Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00

Hubert Kario <hkario@redhat.com> Thu, 16 October 2014 10:26 UTC

Return-Path: <hkario@redhat.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A9461ACF70 for <tls@ietfa.amsl.com>; Thu, 16 Oct 2014 03:26:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.012
X-Spam-Level:
X-Spam-Status: No, score=-0.012 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MANGLED_BACK=2.3, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GVjoCnN2qphc for <tls@ietfa.amsl.com>; Thu, 16 Oct 2014 03:26:53 -0700 (PDT)
Received: from mx5-phx2.redhat.com (mx5-phx2.redhat.com [209.132.183.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3AD541ACF6D for <tls@ietf.org>; Thu, 16 Oct 2014 03:26:53 -0700 (PDT)
Received: from zmail11.collab.prod.int.phx2.redhat.com (zmail11.collab.prod.int.phx2.redhat.com [10.5.83.13]) by mx5-phx2.redhat.com (8.14.4/8.14.4) with ESMTP id s9GAQnxh018340; Thu, 16 Oct 2014 06:26:49 -0400
Date: Thu, 16 Oct 2014 06:26:48 -0400
From: Hubert Kario <hkario@redhat.com>
To: Hanno Böck <hanno@hboeck.de>
Message-ID: <257636459.12399546.1413455208860.JavaMail.zimbra@redhat.com>
In-Reply-To: <20141015140158.41a1faf8@pc.my-domain>
References: <2112FCAD-4820-49D9-9871-6501C83A554D@cisco.com> <543E2D81.1050700@redhat.com> <7F8CB03B-6882-41E7-9705-7126A8F2F44D@gmail.com> <CADMpkcJLrQEtiUGi9B7ZS5402cXTBvvThL9-YwUUhncaXQaVsA@mail.gmail.com> <20141015140158.41a1faf8@pc.my-domain>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Originating-IP: [10.5.82.7]
X-Mailer: Zimbra 8.0.6_GA_5922 (ZimbraWebClient - FF32 (Linux)/8.0.6_GA_5922)
Thread-Topic: Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
Thread-Index: 9+dKQv7djuLB7N2jDqdxcqQ3t0Ms7A==
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/IEmfwT3u_Dei1IX4JhDap6degFI
Cc: tls@ietf.org
Subject: Re: [TLS] Working Group Last Call for draft-ietf-tls-downgrade-scsv-00
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Oct 2014 10:26:54 -0000

----- Original Message -----
> From: "Hanno Böck" <hanno@hboeck.de>
> To: tls@ietf.org
> Sent: Wednesday, 15 October, 2014 2:01:58 PM
> Subject: Re: [TLS] Working Group Last Call for	draft-ietf-tls-downgrade-scsv-00
> 
> Am Wed, 15 Oct 2014 11:22:51 +0200
> schrieb Bodo Moeller <bmoeller@acm.org>:
> 
> > Note that if your server does not support formally obsolete protocol
> > versions, TLS_FALLBACK_SCSV support is a no-op.
> > 
> > Otherwise, you're making real-world tradeoffs, and I think
> > TLS_FALLBACK_SCSV is a reasonable one to make (with minimal
> > server-side logic to achieve the objective), not "punishment".
> 
> Can you quantify that tradeoff? How many devices are there really out
> there that would break? I'd like to have this discussions with
> hard numbers.

I don't have hard numbers for that (I'm +1 this request), but
looking forward, I see many servers that are TLS 1.3 intolerant while
randomly scanning servers using the ssllabs.com scanner.

So it's not only about servers that are TLS1.2 Client Hello intolerant
(they should be mostly eradicated from the public Internet by now)
but also possible future issues.

-- 
Regards,
Hubert Kario