[TLS] Feedback on draft-bmw-tls-pake13-01.txt

Laura Bauman <l_bauman@apple.com> Sun, 16 March 2025 02:21 UTC

Return-Path: <l_bauman@apple.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 38F0CBD66D1 for <tls@mail2.ietf.org>; Sat, 15 Mar 2025 19:21:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.837
X-Spam-Level:
X-Spam-Status: No, score=-1.837 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTML_OBFUSCATE_05_10=0.26, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z2OSuTxyGxqT for <tls@mail2.ietf.org>; Sat, 15 Mar 2025 19:21:22 -0700 (PDT)
Received: from rn-mx02.apple.com (rn-mx02.apple.com [17.132.108.1]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5E29EBD66C8 for <tls@ietf.org>; Sat, 15 Mar 2025 19:21:22 -0700 (PDT)
Received: from ma-mailsvcp-mta-lapp04.corp.apple.com (ma-mailsvcp-mta-lapp04.corp.apple.com [10.226.18.136]) by mr55p01nt-mxp02.apple.com (Oracle Communications Messaging Server 8.1.0.27.20250130 64bit (built Jan 30 2025)) with ESMTPS id <0ST70PMC72JKXV00@mr55p01nt-mxp02.apple.com> for tls@ietf.org; Sun, 16 Mar 2025 02:21:21 +0000 (GMT)
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1093,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-03-16_01,2025-03-14_01,2024-11-22_01
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apple.com; h=content-type : date : from : message-id : mime-version : subject : to; s=20180706; bh=SiX5yCJkwRApGSq2Ypdkq76TYF0yVQaWbO4xdDReqgc=; b=sTBb4vGpn5cbY21qrFj4L23Ked3KE/H6BEwuh1t/xYzGtzvXJeRnRXL45lYhphdIPgtI A4VzzMV4oFz4UXR+zsu+ZzJq7gu/vR1h1oF2ohUlJojJzf7gt7kvyRZ7l2BvxIsYxMly KnUXJHcaCJzni16Wtpw41pL0q/7+1goTEgx1vZscb11nSY/JiWZuwQeizeKAakdthD6z dkML18DDHkThqK9TZdhm9PYd6MX2FJCF4LuawVq4e/V2xvmhUY7ayb2jtfBxtOhicIFq WUpC1uEhQGHSOB0qnMu1rL+CaoayYtfHCtlczESo+fLxicamO9vdIjTpcbssnLp4PUtf cQ==
Received: from st47p01nt-mmpp06.apple.com (st47p01nt-mmpp06.apple.com [10.170.123.80]) by ma-mailsvcp-mta-lapp04.corp.apple.com (Oracle Communications Messaging Server 8.1.0.27.20250130 64bit (built Jan 30 2025)) with ESMTPS id <0ST700CCY2JK9Q10@ma-mailsvcp-mta-lapp04.corp.apple.com> for tls@ietf.org; Sat, 15 Mar 2025 19:21:20 -0700 (PDT)
Received: from process_milters-daemon.st47p01nt-mmpp06.apple.com by st47p01nt-mmpp06.apple.com (Oracle Communications Messaging Server 8.1.0.27.20250130 64bit (built Jan 30 2025)) id <0ST72ES0026XJ600@st47p01nt-mmpp06.apple.com> for tls@ietf.org; Sun, 16 Mar 2025 02:21:20 +0000 (GMT)
X-Va-A:
X-Va-T-CD: 69f1e59f2adbdec55bfbab028fbe6668
X-Va-E-CD: d67a90af552989ef7f4fe31ec96ea33a
X-Va-R-CD: 025b32dff227ff934be0058dc8a8026b
X-Va-ID: ff7dce96-bff1-49b9-8da3-773bc56e1e94
X-Va-CD: 0
X-V-A:
X-V-T-CD: 69f1e59f2adbdec55bfbab028fbe6668
X-V-E-CD: d67a90af552989ef7f4fe31ec96ea33a
X-V-R-CD: 025b32dff227ff934be0058dc8a8026b
X-V-ID: 9c7e63a8-d3dc-459a-b08b-04540de36fc2
X-V-CD: 0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1093,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-03-16_01,2025-03-14_01,2024-11-22_01
Received: from smtpclient.apple (unknown [17.234.201.87]) by st47p01nt-mmpp06.apple.com (Oracle Communications Messaging Server 8.1.0.27.20250130 64bit (built Jan 30 2025)) with ESMTPSA id <0ST72ET092JFJX00@st47p01nt-mmpp06.apple.com> for tls@ietf.org; Sun, 16 Mar 2025 02:21:19 +0000 (GMT)
From: Laura Bauman <l_bauman@apple.com>
Content-type: multipart/alternative; boundary="Apple-Mail=_0CCB7875-81CA-43AB-B4E2-6CE7FC3C7EE0"
MIME-version: 1.0 (Mac OS X Mail 16.0 \(3826.300.87.4.3\))
Message-id: <05B28816-9AA9-4035-B451-8ACFFBE2D4DE@apple.com>
Date: Sun, 16 Mar 2025 09:21:02 +0700
To: tls@ietf.org
X-Mailer: Apple Mail (2.3826.300.87.4.3)
Message-ID-Hash: LCWDQOVE3EGVCMKEAVBYJCSUWQN2VKMP
X-Message-ID-Hash: LCWDQOVE3EGVCMKEAVBYJCSUWQN2VKMP
X-MailFrom: l_bauman@apple.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Feedback on draft-bmw-tls-pake13-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Kx4fPRJMyYNzcNaGcBjINTZCN20>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Thanks to everyone that has taken a look at draft-bmw-tls-pake13-01.txt and provided feedback so far. As more people start reading it, I wanted to clarify that the current draft version does not yet reflect the change we intend to make to allow Certificates and the pake extension to be used together. We’ve filed a GitHub issue here tracking our intent to change this: https://github.com/chris-wood/draft-bmw-tls-pake13/issues/25.

Thanks,

Laura Bauman
l_bauman@apple.com