[TLS] Opsdir ietf last call review of draft-ietf-tls-deprecate-obsolete-kex-05

Menachem Dodge via Datatracker <noreply@ietf.org> Fri, 25 April 2025 07:24 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: tls@ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from [10.244.8.147] (unknown [104.131.183.230]) by mail2.ietf.org (Postfix) with ESMTP id 1C2132105E96; Fri, 25 Apr 2025 00:24:38 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Menachem Dodge via Datatracker <noreply@ietf.org>
To: ops-dir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.39.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <174556587795.299.1854529444619341019@dt-datatracker-7bd7b9d5d5-79vfh>
Date: Fri, 25 Apr 2025 00:24:37 -0700
Message-ID-Hash: DLZ5AD6VAVILXKUCCHYAS6JAPFSM6HTM
X-Message-ID-Hash: DLZ5AD6VAVILXKUCCHYAS6JAPFSM6HTM
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-tls-deprecate-obsolete-kex.all@ietf.org, last-call@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: Menachem Dodge <menachemdodge1@gmail.com>
Subject: [TLS] Opsdir ietf last call review of draft-ietf-tls-deprecate-obsolete-kex-05
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/BK5q8JpLCjKVP4VXZlsIH78tMLI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Document: draft-ietf-tls-deprecate-obsolete-kex
Title: Deprecating Obsolete Key Exchange Methods in TLS 1.2
Reviewer: Menachem Dodge
Review result: Ready

Document: draft-ietf-tls-deprecate-obsolete-kex
Title: Deprecating Obsolete Key Exchange Methods in TLS 1.2
Summary:
   This document deprecates the use of RSA key exchange and Diffie
   Hellman over a finite field in TLS 1.2, and discourages the use of
   static elliptic curve Diffie Hellman cipher suites.
Reviewer: Menachem Dodge
Review result: Ready

Hi

I have reviewed this document as part of the Operational directorate's ongoing
effort to review all IETF documents being processed by the IESG. Document
editors and WG chairs should treat these comments just like any other last call
comments.

While I'm not an expert on cryptology or TLS, I have no operational concerns
with the document. It is well written, and clear as to which key exchange
algorithms must be deprecated from TLS 1.2.

Thank you kindly.

Best Regards,
Menachem Dodge