Re: [TLS] Fwd: Last Call: <draft-ietf-kitten-tls-channel-bindings-for-tls13-09.txt> (Channel Bindings for TLS 1.3) to Proposed Standard

Eric Rescorla <ekr@rtfm.com> Sun, 03 October 2021 19:02 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 362303A0B92 for <tls@ietfa.amsl.com>; Sun, 3 Oct 2021 12:02:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DCT4zycK3q6D for <tls@ietfa.amsl.com>; Sun, 3 Oct 2021 12:02:44 -0700 (PDT)
Received: from mail-il1-x12a.google.com (mail-il1-x12a.google.com [IPv6:2607:f8b0:4864:20::12a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E58673A0B67 for <tls@ietf.org>; Sun, 3 Oct 2021 12:02:43 -0700 (PDT)
Received: by mail-il1-x12a.google.com with SMTP id y17so7786711ilb.9 for <tls@ietf.org>; Sun, 03 Oct 2021 12:02:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20210112.gappssmtp.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=hhXErdH049O4hnyT4rgGZaeqaC1MsAVvEEHGb3iIy/8=; b=cFnNx8Lk097J7h0ZTqk9ckd61u/M8C0QQhGpgyhjIH/94neAE128AJ5nDmXWJzMiK5 3riV0jAfalc39xV80v8x3MM0Jhg6SNzfC794PgaKzgPGQRljtq2IZv3fAn90+zSRuene 0qv6894lgYpcGckHPqC5J58F1nsUtiiA671yh0FHzhJMKgd9mnp4spkMNU8mN4qMxRja xPsLRjtF9YSg3Iy41vsweynbt7KQxlXSWpnRTVOLumC7rAs6dBw1LojSKqsHXlxQj4p5 7umPqbUBXhuW3Y4SfuLnz6LCGw7mANxlooBGVacZf0yxApmkMF0rGxOgLDczP0KFQ2Ol tTcQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=hhXErdH049O4hnyT4rgGZaeqaC1MsAVvEEHGb3iIy/8=; b=rJ4LES7x4L43dY/tuAYrFqePbRCWzegXaSRRDYT6aXcUR/WFAlEjX87cWnmQDO/52u TPwSxbDUSy4aXMwzMDAQTp1ElkSEKwU0r+oL01mDnIyPbNVYqzqqF7h1mLQ+LxY6iphT +5Sob4osg5lZSu1JYIE5d/uzlt6tWJrrAMiS48lLk8eiWA5672bz67rO4CrErGslmyMc e0f0hMj2zOQZk82GdISMXqEHuwxRhC7Jy9odBTJNf+mOS03U1DuqZT2hf4PbjjRqREnl dr/JhjP1BREyYqmcg03e/41A7v/GNRZxRCkXyUouOUXVOWiqFyPuvxUgTho+ytyKxPLa OKBw==
X-Gm-Message-State: AOAM530DNnDfEo0N4W1G/F2uKEA5TeHYsI5+/HSce9G/ABKHR7SQcwKh thHQWVfpx03K8dacKMId9lfBR/Qcu3UOni1Iup5GRg==
X-Google-Smtp-Source: ABdhPJxj+80b2U1Mo2/audfrSDblQ4UaaY+68eOGFMQ4S9EWuNM88gAhjdQ4vCofF88G18WWzAWNMW1FNJj088ruxBc=
X-Received: by 2002:a05:6e02:134e:: with SMTP id k14mr7147059ilr.39.1633287763051; Sun, 03 Oct 2021 12:02:43 -0700 (PDT)
MIME-Version: 1.0
References: <163311243544.13917.11736165165419008870@ietfa.amsl.com> <20211001190002.GC98042@kduck.mit.edu> <CABcZeBPQG82xJdwMrmj4-=9aJymo1xts=D6VZedBW5X9k+34cQ@mail.gmail.com> <92ed26c1-bfde-43c1-93f4-2bbdbd4f6ec1@www.fastmail.com> <CAChr6Sw6Rs42DfS8KgD3qasPcWM_gGZhWN5C4b7W7JsPy0wDzw@mail.gmail.com> <8796f867-12b8-41f8-b124-82b3ab0e2d32@www.fastmail.com> <CAChr6SyKAnBcE9t68coGGXFt9WPLuDuWtVKoCXrK+QrwAVtPXw@mail.gmail.com> <f1bcd676-13ad-49b3-a8e8-8a272e0124e3@www.fastmail.com> <CABcZeBNo0gKjNZOKPYJYraioaw6G=z5ibTqh-o9GkWsDkfDmSQ@mail.gmail.com> <c4d6f2e5-0712-42a6-aef5-0cbada7e149e@www.fastmail.com>
In-Reply-To: <c4d6f2e5-0712-42a6-aef5-0cbada7e149e@www.fastmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Sun, 03 Oct 2021 12:02:07 -0700
Message-ID: <CABcZeBM6y-6ZqaLGZ=8qr+uBnWOOgczhcx=ruy5S=n-YrHweKg@mail.gmail.com>
To: Sam Whited <sam@samwhited.com>
Cc: Rob Sayre <sayrer@gmail.com>, "<tls@ietf.org>" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000eee4eb05cd7770dc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/K6-jmEas1ny9j4xv0c1L7WZSfnU>
Subject: Re: [TLS] Fwd: Last Call: <draft-ietf-kitten-tls-channel-bindings-for-tls13-09.txt> (Channel Bindings for TLS 1.3) to Proposed Standard
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 03 Oct 2021 19:02:59 -0000

Sorry to be difficult, but as I said, I'd prefer to focus not on the
question of the header of this document but rather on what we wish 8446
said. To that end, what text do you think should go in 8446-bis?

-Ekr


On Sat, Oct 2, 2021 at 6:29 PM Sam Whited <sam@samwhited.com> wrote:

> Even if linking this in updates implied confidence (though I don't think
> it does), TLS alread implies confidence in its own EKM mechanism. I
> don't believe this document expands on that. For example, it does not
> detail any particular use of channel binding.
>
> —Sam
>
>
> On Sat, Oct 2, 2021, at 13:12, Eric Rescorla wrote:
> > I want to be clear that I don't think this is about credit. My concern
> > is purely about accurately reflecting the level of confidence one
> > should have in this mechanism.
>