Re: [TLS] draft-green-tls-static-dh-in-tls13-01

"Dobbins, Roland" <rdobbins@arbor.net> Sat, 15 July 2017 08:22 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 18ED1131B34 for <tls@ietfa.amsl.com>; Sat, 15 Jul 2017 01:22:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.92
X-Spam-Level:
X-Spam-Status: No, score=-1.92 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wudPOwjevZtg for <tls@ietfa.amsl.com>; Sat, 15 Jul 2017 01:22:54 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0124.outbound.protection.outlook.com [104.47.33.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1E28131B03 for <tls@ietf.org>; Sat, 15 Jul 2017 01:22:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=LrA/EIZHM3DU6hpMYfL9aAKjChlFEXxxeknUaXuur+w=; b=fotzhr6OT/JAXEhoMx2WIGgP1FxgYRTCjs92EJFliFGFiWklShOlrvfj4cGQUyDkCWoTs6R/5tsKwRJhRO4tHaIsWmYVthTCv8EIhwzT7/fQ3dVXBljVRCNgw8gqxJw4z/lVK0Q7cAmrWX5Z0I7d9Vt9Wsxss0dh3/cVl/B+x1c=
Received: from DM2PR0101MB1039.prod.exchangelabs.com (10.160.129.156) by DM2PR0101MB1040.prod.exchangelabs.com (10.160.129.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1240.13; Sat, 15 Jul 2017 08:22:51 +0000
Received: from DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7]) by DM2PR0101MB1039.prod.exchangelabs.com ([fe80::810f:2255:5d85:2fc7%17]) with mapi id 15.01.1240.022; Sat, 15 Jul 2017 08:22:51 +0000
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: Ted Lemon <mellon@fugue.com>
CC: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, Matthew Green <matthewdgreen@gmail.com>, IETF TLS <tls@ietf.org>
Thread-Topic: [TLS] draft-green-tls-static-dh-in-tls13-01
Thread-Index: AQHS/TNOetAoAc0WMUGwvSG+0rIljKJUgY1igAABS4CAAAIPE4AAAzcAgAAElA0=
Date: Sat, 15 Jul 2017 08:22:50 +0000
Message-ID: <D43C7836-9F72-4D3C-A8FA-E536FCBEEB6A@arbor.net>
References: <CAPCANN-xgf3auqy+pFfL6VO5GpEsCCHYkROAwiB1u=8a4yj+Fg@mail.gmail.com> <CAL02cgRJeauV9NQ2OrGK1ocQtg-M2tbWm2+5HUc4-Wc8KC3vxQ@mail.gmail.com> <71E07F32-230F-447C-B85B-9B3B4146D386@vigilsec.com> <39bad3e9-2e17-30f6-48a7-a035d449dce7@cs.tcd.ie> <CAJU8_nXBFkpncFDy4QFnd6hFpC7oOZn-F1-EuBC2vk3Y6QKq3A@mail.gmail.com> <f0554055-cdd3-a78c-8ab1-e84f9b624fda@cs.tcd.ie> <A0BEC2E3-8CF5-433D-BA77-E8474A2C922A@vigilsec.com> <87k23arzac.fsf@fifthhorseman.net> <D37DF005-4C6E-4EA8-9D9D-6016A04DF69E@arbor.net> <CAPt1N1nVhCQBnHd_MCm79e7c1gO6CY6vZG_rZSNePPvmmU_Bow@mail.gmail.com> <44AB7CB8-13C1-44A0-9EC4-B6824272A247@arbor.net>, <CAPt1N1=rvtssKXCnsNmr1vy4ejb6YDUxO2kDcgh-ZMh5WGjfWg@mail.gmail.com>
In-Reply-To: <CAPt1N1=rvtssKXCnsNmr1vy4ejb6YDUxO2kDcgh-ZMh5WGjfWg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: fugue.com; dkim=none (message not signed) header.d=none;fugue.com; dmarc=none action=none header.from=arbor.net;
x-originating-ip: [2405:9800:b408:a9c1:213f:172e:972e:6441]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR0101MB1040; 7:h+NZlZiHQL9Y1AQNPuzyDnS17oKEHRqVmcWc7bs9UthEUVhLc27h8hTgXQfTWPMq625zhIR3h2HiUXCb9kvGU6H7MO18SHi2Z+jwYlWGnjNZvmFDBQcjZBpLqrMACQwyVNGHOx7fV1Y1/RYqciCy48bKU/Ii9JiEcpybUB7hDpF19puU/x/tedVt/kPnSryhNSwT9PqSIrh32qkf+bnTedGkqZo4DoaX0+VbQ1X1CQpzXKAar9PvEvzPCyj9++9o5kP+4kK8eoO2D/KI3cQNizpfNC3YALD2tST9FyXPGOu5jWDlCSXTKIDDhwVBYVIBp2nx5+WMMeCvCpFZAI+BIBTMk4+LIWDKiM6KSawmknmkU9ksP7v3kb9V7L7VULG6dBCfu4mTIH2Kni6TpoEx0iTZ4WWoGY7Pnbtf6EK8RIGxfbUxY2ZiQ16cCMGEj0lty1iXN3ge/PhtTaEJcOrdZild+qpYrjQ+MMXzOzG8CF0zjVu3KM35VC5QZucA/2ZFhQaL/0ighbI2e93DYazZC+vRt7axLEY+gtAI4Y7f99RWQHl8skDg3tU8IN9RL/EiBsU1WndQijF3GXrYhNuH70OGLKa//smVSA6e9IwrNgSLc1g9k2yE2kiRLrU43RcoE0acUuE+Ryczw+70D2vpJb6+urISILmaqWJdzg15ke1wAm7iQ0+WZmcynvmk4DS4mjjVNISLYwLsDGn7DNHNDVtlq6ec88T8tCsmPKislyHJgUpRjThwxJZi8Af5fyMwoaJ1UtW8lImKW1LBZUw+1TNFKzRI9O/nzFlSdzoLCig=
x-ms-office365-filtering-correlation-id: 811e96bf-6334-4e33-40b7-08d4cb5aaf1f
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1040;
x-ms-traffictypediagnostic: DM2PR0101MB1040:
x-exchange-antispam-report-test: UriScan:(236129657087228)(192374486261705)(48057245064654)(50300203121483)(247924648384137);
x-microsoft-antispam-prvs: <DM2PR0101MB104094D2650D4263B018F47ECAA20@DM2PR0101MB1040.prod.exchangelabs.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(2017060910075)(93006095)(93001095)(10201501046)(100000703101)(100105400095)(3002001)(6041248)(20161123560025)(20161123564025)(20161123558100)(20161123562025)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1040; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1040;
x-forefront-prvs: 0369E8196C
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39830400002)(39400400002)(39450400003)(39410400002)(51444003)(24454002)(6246003)(36756003)(6436002)(99286003)(3660700001)(54906002)(6486002)(189998001)(6506006)(53936002)(2900100001)(236005)(6512007)(2906002)(54896002)(110136004)(229853002)(7736002)(3280700002)(38730400002)(86362001)(8936002)(93886004)(5250100002)(230783001)(39060400002)(14454004)(478600001)(5660300001)(8676002)(83716003)(50986999)(4326008)(54356999)(33656002)(76176999)(53546010)(82746002)(102836003)(6116002)(25786009)(81166006)(6916009)(2950100002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1040; H:DM2PR0101MB1039.prod.exchangelabs.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_D43C78369F724D3CA8FAE536FCBEEB6Aarbornet_"
MIME-Version: 1.0
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Jul 2017 08:22:50.9294 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 54f11205-d4aa-4809-bd36-0b542199c5b2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1040
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/T55brbXPA4BpRKVRp09yl-S_ZdM>
Subject: Re: [TLS] draft-green-tls-static-dh-in-tls13-01
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 15 Jul 2017 08:22:56 -0000

On Jul 15, 2017, at 15:07, Ted Lemon <mellon@fugue.com<mailto:mellon@fugue.com>> wrote:

I think that your first and third points are actually non-sequiturs: the unencrypted stream is available to the entities controlling either endpoint, not just the log.

This assertion is both incorrect & incomplete in its scope.

There is no technical reason that in-flight capture is required to address those two points.

This assertion is factually incorrect.  There are quite frequently reasons to have both visibility & the ability to intercede into the traffic in question at one or more specific points in the network topology *between* endpoints.

This is network security & troubleshooting 101.

  Did I paraphrase that correctly?

No - the attempt to denigrate & dismiss real-world technical operational requirements is invalid, as is the dismissal of the administrative context of actual network operators in the real world.

The three points I made are independent of one another, & can be validated by anyone with a moderate degree of operational experience on production networks.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net<mailto:rdobbins@arbor.net>>