[TLS] Re: Publication has been requested for draft-ietf-tls-keylogfile-03

Sean Turner <sean@sn3rd.com> Fri, 11 April 2025 15:40 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 92A2D1ABCB42 for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 08:40:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RrnWLExnvO3v for <tls@mail2.ietf.org>; Fri, 11 Apr 2025 08:40:52 -0700 (PDT)
Received: from mail-qt1-x829.google.com (mail-qt1-x829.google.com [IPv6:2607:f8b0:4864:20::829]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BB1A91ABCB21 for <tls@ietf.org>; Fri, 11 Apr 2025 08:40:52 -0700 (PDT)
Received: by mail-qt1-x829.google.com with SMTP id d75a77b69052e-4769b16d4fbso11853621cf.2 for <tls@ietf.org>; Fri, 11 Apr 2025 08:40:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; t=1744386050; x=1744990850; darn=ietf.org; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:from:to:cc:subject:date:message-id:reply-to; bh=JV39Ow8XWHnHfmzabp1k1x49pfQpgzGvzg8Nmgf4tzw=; b=FeBb4MxjCI8xqFk74WuBFojOBvQRHiosyGIqkRSHxwDn0Wc3S3qG52idNn3ajejeHq F1g0WD7yd/DpCEj3TcsTL0JzLSNCv8cpSnYtJe9gDmUGu4mvLJouLT9PYW5A0Jh60Go0 Y78cBgy7Y7FQvjdBjDGy7hpyeBSYGRSTrTgUE=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744386050; x=1744990850; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=JV39Ow8XWHnHfmzabp1k1x49pfQpgzGvzg8Nmgf4tzw=; b=mp3PUO0fAmfgRFe/2X7zxc0r/S9/1aEU/wsiQKLzgtBrnyuBGOrvvs+HDtXzfV9uIl eGVytHu+0JeAaYF1s6C+YXJcgfw/d/GnVe25AFjPS6VPpV0YtkIZZC8DNDvvpOu3LhLG 8D+HvYg3NatHOFVlDixM2KYv1uEnNXp2JDYXWblzfEV7WVl60h/v/GtYdqQZuq3NbCyc lEaloxuiz7jj2JgOeoQvJRJdMOnFRoiuQq9xkmAEr0Jf+ALM7VqAg0+1s2mlvC4FaPeH D1ynDcJZMa+4yQzwiqhWjOZ+H31Id1keH08A9OnR468+AhuR2RFYh2g2kiV+s6msrmEX srwA==
X-Gm-Message-State: AOJu0YyVXgzR4XwYrD/hpYHxNGA25cgaErbu4G7FAEPWiBS5TZhq+fqv pMXK6QhIdRD3i4zn+T/DhYCoK8PaHnIWKs5OLKFDxrLAae6k10uGxwBs1sNYvu5OmIS7pLBBY/N q
X-Gm-Gg: ASbGnctBF59IwGmdZpXhlg1+EmayUtksKwprBb13arIWuwIDGbTt4t0C8sL5YfyZAx+ +lLETcQ7inv/89Z66cYh4tuMYWrkE1n9mbJ62qWPApFY/+bR4HcMinEhJai4RKuHETZSUY5Ifbk o23i9rn633JojMg9oHLVbW/9YxN93w+5SNOlAm8RRyp+o1diz5NSuLzR8NMNvwfyQCdx4SayDle TvqZERHY8kgT7TKwY0t3rFdH+d1xLDhvM8qCOR6haLTQzfc3abemqvtLyZYek4cchzlB1F+JfG9 5TWOgYsv7qqON2l9D/9zxpcgPjfljRIhM+NUEUq9ZQSTFHOsll+bLHquN2Sl
X-Google-Smtp-Source: AGHT+IFzm0MFlboMrEgI5GTjl87Rys26ZSu/46l2Gl5hz09TMSi2S9m+mia0E0pzsZVQvqmKSrInVg==
X-Received: by 2002:ac8:6988:0:b0:478:eb5f:f948 with SMTP id d75a77b69052e-479775f4712mr42785981cf.49.1744386050508; Fri, 11 Apr 2025 08:40:50 -0700 (PDT)
Received: from smtpclient.apple ([2600:4040:252a:8d00:2d4e:e8d3:9638:df7]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-4796eb2d020sm27282891cf.36.2025.04.11.08.40.49 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 11 Apr 2025 08:40:49 -0700 (PDT)
From: Sean Turner <sean@sn3rd.com>
Message-Id: <574BA3CD-8302-4E91-B42B-68FB0EBD43C9@sn3rd.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_C6A91F11-F07B-4D80-A591-1ED14B1FF7C1"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.500.181.1.5\))
Date: Fri, 11 Apr 2025 11:40:29 -0400
In-Reply-To: <492e3391-ce13-4bfb-a640-caa61fcca743@cs.tcd.ie>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
References: <174368734611.2714005.3310313743466251329@dt-datatracker-5b9b68c5b6-zxk6z> <d334a79a-2c49-40d5-9567-b5878c040df9@cs.tcd.ie> <492e3391-ce13-4bfb-a640-caa61fcca743@cs.tcd.ie>
X-Mailer: Apple Mail (2.3826.500.181.1.5)
Message-ID-Hash: ULSRN4QRSLY3HKZ44H7HOKTJHX2LXMOS
X-Message-ID-Hash: ULSRN4QRSLY3HKZ44H7HOKTJHX2LXMOS
X-MailFrom: sean@sn3rd.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>, TLS Chairs <tls-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Publication has been requested for draft-ietf-tls-keylogfile-03
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/GXE38LHQVJk219HPq5goi_HO81M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> On Apr 9, 2025, at 8:00 PM, Stephen Farrell <stephen.farrell@cs.tcd.ie> wrote:
> On 03/04/2025 14:42, Stephen Farrell wrote:
>> On 03/04/2025 14:35, Sean Turner via Datatracker wrote:
>>> Sean Turner has requested publication of draft-ietf-tls-
>>> keylogfile-03 as Informational on behalf of the TLS working group.
>>> 
>>> Please verify the document's state at https://datatracker.ietf.org/
>>> doc/draft-ietf-tls-keylogfile/
>> Hang on - where was the outcome of the WGLC declared or
>> summarised by the chairs? Where are the minutes for the
>> IETF-122 meeting?
>> I think you're skipping process steps here in a way that
>> ought not be done, esp when there have been objections to
>> this draft. (And I think I already asked that the poll at
>> the meeting not be used as a declaration of consensus.)
>> Please correct. I object to decisions not being made on
>> the list when there is contention.
> 
> I got no response from chairs or AD on or off list to the
> above. Seems like bad form to me but maybe people were too
> busy.
> 
> I note that despite my request/objection, the IETF LC for
> this has now been issued. I've objected there too. [1]. I
> see that SM also had process comments on this too. [2]
> 
> I do plan to appeal should this document not be sent back
> to the WG to confirm whether or not there is WG consensus
> to publish. (And publishing as-is is wrong of course:-)
> 
> Cheers,
> S.
> 
> [1] https://mailarchive.ietf.org/arch/msg/last-call/KFXyZbe_hi-0OjCtvORwyJm_wpo/
> [2] https://mailarchive.ietf.org/arch/msg/last-call/fLGvbWNGBhux9c6crFJ1ZioKmLg/

Stephen,

The minutes have now been posted; see [0]. Joe posted them for internal review, and I got my wires crossed that the minutes were not also published to the datatracker.

I have updated the Shepherd Write-Up and brought your (and others) continued objections to progressing this draft. Likewise, I have discussed this with our AD at length. The points I believe you have made align the way (beyond don’t publish, this is a bad idea) are:

1. Strong Caveats/Warnings: When draft-thomson-tls-keylogfile was up for adoption, you were okay adopting it as long as there were sufficient warnings. The Security Considerations section includes much more text and an Applicability Statement section was added, which in particular notes this mechanism “MUST NOT” be used in production systems. When -ech-keylogfile, I believe there were more objections, but not a lot of support for more text. Now the drafts are combined, the text in the Security Considerations has been expanded to also include ECH and the Applicability Statement remains. Likewise, a PR has been landed and will appear when -04 is published that adds words specifically about the compilation issue [1]. As both drafts completed WGLC independently and now the draft is a combo, this point seems settled.

2. -ech-keylogfile is not needed because ECH is new. There were people who implemented ECH at scale who spoke in support of -ech-keylogfile. Also, -ech-keylogfile made it through WGLC; the only new comment beyond “make the warnings stronger and bigger” was to merge the draft together because it was odd that -ech-keylogfile was creating a registry for a draft so newly in the RFC editor’s queue.

3. Merging: During -ech-keylogfile, Rich suggested we merge it. I noted that that was going to happen when I closed out that WGLC. There were no objections. I noted that that merge had completed when -tls-keylogfile-03 was published; again, no objections to the initial note.

4. Specification Required vs IETF Review: This WG published RFC 8447 and -rfc8447bis is nearing completion. As you know, these documents set the registration requirements for almost all of the registries to Specification Required, which also implies expert review. This is true for the Cipher Suite & Support Groups. If the concern is about something slipping by the DEs, then we have bigger problems. The registration list is public [2], the DEs are known (Yoav, Rich, and Nick), and the DEs can raise registrations with the WG and have previously reported on registrations [3].

As you note I did not close out that WGLC; I should have, I will send a message in response to the WGLC thread referring to this message.

While I know you would prefer to not use the informal poll we took at the IETF 122 session because it does not support your position it is nonetheless telling. But because I forgot about the change to add more compilation constraints in the Applicability Statement and we should confirm the discussions at IETF on list, we will get a new version posted and re-run the confirmation about progressing the draft call noting that there was strong consensus with some vocal opposition. Stay tuned.

I have replied to S. Moonesmay.

Cheers,
spt

[0] https://datatracker.ietf.org/doc/minutes-122-tls-202503200230/
[1] https://author-tools.ietf.org/api/iddiff?doc_1=draft-ietf-tls-keylogfile&url_2=https://tlswg.github.io/sslkeylogfile/draft-ietf-tls-keylogfile.txt
[2] https://mailarchive.ietf.org/arch/browse/tls-reg-review/
[3] https://datatracker.ietf.org/doc/minutes-119-tls-202403182330/