[TLS] Re: 【Reply to the comments after the presentation in Montreal】RE: Re: FW: New Version Notification for draft-wang-tls-service-affinity-00.txt
Aijun Wang <wangaijun@tsinghua.org.cn> Fri, 30 January 2026 08:52 UTC
Return-Path: <wangaijun@tsinghua.org.cn>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 62262AF58DF9; Fri, 30 Jan 2026 00:52:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R8Gs3lbQCi_S; Fri, 30 Jan 2026 00:51:58 -0800 (PST)
Received: from mail-m49198.qiye.163.com (mail-m49198.qiye.163.com [45.254.49.198]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 28168AF58D39; Fri, 30 Jan 2026 00:51:54 -0800 (PST)
Received: from LAPTOP09T7970K (unknown [219.142.69.76]) by smtp.qiye.163.com (Hmail) with ESMTP id 328bd746c; Fri, 30 Jan 2026 16:50:20 +0800 (GMT+08:00)
From: Aijun Wang <wangaijun@tsinghua.org.cn>
To: 'Muhammad Usama Sardar' <muhammad_usama.sardar@tu-dresden.de>
References: <000001dc7615$cf415b70$6dc41250$@tsinghua.org.cn> <CABcZeBM=59id8msEU2i=qQXiwNKZnHTBAJ85zmEKD8USQF5z_w@mail.gmail.com> <004e01dc7974$957ebab0$c07c3010$@tsinghua.org.cn> <CABcZeBPgw0Fsz0QyD6T2Q8CoZcWbXQS_ptoTqNfbBGydawdVRw@mail.gmail.com> <d16caff7-4160-4eed-8c1a-5011fab57156@tu-dresden.de>
In-Reply-To: <d16caff7-4160-4eed-8c1a-5011fab57156@tu-dresden.de>
Date: Fri, 30 Jan 2026 16:50:19 +0800
Message-ID: <000f01dc91c5$76fd7860$64f86920$@tsinghua.org.cn>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0010_01DC9208.852154A0"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQI7N+UrCa4wrDE8olUN5ROrNp4g5AJ9CNDCAQXilJYCcnx2BQIpYYVTtGwiZ9A=
Content-Language: zh-cn
X-HM-Tid: 0a9c0e189eb003a2kunm9f7fb68e120ada
X-HM-MType: 10
X-HM-Spam-Status: e1kfGhgUHx5ZQUpXWQgPGg8OCBgUHx5ZQUlOS1dZFg8aDwILHllBWSg2Ly tZV1koWUFKTEtLSjdXWS1ZQUlXWQ8JGhUIEh9ZQVlCTU4eVh9OQhpITxkZTRhCSlYeHw5VEwETFh oSFyQUDg9ZV1kYEgtZQVlJSkJVSk9JVU1CVUxNWVdZFhoPEhUdFFlBWU9LSFVKS0lPT09IVUpLS1 VKQktLWQY+
Message-ID-Hash: 5R4ZATJEN6MGJ4U357UQIYKVYVJBWWGO
X-Message-ID-Hash: 5R4ZATJEN6MGJ4U357UQIYKVYVJBWWGO
X-MailFrom: wangaijun@tsinghua.org.cn
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org, draft-wang-tls-service-affinity@ietf.org, 'Mohit Sahni' <msahni@paloaltonetworks.com>, 'Aijun Wang' <wangaj3@chinatelecom.cn>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: 【Reply to the comments after the presentation in Montreal】RE: Re: FW: New Version Notification for draft-wang-tls-service-affinity-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Jj7PlUpDKFFEqX2xJ6gDuJ8tNeQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Hi, Usama: Thanks for your endorsement to implement it at TLS layer. As your suggestion, if TLS 1.3 has no explicit session identifier, we can utilize the implicit one, for example, PSK, as the identification of the corresponding session. The idea of this draft is actually very straightforward: 1) Notify the client securely another address 2) Start one new TLS session which can utilize the PSK of the previous session(then skip the negotiation process for the new session). 3) Keep the application unnoticed, or application agnostic. Best Regards Aijun Wang China Telecom From: forwardingalgorithm@ietf.org [mailto:forwardingalgorithm@ietf.org] On Behalf Of Muhammad Usama Sardar Sent: Wednesday, January 28, 2026 8:21 PM To: Aijun Wang <wangaijun@tsinghua.org.cn> Cc: tls@ietf.org; draft-wang-tls-service-affinity@ietf.org; Mohit Sahni <msahni@paloaltonetworks.com>; Aijun Wang <wangaj3@chinatelecom.cn> Subject: [TLS] Re: 【Reply to the comments after the presentation in Montreal】RE: Re: FW: New Version Notification for draft-wang-tls-service-affinity-00.txt [ Looping back to the point where the question was raised ] I did some preliminary working for you. It is purely at TLS layer, i.e., I don't consider higher layers like HTTP. It may provide you a way forward for this particular question. On 30.12.25 15:40, Eric Rescorla wrote: On Tue, Dec 30, 2025 at 2:10 AM Aijun Wang <wangaijun@tsinghua.org.cn <mailto:wangaijun@tsinghua.org.cn> > wrote: If there is data arrival during the switchover, the internal implementation logic is the application layer will call the api of TLS/TCP to send some data, with the same session identifier. I don't know what you mean by "The same session identifier". There is no concept in TLS that two different TCP connections are somehow the same conceptual flow of data. PSK identifiers solely identify keys. Session identifier is a common confusion that arises from TLS 1.2. In contrast, TLS 1.3 has no session identifiers. It instead has the concept of connection and the identifiers of TLS 1.3 connection are just implicit. Depending on specific scenario, the following three keys may uniquely identify a TLS 1.3 connection: 1. Shared DH secret (g^xy) 2. Handshake secret: In addition to #1, it has randomness from PSK, if one is being used (and your draft seems to be using PSK). 3. Main secret: Secrets derived from this secret have server authentication, as the handshake transcript up to server Finished is included. So depending on your specific scenario, you could replace session_id in MigrationToken by one of those. Having said that, you have to defend yourself why for your scenario, you want to do it within TLS handshake, because the draft is very confusing to me -- in terms of its threat model, desired security goals and protocol (mixing TLS 1.2 and TLS 1.3). -Usama
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Martin Thomson
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Peter Gutmann
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] 【Reply to the comments after the presentati… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Eric Rescorla
- [TLS] Re: 【Reply to the comments after the presen… Christian Huitema
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Peter Gutmann
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Aijun Wang
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Re: 【Reply to the comments after the presen… Wei Wang
- [TLS] Re: 【Reply to the comments after the presen… Muhammad Usama Sardar
- [TLS] Comments on draft-wang-tls-service-affinity… Muhammad Usama Sardar
- [TLS] Re: Comments on draft-wang-tls-service-affi… Wei Wang
- [TLS] Re: Comments on draft-wang-tls-service-affi… Muhammad Usama Sardar