Re: [TLS] [Last-Call] Last Call: <draft-ietf-tls-oldversions-deprecate-09.txt> (Deprecating TLSv1.0 and TLSv1.1) to Best Current Practice

Peter Gutmann <> Wed, 02 December 2020 10:44 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 4899D3A0E85 for <>; Wed, 2 Dec 2020 02:44:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.917
X-Spam-Status: No, score=-1.917 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id r9tKOlZemQ7n for <>; Wed, 2 Dec 2020 02:44:31 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id E4B173A12B1 for <>; Wed, 2 Dec 2020 02:44:30 -0800 (PST)
Received: from ( []) (Using TLS) by with ESMTP id au-mta-25-FFsdkNoEMkmeg73U-7dL-w-1; Wed, 02 Dec 2020 21:44:25 +1100
X-MC-Unique: FFsdkNoEMkmeg73U-7dL-w-1
Received: from (2603:1096:202:2::24) by (2603:10c6:10:10::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3611.25; Wed, 2 Dec 2020 10:44:22 +0000
Received: from (2603:1096:202:2:cafe::53) by (2603:1096:202:2::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3632.17 via Frontend Transport; Wed, 2 Dec 2020 10:44:21 +0000
X-MS-Exchange-Authentication-Results: spf=none (sender IP is;; dkim=none (message not signed) header.d=none;; dmarc=none action=none
Received: from ( by ( with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.3632.17 via Frontend Transport; Wed, 2 Dec 2020 10:44:20 +0000
Received: from ( by ( with Microsoft SMTP Server (TLS) id 15.0.1497.2; Wed, 2 Dec 2020 23:44:19 +1300
Received: from ([]) by ([]) with mapi id 15.00.1497.007; Wed, 2 Dec 2020 23:44:19 +1300
From: Peter Gutmann <>
To: "STARK, BARBARA H" <>, 'Eliot Lear' <>
CC: "''" <>, "''" <>, "''" <>, "''" <>
Thread-Topic: [Last-Call] [TLS] Last Call: <draft-ietf-tls-oldversions-deprecate-09.txt> (Deprecating TLSv1.0 and TLSv1.1) to Best Current Practice
Thread-Index: AQHWtuemkBcnxjhwjkukZnBJ0gfqXKnb932AgAD1RoCABJdrIf//K3OAgAFq8mb//4R+AIAACK+AgAIab1c=
Date: Wed, 2 Dec 2020 10:44:19 +0000
Message-ID: <>
References: <> <> <> <> <> <> <>, <>
In-Reply-To: <>
Accept-Language: en-NZ, en-GB, en-US
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: []
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 5c4fad2c-e05a-48e0-2f00-08d896af3a34
X-MS-TrafficTypeDiagnostic: SYBPR01MB5113:
X-Microsoft-Antispam-PRVS: <>
X-MS-Oob-TLC-OOBClassifiers: OLM:8882
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0
X-Microsoft-Antispam-Message-Info: mJYO85F5mr9Qr/EQMwBl3HdJ/D32SLf0ORQyTLKGPSfSwUj9R5kSIEwDL33AMloqhNtFYPJiYo5fr3Kt4lkiI18APGLIn9XWhqxt0RJBvcvQfscbnvK5D93ygA9sLaijCNY8T+inEL6MtU/0XMGh1riXcMfGflO2L4SSYMN9E5J/+Wj6coXryNrH0ne8Rb5EXjovRtShd9HILhegW7zXcoMsQXu+MZ/0HZqyxOE22/yrshyee0OjDQe7qreIsGsTokk1oh+Agc5mNR6KLjhp24rG60YiEk13IVZQZMZn4m+VHq2M1A+YqMSvt0AseQd63xSMB69uBROpxDmWnpqU+VfLmTbSwuCjrAj1IVm51TNeGPOa0deSx8ZlG1kVi2Lk4RiO3vd3Qp0jsRGzDZie0g==
X-Forefront-Antispam-Report: CIP:; CTRY:NZ; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM;;; CAT:NONE; SFS:(4636009)(136003)(39860400002)(396003)(346002)(376002)(46966005)(7636003)(36906005)(356005)(2906002)(82310400003)(70206006)(8676002)(110136005)(70586007)(4744005)(26005)(54906003)(186003)(86362001)(316002)(47076004)(4326008)(83380400001)(82740400003)(786003)(478600001)(2616005)(5660300002)(8936002)(336012); DIR:OUT; SFP:1101
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Dec 2020 10:44:20.9518 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 5c4fad2c-e05a-48e0-2f00-08d896af3a34
X-MS-Exchange-CrossTenant-Id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=d1b36e95-0d50-42e9-958f-b63fa906beaa; Ip=[]; Helo=[]
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYBPR01MB5113
Authentication-Results:; auth=pass smtp.auth=CAU17A13
X-Mimecast-Spam-Score: 0
Content-Language: en-NZ
Content-Type: text/plain; charset=WINDOWS-1252
Content-Transfer-Encoding: quoted-printable
Archived-At: <>
Subject: Re: [TLS] [Last-Call] Last Call: <draft-ietf-tls-oldversions-deprecate-09.txt> (Deprecating TLSv1.0 and TLSv1.1) to Best Current Practice
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 02 Dec 2020 10:44:33 -0000

STARK, BARBARA H <> writes:

>If someone feels a strong need to ignore this in their own network, they will
>have no difficulty doing so (and have no difficulty justifying it to
>themselves and others inside their org).

It's actually the complete opposite, they will have every difficulty in doing
so.  You've got systems engineers whose job it is to keep things running at
all costs, or where the effort to replace/upgrade is almost insurmountable,
who now have to deal with pronouncements from standards groups that insist
they not keep things running.  I don't know where you get this idea that this
will cause "no difficulty" from, it's a source of endless difficulty and
frustration due to the clash between "we can't replace or upgrade these
systems at the moment" and "there's some document that's just popped up 
that says we need to take them out of production and replace them".