Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

John Mattsson <john.mattsson@ericsson.com> Fri, 08 March 2019 22:44 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CFB5130FF3 for <tls@ietfa.amsl.com>; Fri, 8 Mar 2019 14:44:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level:
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com header.b=LY4RfuKW; dkim=pass (1024-bit key) header.d=ericsson.com header.b=fy21JG2Y
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BZzmTWjVb1DB for <tls@ietfa.amsl.com>; Fri, 8 Mar 2019 14:44:11 -0800 (PST)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B12E6130F3E for <tls@ietf.org>; Fri, 8 Mar 2019 14:44:08 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; d=ericsson.com; s=mailgw201801; c=relaxed/relaxed; q=dns/txt; i=@ericsson.com; t=1552085046; x=1554677046; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=smkZafskeC6USRx16pwQRnt+Tm+5XCvIxlUfvnRvXSw=; b=LY4RfuKWjsk8vY1U1Dc8yhsXEn5/VwRVVxn6m6GngIRR5nudeyLg8d/x9o68BmR1 fMZ2nIf56ba5m4lAWZCZXE7vguR6u8oHe78IyEPTxjtqr/Kl3+skJqoloc0y/wjk 3Sm5/A9VkpHmITQXxqKliW/MeypzlbtR4ggnj9A6di0=;
X-AuditID: c1b4fb25-da1ff70000005ff7-55-5c82f036331b
Received: from ESESBMB503.ericsson.se (Unknown_Domain [153.88.183.116]) by sesbmg23.ericsson.net (Symantec Mail Security) with SMTP id 21.EC.24567.630F28C5; Fri, 8 Mar 2019 23:44:06 +0100 (CET)
Received: from ESESSMR503.ericsson.se (153.88.183.112) by ESESBMB503.ericsson.se (153.88.183.186) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1466.3; Fri, 8 Mar 2019 23:44:06 +0100
Received: from ESESSMB501.ericsson.se (153.88.183.162) by ESESSMR503.ericsson.se (153.88.183.112) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1466.3; Fri, 8 Mar 2019 23:44:06 +0100
Received: from EUR04-VI1-obe.outbound.protection.outlook.com (153.88.183.157) by ESESSMB501.ericsson.se (153.88.183.162) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1466.3 via Frontend Transport; Fri, 8 Mar 2019 23:44:06 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=smkZafskeC6USRx16pwQRnt+Tm+5XCvIxlUfvnRvXSw=; b=fy21JG2Y3CFsKP8Piax26AhTE8YlT756FoBjdHY4k6AL9XBboOfwqyPR3WU4Vl+qG/IPli/tlVmxROGG7uRNDoiKEAGnJVO8KHnZzF5OVUIpVYxvvLI5zs5mJndzEkANR3UnnzE+jtOk2y17B/i8xFYbwqrWnUh9BFc+ECop7uM=
Received: from HE1PR07MB4169.eurprd07.prod.outlook.com (20.176.166.22) by HE1PR07MB4187.eurprd07.prod.outlook.com (20.176.166.28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1686.15; Fri, 8 Mar 2019 22:44:04 +0000
Received: from HE1PR07MB4169.eurprd07.prod.outlook.com ([fe80::ace2:9258:766:85a8]) by HE1PR07MB4169.eurprd07.prod.outlook.com ([fe80::ace2:9258:766:85a8%3]) with mapi id 15.20.1709.010; Fri, 8 Mar 2019 22:44:04 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt
Thread-Index: AQHUdyQNHE9heMDn6kGd04PAAeP/dKVFW3AAgL3H6AA=
Date: Fri, 08 Mar 2019 22:44:04 +0000
Message-ID: <09181304-3B39-464D-B98A-E7C109701507@ericsson.com>
References: <154165491176.26419.11906807559515385277@ietfa.amsl.com> <62386296-c674-44ef-65b0-e3ced823eb92@cs.tcd.ie>
In-Reply-To: <62386296-c674-44ef-65b0-e3ced823eb92@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.16.1.190220
authentication-results: spf=none (sender IP is ) smtp.mailfrom=john.mattsson@ericsson.com;
x-originating-ip: [82.214.46.143]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 18a168ff-cf7a-4509-2e46-08d6a4179156
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600127)(711020)(4605104)(2017052603328)(7153060)(7193020); SRVR:HE1PR07MB4187;
x-ms-traffictypediagnostic: HE1PR07MB4187:
x-ms-exchange-purlcount: 5
x-microsoft-exchange-diagnostics: 1;HE1PR07MB4187;23:n7PGz3QM0rITa5zHc07uKe0HJVm2z1TkbYEvFelChR1dLF5uFLCtBc8yw/2ci/zfOALRu/hYe+sBba+69Z2AOiIiz7SKsbaL8yhc8rEMO6KF5kihn0BNkdqn1rsAF63dDTFSZ3swho+V4UBRelD8SEGNnJdpwubnIqvYLvsshpy5fpXF/OSZ9SV+Qxt2odY55bfg0czcVxhikqcfxcZPMImiyrbYeG7tRpXyvHCa1xVNiUrB0WQNTql9fHL0s8YgrlLojpWclDF9ZvuwBToLCGW1syrIM9f710nT+NXo7DiGvXRndnM8z66CpDJtyz6ZT9MkvHhRr31C9r5zQ+kA+yPwvfM9/cSosJHg/epHYXr+UFPVZfCFmBeEPzRZYFzsjnpXEKoOeBF8QwpSGXl/Xloe1XJmEJkpqATf9Q2+Ul4pvy6i2PBDBL34arRjSYXe8tdlND00Q/Uxj7vzsPQd13o23wKg4Gjhl873Gl8yCrcnJqqEIcbq9YsQDgUfvS4kEwCfTS3sqiKb787oPEUp0ghjPvQ2tX1iQCtr8l9mDGOU1U73xPzfj/36fqYolRsMEGF0ex7f56b+J8a9lDQeBFRTYQHAFkWYRqNRP05aK56OkRhsPdFEMDcNcz/9+eNQPEHoE1p2ZJJhBs++IFDRJvcar8Y1s7xVA6+boRcJfV6Bfn60CBdRtW86L55KODP3c/+H/c0REk7HLcUXJMWf1AF3Z5GT1SYd5tnND0gyiw1jonm2MvQT8yIV2VUNGZnmghJbU0FxeT/PM4Sei2xPzDay3bflJu0RJp19sEGKkVpERBLtz8yYeSN1aAnohytIJhp3x4D7CE4LM3jfheLquT+ZByJffSf/OUZFwtMHgL+LUqCRII+0bsbQ237Ti9/oeVQSXXvD0zEtjLdJGt+YAKXT6x3yQieK9IijJ1ufw/JsNX6u6X0N3T3efbbVl45UeL7ihnXXd7SxP7RxHB3VXuhQeoF67m+jnWJ9Wtz5NI4N/6u7mUf2k2Nrr3qBz5lHKX576PoCyG6dbOZr472hPO11f1/ahbjpFq1FUU73cOcMSH8VGWc1GQ3gEZkiBLL+cDN/f7TbDy3oxTqd/K5tolGa135T/Pip1JH1NkG06YBKAKjjNB/Of+PpbHvVaTPf8wNgbo6e9kVFYJvGCQwNOtqF0KV6RC91cH8aQqiqXJYNHfaNYmSovLC6wcmeBD5QKC9WfUxC8aftPJHNqMiIzNWlIxj4HCbx7QobH7kPoIu1m2WMl2ZsWDwhXthXKn0WKaIsabZw0snhUryWdUALTa3kjns9uY3alTz+0JlR39DXl84cJ3iyWfIokm2FbQjV30gDMfrV6fCkAzrdGKK44w9r/+H3TvPkDw0JH3XrMx4IlQZv0+j65zEGhqO85UqbCGrGLVbn3r9ae4jf9BKe2A==
x-microsoft-antispam-prvs: <HE1PR07MB41872C379D51D1531A927B29894D0@HE1PR07MB4187.eurprd07.prod.outlook.com>
x-forefront-prvs: 0970508454
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(136003)(366004)(346002)(376002)(396003)(39860400002)(189003)(199004)(13464003)(51444003)(53936002)(6512007)(53546011)(14444005)(8936002)(478600001)(44832011)(6116002)(81166006)(186003)(25786009)(58126008)(105586002)(81156014)(8676002)(99286004)(33656002)(106356001)(305945005)(86362001)(110136005)(6246003)(2501003)(82746002)(36756003)(7736002)(5660300002)(6436002)(3846002)(66066001)(446003)(11346002)(6486002)(66574012)(966005)(71200400001)(71190400001)(476003)(6306002)(296002)(26005)(316002)(76176011)(102836004)(256004)(6506007)(14454004)(2906002)(83716004)(486006)(229853002)(68736007)(2616005)(97736004); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR07MB4187; H:HE1PR07MB4169.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: MlCAdQJAM5/ZYr+pQshqQmDXbK3LgmUYCiyruACb9MOM1Z8HrC+U5fRyXkIogv+8l9o/Wm2jyc1kV6SA59/OcyPSr9fSX7dzc0crXFVpmqDkC+if77FeBzJ8zIaOq34vzcqmypAKZiMt1SSTQQwzvx/rMdHjaBu81fwXxDykrgz8l+vtr6FDTbhK0LNF/RLbzoSN0idv82CWLdwRSKrxrkOLX0v3AULTA1PTwjlwiUrFWYGU3SUAufRG4R8nEhjWyzYDB8UnF9QfJMG5YypoiX79VjDTP+WBaRV7g/s/N69gaLlcY8Uc735qdNGhc8wz9SxSYzGxfmjSplV0doevjBySbd1xNLHcUuMIs1l0YU2raniT9gyxC4R53c38P3w+BLsM9TsqY6wEn1hq7WlLVyMsMSlDX6AoU2WAf/WD4Aw=
Content-Type: text/plain; charset="utf-8"
Content-ID: <0B4B8ECD763217439395367C410BB600@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 18a168ff-cf7a-4509-2e46-08d6a4179156
X-MS-Exchange-CrossTenant-originalarrivaltime: 08 Mar 2019 22:44:04.7520 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB4187
X-OriginatorOrg: ericsson.com
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupnleLIzCtJLcpLzFFi42KZGbG9RNfsQ1OMwY9jphbT915jt/h0vovR gcljbfdVNo8lS34yBTBFcdmkpOZklqUW6dslcGX83riKrWCFVsWcOWeYGhjnaHYxcnJICJhI 3Ov8zwJiCwkcYZTY9qm6i5ELyP7KKDHz4WtGOGdZ03kmCGcxk8Sh3jdsIC0sAhOYJXbcgWqZ xCRxY/I2dgjnPqPEqz9PwarYBAwk5u5pALNFBPwkrh6eCrSQg0NYwEti518uiLC3xMU1q5kg bCuJ1p5PrBALVCRa57Uwg9i8AvYS21tes0LcWi5xds41RhCbU8BW4tv+2WA2o4CYxPdTa8Dm MAuIS9x6Mp8J4k8BiSV7zjND2KISLx//A5sjKqAvsaXvAQtEb6xEa+t0VogaRYnT+1ZA1ctK XJrfzQhh+0p0r1gE9qOEwE1gsMxfDpXQkji2F+R5EFtKYv/meYwQRfOEJVbv/gZ1RbZEx/+j bCDPSwjISPw8IjOB0WAWkltnAWWYBTQl1u/Shwh7SEx8uosZwlaUmNL9kH0WOCgEJU7OfMKy gJF1FaNocWpxUm66kbFealFmcnFxfp5eXmrJJkZgMjm45bfqDsbLbxwPMQpwMCrx8F651xQj xJpYVlyZe4hRgoNZSYR322OgEG9KYmVValF+fFFpTmrxIUZpDhYlcd4/QoIxQgLpiSWp2amp BalFMFkmDk6pBkbWe3YVnMzR+xf23PESO3fVz3GG0PmeeD2mKlEvXxWxiyYTDRLM55mdXvI6 vO/aUpePK+IEpFZ/CNJ7sp5LeMueySd/hjdvkt1iM6slLHJVsr30z3cnUraUWBY8cjyqxi/G XsVxfFpL5u/fzyLkr8f5vuy9fLKa8V5hyZw2nivBH112XetY8FeJpTgj0VCLuag4EQD7m5Wq IgMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Rgf2xcEd_9UajfUWMjJfVzC-bpA>
Subject: Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Mar 2019 22:44:19 -0000

Hi,

Thanks for driving this. Great work. I would like to see deprecation of done more often in IETF and elsewhere.

3GPP has deprecated TLS 1.0 and DTLS 1.0 some years ago (but could at that time not deprecate TLS 1.1 due to interop with older releases). I would estimate that 3GPP will deprecate TLS 1.1 this year, at least that is what I am going to suggest. I think that 3GPP will deprecate non-AEAD and non-PFS cipher suites at the same time as TLS 1.1.

Moving deprecation of SHA-1 to a different document makes sense to me. I would want such a document be deprecate a much as section 9.2 of RFC 7540 with the exception of TLS_PSK_WITH_AES_128_CCM_8 for IoT. I.e, I think such a document should forbid non-AEAD and < 2048 DHE as well as changing the MTI cipher suite in TLS 1.2. 

- I think the document should mention DTLS 1.0 much earlier, probably even in the title.

- Nit: The document uses "TLS1.0" "TLSv1.0" while most other drafts use "TLS 1.0"

Cheers,
John

-----Original Message-----
From: TLS <tls-bounces@ietf.org> on behalf of Stephen Farrell <stephen.farrell@cs.tcd.ie>
Date: Thursday, 8 November 2018 at 06:36
To: "TLS@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt


Hiya,

This version attempts to make the few changes discussed
at the meeting on Monday. I wrote a script that gave me
a list of 76(!) RFCs this might need to update, and may
of course have mucked that up, so if anyone has a chance
to check if (some of) those make sense, that'd be great.

Ta,
S.

On 08/11/2018 05:28, internet-drafts@ietf.org wrote:
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Transport Layer Security WG of the IETF.
> 
>         Title           : Deprecating TLSv1.0 and TLSv1.1
>         Authors         : Kathleen Moriarty
>                           Stephen Farrell
> 	Filename        : draft-ietf-tls-oldversions-deprecate-01.txt
> 	Pages           : 21
> 	Date            : 2018-11-07
> 
> Abstract:
>    This document, if approved, formally deprecates Transport Layer
>    Security (TLS) versions 1.0 [RFC2246] and 1.1 [RFC4346] and moves
>    these documents to the historic state.  These versions lack support
>    for current and recommended cipher suites, and various government and
>    industry profiles of applications using TLS now mandate avoiding
>    these old TLS versions.  TLSv1.2 has been the recommended version for
>    IETF protocols since 2008, providing sufficient time to transition
>    away from older versions.  Products having to support older versions
>    increase the attack surface unnecessarily and increase opportunities
>    for misconfigurations.  Supporting these older versions also requires
>    additional effort for library and product maintenance.
> 
>    This document updates many RFCs that normatively refer to TLS1.0 or
>    TLS1.1 as described herein.  This document also updates RFC 7525 and
>    hence is part of BCP195.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-tls-oldversions-deprecate/
> 
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-tls-oldversions-deprecate-01
> https://datatracker.ietf.org/doc/html/draft-ietf-tls-oldversions-deprecate-01
> 
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-tls-oldversions-deprecate-01
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>