[TLS] Re: Opsdir last call review of draft-ietf-tls-rfc8447bis-11

Sean Turner <sean@sn3rd.com> Fri, 11 April 2025 16:10 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 08C311AC4291 for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 09:10:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FxmKvzwyIlYg for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 09:10:36 -0700 (PDT)
Received: from mail-qk1-x733.google.com (mail-qk1-x733.google.com [IPv6:2607:f8b0:4864:20::733]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 147011AC3F50 for <tls@ietf.org>; Fri, 11 Apr 2025 09:10:02 -0700 (PDT)
Received: by mail-qk1-x733.google.com with SMTP id af79cd13be357-7c54f67db99so320452585a.1 for <tls@ietf.org>; Fri, 11 Apr 2025 09:10:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1744387801; x=1744992601; darn=ietf.org; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:from:to:cc:subject:date:message-id:reply-to; bh=CcrcXj0OBHo1Ym6LmyRdOBPXnBy+QYqDxhBtns/SPxk=; b=kOkc+xi9yArIOSTQPTcdl5Gt08+88tTrpJLoIg7gdLmFxjFhjZaex32zTMYSjcMEVS E8mv6q7/lGTE4ImDVRs8qamNnAk9xPaAHyCg4L0fSOrpj6HY1dheg6LtpLirbRjDP1I0 yT0EkW/oa4v63TuR8Aqej63NMS7sMKIIGpsC4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744387801; x=1744992601; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=CcrcXj0OBHo1Ym6LmyRdOBPXnBy+QYqDxhBtns/SPxk=; b=LkWMFhMZs+DNHTDE6w01QKP9WjPDoFgrm2DTvPPO1VwnhyEHyYtZgcTWIzf/TNvUEU RBoi/S+0f991L65ha0w3UuxpkJ3JHtKMYzWUIj1dJrpQdREYDSuU+GE1FGKA4lup04dm fBloYEmQdQlP5XM7Ys0kZZIP5bzmEQSIEhTxdP3H4a9t4uD70qMQ13VkkyyGz+Q0iUZq EwMfnQ2AsMUt+VAImAs5KrLMfITROBmmQdwxq4g6cw2tZlBPEoHr4J0pIdg9ZEx3vFiQ qUvbYd4e5o27MRJ8FV0bX/awbRZFQQEDLpDPzgiA0AfZBdzIpBoGgZUqvfvygPBMO4sK GJgw==
X-Forwarded-Encrypted: i=1; AJvYcCWLn8lKt31539YGkt9jODpBfPVYGkxJ7at2uE+UKzkuft8rlggwlMU/3jNYxozff5vBb0U=@ietf.org
X-Gm-Message-State: AOJu0Yy7ogVcbn/1c0JpZ0A8EKS2LZx5Yg7ihzF7LqxCF7QlPbIsZppg Zh1RpNy/yc8UVhGYHihdPYngl6YJnkgimltoCeENbxlAdt1rSdBqH+2omG40GCNMNKHTw/wrfbs k
X-Gm-Gg: ASbGncvTDFo88kjeSqrwkS0ju8OMYHpvmYVrvrgc0w68Ce2B5G8nqIsTUon/JvPTHJZ GpzxY3bJWJionWBl8tKY+f5BwCkfhGRU1lECv+uVrQYpVV5NGaVIiSH+gnsnbsdYMfEH2BgSvWX SOCsLfWhF1akAVTIZaqRRTW6dDeBf36h6gFMfxwIHXyBV8Mgr9PRPEbb3DVWEnCn+xWrPMML2hQ muTuzN73p/ffWdRrUK0XZKgAEuH67DPqpLkqsFpMlBF27ex2b0fSoOb91ETUvZiYmN+oR3AiizK e5pkG8mmrYEOXj1iO6BeuW+6X45q+Df6SfM/XRe7thWZvSTbtqEa3bPS1r+MTJ9kZvdqbvU=
X-Google-Smtp-Source: AGHT+IHnsbZ+mVF7u9evO05GCcKCVsyP3cu6bDai3zz/Gfe+C0aoPYBNKr3nMa8+AWJbotI2Xhbh6g==
X-Received: by 2002:a05:620a:2588:b0:7bc:de68:e932 with SMTP id af79cd13be357-7c7a76b90c6mr956039185a.23.1744387801095; Fri, 11 Apr 2025 09:10:01 -0700 (PDT)
Received: from smtpclient.apple ([2600:4040:252a:8d00:2d4e:e8d3:9638:df7]) by smtp.gmail.com with ESMTPSA id af79cd13be357-7c7a896b04esm279368285a.63.2025.04.11.09.10.00 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 11 Apr 2025 09:10:00 -0700 (PDT)
From: Sean Turner <sean@sn3rd.com>
Message-Id: <C5410CED-DC24-4CEF-BD1D-649ECFAD5FF8@sn3rd.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_47E13452-6A69-47C9-A44E-5934E3F47E9D"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.500.181.1.5\))
Date: Fri, 11 Apr 2025 12:09:39 -0400
In-Reply-To: <174369205715.2732618.18280102439496098010@dt-datatracker-5b9b68c5b6-zxk6z>
To: Giuseppe Fioccola <giuseppe.fioccola@huawei.com>
References: <174369205715.2732618.18280102439496098010@dt-datatracker-5b9b68c5b6-zxk6z>
X-Mailer: Apple Mail (2.3826.500.181.1.5)
Message-ID-Hash: VXAIUJGBYIEHSM6TX4JKCE3L2FBAWPXD
X-Message-ID-Hash: VXAIUJGBYIEHSM6TX4JKCE3L2FBAWPXD
X-MailFrom: sean@sn3rd.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: ops-dir@ietf.org, draft-ietf-tls-rfc8447bis.all@ietf.org, last-call@ietf.org, TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Opsdir last call review of draft-ietf-tls-rfc8447bis-11
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/FQTzDvQ4f2TJ9LygwNq7ZLPAgWA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> On Apr 3, 2025, at 10:54 AM, Giuseppe Fioccola via Datatracker <noreply@ietf.org> wrote:
> 
> Reviewer: Giuseppe Fioccola
> Review result: Has Nits
> 
> This document updates the changes in RFC 8447 and requests IANA to make changes
> to a number of TLS and DTLS registries. In particular, it updates the
> "Recommended" column in TLS registries by defining a third value "D" for items
> that are discouraged and adds a "Comment" column to the registries that do not
> already have it. This document updates several RFCs: RFC 3749, RFC 5077, RFC
> 4680, RFC 5246, RFC 5705, RFC 5878, RFC 6520, RFC 7301, and RFC 8447.
> 
> I think that the document has a well defined scope and is quite clear. However,
> I have few suggestions:
> 
> - In the Abstract, I suggest to replace 'adds a Comments column to all active
> registries' with 'adds a Comment column to all the registries that do not
> already have it'.

Done via:
https://github.com/tlswg/rfc8447bis/pull/76

> - In section 3, I suggest to replace 'The permitted values are' with 'The
> permitted values of the Recommended column are', just to avoid any confusion.

Done via:
https://github.com/tlswg/rfc8447bis/pull/76

> - In the sections from 4 to 14, I suggest to add some explanation on why
> specific registries are changed to discouraged. Some insight would help the
> reader.

We had other comments along these lines. I went through and looked at whether there were links to the drafts that gave info on why D; see https://github.com/tlswg/rfc8447bis/pull/74. Mostly, we added a ref back to this document which includes the info.

> - I would also add some observations on the operational and interoperability
> impacts, if any, of the changes proposed in the document.
> 
> - Currently, the section on "IANA Considerations" simply says that the document
> is entirely about changes to TLS-related IANA registries, as per RFC 8447.
> Instead, I would put all the relevant sections on IANA requests (i.e. sections
> from 4 to 14) under an "IANA Considerations" section. In this way you can avoid
> the IANA section with no content.

On these, two we’ll take them under advisement. On the ops and inerop impacts, I am not sure there is much more to say beyond hey make sure your implementation is updatable and configurable. On the last point, we could do that, but this draft has been in this format for 4 years and RFC 8447 before it has the same format.

Cheers,
spt