaUcA7cvDcLvS2uHUEzjgEY9GzphIKKwYBBAGXVQEF AQEHQILCPWOwW36e8D3pY8GmvvtItIT+A5uV80ist+WokVsQAwEIB8J4BBgWCAAgFiEEMG54 R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwwACgkQ5Njp+ZeoM92bcAEA8R+8cpqRUIS+SoAN iO05xE6O/wEx8/e88BqzAYki3SoBAOQdwiPX+MQrAxkWD8xxOsdMOAtxYKpkD1n8aPJUw6QJ
In-Reply-To: <CAG2Zi20ftTgxva4xT9rNZwb90SXThWEG9NX00yMwcbYC2Ps0pg@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------1N9uEAxEjFpZHdHFBeymptiS"
X-ClientProxiedBy: DB3PR08CA0002.eurprd08.prod.outlook.com (2603:10a6:8::15) To DB8PR02MB5946.eurprd02.prod.outlook.com (2603:10a6:10:11c::16)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB8PR02MB5946:EE_|AM7PR02MB6209:EE_
X-MS-Office365-Filtering-Correlation-Id: 01108f33-3d5a-4705-9998-08dd61c8294a
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;ARA:13230040|10070799003|366016|376014|1800799024;
X-Microsoft-Antispam-Message-Info: CAsnpLb/6x1nvBWa6EAcXMbIIO5nbVdX5rQJSkTjebyfcffRNg8FOEvhS/AE90LXiKmKQJxhfyTvKF9mUZuNyQkfHChGqhXxo0jnXlrOpEY4DK7mhqcwSbv02NKoI9GzdtL7vxb4m0vXNDHtvcH0ti3AfCM2cvf0Lr+Be+dXZpcvlJQYYBGN6u11a1CEKZoUKrfLtZ7YcDV44kRldakOpwnH+Ln5QeKfilJ6tozHzgZtqga5+DXQXTqFqZ3xTyaWwPDYPqV03LmciOpq426Sbf8jnK4BfD5S+VvXy7p7QcjzpMdytSeJ3KBG1/wPwwa65v9PIIP7PgYj5jq6Z5fZyeqwUE0zz8IY1233M4cqRf8g1j1vnkTAtSDL2ELbifgK6XVdWUmnr3LevKyfLdrXxJhJR6MQzhKfB9iqZDi0kb+/+oxD1CuEXs0FG3NWqznuMwh+b611cHnaCpXO98ECoYmF12EN714ThSb+4k6l72zNmR3p3ym3ulKEWKrxo8jm999D8f4557y3J4frPOrhrmWyKJQNsJjRm4Ni6dSanqOSJfZrkIcJi0phLJGle385huB41+jHN2hoO+WqWgPBXiYGjr/Z8OHGGJWXwh9hqYTxj4PNGJ56SW2/ZEiUXPf4AnDcO6c+9lr2lroghNh0dRPJLsXLOtE/m8H79BePKWrbhu8KvLKbSVX2ZAcW0kR0ubVcz+MNGtTsHsFjeq+igZQYGsR6NSL4QkblPBfvqNgRG+S1lPnnZ7CnLs4XqLvPAE8xmovw6PCFuZ3nk1frx6uBVXbYoMt9vej7r/wZ12BJKos/C5SAOc3YOtfdy12sl4pEpiIBcMcud2ONbQEdqahZg7The3VnoDtkcprXLOCtn+4bVw2BKOHe+WHkTovutRSqrXkKlx70TLt2oZnQGJbTSGEt04fqj8R1fiH0HUkOHCrObUGw/vbP32KFmr9UkPaBlr5I3i3rmfh9JGtnpm+YtKThDL4eoD5AmK6A4BSvVwarErvEjRoy4S9Yqj8xpEUzK6eRv+mTnttFNscJqyElr7IH3Mlf9UKhG2h/k95SqEchN/rIYiP2zoZMf4/NqbYmzxKXPUMdmUokKJ4a5S6aOBmL84E+1vW0y4HKOGsjLrqMvboWEyD+L4o96eydtC5GnFVh0v12PuZkpliRKrlDtQ4QjZ6/g6aClXPczr3QdlocieeNQ8rFP3KiopPRWs1oYB+TbChoAP8QD0ZOAxtBBL3vCGWYiH2Mfrj9/5wXdFjTQDpuypj6UE7cv2tuAyO3kQcBGJWkdKg/Iuthb6RsWqh+QTQj0iRi+RwxgaQHC6WXCvnx0o/EcRgs27Q04o2bfyEUdpcu+KEA0v/wOyvug8tJbLKfufedU017H700gSWP5oF/rceW+LaFYkjx
X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DB8PR02MB5946.eurprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(366016)(376014)(1800799024);DIR:OUT;SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: VByx7Y+8rUJnFIkjQiOVm9Vrj2oEZNBtAGSNNEFWHkUvvsJQqFkPcwOqvx7/CH72uakq+d7M/xPOr9gjdNdonak1BXFb08UeS9gBHe/UVamCrSdi6xfwzajIQJsRne2HU9FXOsLz7TXi7QAN8FSmWpuLrlwcYMVgGnYq4/NhNqZnWLZTaOeQlL6KlhVgn6lRm8T0ldzZ0Y77zsilvBsI5w4FLFEMiMW1y3kcklcH6MuN88y4PP1f6VLpbQpRDr26RhOJmeuJGu0cVH7By0s+BV77Um3iA3s4ubj0UumVWKb0Xu7rY6TJpkAIH0mRWbFsnLZ+dsczD1x9sXleO1AH8vC7LeBPcMo+RAwgphfjRuAFZVaz41BAjVl+9hHfp129kwBVgKpRciGp4EHCFDUuVMyxPoYvAP0bpsro4Bul7DE8LZ0f168wWQFlW/K4tC+zgdyKcPp6ud/z6AcoXEIFxK5eDIBaHG6fPVOwlsHAh9gIbQpaOlWkJx2AoyTmBr+6Ty7X2/LZt4pF6jRGf1N2x7C7utnAcTjMbrCoATmaC44cvO6ako1KZlUfmoceTlPMmu7PmJxTqwIS9c5aErZj7oP14kAsRA0NAKwKgQL7V8ramWt8o+yFcHwrXVt0jf5AFAGQ0C8VBYMlnfJuxm6TA7ujLJSEbg1stz38Crcm1I3FYpaKnNmntU3bKorcCp2Ke37K1JDzTpGI5rx2ZoGaccxOFIFnmEtm1egRMv3uM2HTAfBfmX7D8emSR5QQTsYac8zYqABs7/y3Efwk2OPurxRXBxitfLJ7xdM2iOMMFmxK9xhKo99HPfKWkDNn/iZx/Z04Ah/hAT2s3EvuqoFgsCYUDtrqFQrSoKKq9TybQ13HY0fIDrEMMFjW6OhmzMj2P/ChoaNBIiyZGtmzapLyuuQc+yHZTIuL4N3lxEeloJ+gXZblQ53I/2o329JjKIFfNN2bgmdwbShx4y2iEID258c8BV4sGiZPexlo14m2xIWaJ716iBf3msW7i8L1Bs4802El6E7E4jYs7qtp4emBvlzNOryO3Kk4xDgoPuS/sMacvD++yjEF9lF7e67H7MCrgIKsaQMgJHeDj+UlgGmqMYAJfHiolEtUVNgEhleikxSIwEdkQhb5OyTW2LxSS9ECWhFWNiktc4ID5yWSQw4BNQNKRyurAYDriv3oAByyZId1lOgz+l00jJQCVxA4ta5IR6ecp7En8ps53GS3pZal8zsGZwQsZXIwahYNP8GeIOoZKmq9rei96VveH1WHk4lsJOiCer38Lh5EFnF5pc2g/YCyNef5FKUaTxZl/cQwz6xyA17Wer30XlvdtXSd+NsQJnYCD2p2ilglpI8afo48WW1Pi/S27EdRJPvl3EM3Akrcg6TKe9vKnW46HUWNag0BJ7i69ohjK+1/76rSanSqrtXDi6Un4pfs2oo8iXXd9rWc9tXwN5MKBpsd4fEXn1ae1eB8eYdFFBV+0JDtfECpklrSMdkSafNVRQ7rjE65JVECDlbFKjhFjbZYhtN6oFkhDIckNl+EHfFAXdlPQhKK2KvGnnoUlLMXqQIOgT/kP1JTl5cIriYj7+KCXiCSFHgpv9RdoA8+MGPoznARW+Qhvmt/7Yd0ZH09dBTemh1xcmtUGGMsx36K1KwmpISltI6v
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: 01108f33-3d5a-4705-9998-08dd61c8294a
X-MS-Exchange-CrossTenant-AuthSource: DB8PR02MB5946.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Mar 2025 00:44:07.1536 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: RMu+5/IYVXnNfWdaEy3DQrDzOMIiGxZUrbgN8W/bC0tJlCA8i3y7BhigJhzUJD2A
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PR02MB6209
Message-ID-Hash: P4Z54YRFFHYB4QWTNK34O36U6Q2XKCL5
X-Message-ID-Hash: P4Z54YRFFHYB4QWTNK34O36U6Q2XKCL5
X-MailFrom: stephen.farrell@cs.tcd.ie
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Question to draft-ietf-tls-esni 6.2.1.
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/518648Uqcm7f6uDdoDhYkqePzew>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hiya,

On 12/03/2025 23:25, Christopher Patton wrote:
> There's also this draft, which could be used to probe servers for ECH
> support:https://datatracker.ietf.org/doc/html/draft-ietf-tls-wkech-05

Just on the status of the wkech draft - we're playing about
with (re-)implementing that using python now that we have a
PoC ECH integration with cpython [1], so there's nothing to
report in terms of the draft content this time, but should
be in the not too distant future.

If the WG want to make other use(s) of the mechanism as part
of addressing this question, that'd be fine.

Cheers,
S.

[1] 
https://github.com/defo-project/ech-dev-utils/blob/main/howtos/cpython.md