Re: [TLS] Adoption call for Deprecating FFDH(E) Ciphersuites in TLS

Carrick Bartle <cbartle891@icloud.com> Sun, 29 August 2021 04:52 UTC

Return-Path: <cbartle891@icloud.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 746CF3A3301 for <tls@ietfa.amsl.com>; Sat, 28 Aug 2021 21:52:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=icloud.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id amKtqGnHeV2Z for <tls@ietfa.amsl.com>; Sat, 28 Aug 2021 21:52:15 -0700 (PDT)
Received: from mr85p00im-zteg06012001.me.com (mr85p00im-zteg06012001.me.com [17.58.23.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1DF663A32FF for <tls@ietf.org>; Sat, 28 Aug 2021 21:52:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1630212734; bh=+r2/pQCCqpSvqWrnu07XIGjQdNJKog088axz/qgAeLY=; h=From:Message-Id:Content-Type:Mime-Version:Subject:Date:To; b=jxLfrSk5psCQQMCyR6CscjBa5pdZQoByeLQsKvyO8KRYIqQZSpowYOyyqEtDRlu5I CJfW8OaRs86yMqC3qdCzzJVOxUnoX5OlK24ZTvdG8iPfXqSlvE/uAUoq+CWlATSe/U C6qsMyLHYoKM/J5AV5sgpE7KWzj1ppWdiIixc5zOEqbl+fI+xJ6MfwrAtNEoZ9+Dx3 yDV0e52N/ewHg/mVbdXDggfZTyE1yyMaUu5cJsQ6m6228tQdd1XDub41K+JKpU0arV MamJ9WitePf+1i2Kae+2Ad9Syvof4AmgokWbbdP8VObdaBp/SnknJa6sa89PfQiIMl bwPAF0eachkfQ==
Received: from smtpclient.apple (unknown [17.11.79.97]) by mr85p00im-zteg06012001.me.com (Postfix) with ESMTPSA id 79476A00197; Sun, 29 Aug 2021 04:52:14 +0000 (UTC)
From: Carrick Bartle <cbartle891@icloud.com>
Message-Id: <424B793A-FADF-4546-ACDB-CF81569BA874@icloud.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_4151B0FD-4CC3-4637-89A1-0714691465D1"
Mime-Version: 1.0 (Mac OS X Mail 15.0 \(3689.0.4\))
Date: Sat, 28 Aug 2021 21:52:13 -0700
In-Reply-To: <CAChr6Swdk948qN69VsE396AKXun3XwGTVjqmMsf90r4RHAKAeQ@mail.gmail.com>
Cc: Filippo Valsorda <filippo@ml.filippo.io>, "tls@ietf.org" <tls@ietf.org>
To: Rob Sayre <sayrer@gmail.com>
References: <CAOgPGoC4C0bWz0h0iyzGzMPEoDKAPv4euoOkmS+6Uuxncux4Zg@mail.gmail.com> <cc9c9d9f-d6b1-3b93-1231-a9a9c34a7fcd@gmail.com> <67533325-2983-47B7-871C-D90799D09532@ll.mit.edu> <CAOgPGoDAvnFic3VmEsge3i8C2FEfWp74ac_ievtfNo=MQB+C8g@mail.gmail.com> <C8E91D9B-2326-4AAF-9952-69481081E337@ll.mit.edu> <BD109A95-129A-4995-AFCA-FEF10DBD6440@icloud.com> <CAOgPGoBMhhsTupXuWF__zkLuy-4qQhha_Kp1_+ToZrNoaFUsgQ@mail.gmail.com> <13b9e674-9e0b-46aa-b5d6-49798c310d85@www.fastmail.com> <5D5FB49A-7D18-4EC9-B572-BD860479CD5E@ll.mit.edu> <bc91502a-471e-484e-ae5f-d843b703edd6@www.fastmail.com> <64c6ca0a-b3cf-cbdf-c1be-7cc4cc050a52@gmail.com> <0ba2ed9a-3128-4956-bd9d-2b961cbcb6d0@www.fastmail.com> <CAChr6Sz-tpipLTg_-cGYSoHmWz-VYK=ZT5W-3_cHQmSVnK-Kmg@mail.gmail.com> <4D0CEB0B-2134-4DE8-88D1-0A1B87444E64@icloud.com> <CAChr6Swdk948qN69VsE396AKXun3XwGTVjqmMsf90r4RHAKAeQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3689.0.4)
X-Proofpoint-Virus-Version: =?UTF-8?Q?vendor=3Dfsecure_engine=3D1.1.170-22c6f66c430a71ce266a39bfe25bc?= =?UTF-8?Q?2903e8d5c8f:6.0.391,18.0.790,17.0.607.475.0000000_definitions?= =?UTF-8?Q?=3D2021-08-28=5F08:2021-08-26=5F02,2021-08-28=5F08,2020-04-07?= =?UTF-8?Q?=5F01_signatures=3D0?=
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 spamscore=0 clxscore=1015 suspectscore=0 bulkscore=0 adultscore=0 malwarescore=0 phishscore=0 mlxlogscore=999 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2108290026
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/CNlHuedvMdt5rh0GRpWJ1p_hydk>
Subject: Re: [TLS] Adoption call for Deprecating FFDH(E) Ciphersuites in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Aug 2021 04:52:21 -0000

Sorry, I'm not sure what you mean?

> On Aug 28, 2021, at 6:20 PM, Rob Sayre <sayrer@gmail.com> wrote:
> 
> On Sat, Aug 28, 2021 at 5:29 PM Carrick Bartle <cbartle891@icloud.com <mailto:cbartle891@icloud.com>> wrote:
> All the ciphersuites mentioned in the draft under discussion are already listed as not recommended because they don't offer forward secrecy.
> 
> Excellent. How much WG time should we waste on so-called "embedded" use cases?
> 
> thanks,
> Rob