Re: [TLS] Working Group Last Call for ECH

Stephen Farrell <stephen.farrell@cs.tcd.ie> Tue, 12 March 2024 01:12 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCCE4C14CE5F for <tls@ietfa.amsl.com>; Mon, 11 Mar 2024 18:12:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.009
X-Spam-Level:
X-Spam-Status: No, score=-2.009 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IunfNPqtSmq0 for <tls@ietfa.amsl.com>; Mon, 11 Mar 2024 18:12:31 -0700 (PDT)
Received: from EUR02-AM0-obe.outbound.protection.outlook.com (mail-am0eur02on2110.outbound.protection.outlook.com [40.107.247.110]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 06927C14CEFF for <tls@ietf.org>; Mon, 11 Mar 2024 18:12:29 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=npTXhumZ0Tm4MAhxDtpKFpblmUwJbAbFOpzPK1TaxfkXaP4UOqOZFo1aG5myUpZupGsv2bYT1WBoPqczWm4G52LgRrGL1aKDM/csNyzsYpDqXFSSRSkAT4UuHnrrsVFe37d9YaKs1WLTsxxFIov/d4QrcUdzatdpSvb1xF+CBz5Er2yPjZXbRWQw75/Jui0WcLl558kAAEYHojlLpPHgjGf0Qa8KQ7aX+JZBXjtY8JPgFxXCC44mq+90TcmoI71zmbld+j/PNxtvDk+2RDjPVZIJnZ+qshCA3ZRGI3JrPKXugy1GAJHl+KupLDuqiEOqwLXhgZFq3JrVkIy+rftuLQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=euSSgiJoxFOLaGqT5njsL2LYh5mYFX/xnZFYF0ssuy8=; b=VIAgpmBMQ1rm7Moaot0gJ3spbjJWlVTThJDZ5xw5cNZA2WgBBxUsdCXSxbrfGl+Hu4b7DgUSPbjgJZ+7oHiWhObypZMJHx4bl67hnaQR1h+2fMb361BIO6jRUlo/0NyuE33AdxaTbj1qnvGAzV2ZH25uaD6mTu9Km9Wvgm0Q/3kj6Ujs8NurKsNTjJryDn5nVcvJoHOAf9eoxb34CYPulk2rTbLXpATA6iDam42D9OezNkMVQuKN4E02lmHHf9rLmGdJUZFKsXnEdyGP6cmXIE1Il3hY6VR3MUSXGr+pzwJO1mlaQh0Rq1ke7y7ChI7p9OZUaChVJT3MYwL+nzuG4w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=euSSgiJoxFOLaGqT5njsL2LYh5mYFX/xnZFYF0ssuy8=; b=rdiIRFu8ldEccH1Nbq0aHc2AOJ/L2mwITAh50PcRk3oqVDVgJAPI48mm7rUw4ti/7AntXdZ35jBcdVkUbuIdHaQ/hIURNCyWTCfSafHCjMmPT/yLf84zmueAc6uaxVumE6XXASX7mEhZLzp/EjeabN6o/82nSRUni1pRTnK2Iia9QvkuqrPyFQmFMHes98I8WniW736JB1pTSjs8fibzPlHnSsUP4bntVN2Nkj83BAE+UKS7Dp6iT9J5n0wgZQN6YUkcafLmJ4fNlKbCpF3TenEFDYHnIIqiH7ldwOhFC/po4AUBCtHMCaMyi9GEB8XruBOydTJ70PmVixkrVE4bRw==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by PAWPR02MB9855.eurprd02.prod.outlook.com (2603:10a6:102:2ef::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7362.36; Tue, 12 Mar 2024 01:12:25 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::29da:8147:6e33:c2b7]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::29da:8147:6e33:c2b7%4]) with mapi id 15.20.7362.035; Tue, 12 Mar 2024 01:12:25 +0000
Message-ID: <e5fdf97b-58b6-4cad-b398-e3598f1d468f@cs.tcd.ie>
Date: Tue, 12 Mar 2024 01:12:22 +0000
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: Rob Sayre <sayrer@gmail.com>, Christopher Patton <cpatton@cloudflare.com>
Cc: tls@ietf.org
References: <CAOgPGoD4iiJ7kivRo4xbe0peiMG3YdzUvmVHC2KvqnMOpm+N7Q@mail.gmail.com> <CAChr6SzdcXTuUpjifniwVZcE6yJ+eUMokXy--Y-YcyYqU5TotA@mail.gmail.com> <CAChr6SzepG0bihTdV9dXbaHF9fE4mHrfJfwA1qC_rFaK0ZHTqg@mail.gmail.com> <CAG2Zi20q2csHdRXpFGd323FmMP2_1QDX8O+6HyjmdJrNMKcRgg@mail.gmail.com> <CAChr6SxkZ3KQuWBCJvfQtkZ9ta2Xh5XmWpZWLNVfA-viHYsoHA@mail.gmail.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Autocrypt: addr=stephen.farrell@cs.tcd.ie; keydata= xjMEY9GzphYJKwYBBAHaRw8BAQdAo6JvjmSbxHdQWPZdvciQYsHhM1NxQBU398Mmimoy4p7N M1N0ZXBoZW4gRmFycmVsbCAoMjU1MTkpIDxzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllPsKQ BBMWCAA4FiEEMG54R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQ5Njp+ZeoM93bogEA25ElRyX0wwg+kGEN1AoL60MoZfvQZ/VtmXY6IC5j +csBAIBpkL5ySuzJK2zLNZn9qQGht8IaUcA7cvDcLvS2uHUEzjgEY9GzphIKKwYBBAGXVQEF AQEHQILCPWOwW36e8D3pY8GmvvtItIT+A5uV80ist+WokVsQAwEIB8J4BBgWCAAgFiEEMG54 R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwwACgkQ5Njp+ZeoM92bcAEA8R+8cpqRUIS+SoAN iO05xE6O/wEx8/e88BqzAYki3SoBAOQdwiPX+MQrAxkWD8xxOsdMOAtxYKpkD1n8aPJUw6QJ
In-Reply-To: <CAChr6SxkZ3KQuWBCJvfQtkZ9ta2Xh5XmWpZWLNVfA-viHYsoHA@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------ryqY25BlC70hSVHd5Vbf8PJC"
X-ClientProxiedBy: LO2P265CA0336.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:a4::36) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB7PR02MB5113:EE_|PAWPR02MB9855:EE_
X-MS-Office365-Filtering-Correlation-Id: a2eab6c5-4bbd-4471-2900-08dc423179bf
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: bDv3JGAalmvaf+f7B8Dd8sQLiWLG+zv7AbCzUxGVqRZjSjoQdN+zhZh5V0NL4LBVqnvXdu2kpymFQW4UFW9K+wIo2Oczl5a2TNAjVdVGyv93HsDEICmV7QkArx1PWqp4X0i/WZSBlGrEeXmFxkNZPwce3TCqS+j5CJDoInacDRaH8gwc6to1Y2V0cu86anjbuHUEMvTPU3985cqjg+z6mKUcAMq2Wm5AhZh6oQkJbCarCIIBb+DGMD00e6WVNOMb/hIjqreZZfRHCGf+iN52kDRMre+aZU8siolJlm3wgzG5LHZwnF4GPi5Qq5C0/XQaYb2Rk3LIuo7OVHui01qvd1CkbLtDefT9uESF0XJBw4bYxq83UNXwubIQIRhxTKe9+ZQHNvtOmRvSPocGIZ75QXQWXxYnPRoc8mpdEyR1uy+SdsfPXCimZMmdrlkNxJpeCduDYl2etVMgZL6pQRqJnuajaDG0F/XcUMFbeEvRvMYUBHIvKrxhP2PBtw+if6TKwaS6hVQAWUFJmfupJGfUVc6e9I3qLXR/Wd5Xn+dvocrRYSs/KRVGhMVZbT2iFAH4C+JsTHnAuQtlKK404hKaaa8q1NrBDR1SyTZb2FDe4N4=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(1800799015)(376005); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: wQYO+GiCnNynxPqXg996ZFeORj3b7LQYnCN8O+CcAWlazr6OyynuJmjr7Waj+GNrjMih4NGyPsM0EPkuLkcUyzVSkATIndO1EK1ngqUEaLebE6vBCMyVQItQzz0DGiKjK+oseZheS0l9TyFHOeBFbozBVdETRRt3mRVPBR7p6x2rO7fD4zMYlGJdWKiwQEfgSYchIa4buqGwiLKmOFEn8scKBv6d96GbGtZk9xB4tmz2wETDhofxx2CP+2PDkuTv4Wfppl49oOBcviuof1QR5Pn+rNptiOTAFIBdMqRsGmz47Jp3WslNu+fyzp7a1G6E8a14SztINWAC6APduPAnZ7kXPtOm24KcJgcQ58yP4BAHqkDFXX6c/SpWetpy0wcMbeNiYrh6uUkZ8tqrEbhn9JnA3o/oQhzH+y74XGkpm9SYwmSrWY4FfGGZlq8jzyrxxv7B8JO/uTPv7mwnTs0lKP5S81luuWd7RYmgHE4T0DwomqtkO+je/hEeOO/XMzUf2Gjz58jsMYNcw0TYCZItcXvsy0XqZAzpRL4/IQetqGVbTS6s71CAnPwt1IkhwmnGwa5FmKgNRVEVZgbUjtlY3fz/nXaKdRxM0CUAcWmJiyh5uWZdLZwmjbWW813b2lzoM6IpOJLsGx8AgZkso0V8RqmFeWEFXZiOdi709J9r9uakYopKYUu7ddAEbEiLFd8oVTcufMqc/25UIp9yEFJMilwEYbncruMGzvw/jEhEv/alW0hU5MpteoDQg9YwDXinT57A+n35XBefHsTqXz/HwDYZId7KrMNs/VPLqpEfgdcVy13cueX065hQItD+ZoE8eMm2nai4jGLfDFQs6m67bReNP20bh2NsaO1/Bo0MTtnyxhY+1icV7XGXtKlrsK8dsZKil6xJ8RH2LCiBCuDd9gLiiPjKkbSj9tS4kUf4W8UdiEeyo2zBk8RmD7kD6BcBqCLi7+wZBQu/eBXkmFfNG7Yl2WtmvVXvk7vooV+ZpQjvr8TcpJOrQIvdfJTTF+umNDBS0rc9WHMkg61DJnZz5I4mSIo1xa5cDOpuHit33B7FDhV3t7f992eZDxj5ZDg5v6dhIIsTUzni1WxLtTN1BA1aJ4lmXfzzwRBLfsBS44eZr3IcsHeKwoTD9u2oJz1CZEyMS2C0MJgHwIwyoWvpx1oGPC7wm1zZF9Eruikn7TVV5Z7uG6cBUQzix56UkQLw4h5gRW7/vEkoetJ/80gSNy2T6Te9zsfOwSg6N623zP/gz41A8JeTP1szZRIFhdB3iUOck3ag5iS+ivpI8+dpJqXXlmShz8d6zbYZjj1hjjwWcb2DqIwDRJvQcA1AYdRuM+46rAtK4Icd2vWnAGho4lVfvs0fM+/1TPmhAcSgXosdiKG7owdzm8oiFMfs6FAQd1z8fyAIWldgkT5cxKItwcw4fXb9ZFvH1uCJYqfF3kdKH+WRgn+Nodjuz47pJc+86T3dCC8U3Skvp+pQ8OHWtyt+6vp52k9Ecz491EFtDa9/80LyI7PSXktEe59MHQwPrNv1gA3S9vwLdNDiHSUm8ekPfp76+jK6ghxsRLteWZSZZlFp+EijWGjHqJhvK2SAPu3XYCwNMg+WfsBn9NGiP2fTHAJosfD8c/2PODXPYQqu8tyyrAoYf/dsnDIgB9pA
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: a2eab6c5-4bbd-4471-2900-08dc423179bf
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Mar 2024 01:12:25.4895 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: jAxz+O0qENsY80oas2CsLEjMU+paxaQ1ou3qG4ZkniTYubr6Pwr8OgytRq9+r+5M
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PAWPR02MB9855
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/7-bHdKr2sb-9unXDVPljth-Jv28>
Subject: Re: [TLS] Working Group Last Call for ECH
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Mar 2024 01:12:35 -0000


On 12/03/2024 00:49, Rob Sayre wrote:
> On Mon, Mar 11, 2024 at 5:21 PM Christopher Patton <cpatton@cloudflare.com>
> wrote:
> 
>> I don't believe there were any changes from draft 13 to 18 that would
>> invalidate security analysis for draft 13:
>>
>> https://author-tools.ietf.org/iddiff?url1=draft-ietf-tls-esni-13&url2=draft-ietf-tls-esni-18&difftype=--html
>>
> 
> Hmm. It does look like there are few substantial changes in that diff that
> might be worth re-checking, but I'm not trying to delay things with
> nitpicking. If others feel the analysis of -13 is enough, then let's go.

Not quite answering the question, but I don't recall any code
changes affecting the crypto plumbing or interop since -13.

Cheers,
S.

> 
> thanks,
> Rob
> 
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls