Re: [TLS] Ciphersuite Recommendations

Yaron Sheffer <yaronf.ietf@gmail.com> Thu, 14 November 2013 21:00 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6601411E8135 for <tls@ietfa.amsl.com>; Thu, 14 Nov 2013 13:00:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.999
X-Spam-Level:
X-Spam-Status: No, score=-101.999 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, J_CHICKENPOX_21=0.6, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uQ52xb3Q5vBv for <tls@ietfa.amsl.com>; Thu, 14 Nov 2013 13:00:21 -0800 (PST)
Received: from mail-bk0-x22c.google.com (mail-bk0-x22c.google.com [IPv6:2a00:1450:4008:c01::22c]) by ietfa.amsl.com (Postfix) with ESMTP id AC58C11E810D for <tls@ietf.org>; Thu, 14 Nov 2013 13:00:20 -0800 (PST)
Received: by mail-bk0-f44.google.com with SMTP id d7so1310999bkh.17 for <tls@ietf.org>; Thu, 14 Nov 2013 13:00:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=fbIK8ddPAP3oxM7lmD6aP1hOKeKLK/ctbruuBzvFPEA=; b=j7fiCVHpd/rl73Smdqrfm5IFsAUBcP7onspQxzqcNLcBdvFmfVFKsoqxrW7Cn3L0di 1uY6cDZChDgacLA2yLZLYRgnycBuzNsuOS8PP57esp4ulKLfr4R9GWe798dBDnGyIXLq 16Q9yt53R+93jo+yNYbqdZXprSCWsF/koGc+raTigLewYBNs1bCZ7xOGuAQOoQFLwjOH neH3KMToTAZnV6ONPb7AVU66rslzkiy0iZkglCjs/xH1AeP7ZERxbO+Dshk5n1wUtJUf cLBFgnBHehQY9wEZRChVfgJtOJzNGQ2vE/EQaQVI/2dE7+xQdadvdeMHPRo9QIjkwZef 6Q2g==
X-Received: by 10.205.33.197 with SMTP id sp5mr740089bkb.87.1384462817995; Thu, 14 Nov 2013 13:00:17 -0800 (PST)
Received: from [10.0.0.9] (bzq-79-182-173-156.red.bezeqint.net. [79.182.173.156]) by mx.google.com with ESMTPSA id on10sm4794928bkb.13.2013.11.14.13.00.16 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 14 Nov 2013 13:00:17 -0800 (PST)
Message-ID: <528539E0.7050702@gmail.com>
Date: Thu, 14 Nov 2013 23:00:16 +0200
From: Yaron Sheffer <yaronf.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.1.0
MIME-Version: 1.0
To: Adam Montville <Adam.Montville@cisecurity.org>, Peter Saint-Andre <stpeter@stpeter.im>, Tom Ritter <tom@ritter.vg>
References: <05BCCEB107AF88469B9F99783D47C1D6065CDEC3@CISEXCHANGE1.msisac.org.local> <CA+cU71nfMXw+-SwkkqGYut8qxXKNeWnWNRbCSFrKD=5+=E1avw@mail.gmail.com> <05BCCEB107AF88469B9F99783D47C1D6065CE3D2@CISEXCHANGE1.msisac.org.local> <52853893.4020800@stpeter.im> <5285391B.8030707@gmail.com> <05BCCEB107AF88469B9F99783D47C1D6065CE405@CISEXCHANGE1.msisac.org.local>
In-Reply-To: <05BCCEB107AF88469B9F99783D47C1D6065CE405@CISEXCHANGE1.msisac.org.local>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Ciphersuite Recommendations
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Nov 2013 21:00:21 -0000

I'd certainly appreciate such a review.

The document was presented at the recent meeting of the TLS working 
group, slides are here: 
https://tools.ietf.org/agenda/88/slides/slides-88-tls-0.pdf

Thanks,
	Yaron

On 11/14/2013 10:57 PM, Adam Montville wrote:
>
>
>> -----Original Message-----
>> From: Yaron Sheffer [mailto:yaronf.ietf@gmail.com]
>> Sent: Thursday, November 14, 2013 2:56 PM
>> To: Peter Saint-Andre; Adam Montville; Tom Ritter
>> Cc: tls@ietf.org
>> Subject: Re: [TLS] Ciphersuite Recommendations
>>
>> Yes, this is our intention.
>
> For what it might be worth, I'll ask some of my constituents to review the draft and provide usability feedback.  These are operator/administrators who would be asked to configure their systems in a secure manner.
>
>>
>> Thanks,
>>        Yaron
>>
>> On 11/14/2013 10:54 PM, Peter Saint-Andre wrote:
>>> -----BEGIN PGP SIGNED MESSAGE-----
>>> Hash: SHA1
>>>
>>> On 11/14/13 1:50 PM, Adam Montville wrote:
>>>> Yes, that looks about right.
>>>>
>>>> I was surprised, actually, that there was no IETF guidance available.
>>>>
>>>> Anyone on this list think it?s a good idea to provide some?  I do.
>>>
>>> Isn't that what
>>> https://datatracker.ietf.org/doc/draft-sheffer-tls-bcp/ is doing, in part?
>>>
>>> Peter
>>>
>>
>> ...
> This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
>
> . . .
>