Re: [TLS] draft-green-tls-static-dh-in-tls13-01

"Dobbins, Roland" <rdobbins@arbor.net> Sat, 15 July 2017 07:39 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F11B131AAF for <tls@ietfa.amsl.com>; Sat, 15 Jul 2017 00:39:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PJ98ICLXLsi3 for <tls@ietfa.amsl.com>; Sat, 15 Jul 2017 00:39:01 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0103.outbound.protection.outlook.com [104.47.38.103]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A55B4131761 for <tls@ietf.org>; Sat, 15 Jul 2017 00:39:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=FnfZduUF8cuIPDUNr21x4R6BDMeMNLmD/TPNo3r9Lcg=; b=lBpubleSCwgIzVJ5Wu3RbkAfVEEobdShSgWBrrrPsBpfxByV4/qIR6CmPpatpWB/OzIQsDbqaIrPOUzhDdTaZVjY1vSEqwtNYISkr3/Nr+mYo3f+eUMUy08fzZ27U3hk1fEUKl63SFeQDLQmmA3hgwyshznEmPulQYIQNRX3t0E=
Received: from DM2PR0101MB1039.prod.exchangelabs.com (10.160.129.156) by DM2PR0101MB1037.prod.exchangelabs.com (10.160.129.154) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1240.13; Sat, 15 Jul 2017 07:38:58 +0000
Received: from DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7]) by DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7%17]) with mapi id 15.01.1240.022; Sat, 15 Jul 2017 07:38:57 +0000
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
CC: "Salz, Rich" <rsalz@akamai.com>, Joseph Lorenzo Hall <joe@cdt.org>, Matthew Green <matthewdgreen@gmail.com>, Nick Sullivan <nicholas.sullivan@gmail.com>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] draft-green-tls-static-dh-in-tls13-01
Thread-Index: AQHS/LbQetAoAc0WMUGwvSG+0rIljKJUZVeAgAAD9wCAABgasA==
Date: Sat, 15 Jul 2017 07:38:57 +0000
Message-ID: <FD5D1E4D-23CE-4483-B717-ECD249AC76FA@arbor.net>
References: <CAPCANN-xgf3auqy+pFfL6VO5GpEsCCHYkROAwiB1u=8a4yj+Fg@mail.gmail.com> <CAOjisRxxN9QjCqmDpkBOsEhEc7XCpM9Hk9QSSAO65XDPNegy0w@mail.gmail.com> <CABtrr-XbJMYQ+FTQQiSw2gmDVjnpuhgJb3GTWXvLkNewwuJmUg@mail.gmail.com> <8b502340b84f48e99814ae0f16b6b3ef@usma1ex-dag1mb1.msg.corp.akamai.com>, <87o9smrzxh.fsf@fifthhorseman.net>
In-Reply-To: <87o9smrzxh.fsf@fifthhorseman.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: fifthhorseman.net; dkim=none (message not signed) header.d=none;fifthhorseman.net; dmarc=none action=none header.from=arbor.net;
x-originating-ip: [2405:9800:b408:a9c1:213f:172e:972e:6441]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR0101MB1037; 7:1PKvY8dZ2IdYnFgridQBLrvoaKxqNvOVFN777xGm2znGWCJa+xX1fO6KsUvmXPWUe+v7TR82TwVMiav3IFW9CCyVkHIKUBRollyVQf0EbR/8G5i7PtjAxqLxa/Rd9649JYEPSUOFr9WLPhVuAGHBnUpwj3pL1xUmKP8P8iOyM4T/RJeylrIXWjAOLU94eNCxZiAygq2p0FBDvatCMGvTJ0oxwhb+kcJnc34FVMb3h9+rqcgSZxRmDPf96LoSGxAodff04Tfu1JHqCQlt/0GKbF0WNwqJu82EmivuT2AlsJbd3kwFwrpTGCiXiWC7yhHXcb4te6SpKHtGHWa2Tx/jxC5V5eH3T5LslEHEDweS+3+4ZuqqNPJpI782P5Q3DA8YV1+96+DclbdFmEUprGVIojozZ3BzPMYP+/R3Bdh7Yv9uQ9+Sj4YwHof6L0uSYbavqmvVyp5LfZpSiSObGJZSJXCterc4uxrNIiC0uzs3LUH+cwHvGCbK6bcIjkwvmBbpKBLT7dYAeAYZR1AQ4w8/zLolfMfukKnrl2EJFNthQCVcP2h1BTmy0pYE94a+3ore/na1rXQK907vaSA5/K+CYp1JZ6+pfVgE1kBFPblyJLN3QgHX2JVVqHMep74pIrqSSrUNqCkcoKVNsuD4qK52WOtQu8gdNQYSZfIcY46E4JN1vlyUFwA+zAOexR+oZzo92lzD9OyDwg2Sx1fkN1y3sThRiXBzsvIYsmTwLrfxjeOh2alOlR7McAmi8h46qq9TuapUkFA/JlmYV4gU8QAjql93URJBlE5QIty48KQP+cI=
x-ms-office365-filtering-correlation-id: 6a6c1499-a417-4f76-55d5-08d4cb548d93
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1037;
x-ms-traffictypediagnostic: DM2PR0101MB1037:
x-exchange-antispam-report-test: UriScan:(236129657087228);
x-microsoft-antispam-prvs: <DM2PR0101MB103755C41C7DB1D5EC261F51CAA20@DM2PR0101MB1037.prod.exchangelabs.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(2017060910075)(100000703101)(100105400095)(93006095)(93001095)(10201501046)(3002001)(6041248)(20161123562025)(20161123555025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123564025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1037; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1037;
x-forefront-prvs: 0369E8196C
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(39410400002)(39400400002)(39450400003)(39830400002)(24454002)(33656002)(3280700002)(83716003)(36756003)(229853002)(6916009)(53546010)(7736002)(82746002)(5250100002)(6486002)(2950100002)(6506006)(305945005)(8936002)(14454004)(189998001)(110136004)(6436002)(81166006)(8676002)(2900100001)(6246003)(38730400002)(25786009)(86362001)(102836003)(6116002)(39060400002)(478600001)(5660300001)(53936002)(54356999)(2906002)(76176999)(50986999)(99286003)(6512007)(230783001)(4326008)(54906002)(3660700001)(93886004); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1037; H:DM2PR0101MB1039.prod.exchangelabs.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Jul 2017 07:38:57.6986 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 54f11205-d4aa-4809-bd36-0b542199c5b2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1037
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/5nFrRv2zwz4GxAMTcDUbafblO7s>
Subject: Re: [TLS] draft-green-tls-static-dh-in-tls13-01
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 15 Jul 2017 07:39:03 -0000


> On Jul 15, 2017, at 13:14, Daniel Kahn Gillmor <dkg@fifthhorseman.net>; wrote:
> 
> * This proposed TLS variant is *never* acceptable for use on the public
>   Internet.  At most it's acceptable only between two endpoints within
>   a datacenter under a single zone of administrative control.

I would strongly attempt to dissuade anyone from using it across the public Internet. I agree that it is best-suited for use on networks within a single span of administrative control, & that's the use for which it is intended. 

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>;