Re: [TLS] secdir review of draft-ietf-tls-ecdhe-psk-aead-03

Dave Garrett <davemgarrett@gmail.com> Fri, 19 May 2017 07:21 UTC

Return-Path: <davemgarrett@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 918EA129ADA; Fri, 19 May 2017 00:21:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L8ieFsHbj3_R; Fri, 19 May 2017 00:21:51 -0700 (PDT)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6ACF0127A91; Fri, 19 May 2017 00:16:36 -0700 (PDT)
Received: by mail-qt0-x234.google.com with SMTP id c13so51911702qtc.1; Fri, 19 May 2017 00:16:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:user-agent:cc:references:in-reply-to :mime-version:content-transfer-encoding:message-id; bh=1l6wwkBmmZlH9uo3WF1lXR/upb5w3DhmVxp3H96FKuE=; b=CFImJbKua/vDQNK96rHApq84iAOeHIUZnaZcwkHkBj14ZqF8y5wUjljxV4GhebYG4u Y2mD095XN+5VHGPymg1T/Y59+ErQuJKUvdDc9JdtiHkRe2oNxXiW7gBTlP04G6iCVAXw GyxkheQyUBqWkZvqWEX/zy2Vb/kjsxTqy/k94BCJstWCzSAAceKLoZYYhjZ2kKdP4RSb GtbFPGTP8CBi9UxOrgBbgErHc21RqarB/LyVGjAoCUqQEmFqMjkDcN153HNCQ2EpdR5n alkbnvU6z+hSEbkYM7gEy/RWYew37WVDNg3Y1y2Fxja2wrc41Ub+tbXva7pXQ7Bw07wn ry0A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:user-agent:cc:references :in-reply-to:mime-version:content-transfer-encoding:message-id; bh=1l6wwkBmmZlH9uo3WF1lXR/upb5w3DhmVxp3H96FKuE=; b=iAyoaT7C+wAskUFNVLQJZJxw9SFTICp4NV4RcMkZE8+w8SObNW1B9YPPHECwfqus9f h5xS67so4uRBozDGHZBaBTM2Wa2lInLfsGnaYRYtXlJIdK8e1H36pONcOuaCuIjYim9W i2vdh+pNz72MeG1+ilekDAKpqO96+c0Wal5eZ7Z1IAWQsh5p37r4NHKGSJoQkYrLROiP oQ4uYqunQItjMGe547yI4kQAsTTzUd2baBXZzURPEVJ8vM51ZHqOZKvQz2fXgSfH2WCT XN8YkPo3Ql2Ea3WwrGSpb5OGp4AbtH7zv/XpoHkJ/bQaN65/XAF1+BoxFKWVN4eogpXv vrqA==
X-Gm-Message-State: AODbwcCzJz/ZSNp/ezDRdOCVUE3hGnarFT8+qvE+GSsA3Ug7fPUroj1W NzQK/92nM/OhOA2oOrk=
X-Received: by 10.200.56.243 with SMTP id g48mr8729225qtc.79.1495178195474; Fri, 19 May 2017 00:16:35 -0700 (PDT)
Received: from dave-laptop.localnet (pool-71-185-36-197.phlapa.fios.verizon.net. [71.185.36.197]) by smtp.gmail.com with ESMTPSA id o13sm5426365qke.30.2017.05.19.00.16.34 (version=TLS1 cipher=AES128-SHA bits=128/128); Fri, 19 May 2017 00:16:34 -0700 (PDT)
From: Dave Garrett <davemgarrett@gmail.com>
To: tls@ietf.org
Date: Fri, 19 May 2017 03:16:32 -0400
User-Agent: KMail/1.13.5 (Linux/2.6.32-74-generic-pae; KDE/4.4.5; i686; ; )
Cc: Benjamin Kaduk <kaduk@mit.edu>, iesg@ietf.org, secdir@ietf.org, draft-ietf-tls-ecdhe-psk-aead.all@ietf.org, ietf@ietf.org
References: <20170519043827.GL39245@kduck.kaduk.org>
In-Reply-To: <20170519043827.GL39245@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: Text/Plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id: <201705190316.33316.davemgarrett@gmail.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/R-aIWr6ngokqJbihDWYVPNk2NJw>
Subject: Re: [TLS] secdir review of draft-ietf-tls-ecdhe-psk-aead-03
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 May 2017 07:21:53 -0000

On Friday, May 19, 2017 12:38:27 am Benjamin Kaduk wrote:
> In section 4, "these cipher suites MUST NOT be negotiated in TLS
> versions prior to 1.2" should probably clarify that "these" cipher
> suites are the new ones specified by this document.

Probably should be: "the cipher suites defined in this document
MUST NOT be negotiated for any version of TLS other than 1.2."

The sentence mentioning TLS 1.3+ could be moved up to right after
and just say: "TLS version 1.3 and later negotiate these features in
a different manner."


Dave