Re: [TLS] TLS Flags and IANA registration policy

Eric Rescorla <ekr@rtfm.com> Fri, 29 October 2021 23:19 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB8243A19D8 for <tls@ietfa.amsl.com>; Fri, 29 Oct 2021 16:19:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lWbiTJcKxn77 for <tls@ietfa.amsl.com>; Fri, 29 Oct 2021 16:19:46 -0700 (PDT)
Received: from mail-io1-xd2b.google.com (mail-io1-xd2b.google.com [IPv6:2607:f8b0:4864:20::d2b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4A6823A19D7 for <tls@ietf.org>; Fri, 29 Oct 2021 16:19:46 -0700 (PDT)
Received: by mail-io1-xd2b.google.com with SMTP id e144so14442062iof.3 for <tls@ietf.org>; Fri, 29 Oct 2021 16:19:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20210112.gappssmtp.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=YHaryCyLTMTMVGyo53K3UR1SYYCAOngdOnSGn84V7aM=; b=zrHzgWqNO3miT3b75svDhjBYYvPEHF5fF7WPsFWSoZ0h/RoKTtzXyO9zwMicWqqDsw 4ecCx3iKTPB6394xIZ26FXBi1KWeycSE10aRyv9fpbBbbiJ5y760uDh26EDge3L8sj0r TcWnvxWCcZgQjGwqrFXl6Bl3YsWaTcGNnc3VK/Yhev6K1XWNR1vtF+NqiWo7yJ0x/UQJ PpGUIHaI6GcXSn+Bg9KhMoyMMcPbZc8WiEabfT9weNKK/63NzAfN6rpnHpp+wtsuzK3V CaQhTetpnB+YehCjSaRswrE2z3mCiouIw5uJXkYwofwLy2HvLAoFaRCN376nyOzNdi55 xNOg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=YHaryCyLTMTMVGyo53K3UR1SYYCAOngdOnSGn84V7aM=; b=15U+x0hIDu8eRcI/e29w8/n2ogHK8eWJPFE5cepmvz9NZd0swyyNCkYPyDP9MsZfrT nQ14uwD5dW7AZNPTHqSpLmb1dE13rMB8JScSjVp3pDTVij+dzs95EGP7G/jcP8ldT0wh cmhkDWuS1Y2HmsNdT8ILW0C+H9SEjapiL2I5SJ2jG0jZO3YZtb3ZrkF2ORuW5xInRJTM eYLhlkks08hm3IHq8KXdxRiOfbfGRj1jtf3BhhtGIIsmHalR3AwrZ/MzgFp8PqHm5UDu wkQIsQsAMfSQD1VLII9ITrU9yBQ7o/xwBkPGgfQFJMLGuTUigfOdet/l1hGfGzJfjuIf 4QAA==
X-Gm-Message-State: AOAM532LeG9Z4Nz2N2i01qvQt9pV+FpE5t20/VbMf/8z7IMkliAxnLkp JSupPc5cz6X3yrEFB2Tkt7k5MEKiruRwDI9LzPJutTrH2AU=
X-Google-Smtp-Source: ABdhPJxpeja367izzgL2ZpXNOBfj6g2Sq7XxwQrBGHDD/6oKxrgB46R6fg7QEb0Dtu/LnhfXEz3Hq6CO5kHGnj5AJqk=
X-Received: by 2002:a6b:b2cc:: with SMTP id b195mr9999114iof.148.1635549585270; Fri, 29 Oct 2021 16:19:45 -0700 (PDT)
MIME-Version: 1.0
References: <DBBPR08MB59153B444624CEA8EC6E9A66FA819@DBBPR08MB5915.eurprd08.prod.outlook.com> <YXPSz6Uw9CDgl7tX@LK-Perkele-VII2.locald> <DBBPR08MB59157A0F39745E84309DDD8DFA839@DBBPR08MB5915.eurprd08.prod.outlook.com> <YXb02ETjp3dbFrXh@LK-Perkele-VII2.locald> <6DC9931F-7CEC-4DD3-87BC-EEA93A7B9646@akamai.com> <DBBPR08MB591549A109FC15BE09C22C73FA849@DBBPR08MB5915.eurprd08.prod.outlook.com> <CAN40gSvYVSi6A7PVOiqmCxqwa2x3Y9ppowvXR9L46TJ1jmE=WQ@mail.gmail.com> <EADE1F53-1A25-4483-9D42-ADC71D935CBB@akamai.com> <CABcZeBMgW-rbooFPX6psv+jKeHLKuUEqtThA4inR3jiXTLt1qA@mail.gmail.com> <81AEBCC0-4704-4ED0-8A49-B3DC5842C005@akamai.com> <CABcZeBM39bQ3SwCD+NnewLnXd+wo-J+mMr5McsO2i4y922Eqbw@mail.gmail.com> <CAN40gSvu=1wWoYD3p9ygmDP0w13-yuH0SdeOR2mN8UScnuZw7w@mail.gmail.com> <CABcZeBMY1Z_CmPNatJA5kca1d4jvfg7GquK3+b+fdfwBxS2suA@mail.gmail.com> <CAN40gStbPOcUk--NsC9aweep3toFc08roq5e0Jo2Reo0a6+c9w@mail.gmail.com>
In-Reply-To: <CAN40gStbPOcUk--NsC9aweep3toFc08roq5e0Jo2Reo0a6+c9w@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 29 Oct 2021 16:19:09 -0700
Message-ID: <CABcZeBNMagKRjegu=U9oP6r+R76MWs4FrWULw7diMS015AU1Bw@mail.gmail.com>
To: Ira McDonald <blueroofmusic@gmail.com>
Cc: "Salz, Rich" <rsalz@akamai.com>, Hannes Tschofenig <Hannes.Tschofenig@arm.com>, IETF TLS <tls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000000b04cc05cf861095"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/PqGL38DnxH9AjeR6JsTOPMRAYCA>
Subject: Re: [TLS] TLS Flags and IANA registration policy
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Oct 2021 23:19:51 -0000

On Fri, Oct 29, 2021 at 4:01 PM Ira McDonald <blueroofmusic@gmail.com>
wrote:

> Hi Eric,
>
> I agree.  Let's get the semantics right.  You mentioned a 3-tuple w/
> "Discouraged".
> Should that be "Deprecated" (for clarity)?
>

The implied semantics are are:

Recommended: The IETF has consensus this is good  (e.g., AES)
Not Recommended: We're not expression an opinion on this, it's just being
registered , so caveat emptor (e.g., Brainpool).
Discouraged: The IETF thinks this is bad and you shouldn't use it (e.g.,
MD5)

But I think the point being that Deprecated might also be new stuff we
think is bad, not just old stuff.

-Ekr


>
> On Fri, Oct 29, 2021 at 5:17 PM Eric Rescorla <ekr@rtfm.com> wrote:
>
>> Well, we certainly can change it in 8446-bis.
>>
>> My put here would be: let's get consensus on the *semantics* we want for
>> the various categories without worrying about the names (call them A, B, C,
>> etc.) and then we can name them after.
>>
>> -Ekr
>>
>>
>> On Fri, Oct 29, 2021 at 2:14 PM Ira McDonald <blueroofmusic@gmail.com>
>> wrote:
>>
>>> Hi Eric,
>>>
>>> Thanks for the background.  I still sympathize with Hannes' point that
>>> "Recommended" means "IETF Consensus".  I have to explain this
>>> too often in the insular automotive industry.
>>>
>>> But I certainly wouldn't write an RFC to change the title of a single
>>> column in an IANA registry.  I've been one of the Designated Experts
>>> for the IANA Internet Printing Protocol (IPP) registry for 20 years and
>>> we rename IANA fields as needed by a direct request to our IANA
>>> folks (after consensus in the IEEE-ISTO Printer Working Group IPP
>>> WG - successor to IETF IPP WG in the 1990s).
>>>
>>> Cheers,
>>> - Ira
>>>
>>>
>>> On Fri, Oct 29, 2021 at 3:18 PM Eric Rescorla <ekr@rtfm.com> wrote:
>>>
>>>> Previous discussion is on this issue:
>>>> https://github.com/tlswg/tls13-spec/issues/1214
>>>>
>>>> On Fri, Oct 29, 2021 at 12:13 PM Salz, Rich <rsalz@akamai.com> wrote:
>>>>
>>>>>
>>>>>    - I am actually not in favor of changing it to IETF Consensus. I
>>>>>    think these have different meanings.
>>>>>
>>>>>
>>>>>
>>>>> To be clear, I wasn’t expressing an opinion on whether or not to do
>>>>> this, I was just showing folks how to start the change process.
>>>>>
>>>>