[TLS] Transcript-Hash during Handshake

"Le Van Gong, Hubert" <hubert@levangong.org> Wed, 22 November 2017 03:38 UTC

Return-Path: <hubert@levangong.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF0EE1205F0 for <tls@ietfa.amsl.com>; Tue, 21 Nov 2017 19:38:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.121
X-Spam-Level:
X-Spam-Status: No, score=-1.121 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_NEUTRAL=0.779] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=levangong-org.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tVhjT8wtQ6SG for <tls@ietfa.amsl.com>; Tue, 21 Nov 2017 19:38:18 -0800 (PST)
Received: from mail-pl0-x234.google.com (mail-pl0-x234.google.com [IPv6:2607:f8b0:400e:c01::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6E96124BE8 for <tls@ietf.org>; Tue, 21 Nov 2017 19:38:18 -0800 (PST)
Received: by mail-pl0-x234.google.com with SMTP id v15so93715plk.11 for <tls@ietf.org>; Tue, 21 Nov 2017 19:38:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=levangong-org.20150623.gappssmtp.com; s=20150623; h=to:from:subject:message-id:date:user-agent:mime-version :content-transfer-encoding:content-language; bh=+vx7UKZjIz/ot74xCbd2V8mJNkyYnhIuPdTzGp4+oHY=; b=OVxMhodehmlHKEJaQss1npN1hHd1RztRuT1vg8n/NQWCAKBHWxuMQ4l759T7ejWEOn arnPwmQ1Nodg5GNBfLMsNzTPCSzsZ4q30FlbHdKrmp+9Pl6TzbNdLQbmDwx9zC04iNuO W6FFELidGRe29cTlez7wKWk76zBuwn0pMNKn0iHZMcIz0zVaK1YHkS+XmSvjzW00yZ9G gniU3VpQWHGbUL40MPtoXAvNEqvCrZJHNFW8WTiR4WtZsX+rdiVS3KoDIaKm2WBaXkrG RZf/Epv1iEOtCY+SLDAWk6CuFlR4LjQCukJ6dQx/U5G9mEMzL9ifHmyBAAYQPEzvH9Kw wjKg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:message-id:date:user-agent :mime-version:content-transfer-encoding:content-language; bh=+vx7UKZjIz/ot74xCbd2V8mJNkyYnhIuPdTzGp4+oHY=; b=hmtV0t9jOT0WzcoIdudXTi8eXNqKVwa+1aRUME2ZKqeIrQYXARJ3sarjego2/w1Hck UQL7arc7CHXKpkdILZIa6X4kHmD/6twr4dCiY30gdhwkV3Kym3QGhKtP83Ui7FP0Cv9E 6J0s18rIbF01w/ipaFnIO4bPUXXD25nY9xE0mlpG5JpK6ducIkH6cl/94pHvkWfhNdB2 DgxS3rpx62ARbFdA+43A2bTWe9NG6TTMRceJgZt2dF8EtXwkrOY5zYEc0jyIcIZmQA3L uWVPAfS3DnkFIMGmwA/K47sl0EEqnBhD+R+UTTXvESeBWGQwBd0nG0Am1q9zHI4lD9f4 bi+w==
X-Gm-Message-State: AJaThX6EuA5ZgE3flhmFRrqbyBvGhKz+Case9FJXXIPzGLhjR4JvRizG fm7sQoxwUeLEuxqAup4Q0m3akvy0
X-Google-Smtp-Source: AGs4zMZfujtHXr8p5XfnHtHQdWnj2K9QuzoXsyzj1/61YH0/jWkjAdkyqWWFini/Nbylnwqi2OQ1Cw==
X-Received: by 10.84.129.36 with SMTP id 33mr20295900plb.303.1511321898376; Tue, 21 Nov 2017 19:38:18 -0800 (PST)
Received: from [10.231.102.52] ([173.224.161.129]) by smtp.gmail.com with ESMTPSA id z2sm21473856pfh.39.2017.11.21.19.38.17 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Nov 2017 19:38:17 -0800 (PST)
To: tls@ietf.org
From: "Le Van Gong, Hubert" <hubert@levangong.org>
Message-ID: <94ced158-63b1-e7a3-024c-44d1149e7202@levangong.org>
Date: Tue, 21 Nov 2017 19:38:16 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/IdYeF3U_BdiuiM_5HPEvi36G7LY>
Subject: [TLS] Transcript-Hash during Handshake
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Nov 2017 03:38:20 -0000

Greetings,

Probably a trivial question but is the transcript hash (during 
handhsake) calculated over decrypted versions of messages like 
EncryptedExtensions or certificate or is it done over the raw/encrypted 
messages?
I could not find an exact confirmation in the spec.


Cheers,
Hubert