Re: [TLS] draft-green-tls-static-dh-in-tls13-01

"Roland Dobbins" <rdobbins@arbor.net> Thu, 20 July 2017 19:51 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EF98131B9E for <tls@ietfa.amsl.com>; Thu, 20 Jul 2017 12:51:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.922
X-Spam-Level:
X-Spam-Status: No, score=-1.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TWOOUwrx-_Lu for <tls@ietfa.amsl.com>; Thu, 20 Jul 2017 12:51:29 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0128.outbound.protection.outlook.com [104.47.38.128]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3EE36131B8D for <tls@ietf.org>; Thu, 20 Jul 2017 12:51:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=x0cN4qqAzTrvc3/z4xUDKwC1I5mQL3YaFs4OySqln+Y=; b=UBHejRg8oF6dz/zh5G/wD2tTJaZlav9rG3wDdj+PZ0FDgd9c6a6vSBN8XtabyeLWjmm2Ws1plfX4BtBrdcTqWXjArR9k4NWepH1qsNjmpMV5csfdpZNqNULGR/bWs2q2/MDBWyt2GWwqAm0xfWyb5l78vZpM+YIjOhFkOlKX8cY=
Authentication-Results: cem.me; dkim=none (message not signed) header.d=none;cem.me; dmarc=none action=none header.from=arbor.net;
Received: from [172.16.1.3] (88.208.89.131) by DM2PR0101MB1037.prod.exchangelabs.com (2a01:111:e400:3c19::26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Thu, 20 Jul 2017 19:51:26 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: Carl Mehner <c@cem.me>
Cc: Simon Friedberger <simon.tls@a-oben.org>, "tls@ietf.org" <tls@ietf.org>
Date: Thu, 20 Jul 2017 21:51:15 +0200
Message-ID: <A4022830-17AA-4D94-811A-F548B4008B45@arbor.net>
In-Reply-To: <CAEa9xj66Hzpw1OZRfJT_LqqMRbykrKAFaj7GBRb6a1d1VfUMzA@mail.gmail.com>
References: <CAPCANN-xgf3auqy+pFfL6VO5GpEsCCHYkROAwiB1u=8a4yj+Fg@mail.gmail.com> <CAOjisRxxN9QjCqmDpkBOsEhEc7XCpM9Hk9QSSAO65XDPNegy0w@mail.gmail.com> <CABtrr-XbJMYQ+FTQQiSw2gmDVjnpuhgJb3GTWXvLkNewwuJmUg@mail.gmail.com> <8b502340b84f48e99814ae0f16b6b3ef@usma1ex-dag1mb1.msg.corp.akamai.com> <87o9smrzxh.fsf@fifthhorseman.net> <CAAF6GDc7e4k5ze3JpS3oOWeixDnyg8CK30iBCEZj-GWzZFv_zg@mail.gmail.com> <54cdd1077ba3414bbacd6dc1fcad4327@usma1ex-dag1mb1.msg.corp.akamai.com> <CAAF6GDeSv+T1ww5_nr6NPgg9k44j7y04tJWC=KeaJF7Gtt+TVQ@mail.gmail.com> <9bd78bb6-1640-68f6-e501-7377dd92172f@cs.tcd.ie> <CAAF6GDeGKEBnUZZFXX0y0a2J2+sVg8VaHh-4H9bhN0Zzk-x9uA@mail.gmail.com> <6707e55d-63d3-01e2-4e98-5cc0644e29e0@cs.tcd.ie> <35f4c84c6505493d8035c0eaf8bf6047@usma1ex-dag1mb1.msg.corp.akamai.com> <CAAF6GDcq6_ML3yHSQTy-t5irYLS10VVzk_R+7nAUKqQpgcCkrQ@mail.gmail.com> <a22d69c80d8d4cd2981cd6ede394c96f@usma1ex-dag1mb1.msg.corp.akamai.com> <F533492A-ACF1-498F-A03C-B829DDFFDD36@arbor.net> <8d485710-d55e-28b9-3197-ad2d9880f5eb@a-oben.org> <CAEa9xj66Hzpw1OZRfJT_LqqMRbykrKAFaj7GBRb6a1d1VfUMzA@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [88.208.89.131]
X-ClientProxiedBy: AM5P189CA0018.EURP189.PROD.OUTLOOK.COM (2603:10a6:206:15::31) To DM2PR0101MB1037.prod.exchangelabs.com (2a01:111:e400:3c19::26)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 30fdde9e-4b60-4b7d-1463-08d4cfa8b5b8
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(300000503095)(300135400095)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1037;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 3:pkOB8XJmI0CqVbDXK7BKD9cI73fFMPdngnJ8AKEZh9UaepSkXQBsvmNh/VWYU7zcRYKZBiYcNI7x5kduW+WPvIOBAsGnOu+4n0tAsF/8rC0ttaM330RTZJPsMtEF1Ga+7oBo8FKnoY35fMTwoOyFUKeHC9M29CleKu4JbnJnIDq7/9pOd5C/qrJ37nz+o0rkL4MwwnUNTZBJyiMqqxYXIlD6NJh0mdp6j5cbNF/AaoNnu6RA78YoG5ELxrEWFNAutxxUIsLPw++lwmx7ZEQOXgyoh9Cm4yz+gVsZ3tfENa4APcAAzWZuweq4n8C8rISL/7g9WPYpVRpcH4VMi54q0a6m1HDiKMHQvufWWC/twgxqKAoDm+f2Y2PpnAoszvqw+IvTpA+fQCQH/PAGNxu4Alq+ZXtoaSrdVts72mFhzR3viZrjz57Ub+6DhN7lmQOJx2tlOHf4M36Fv5cPxtGAp8tfzwnCoZAJRRzK88KCNAc6k/jCSnQ2ghMObxHH1AWoMI3IjZp2XS2KSrfvLAT67f9gdZVAmlFp+GJIQVzWQKQNQmYdBAxevfRdr+DvOAZgOlEuL6FhFhJm+x5TMyG+uI8gNvTKw9DXZ4qblC0QSbYIeq1U5cecKmtNMUBA6RzlE76mXzZmONAS5IE6kgTinytkXXP1+oz1lq2cl9hYPqFt6p0JNSolEoSp5dyIX153sALO9tH+sYwXmVztlYio0PK3rVEeio6rzNZEPd0iYw0=
X-MS-TrafficTypeDiagnostic: DM2PR0101MB1037:
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 25:1JyLW4t/KB6mwuPTyuKuj8RrqGCPxicMgKiWzTaS9S1Kup86W5ZBobE1cI+2jGVPm2evkn/LheYXgq1mB05iIQA1ofmzzMOAxTG+PZIDeOIdCtDSl5uW/ySNnYqDCiC/NSQRiLanZRXHDbQGKaeERJiku1KMvbB5S0Oke8LyJuQ8iNgpARHKKSi5WOhoLtpxwi9QvlsodANmtak9RU2VPNNFcoXwcG8yOpiff4BuhI0fNXqDjbnEzdJ9nle1tSgXIiLfiXGtvIsMCuJ0jY7ht3OCSi8sht22Rs7NJioWbbvPE81fBFYrjBkGyGYqsefMLlyU7PpTSE6io/6QWsSsdMKSIfeJbBUtolB7UA/AGf4wXGKL+VygJG2kTszB94wMMmkrH2H7X5x4JTJmuGXNVaj19yRrYenvMn3Fy8RQxOC1XEKV75D9IBl1qkbMd/xObrgbskiMG6ZClxdZn4ohPwoFbB/fO7Rl2SI7EpkgnVjcVxN5+KJKNLH5IqcMVhTivz7InO9FJuxg57wA55cs+w7chBISZbahxMnnz7Uz+9h12HX3GNEqTv3OHyIRHlwDx348OVt3xfjQEiaXA4thTiGp5InCipsGCSCQ7TWVYFm2Jija6IVikpkKqqNqhHADh1/QTWXftma/hknl8IySOb5svZUMmUssjCr2hNlyW/nTmj5fVGEnjNyTNk2xeWX0uTsA3LxxXVTSMxnqLAGlaPELqztp9ZCaFgFdhhXbulFmM2KoGXM9fcC8yZv7ayW0QFpb8lU5fJYdzgUqjoyq784zCPiZJkCKpQ4g+5zzuj0/PndIdl1kDeZTaNwLzq4nNgpEQFQp03hnr8KlAOtel4XcKDHO+tyIi2IoMWD50biDh88XxRTMmLS1FyMGWSnWb8MCcWSnuFORVK2cN54OlV3z2APuOKnL4LnfO8xqK/c=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 31:lpeMXQTwKxOuG9F0CdNgc9uhQhXuHW1UeQxfT6YgN34MyDF21Ed30NiFmBLl2ncw5XTbR/S82xO0kLhKO2pf9eYJ0j5i4C/WufFovK9IuhsegrX8xxQBU8K8NV8/GJlv73YyqkQkd9PwomYT+WX87wQaOkH/zpATCQQGiHBbGHS4R7zUglxIynWx81s56sg5fUI7Nm3QgC4z+E+yEGzkH1Jv2cURKOjiCZc3HrUKpWvZEOB2FVdIqDRh+LNzwHOX58AQb+5X7NqNMHKR4BrigA++Y//WLEEXyCqP9yD8f2BYqRFkDW/T+/hxvkdXC16n1UpAyqkhA/1Z8//H51JOVriEFCUHwDBZSfrDn3pWRB4ABvRZ2IdNDwtpYlX9hMPnHgy7OrfBBKs8zkXrNnYvC0hInJL4eFr/WToLaRiZjnaZf5IH6OiaZ55MVtI77mP5YLsoG98/gxe7fb+Ou2vPxa/GqrmZOdX9DxhzDi3F3we3znoJPMBI40ymS/hYr1DWZ/Gb+z6VDSf8TNRD0UoCb+wcq16PrXMt8ssS8OniFTpz7yJn1cKAzOU4+KAnwTjFfcUULqX1NoULq5TpUBrwBaVlsqlnQFQhNjngsmjkmjRlRbospLlXhz6wQULcdaf3dMjSQIUsaykf87z+6DeUNZ4nkFbUdjPIkaFlXtZraA2hUBy3WU2ISqv3SDLPTtnDPt4l+CIoYEZMpH6OR9IyqQ==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 20:4csk+uM3u2XfL1XYxdr8L1TfwRdVNTAz53gEtxPogxTVxTa48flBm7B2R4HqCxs6i9LeeZKnyrTA2xYA770++mSBQhfo2z75S6303KFZC6QVZXr3FtYc+rDMdKrkd0cbiR0j4A3GCwys6X08xUpSnNcW5orSQw1eIcHDmc6fe4bYtT8vy4jWmPj2Lf7y4wSP3FsMBG3OxSYNcMeyhkF9Z2/Y4Pc/jT0e3AtXDOt7hVWIsfCgJtAUszg++O0spm3MmB6tGMiXQW4Qsh43olj3op063YBmez4GcyjA879AXGEZEbha06bf+lQ+vKZQimQa6FdFgn6nm4qnupkruwbtN5ZUnGuil4L6Zo5i2StG1axqpbErDC2xx+p2soSR3G4kJsR9lShe8J6vZP8n5vc8mN7hxTmU6TRB7r0ymwn92rPRJqq8Y9aQyBDyELu4PicJpZ1uMRu2g5pawJtfQifI+HID5k5WFm/lfTqpMDwYaE6/zagVNHXBGAmXjBKJAnMC
X-Exchange-Antispam-Report-Test: UriScan:(278428928389397)(236129657087228)(247924648384137);
X-Microsoft-Antispam-PRVS: <DM2PR0101MB103763A76BF4E7FDA9A8D866CAA70@DM2PR0101MB1037.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(2017060910075)(5005006)(3002001)(10201501046)(100000703101)(100105400095)(93006095)(93001095)(6041248)(20161123555025)(20161123564025)(20161123560025)(20161123558100)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1037; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1037;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 4:JyhKmQwC2lrVhtDoo1ic0vnn/Huu1nnEhhBitHKSFL2kqABygr8nxn7DBDPuvTa3GbaBW2SSSIlXkMkFhCG+Qa5i1iLNlWW5L4i/lmxv2IDC6npGbOOZ1UDulpXXEJrM8dMpURCkpJimxjbdSqnhTn2NGtaLSmY3+qNsIZN/ouo7JFYEtsEdkxuy5XIQrFszpV9w0AF70tTdrtUhSBxxxRlkhPMXnIpilqgdj7GFptoKpHH34hLAawwcczoLs1l6+khgosSNplLgoZPWvc2n8JBZ4zm49BRE95Ws6Rj5NDF/f/C1nnLGbAFkeGRXILPQ/dNgDjrZJlPwZU0bW0tgnuJvua0H0Iqwm/9yylAr6WhHWWWbuZJ0VuNlkCFjp0iO+K9WB0MtvqZgB01LHuTOnlCRIOR1Rl694lZ8hnITtBUGxbESuWhUewB3LEdyj2aaI17tWaOqDnpRHlCn6pPxsptzk6PxT7KVhxgeJN8tAgBPl9m2gSnDobm2IU0XaMgSf5gUExRlVZUY/JfBeeulcEjLGOq/fUsZhm3za03qUbMTfD6XZpHVp2IUrIF+SrNoZd8iwinTSqNh9DuZDWS4Mya4F6zk2lXD9y+D/il3Jga8YZvmTR8FwUTa4hSAP/bPKoTLHuXTP6RNOQQCz0NxLseoZmDyW/Og+LkaemPW0j4aMOJdtXqzNi0Gi3Sbi7SRPwpEiXWTzxQdHv5bWGdjaUF7WDd8w36KMeA+2Z9kwu2BiXi06UgxZqeqlILgi1C22q/D/WIXH0ADxvWZN8pSTV4NA5/6cdAXnIKtCZAKIs/T3jh45V1waPQZ8tiihFzyneSsZqxz5Rwu0isMfXjM0JfuYbVkOvi03YB4Hz9RDKR0ZzSZIkGhZDFxXSiqdP26xX6vRfLS3P25Gx/KhEoNLz6ma+R8MklY9oDAVMYK9CTaqkiaTKwUHiGydWevhBsmCTZSJd96FGfbMHW0aXqwO3gIgv0VwS5PK2AtHwQN2aGgmRQNFNvB2XrbMM9MCoq9lfyLxvIMHytDcDtpCKPdbhwURn9epADoU3QKr+k+fy6MSv2Hv4eupIMNM9m2GFogU1ZHHTcVh613pAS6c3HhaxALgHE3gr3FbuF6dirY7/T0EOzQP4LVfpe346nfR/2j9FtmBYP99Dd9eZKffWnBXTTqvjPCYT4SKNjmm8DUNe/dBh7Ywpjku1APPufB1yNiveVfqKfs2IInSAIbmHKmy4c08TjRFtVNxGZxXUDxUywASif29jzOU6UemR1Eo/Kj
X-Forefront-PRVS: 0374433C81
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(7370300001)(4630300001)(6009001)(6049001)(39850400002)(39410400002)(39400400002)(39840400002)(39450400003)(24454002)(8676002)(77096006)(229853002)(6116002)(7736002)(6486002)(305945005)(2906002)(82746002)(42186005)(53546010)(53936002)(7350300001)(3846002)(81166006)(110136004)(478600001)(83716003)(86362001)(50226002)(54906002)(6246003)(6916009)(38730400002)(5660300001)(93886004)(230783001)(33656002)(4326008)(66066001)(189998001)(76176999)(25786009)(47776003)(36756003)(6666003)(5003940100001)(50986999)(50466002)(2950100002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1037; H:[172.16.1.3]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 23:97yhBCLJxt03m/OneW2bqZq4gFMHszQQ/804j2wJDLOjGOPdm9Zl4TXE3tYFoOP7400I7NOAsalZvNJ9CktO7tQHjEiLlSpQhEasrALwwoeyg9T6ORIOW/PtqMFzi/wHfRAHIzT9MWMYGxQbvDJKpHWcN1aOB30JakvNIDZainKNGPCJxQAV7n7MTJ7whQ1WJflBw8u2LfF9MdQ2Mc2pRKPpFSoPw2JsQzOy/rS1ntV6kacVzi/tt1NSPPQsn3KvF/d78J/fLuko3zPvPwMt8WU+PXHjKSLki9ea/WGCTMCo750CYHyNrZ0RxP+rH8oRDU3TponulGCxtO4JKNLlcc9cUlrgs5rchuaX/FeV3TKWLj8yQia58wyhzLUKFDqjUsHQDJpN5sGiGHpkCif+ne4pePB8Nbo0SDKsv2Jns/FyVK5bQCiJQOzJV2laOP4CV+uZayIDWisppXGT2clN5FpX7iCDSc8trO3gEcwmwHIgp/BiNq6GiEVZ0HxTika66WNyGaeeBoCmuoMEx6xiSSrKphYgZrrSOwT8nkfaxOhwBhiQn1CKHdFZyImwgP87gvGRNEsm/obLVfw4kKlMoOo4Nuv8IoeLHQcQvbtpdCb0PsVLa51FynPwJfG8d0CI7J1OoNBEw0TdQyf2xOWTL78R4uKwwUhk35uG4JgCezUGLejmNHq1ArXQSQxiifJLQ+S63UfUIDRAnseyhYuBUhqTJg37XiTofuqzwzybJZINtNdzD76kyhD9ZWZWHOXqsR7P/gO5FE2Or9ekUt49w+35qL6HxrArHABe/dY7CxSKm3TaBVikL1v/kmwPrH44u0XhW5/k58/fT5XV2S17Hk42m8UkA18bsNKUjJlQbVNvK15yPU3KuTPq1+i1l5WjK6i09oeCatp7/GjfQIfWIH5O3it85rhteTZRIa8frTTrqUfPKohLbQOFhDOGVV0dw1SsSE2hVY/6T7u2sHjV78aGjVlbCClMjPFCmJcwvLXOQ+Jk5oJiMXXAqS2mXBwtk7FxlJP9WGvmLRWDQ2AXeAFCynzvBiER9yFjir+gJ/oqkg0ihPFY0KONev7BO78tbCCCFVzmD38EyWSmsN7AifUJhHmpnyybKTdtRlP3ActdChbktWLFzl2IXH8CqpMaGmKHTkYsELNlAEjfavxQ63ioXOE9tf09Afi9glNdEVARgZXrZ7h+ivzkUe1/ABHcGY3dGaMntNUmzzHyHu8H1ajTwRaKYl8bjzdaCnsIpLg=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 6:qOPrNUBndhqEQuAYf0vvseM4zcL8tv9fVZJvWTSAXsG8wb8yMTVuxHov5aDOelR893YeiUs2bqAc5B16b/OiWY4nSnVjlCmZuiGy1geSJnXGZvp7DgpqiwsryEsqNAr7S1SYapquxOBnAAJHs9HFJddJhca+xEBSYseYK3fIzwu1ntYQsrAC2zG8R7rVUzCiT7CnZS5A7rWewSc/7KNG1c2hndra1RTzi1VQf0N1+lJPjOFCDrzjhupXB/YjOel5zkTsikGlRwwEK4uLtwBNtdZtOIDYyeZI6iTJndaQ2mlpVr87TyYkdGr1QVyazpDNgi0mJViL/xaikvXE0BBAnDCDNz4ekC6fYzWRttYRzlfcayKdebpfPOhzh7PqyxcWk2MOCEXGF/Jpme7hGqZWL+sK0gydcsg7w3DoYC7ULc91sjOk2zuDc93XabBeFBjLej5wpFuy7i10kJCmoqADhzWLjqLuttBXVT3ZrqRTDhQNJiC/QPSC5QorLtysXdEbymqNC2NCDwvMzv9BkLGuCKBeqWSr+aaQNRZixKeh3p2z/lLaNRYdjXYUFvaLXQnsL1NTAq4+jynJV1tzcp5JZu3j43woy2XdPbdVyU2eVeMj4TUc2GZs95kh6mHYOg4nKMmfAGXKDFH4PqkCqAmZ5vLxxD5li5bq7R9PLB9XjQMmXurUrcSF8sdqj35iB8/xcPNKWdI+or5u904BqFhSfD5QDyyrs4hRfzVG+fymKi4x2DUOtU8Bw/JTUEBOD/xPtMgtcivYt18wI9c66cpxkAmNP/Bz0CH2Q7Sad29yqV003k/WXLIXkcVUrCpafZZeTlqvB/5l886RvVoXvosw2kpc7MKkL47pBr0NUdimSLLjCYm6lN+ew55cSkDo6gyGaxQ67g/CWFk8QM4JXnnp/azhkcxhasPJmxI914oOkSerKl0Q7E2eWjz6XtGM5idsHpCXVEj7f+aFx3ADWucO5YFfNGyLcwuuzJVTI2Z201o=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 5:ugxCB/hbkroCzjxlSWZSP/x3Z3uWu85m/f5WzSIp3MK0s8XqjP0xfjniQlS8DNbXNuSwv82mhLIZ81AN5k0qlxIUExuNnlPRwIX/iJ7O8lqEarcOJ7RMVJ9nP5ja+fZWLmuYFCsTQ8JkQTUNQU7a7tUB6g9ANzFqLd8kcltz1yD1FG22DgnpKDiDvY7FP/tQIT8TOVoAvcUfGzoxtYO7oMLicP1npoBQpgqIiNJiaodV86gkMocXPtARVXvuAp2Iaoq8wqjHPaJk9/WfrC0b0tWWZLB4w0B7cxIc1fj/ku/0FSzA2pHgZqcwSA6L9T7K6bpWtluXQHeo4+gB7nShzlYL3Nd2GecOfuuLLuawyGJC9gtGHZdcraptc0s37GfZLsjQ4owsbzKuprEsDlrkyEisAn/GZarYyfY585A9X66IYe6LtdivpgUloYbbF2j1WnyrdcWRH86PzJGOvon7twQ+O67IGiDI9CkqM/ayxu1BzBDVUD1I4p+chK75Z05c; 24:RvUPH6yg0ronX5wFYKhX82gTZHGWDluIkwdglyjngKGJtv3xxg9yC9DaWwEak1kKSmkLR/nAPd1vUiZ7pf0hH/IUVarwB5ffXSZd//IOuMY=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1037; 7:sq0IoLYfOzGg1W0BTh3AZ3SF3f7OkaZLc3Mk2jvNnLgjkPhrjEEP4cShEeHV81Cf5Gc8bDyXCDsuDzJ0w+6D0JHYp4REhZ8YEnm061s8m0ZdJME77XvXeRUnJ/uwLebhkI+GR8GzvWM5KKnQFodH4Xq0lxk8mnKSfSkrLEqkG40+dq3RyopzYbhBmr8IBwk4K4vToUk+jY6TQiu7wJYIzgyHAjhXdEN1h7+A1Iw75xyovPPte7PNusZ964RznAys9xmMRf3CHN1t1OEzS7mGitpCzvuYZwswEeqhKNePVRghVj1JG3on/i3rSfG4uwZgAeNsmm604DGSaa92nFcvsqDtgfDhPeyEWDCTps1AAvjLN1pSzY1rhFNSQ6rp1bpilfe2yRYjw4p00fW33oVhdZW1y/SQIvt1lS87Uns9DZSRMDEGYDSGlHmPL1HSBSYgoDxjF0u8UdfbaKe7Eqn3+AfjLKrLOOjkl0OLX49cqHwQO7DLCUReLbL6EWt5/RaqB4kQs0wAns8YT66MjvXpjDvbsdq1xaaFOgHCZisX+xnnFe0StpvIlpY4quYtW+AQDaPpgaOUMzomXQogbuhgJzrtxwFGlqDPaBcjOaKzviFvnVHV5AkWYLVJTpT3fQIC0MXkwymkIDKUr9VYNLhLjSkwDBF3Pok0BVTDULCQTUnp18GmCMy15UlBJyo1X+5qbwKtvJYpIRHx7GhfiE7FNVfM+0hTxKUyr/NAxqbwNWnZf3A22sq0nhib6UuLehQVTONRdbaKX0Ccpd1Rj91dCOkM9s2Nc+m7eQXWVAbqHT4=
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Jul 2017 19:51:26.8621 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1037
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/I4yz_mT2J-xKXNDQVUnA0sGZtKs>
Subject: Re: [TLS] draft-green-tls-static-dh-in-tls13-01
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Jul 2017 19:51:31 -0000

On 20 Jul 2017, at 21:21, Carl Mehner wrote:

> It's not an overnight change, but it is a practical one, and one that 
> could end up making these complicated applications that "need" 
> static-key-style decryption work more effectively and efficiently.

The problems of capex, opex, scale, additional complexity, and 
potentially broadening the attack surface via additional inline 
termination are also considerations - these tradeoffs may work for some 
organizations, but don't for many.

Whether or not one can obtain sufficient application/service 
instrumentation is also highly situationally-specific.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>