Re: [TLS] [OPSEC] Call For Adoption: draft-wang-opsec-tls-proxy-bp

Töma Gavrichenkov <ximaera@gmail.com> Thu, 30 July 2020 12:03 UTC

Return-Path: <ximaera@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 908A53A10C4; Thu, 30 Jul 2020 05:03:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vO06cVBKgEUA; Thu, 30 Jul 2020 05:03:54 -0700 (PDT)
Received: from mail-yb1-xb2f.google.com (mail-yb1-xb2f.google.com [IPv6:2607:f8b0:4864:20::b2f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4FB4D3A07D7; Thu, 30 Jul 2020 05:03:54 -0700 (PDT)
Received: by mail-yb1-xb2f.google.com with SMTP id y17so14284186ybm.12; Thu, 30 Jul 2020 05:03:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=T/v+rz6kg9tH1VeHNm0DZaXzOJP63ZInGslUhyP1NjY=; b=VaSQzBbkx9NSoTCGD2cb+cOhoeTyTlruuSXHOQd3ypVczp2rQw2QK9piWdBX1Jbs1z 3t6qUuvM569oRCAxVHYQ28E+tcO5ascoboZ79iQqujEETjvmAWt8XplUQGpjCmNDYpmH ev2xirrM5mi1iOjdpYT7HP2VF2MCsBuiQEHV5tYugAqM9d+MJaIjzXXF5V+IAAjrnG1j mLvjRw3UQT5hsEAlJeiwOzfAzfay9nsR1uDNKRyjBHNGQLgrt7nhOU4Wcj7xutjE0SUx kcwCwww0E9QSCX5ROBbVBjSE5LIXWL+JgFpUAQFmMAbu1HLqBBGmEVAnjpxxJC3LmwsZ jgsA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=T/v+rz6kg9tH1VeHNm0DZaXzOJP63ZInGslUhyP1NjY=; b=JPH5V2SS/rJPpX22LJQt0Xr8A5Q6LkFHuPrPQy2203i5OMrl58j4V981DUikSEjHe5 ngQbugUWBaVSKRnba0Mczdz9MViZgyyC3R1WXooyDmzxXjmdUtB3blfX6zJ/Lw9TAZQE Uk9RkdA/G26cj3BYWicTAj4L1u2EDHT9sJGssTHcofx/ivstqNWCYv/rcgVq3mkBjMxO GEuVUMQVtvCW15aYVUOKqrE6/5hm1IBPubosLnbjaBNArEdntegCYxCB3XNYlCqplWZW REhCjJSX6PnYaQKw/j/bQrQRJK556d4MffJJnNAyf9kqPQBEXJjXH1yLByLV/nG6pDRR Bllw==
X-Gm-Message-State: AOAM533YC+uaTMVPSWq1EBXg/kCtj0hDX7gL+qb/ykoeIdTUZEe3dYBt +MBAcs+G4/iuSR80iQh+JMqDq7FgWHH8hKsaRdU=
X-Google-Smtp-Source: ABdhPJyGOyrPoZliAw+GatM1hBZg0aE7uYRturxpD3jUVysivnMyNGL8Kewtnn8QTB35Q/TcHRAMepbg51LKdvXDW8E=
X-Received: by 2002:a25:d4b:: with SMTP id 72mr3876791ybn.22.1596110633437; Thu, 30 Jul 2020 05:03:53 -0700 (PDT)
MIME-Version: 1.0
References: <DM6PR05MB634890A51C4AF3CB1A03DA0BAE7A0@DM6PR05MB6348.namprd05.prod.outlook.com> <CAFU7BAS=ymUPTAGB_fOSrHTG0OajV1n5M1-yOBWxvGam-a89AA@mail.gmail.com> <d9d6d8c2-3916-be28-d01f-f040a28ce361@cs.tcd.ie> <9F2FDA20-12AA-4523-905D-7C9380B7A390@ll.mit.edu> <43A56381-0BA8-4123-A2D5-950FD1EDFC86@cisco.com> <845E6D98-DD1C-4FD7-AEF6-A262C10B35A8@ll.mit.edu>
In-Reply-To: <845E6D98-DD1C-4FD7-AEF6-A262C10B35A8@ll.mit.edu>
From: Töma Gavrichenkov <ximaera@gmail.com>
Date: Thu, 30 Jul 2020 15:03:40 +0300
Message-ID: <CALZ3u+Z1ARk8=EYBq8XCJFVvOojTWJ+_VKxkg7YbqqU=b=dKDg@mail.gmail.com>
To: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
Cc: "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, Jen Linkova <furry13@gmail.com>, OPSEC <opsec@ietf.org>, "tls@ietf.org" <tls@ietf.org>, OpSec Chairs <opsec-chairs@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000540d3905aba777bc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/99s1EBbrZA6iv02DLzJ2K14KbVE>
Subject: Re: [TLS] [OPSEC] Call For Adoption: draft-wang-opsec-tls-proxy-bp
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2020 12:03:56 -0000

Peace,

On Mon, Jul 27, 2020, 4:18 PM Blumenthal, Uri - 0553 - MITLL <uri@ll.mit.edu>
wrote:

> in this particular case, instead of "if you want to do this, then do it
> that way, and I'll help you inter-operate" I prefer "if you want to do this
> - you're on your own, don't seek a blessing or advice from me".
>

I don't think this is how it works.

I would personally prefer an explicit "this is not recommended or in any
way endorsed".

I've already heard that "IETF considers this a grey area to be defined in
future, and some interoperability is outlined in 8446" in middlebox sales
pitches.

>
--
Töma

>