Re: [TLS] Last Call: <draft-ietf-tls-negotiated-ff-dhe-08.txt> (Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for TLS) to Proposed Standard

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 08 April 2015 22:34 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6516D1A909A for <tls@ietfa.amsl.com>; Wed, 8 Apr 2015 15:34:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UNE8cwbL8DJQ for <tls@ietfa.amsl.com>; Wed, 8 Apr 2015 15:34:45 -0700 (PDT)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F92D1A9091 for <tls@ietf.org>; Wed, 8 Apr 2015 15:34:45 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id B78FCBED5; Wed, 8 Apr 2015 23:34:43 +0100 (IST)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Qog2KW3ts2T; Wed, 8 Apr 2015 23:34:42 +0100 (IST)
Received: from [10.87.48.73] (unknown [86.46.18.59]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 50293BE79; Wed, 8 Apr 2015 23:34:42 +0100 (IST)
Message-ID: <5525AD02.7000102@cs.tcd.ie>
Date: Wed, 08 Apr 2015 23:34:42 +0100
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, Benjamin Kaduk <kaduk@MIT.EDU>, tls@ietf.org
References: <20150404020709.31136.3025.idtracker@ietfa.amsl.com> <alpine.GSO.1.10.1504081555360.22210@multics.mit.edu> <87y4m21caq.fsf@alice.fifthhorseman.net>
In-Reply-To: <87y4m21caq.fsf@alice.fifthhorseman.net>
OpenPGP: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/BnEmMcNPdMFbff0gfWyBrYUu9ng>
Subject: Re: [TLS] Last Call: <draft-ietf-tls-negotiated-ff-dhe-08.txt> (Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for TLS) to Proposed Standard
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Apr 2015 22:34:48 -0000


On 08/04/15 23:32, Daniel Kahn Gillmor wrote:
> On Wed 2015-04-08 16:01:24 -0400, Benjamin Kaduk wrote:
>> No interesting comments here, just a note that section 9.1 has:
>>
>>       Pretend that a non-compatible client is compatible (e.g. by .
>>       This could cause the server to select a particular named group in
>>
>> which seems to be missing something...
> 
> Thanks for catching that, Ben.  That should be:
> 
>   (e.g. by adding the Supported Groups extension, or by adding FFDHE
>   groups to the extension)
> 
> I'm accumulating these changes (including the note about relaxing 4492's
> MUST NOT) in git [0]; i don't know whether i should push these edits to the
> RFC editor now, or do them in batch after Last Call.

The latter please. If we hit some major change or debate we can
revisit that but so long as they're small changes re-issuing at
the end of LC is fine.

Thanks,
S.


> 
>     --dkg
> 
> [0] visible at https://github.com/dkg/tls-negotiated-ff-dhe or via
>     git://lair.fifthhorseman.net/~dkg/tls-negotiated-ff-dhe
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
> 
>