[TLS] Re: Jonathan's "pause" extension

Jonathan Hoyland <jonathan.hoyland@gmail.com> Fri, 24 July 2026 12:53 UTC

Return-Path: <jonathan.hoyland@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 960ED11E2BD2A for <tls@mail2.ietf.org>; Fri, 24 Jul 2026 05:53:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784897591; bh=0uMxpBE6yEZPVgxZESRlE0WmlHCPo+du7JTG0pPoraI=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=DGn4yGWHct0PIsziN9PcS9xjPHYtBP4n98YCRE9Xv2Sp952rMq4ZawdxiqGBHO2NZ kYQfv3hcAc7HlfVY83dWJ/tN8Jb4IDuK98qz7+RcOXpiYWRqCuNRn2sQSiZXr/25bE /cU5gqEl9uINKdV64JIVMDTBKWZqbBdg3wPfBaGI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xWcOqOdCuZ21 for <tls@mail2.ietf.org>; Fri, 24 Jul 2026 05:53:09 -0700 (PDT)
Received: from mail-ot1-x329.google.com (mail-ot1-x329.google.com [IPv6:2607:f8b0:4864:20::329]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E409011E2BD14 for <tls@ietf.org>; Fri, 24 Jul 2026 05:53:09 -0700 (PDT)
Received: by mail-ot1-x329.google.com with SMTP id 46e09a7af769-7eb64085c45so156829a34.2 for <tls@ietf.org>; Fri, 24 Jul 2026 05:53:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784897589; cv=none; d=google.com; s=arc-20260327; b=Ao9v0o5E5onPnOZj8RfQ8rH0k3SsOEOrFFHyvChKAOleeX/hehQHD4vVlpR5fY0Whu oOGvTKIILVMhJMtqrt550+horuRrcXTFRap2DGOTSEGeIBuTYebUPDhKaQWJAdFu+XY2 odec5f9bvmVbXGhwicX1ixyXr5IUnK4tTjbDUHvjh0Uh2fdtLJaU2XvFKCGOPJ2uCNJQ UmRSQovspIiD92KoSyfAnZxmEFFpYSAyoVw4OnguWUnZxs9RtXkSVUMsBzgM1yyYUPMw qFEjZap5k02PM/bQCXNkTjiuBeM9Dw4hwlyyptTw21dglB2DJXbnsoEZgfG0grd8vMs/ lfmQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=brU1/1Bx2EphrRSIj6scweHJUzQX+toiTnKAuM2D5dY=; fh=QFBJUIey73h81N2DUohGM8W49vcUAch2kOGF11madJ0=; b=mjlnSPy/lLuvlt5LfZFQWckocWriV13wsH72lc192kKi/Xz+940gqXE/+6m+tNgJiV hA4aoBZh3o1YtTQyrEDtaOBe2p+P6hXMJ/0Yaucf+dUItyIOTK9/5jhvGSEuAp6um+GO AI5uJllt4MkPbiZBL+oxwra8RYMJ6FYZDx7rshDYieD49MW7sdoo1NszTYFGCcNSxPQ+ YVejN2u7oaryrSudjkX3zsxfL05py2yg3KxHXVlheveu2Dc0TVHl5aL+M6DcNotHTxo5 2ZxOBy7cx/4EQnAx+epnmH3VDhRtCO/8RVjyFcH1/7dRW30laEFB686XWlirseQ2RGti QzeA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784897589; x=1785502389; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=brU1/1Bx2EphrRSIj6scweHJUzQX+toiTnKAuM2D5dY=; b=ggq+IAmahyyDttgQc3k93zT8rPq56hTZ2HaUuMdjT1e/PMfvTocbmkulwF1rtiDoRG HaaDO65iYKakizPNg1estFvWRzWf2ZqBjlYBXw15AQ31GabiTZYOnMnmErTRicTz40u8 M0DZK1Dvpmgg1zj7Y+ve0mR8z56dSowbU429PSgM/2MackDnYCLLg7YYYk3vxdj4423x QzbDgGOBuVqGoRX4oFvsPMVSiJSeTaZzbGbbUkNkl50K4RcZBqyrCWb3h0Uwp8OZ2Hhs CcYFjSrY07DWiDlbS28SQ9804QJ0T92S6FrodWqkj5dgS9s/zmVETges9IKmsC1USpdx Oohw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784897589; x=1785502389; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=brU1/1Bx2EphrRSIj6scweHJUzQX+toiTnKAuM2D5dY=; b=FKuzvKXL8uPCx/pNk17MzQUfDAUIWkG1TOUX2yfKySr3KqyIiSi4wEuY2qlglLghOL StncEltQmOY1xmoZz+nPzbW8U104F1XtjFT9ARDThvgAmYjLR7oFA3cF2J/HDgSnNTiQ +KYt18dSstZN2mTzy0xq63/FRLMe4VAMLtjSGVbqwgw537O/rFg7nIMhZyBoipicPwX1 mWSt8KRRulswmtuUcRvbqJ5nESoFNpJpVQ706HDWR1s88QmnI70bJVwzGFwvx+YcPhKS rms2MPSLl3gXsdGH4rLPFKdanW9bAZArJFPo9ehmsYrYptfgRMgj0vpXkRUZmItVjAmq Kv4A==
X-Gm-Message-State: AOJu0Yyb8yXMokAMxJv9alGFSGtcls8Ux+ActI8EjB7HeCOik8bsXShg gxVBkaHV2/Ds7HnI++SCYhRWGZskw8PhlmEaEU8+++xWRChxolXL1m6iOzlbYiVX+mNWIstlnrC 7v9HT5O5oFSHqneSrTiXg0Lp4QQHW1Y9QegLLdQ81eg==
X-Gm-Gg: AR+sD11GJFhCVpGr/yjBoXK+2WtUP1wq5i89oTObN76I47TlfsPZ8aUZYphOBHpmsbE UsdW/nKAuP5TYEyHVaoT2h9gJKlzxVhbVbp4BSmTchGtVGqtHwUfXdA4Lg/0ax6dlBEmwEzo10r ulIFYHCE9be4/L/kh9e+GhuiWLd4S6XZdDOQgc/yWozA9bcvsDjMjbOQuGdrCkVhGM859YPoNac 7ci9r7AQ4RSC14hrn6coc2Dvm4bwdVvnpAIP7LfzVMap0xoD51pf/JzMgpVrIvbwpSK5hCoB5rL YibZjwXCT3bxFg4Iv/kO0CtVI8Ku1+g8OPtc3hdfXjW7t2Zd9UV0SDP7wY9VIghMlR+r+BT7HO4 C
X-Received: by 2002:a05:6830:4412:b0:7d8:b269:e99b with SMTP id 46e09a7af769-7ee43dbbbf2mr4271437a34.17.1784897589076; Fri, 24 Jul 2026 05:53:09 -0700 (PDT)
MIME-Version: 1.0
References: <MN2PR17MB40310666BBE1097CC321967BCDC02@MN2PR17MB4031.namprd17.prod.outlook.com> <d4742a96-e238-48c0-83c7-2d81c3579e28@dennis-jackson.uk>
In-Reply-To: <d4742a96-e238-48c0-83c7-2d81c3579e28@dennis-jackson.uk>
From: Jonathan Hoyland <jonathan.hoyland@gmail.com>
Date: Fri, 24 Jul 2026 14:52:58 +0200
X-Gm-Features: AUfX_mzSE10Eu0cVGHOBgiS2iBxRaiW5FxOusKIW7y0aafxXoa_50Y5OrNd6kh8
Message-ID: <CACykbs36TJRrebb+P_MOU83uUNqA44PLd79vBbCtqJwVv_h5Aw@mail.gmail.com>
To: Dennis Jackson <ietf=40dennis-jackson.uk@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c1e6c706575adac8"
Message-ID-Hash: U3NYB462COJYC6LRW3YN2L5V4PPJP75J
X-Message-ID-Hash: U3NYB462COJYC6LRW3YN2L5V4PPJP75J
X-MailFrom: jonathan.hoyland@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Jonathan's "pause" extension
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/8FY7yocqQOSN3aTGMRnDYe0v5Q8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I think it should be handled at a higher layer where possible, but we don't
have good handles from higher layers to lower ones.
Most attempts to bind stuff to the TLS layer seem to fail the moment they
find that most libraries don't support it.

Having a "pause" extension at least gives the upper layers a knob to turn
that allows them to drive the upper layer protocols and know whether data
was transmitted before or after the upper layer protocol completed.

Regards,

Jonathan

On Thu, 23 Jul 2026 at 12:04, Dennis Jackson <ietf=
40dennis-jackson.uk@dmarc.ietf.org> wrote:

> I feel that all of this 'supplemental authentication' *should* be
> handled at a higher layer, whether that's a HTTP middle layer or the
> application layer.
>
> My suggestion at the mic was that the TLS WG should provide some
> guidance on how to do this safely and effectively in a application
> agnostic manner. I don't think this needs any changes to TLS.
>
> For example, sketching how to combine TLS Exported Authenticators with
> additional certificates or PAKEs or other authentication flows and
> pointing to existing drafts in other WGs that already take this
> approach, e.g:
>
> https://datatracker.ietf.org/doc/draft-ietf-httpbis-secondary-server-certs/
>
> Best,
> Dennis
>
> On 23/07/2026 11:52, Salz, Rich wrote:
> > I wanted to bring to the list a suggestion Jonathan Hoyland might at
> > the mic line today.
> >
> > During the Supplemental Authentication discussion, several people
> > brought up the idea of using exporters and channel bindings (9261,
> > 9266). Yaroslav pointed out that it requires application changes to
> > use them.
> >
> > Jonathan suggested a “pause” extension. Rather than changing the
> > handshake, this new extension would tell the peer that more data is
> > coming and do not accept/send application data until the pause is
> > lifted. He and I chatted after the session, and we realized this could
> > probably handle multi-exchange PAKE traffic as well. Anything that
> > would modify the handshake, or is normally post-handshake (cough,
> > authentication, cough) would also work. Probably need to nail down the
> > semantics such as when to lift the pause (E.g., when you don’t get
> > records with the pause extension or wait until the “done” message is
> > sent, etc), but this seems to me like an elegant solution.
> >
> >
> >  during the presentation on Suppl
> > During the Supplemental
> >
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>