Re: [TLS] Rethink TLS 1.3

Eric Rescorla <ekr@rtfm.com> Sat, 22 November 2014 01:11 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C57231A924A for <tls@ietfa.amsl.com>; Fri, 21 Nov 2014 17:11:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level:
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kmTInUm7vIT3 for <tls@ietfa.amsl.com>; Fri, 21 Nov 2014 17:11:32 -0800 (PST)
Received: from mail-wi0-f177.google.com (mail-wi0-f177.google.com [209.85.212.177]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2072E1A923B for <tls@ietf.org>; Fri, 21 Nov 2014 17:11:32 -0800 (PST)
Received: by mail-wi0-f177.google.com with SMTP id l15so898639wiw.10 for <tls@ietf.org>; Fri, 21 Nov 2014 17:11:30 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=5+HWsxDSR0gqBgvo44cVVjEpeD7UNXzL8UXJQxWldRg=; b=fchhJNpLzFqIoI7JxDpJB+n2zK4E6pdMNfbsh7MoNl/Vm2L/zmTFS6kU6QzSRb09wy pEE8DFdG6ELttsQ9jhOBmu7XgF41LU/Q0bFfnVsnCmawO4h1UVqaPqWtSq3BieQQ6bfc RKNhFuuLzDF2N3DaqrUxp1ZrfIiS/6/PmM6/Uc5XCRiyKoSp3sUE0ExAjAe6oLB6Jdsh E8bdU2T5i9IV/4Sad/umqKHLJt79XiX/5BEuU+Db8UrMRZVc4DZ6GS0O+WVBHjlLJxdm uIn9PAxBrKu2nFwt/9eEEDbFtzFI+aufj+GU9vd5w64uDL9dC3Fmyz9y2aFA+koXVKHe 0PzA==
X-Gm-Message-State: ALoCoQn5LbgZdVRl424hv4XHELeOGD3e2W1syV+Ggj4rIF1ENzxYNG9v0C8vdutCzXDGMeWomPDS
X-Received: by 10.180.14.226 with SMTP id s2mr1588584wic.61.1416618690774; Fri, 21 Nov 2014 17:11:30 -0800 (PST)
MIME-Version: 1.0
Received: by 10.27.130.34 with HTTP; Fri, 21 Nov 2014 17:10:50 -0800 (PST)
In-Reply-To: <CACsn0ckmYrx+S--pP6P7VgjsmqQsoYnp+m-9hTPT-OJ9waUtkA@mail.gmail.com>
References: <CACsn0ckmYrx+S--pP6P7VgjsmqQsoYnp+m-9hTPT-OJ9waUtkA@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 21 Nov 2014 17:10:50 -0800
Message-ID: <CABcZeBN9iYTPEvHf4JsGCbB9iVJ0wfff=-J1zdo85FNqV=4WWw@mail.gmail.com>
To: Watson Ladd <watsonbladd@gmail.com>
Content-Type: multipart/alternative; boundary=f46d04138c9fd89a530508683da7
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/FjqSX_i-d1E5SXp4yqGRt4IEp4o
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Rethink TLS 1.3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 22 Nov 2014 01:11:35 -0000

On Fri, Nov 21, 2014 at 4:57 PM, Watson Ladd <watsonbladd@gmail.com> wrote:

> Has TLS 1.3 fixed flaws in TLS 1.2? Some: session_hash remains
> unincluded, but the record layer is finally fixed.
>

We have a pull request up for session hash up at:

https://github.com/tlswg/tls13-spec/pull/89

As I said in Honolulu, I've been planning to incorporate this next week.
It would be great if you could take a look and send comments.



> The current draft is not in a state where it describes a protocol that
> we can analyze or implement.


If there are specific things in the draft that you don't believe can
be implemented (and that aren't otherwise called out in TODOs or
Github issues) I would greatly appreciate it if you would let me
know either on list or by filing issues.

Best,
-Ekr