Re: [TLS] tlsflags and "responses"
Yoav Nir <ynir.ietf@gmail.com> Wed, 23 February 2022 20:43 UTC
Return-Path: <ynir.ietf@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C20303A0C32 for <tls@ietfa.amsl.com>; Wed, 23 Feb 2022 12:43:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kPNcM2lSg-1P for <tls@ietfa.amsl.com>; Wed, 23 Feb 2022 12:43:10 -0800 (PST)
Received: from mail-wr1-x429.google.com (mail-wr1-x429.google.com [IPv6:2a00:1450:4864:20::429]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B23483A0C27 for <tls@ietf.org>; Wed, 23 Feb 2022 12:43:09 -0800 (PST)
Received: by mail-wr1-x429.google.com with SMTP id l13so576896wrt.2 for <tls@ietf.org>; Wed, 23 Feb 2022 12:43:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=kGmefgReNnjMvz8hkJXx7Budyr0TevTcMcjWWiThCNU=; b=Xhjv0N5WQVrF96y+fXfr0p8BXRcRHU3ssXPHItbkFk77l2vgiwMXbu8k+NP4ZY88D+ fQLceUz4LMyKIeQZhtqnK0xtwRq9ucfjFu+QsDrns7c8jMqpAElvNImzkC7mUXpmBCGh k+xHFTmb8AJzHEJWU19WIbNQhkfhIuEBZFK6XdYFiKH9JWOOHPSWen7X0AoiJfWX9xh9 iXCCelJ65Z4Dg81Z2YOH/yrpYQxL1on2h0m7t0T+eSKQbHL6epyJL4DiveFjl/ONLPk8 +miUTc3CPx9Fl33niQgaPPmJuGqSCWGoSAeJbh1XgRB5PZXR7pkWMGrMmk/FQbKqmY7E joIA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=kGmefgReNnjMvz8hkJXx7Budyr0TevTcMcjWWiThCNU=; b=MIbvKT1PA0bRM+cXJ79x1GOzGvfB5/TvQpFPwexa2QswY4dKKokcGVGrB2ouJmMOgL d0WTnsN/xt2EfTmueLAhg/UkQQ/GS8en5bDOIUA+Ou2v9KDRtJdfwJSPdlRKvaEQBqJ9 A9mm/fpbVtxTNTG5C3YjbHH9PlqzutDz9uuwD0sdZUK3/8mtycorX7che+EQtadSaZbb rW3pW/NS4CfCCI8DCPboGNDqoTY2oJl644jfzXtTAu4hlzOQ55/KEkBY95HKmuKyeDFH 7njyktxVSjSUL6jikP7Jz6/Ugow0dlYsBXchiOXU+0Yf9iQOqsAH93uTJc17vgXwPiF9 2Q2g==
X-Gm-Message-State: AOAM532Nb1O+LUWzWVF/yehi/RHzjVVR5vTqhY7o8MIV7wNODAqD0J6u fAGN0y+mG69xREuBRwLo4J3m8WAz0qGjWtjO
X-Google-Smtp-Source: ABdhPJxTq4T21mznOgNKeO6aeL4dbmPKvg9lBvY763eFtofxmzIucoN/sMKf8xMYYHkTxJ9u62I80w==
X-Received: by 2002:a05:6000:2c6:b0:1ea:937e:872b with SMTP id o6-20020a05600002c600b001ea937e872bmr966872wry.233.1645648987536; Wed, 23 Feb 2022 12:43:07 -0800 (PST)
Received: from smtpclient.apple (84.94.37.215.cable.012.net.il. [84.94.37.215]) by smtp.gmail.com with ESMTPSA id i13sm577404wrp.87.2022.02.23.12.43.06 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 23 Feb 2022 12:43:07 -0800 (PST)
From: Yoav Nir <ynir.ietf@gmail.com>
Message-Id: <D8A1140C-F6C4-43CD-AB00-C0A6EA1E76EB@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_6F6FCCDF-EDB6-4568-A5D6-41E45949A000"
Mime-Version: 1.0 (Mac OS X Mail 15.0 \(3693.60.0.1.1\))
Date: Wed, 23 Feb 2022 22:43:04 +0200
In-Reply-To: <9C21D828-A4DF-47C8-8EA6-2229DD004C49@gmail.com>
To: "<tls@ietf.org>" <tls@ietf.org>
References: <2a04def6-d4cd-43ab-96f3-9e09958da9da@beta.fastmail.com> <9C21D828-A4DF-47C8-8EA6-2229DD004C49@gmail.com>
X-Mailer: Apple Mail (2.3693.60.0.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/SIvCO_ZFmNfTEeyiuZOcdBzTdAo>
Subject: Re: [TLS] tlsflags and "responses"
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Feb 2022 20:43:15 -0000
Hi. I have merged the PR following review and proposed changes by Chris and Martin Thomson. The only point that remains open is Ekr’a suggestion to allow (require?) sending the extension when empty. Yoav > On 22 Feb 2022, at 7:35, Yoav Nir <ynir.ietf@gmail.com> wrote: > > I have just submitted PR #20 to allow unacknowledged flags. It is a rewrite of section 3 (rules) > > https://github.com/tlswg/tls-flags/pull/20 <https://github.com/tlswg/tls-flags/pull/20> > > It still requires that the flag extension not be sent when empty. Let me know if that’s a problem as well. > > Yoav > >> On 21 Feb 2022, at 2:21, Martin Thomson <mt@lowentropy.net <mailto:mt@lowentropy.net>> wrote: >> >> I missed this text in draft-ietf-tls-tlsflags: >> >> A server that supports this extension and also supports at least one >> of the flag-type features that use this extension and that were >> declared by the ClientHello extension SHALL send this extension with >> the intersection of the flags it supports with the flags declared by >> the client. >> >> While sloppy on my part [1], I want to make it clear that this is a show-stopper for me. Requiring an echo prevents a flag extension from attaching semantics to a "response". >> >> I agree with Ilari's earlier point that these should work just like extensions. If the server has no need to echo a flag, it should not be required to do that. That allows the flag value in a "response" to carry semantics. >> >> Cheers, >> Martin >> >> [1] I missed this in the second WGLC, though in my defense, I don't think the resolution and changes resulting from the first WGLC were very clearly communicated. >> >> _______________________________________________ >> TLS mailing list >> TLS@ietf.org <mailto:TLS@ietf.org> >> https://www.ietf.org/mailman/listinfo/tls >
- [TLS] tlsflags and "responses" Martin Thomson
- Re: [TLS] tlsflags and "responses" Eric Rescorla
- Re: [TLS] tlsflags and "responses" Christopher Wood
- Re: [TLS] tlsflags and "responses" Benjamin Kaduk
- Re: [TLS] tlsflags and "responses" Martin Thomson
- Re: [TLS] tlsflags and "responses" Eric Rescorla
- Re: [TLS] tlsflags and "responses" Yoav Nir
- Re: [TLS] tlsflags and "responses" Eric Rescorla
- Re: [TLS] tlsflags and "responses" Yoav Nir