Re: [TLS] Proposed text for removing renegotiation

Martin Thomson <martin.thomson@gmail.com> Wed, 28 May 2014 20:17 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A955F1A0051 for <tls@ietfa.amsl.com>; Wed, 28 May 2014 13:17:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eqyEDf2ffnAe for <tls@ietfa.amsl.com>; Wed, 28 May 2014 13:17:31 -0700 (PDT)
Received: from mail-wi0-x230.google.com (mail-wi0-x230.google.com [IPv6:2a00:1450:400c:c05::230]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 276A61A029F for <tls@ietf.org>; Wed, 28 May 2014 13:17:31 -0700 (PDT)
Received: by mail-wi0-f176.google.com with SMTP id n15so4359926wiw.9 for <tls@ietf.org>; Wed, 28 May 2014 13:17:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=45Mp8iaYPO4xlaSdlL5tlGw80MJHzrrL0lbZONK7kXE=; b=rm15vPAjTk09wTewu1M2K3wYShL73vzJL4rp1b2b0S7i+/N/oMmTJ49eNqrQJTGdNX HIW2Pph2khpg737FZxBPyaDtJjdppXXPrDQHJ/4ac8tPOalF626fw/P5n2xWebywmpwn 638PYF58gr2MC3MrKD4AjFZ9vG8oMJ7bQnFEEaeDOq5nykqeXeOmb9kS/zXkbTrpRPO1 r57xu3zafyX5KjPKQnDJNJ9BcaJlA1sHaFmzfY7UI2YfCyjcmlND28SJcmB5KIxSJpF4 Cw9a5L3rP8IMFtuzSt0gkbVVjEOMH5FFmUVNN6wq7qV6ni0caAkfUgkn/oi2VfS6+Xok CsNw==
MIME-Version: 1.0
X-Received: by 10.180.19.233 with SMTP id i9mr3169620wie.38.1401308244563; Wed, 28 May 2014 13:17:24 -0700 (PDT)
Received: by 10.194.235.163 with HTTP; Wed, 28 May 2014 13:17:24 -0700 (PDT)
In-Reply-To: <2A0EFB9C05D0164E98F19BB0AF3708C7130E4C1428@USMBX1.msg.corp.akamai.com>
References: <CABkgnnXaLKmxXL01hQEdxHSNGt3nZQQNBLDD5H2LqBzTo3vK4g@mail.gmail.com> <20140528004408.D184F1AD1D@ld9781.wdf.sap.corp> <CABkgnnUrMpmUH7DBgoZUAofe4J6PqNfYn9ORcmwu4385VAUX5g@mail.gmail.com> <53863F1D.3060707@amacapital.net> <CABkgnnWCqwVR1TFn8bM5=yNrmYSLMst1r3U_MR5eMD+Dkyv0rg@mail.gmail.com> <2A0EFB9C05D0164E98F19BB0AF3708C7130E4C1428@USMBX1.msg.corp.akamai.com>
Date: Wed, 28 May 2014 13:17:24 -0700
Message-ID: <CABkgnnUQdjPBbKxHJ2hMdm+ro8rW+JVu2cdP9H3tZw024pHOdw@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/GsVgnnqPNaxWJD2z3ttomUXaRno
Cc: "tls@ietf.org" <tls@ietf.org>, Andy Lutomirski <luto@amacapital.net>
Subject: Re: [TLS] Proposed text for removing renegotiation
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 20:17:32 -0000

On 28 May 2014 13:15, Salz, Rich <rsalz@akamai.com> wrote:
>> The whole point is to avoid the DH.
>
> I'm not sure that should be a major design point.  For the one use-case we know, do we know if those long lived xmpp connections are to small clients (such as android phones) or server to server?

People who like resumption keep saying that this is the primary
advantage.  Maybe they like the latency advantage, but most of that
would be obviated by faster handshakes, or false start.