Re: [TLS] Nuking DHE in favour of ECDHE (Was: Re: Confirming Consensus on removing RSA key Transport from TLS 1.3)

Andrei Popov <Andrei.Popov@microsoft.com> Mon, 31 March 2014 17:15 UTC

Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA5B81A6F44 for <tls@ietfa.amsl.com>; Mon, 31 Mar 2014 10:15:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.602
X-Spam-Level:
X-Spam-Status: No, score=-2.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yXoabPpHewaL for <tls@ietfa.amsl.com>; Mon, 31 Mar 2014 10:15:29 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2lp0240.outbound.protection.outlook.com [207.46.163.240]) by ietfa.amsl.com (Postfix) with ESMTP id 344DD1A6F56 for <tls@ietf.org>; Mon, 31 Mar 2014 10:15:21 -0700 (PDT)
Received: from BL2PR03MB419.namprd03.prod.outlook.com (10.141.92.18) by BL2PR03MB417.namprd03.prod.outlook.com (10.141.92.12) with Microsoft SMTP Server (TLS) id 15.0.908.10; Mon, 31 Mar 2014 17:15:16 +0000
Received: from BL2PR03MB419.namprd03.prod.outlook.com ([10.141.92.18]) by BL2PR03MB419.namprd03.prod.outlook.com ([10.141.92.18]) with mapi id 15.00.0908.008; Mon, 31 Mar 2014 17:15:16 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>, "<tls@ietf.org>" <tls@ietf.org>
Thread-Topic: [TLS] Nuking DHE in favour of ECDHE (Was: Re: Confirming Consensus on removing RSA key Transport from TLS 1.3)
Thread-Index: Ac9LG4WcQ7PNLxYPxkG9wW1NfjsVjwB58WTQ
Date: Mon, 31 Mar 2014 17:15:15 +0000
Message-ID: <9d9167782e4b4dc0af862d9e0bde68e3@BL2PR03MB419.namprd03.prod.outlook.com>
References: <9A043F3CF02CD34C8E74AC1594475C737239546F@uxcn10-6.UoA.auckland.ac.nz>
In-Reply-To: <9A043F3CF02CD34C8E74AC1594475C737239546F@uxcn10-6.UoA.auckland.ac.nz>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [2001:4898:80e0:ee43::2]
x-forefront-prvs: 0167DB5752
x-forefront-antispam-report: SFV:NSPM; SFS:(10009001)(6009001)(428001)(199002)(189002)(377454003)(13464003)(69226001)(83322001)(94316002)(19580405001)(81342001)(54316002)(81542001)(74502001)(19580395003)(95416001)(80976001)(95666003)(31966008)(86612001)(74366001)(74662001)(94946001)(74876001)(97336001)(63696002)(47736001)(47976001)(49866001)(4396001)(97186001)(85306002)(20776003)(54356001)(81686001)(76482001)(98676001)(87266001)(74706001)(79102001)(2656002)(15975445006)(83072002)(33646001)(93136001)(90146001)(85852003)(76576001)(59766001)(76796001)(92566001)(86362001)(77982001)(56776001)(56816005)(53806001)(50986001)(81816001)(51856001)(87936001)(93516002)(65816001)(46102001)(99286001)(80022001)(3826001)(24736002)(491001); DIR:OUT; SFP:1101; SCL:1; SRVR:BL2PR03MB417; H:BL2PR03MB419.namprd03.prod.outlook.com; FPR:F8F2D1F0.2D2F9532.FEDA779C.C003DEC9.201DB; MLV:sfv; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (: microsoft.com does not designate permitted sender hosts)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/JHtxDJHzakdCl1j0m4Mlpz0cOyo
Subject: Re: [TLS] Nuking DHE in favour of ECDHE (Was: Re: Confirming Consensus on removing RSA key Transport from TLS 1.3)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Mar 2014 17:15:32 -0000

Sorry, can't comment on features/functionality to be delivered in the future, but I would not rule out the possibility of adding pre-1.2 DHE_RSA cipher suites.

Cheers,

Andrei

-----Original Message-----
From: TLS [mailto:tls-bounces@ietf.org] On Behalf Of Peter Gutmann
Sent: Friday, March 28, 2014 11:53 PM
To: <tls@ietf.org>
Subject: Re: [TLS] Nuking DHE in favour of ECDHE (Was: Re: Confirming Consensus on removing RSA key Transport from TLS 1.3)

Andrei Popov <Andrei.Popov@microsoft.com> writes:

>"Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 update spring 2014"
>adds a couple of DHE_RSA cipher suites: 
>TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
>TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

Those are all 1.2 suites with its barely-there deployment, what about adding
pre-1.2 suites as well for the 99.whatever% market penetration the earlier versions have?

Peter.
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls