Re: [TLS] draft-green-tls-static-dh-in-tls13-01

"Dobbins, Roland" <rdobbins@arbor.net> Mon, 17 July 2017 12:47 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E98FA131B59 for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 05:47:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.92
X-Spam-Level:
X-Spam-Status: No, score=-1.92 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bhp-udbZR0nJ for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 05:47:38 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0097.outbound.protection.outlook.com [104.47.38.97]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CE73F13146E for <tls@ietf.org>; Mon, 17 Jul 2017 05:47:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=8wxMwGBG4REUh2nbJsrVI4N5s9Rb5lVr5Nd86AU2mt0=; b=TUZFN4YpI3M6V2Mb0e/g/SpqzSQTgkMynYI/v4vTw/IX3B8oAI+HAlKy5NDID8Mq+s49H7oa0JwP8n0ds390urbtQ/rKKP5cctvnxUmZOBYdwTr6djaFf9S/2VkGgLG+ad9PIMHxQict8fEQ7v8PzDoKkgcWGEbWpj7OYIHTPrA=
Received: from DM2PR0101MB1039.prod.exchangelabs.com (10.160.129.156) by DM2PR0101MB1039.prod.exchangelabs.com (10.160.129.156) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 12:47:35 +0000
Received: from DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7]) by DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7%17]) with mapi id 15.01.1261.022; Mon, 17 Jul 2017 12:47:34 +0000
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: "Salz, Rich" <rsalz@akamai.com>
CC: Colm MacCárthaigh <colm@allcosts.net>, Matthew Green <matthewdgreen@gmail.com>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] draft-green-tls-static-dh-in-tls13-01
Thread-Index: AQHS/LbQetAoAc0WMUGwvSG+0rIljKJUZVeAgAAD9wCAAL5cgIAAG3oAgAA+T4CAAB0IgIAAQ4qAgAA3lACAAA63AIAAA1UAgAAC5YCAAiZlAP//l1IAgAAJfdWAAAJIgIAABEUl
Date: Mon, 17 Jul 2017 12:47:34 +0000
Message-ID: <2C2FDE20-F5C0-47C0-BF0B-387960CF096B@arbor.net>
References: <CAPCANN-xgf3auqy+pFfL6VO5GpEsCCHYkROAwiB1u=8a4yj+Fg@mail.gmail.com> <CAOjisRxxN9QjCqmDpkBOsEhEc7XCpM9Hk9QSSAO65XDPNegy0w@mail.gmail.com> <CABtrr-XbJMYQ+FTQQiSw2gmDVjnpuhgJb3GTWXvLkNewwuJmUg@mail.gmail.com> <8b502340b84f48e99814ae0f16b6b3ef@usma1ex-dag1mb1.msg.corp.akamai.com> <87o9smrzxh.fsf@fifthhorseman.net> <CAAF6GDc7e4k5ze3JpS3oOWeixDnyg8CK30iBCEZj-GWzZFv_zg@mail.gmail.com> <54cdd1077ba3414bbacd6dc1fcad4327@usma1ex-dag1mb1.msg.corp.akamai.com> <CAAF6GDeSv+T1ww5_nr6NPgg9k44j7y04tJWC=KeaJF7Gtt+TVQ@mail.gmail.com> <9bd78bb6-1640-68f6-e501-7377dd92172f@cs.tcd.ie> <CAAF6GDeGKEBnUZZFXX0y0a2J2+sVg8VaHh-4H9bhN0Zzk-x9uA@mail.gmail.com> <6707e55d-63d3-01e2-4e98-5cc0644e29e0@cs.tcd.ie> <35f4c84c6505493d8035c0eaf8bf6047@usma1ex-dag1mb1.msg.corp.akamai.com> <CAAF6GDcq6_ML3yHSQTy-t5irYLS10VVzk_R+7nAUKqQpgcCkrQ@mail.gmail.com> <a22d69c80d8d4cd2981cd6ede394c96f@usma1ex-dag1mb1.msg.corp.akamai.com> <F533492A-ACF1-498F-A03C-B829DDFFDD36@arbor.net>, <057af2f23acc450a9b896f9f0c81b06d@usma1ex-dag1mb1.msg.corp.akamai.com> <96E48B74-B718-4F9E-A12E-E43E6A5147AB@arbor.net>, <ea5ec18b4b344e58bebb7f7c522b6258@usma1ex-dag1mb1.msg.corp.akamai.com>
In-Reply-To: <ea5ec18b4b344e58bebb7f7c522b6258@usma1ex-dag1mb1.msg.corp.akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: akamai.com; dkim=none (message not signed) header.d=none;akamai.com; dmarc=none action=none header.from=arbor.net;
x-originating-ip: [88.208.89.131]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR0101MB1039; 7:ZSUppn341bgmbcZVXbvYUuPOn1+W8zZ1biwuISTaCgKceiIP47Uv5xKAyqxXw69/jQBarBXZyMG52mV6uJIHQ5sN+YE/rulaXwBFjedGd91F/aDt7CukPZcb5CcJIUPsdkS5lWj3Z7hlzkWZdxa0SQFmGkn7LpVyJbKpKWugaJqz0wlyEJ6y/Zl0r/558nSQEEYAMSJ6vJOeVvDLhkdq1hw1V5f6yvaVOo9XcEUBZou71jfGbyY/XBoq98hOzjs2xhbqm/JVOMAVdeyyBEaZ3rG68ejf7VY6jx4KlH433sI92UxgIFi9Kg+E0sm0EnE3yqkd0clYmc1kNtlOLdjZok4Gs8GWFHpHu0jzXYC0+FwOHyBFhW2fUwI+ibJutwXzaR/XGy5u5rUS8H9Njnuzqqdf3lMYxI4Z9Hm8No7dkQHWlqubnQbuQs6u+23G0qKvSvF12iiGpO3YvYkYDDL+LPxZ2Z6D9CigsGiTAgfGoFnfe/TmA+fMDXERpMuyb2gj56ciBWp3uL+Db8KRFPJOXrRPYzAfTUSX180+XDiHhaMkfS+8lxDJojeRzEZyibUyJMOKjCdV/QLGNNZF6ZTsFdA0bRU1lffFPVKKkFhtX5FSgW80bDrjE2WCK/87K0jdoPcEwKkTR0TDGb+iRH1vM66g+jZa0EeKwcykenoBHIgDcTsRd4NeYzIvKOiVGUu8BxNIQ6iFKCUL3wALGipgGDjmHTlGDWWRzb53I55EztO9pa3+iqa8ljxCI3CJ+ZvCnLDLhC4D+4pzMr0kaaMBS8IKgN2ni83HYvO57p0IkS8=
x-ms-office365-filtering-correlation-id: b9b92000-1545-4cac-4717-08d4cd11ff70
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1039;
x-ms-traffictypediagnostic: DM2PR0101MB1039:
x-exchange-antispam-report-test: UriScan:(236129657087228)(155532106045638)(50300203121483);
x-microsoft-antispam-prvs: <DM2PR0101MB1039B8CECE51E6DF7CB747A0CAA00@DM2PR0101MB1039.prod.exchangelabs.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(2017060910075)(5005006)(100000703101)(100105400095)(93006095)(93001095)(10201501046)(3002001)(6041248)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123564025)(20161123558100)(20161123562025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1039; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1039;
x-forefront-prvs: 0371762FE7
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39840400002)(39450400003)(39410400002)(39400400002)(39850400002)(6506006)(6436002)(478600001)(8676002)(189998001)(7736002)(33656002)(2906002)(8936002)(229853002)(54356999)(76176999)(50986999)(6512007)(236005)(99286003)(54906002)(4326008)(54896002)(66066001)(53936002)(14454004)(39060400002)(6486002)(81166006)(6916009)(2950100002)(36756003)(6246003)(25786009)(110136004)(38730400002)(2900100001)(5250100002)(86362001)(83716003)(3280700002)(82746002)(3660700001)(102836003)(230783001)(5660300001)(93886004)(3846002)(6116002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1039; H:DM2PR0101MB1039.prod.exchangelabs.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_2C2FDE20F5C047C0BF0B387960CF096Barbornet_"
MIME-Version: 1.0
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Jul 2017 12:47:34.7737 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 54f11205-d4aa-4809-bd36-0b542199c5b2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1039
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/67sTnlpoIKfssWKbdrsQZpKuM8c>
Subject: Re: [TLS] draft-green-tls-static-dh-in-tls13-01
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 12:47:40 -0000

Predicting the future is hard.

Does anyone have a crystal ball that says this MUST be done within, say, three years?

We can look at the PCI DSS timeline for previous revs - there's no guarantee it would be the same, of course. And there are other relevant regulators, as well.

Perhaps someeone from a regulated industry who's on this list can give us some insight?

For example, are any vendors committing to do this?

Vendors will do it if their customers/prospects  require it.  But many vendors insist on either Standards-track or WG-Informational (*not* Independent Stream) before they will commit.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net<mailto:rdobbins@arbor.net>>