[TLS] Re: [Last-Call] Re: Last Call: <draft-ietf-tls-rfc8447bis-11.txt> (IANA Registry Updates for TLS and DTLS) to Proposed Standard

"Salz, Rich" <rsalz@akamai.com> Tue, 18 March 2025 04:53 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C444AD814E2; Mon, 17 Mar 2025 21:53:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com header.b="iprYfJQg"; dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=akamai365.onmicrosoft.com header.b="g+uQClTN"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HuFwAGgFBHaa; Mon, 17 Mar 2025 21:53:16 -0700 (PDT)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) by mail2.ietf.org (Postfix) with ESMTP id EC222D814DB; Mon, 17 Mar 2025 21:53:15 -0700 (PDT)
Received: from pps.filterd (m0050095.ppops.net [127.0.0.1]) by m0050095.ppops.net-00190b01. (8.18.1.2/8.18.1.2) with ESMTP id 52I3051a031076; Tue, 18 Mar 2025 04:53:12 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=cc :content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=jan2016.eng; bh=3U4bVDJIwjBBz1D6DdyINa Tllf/AaWBVQACvaueuuFA=; b=iprYfJQgXAOqcGaMiJUN4Yjc1k/tfH/fVc2kmu KTTt8AAaHkNiJJvPrtzv+ROQnyFjJFs9RL6LL1yozRB/VVoSvvoI6ayiwyWev9Wj b7zM+k4KMmfNMeriTOh2voaEX3l7s6nymWFoJoIz7SLG+gdZGc3u6B+H0+8P9YrY WzNk5tqi2xRcw4d6SEN10y0s2OI3a1vvlwI/2+P6YDzGZogJ2S1m7W6Be2IJhbY6 noEbqAYiwYqeXC2AqqI331lE2/83KwFtBlIkW9xW5cF9vJSmhd3DmGRgpHyu1U7y Oi5+Y+tMOcNzFomzLp93xCNNrcJuoVw8x/v92Qdq/W7Oo5qg==
Received: from prod-mail-ppoint8 (a72-247-45-34.deploy.static.akamaitechnologies.com [72.247.45.34] (may be forged)) by m0050095.ppops.net-00190b01. (PPS) with ESMTPS id 45d1yf13kr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 18 Mar 2025 04:53:12 +0000 (GMT)
Received: from pps.filterd (prod-mail-ppoint8.akamai.com [127.0.0.1]) by prod-mail-ppoint8.akamai.com (8.18.1.2/8.18.1.2) with ESMTP id 52I1EFER013697; Tue, 18 Mar 2025 00:53:11 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.205]) by prod-mail-ppoint8.akamai.com (PPS) with ESMTPS id 45d4vww1dy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 18 Mar 2025 00:53:11 -0400
Received: from ustx2ex-exedge3.msg.corp.akamai.com (172.27.50.214) by ustx2ex-dag4mb6.msg.corp.akamai.com (172.27.50.205) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.14; Mon, 17 Mar 2025 21:53:11 -0700
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (72.247.45.132) by ustx2ex-exedge3.msg.corp.akamai.com (172.27.50.214) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.14 via Frontend Transport; Mon, 17 Mar 2025 23:53:11 -0500
Received: from MN2PR17MB3901.namprd17.prod.outlook.com (2603:10b6:208:1f6::24) by MW4PR17MB4290.namprd17.prod.outlook.com (2603:10b6:303:73::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8534.33; Tue, 18 Mar 2025 04:53:08 +0000
Received: from MN2PR17MB3901.namprd17.prod.outlook.com ([fe80::7515:e7d8:ada3:1849]) by MN2PR17MB3901.namprd17.prod.outlook.com ([fe80::7515:e7d8:ada3:1849%5]) with mapi id 15.20.8534.031; Tue, 18 Mar 2025 04:53:02 +0000
From: "Salz, Rich" <rsalz@akamai.com>
To: Paul Hoffman <phoffman@proper.com>, Joseph Salowey <joe@salowey.net>
Thread-Topic: [Last-Call] Re: Last Call: <draft-ietf-tls-rfc8447bis-11.txt> (IANA Registry Updates for TLS and DTLS) to Proposed Standard
Thread-Index: AQHbl8A54e/DTlclNE2YsxWj2L+NLrN4Uh/S
Date: Tue, 18 Mar 2025 04:53:02 +0000
Message-ID: <MN2PR17MB3901536C5B46BC0C10D681C5CDDE2@MN2PR17MB3901.namprd17.prod.outlook.com>
References: <174184001345.838119.1665635750501653391@dt-datatracker-775fc5cbb8-824tp> <6BB43AEB-CF42-4FE2-998A-DB85B373D464@proper.com> <CAOgPGoBg33o7N95PSue3KMwaOz=DcaP7tnNenX=WYQ_jitAyYw@mail.gmail.com> <492866DC-4B28-441A-87D9-54E27A7B02E1@proper.com>
In-Reply-To: <492866DC-4B28-441A-87D9-54E27A7B02E1@proper.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MN2PR17MB3901:EE_|MW4PR17MB4290:EE_
x-ms-office365-filtering-correlation-id: 75b56939-4aec-42b2-1403-08dd65d8c3a7
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|1800799024|376014|8096899003|38070700018;
x-microsoft-antispam-message-info: IWvNLuwywb83zVBsTB5xFPH/N2d/BLb+wpealyVVsfd7ntHp6lbMn05qLh8tHa55HOWWtW12dv+gLnjDBl0ucPIVj8+/JIsrPHsS7upHeJJ2oba8DnPbWPqvy2qOVviknVMcJ8jNS9NH2QemS1vYMBUL6jIYvhkNGeqftuWC7ZfO+UyDwAB3vTlu0NeLR/1X4XyN3eQNGo3rkJS/YS84uusvSBbGO85IioAw71oPX3JMI7BZ07SCCuXAuuNZB2np3+ii8q3ogAslp02BrjoM5AJ3GRBwqCB1Y5ok5Mlnji7dL/hEnjN8Ho5RxZnZJA2B6cnmrTPmQnq82iUle+nDYpbZPXprZC9bveyID7qAMQCGo6u2VqxxVgG3xW9BgU73fLHwNr0V65c+L43sQ2ADeE6WJ0+02AoYmy7JlzbIQr3/2KpPQYmNy9lf2Hgtp7RZuzfg3BFwEimDbPZgjmeCZFaCrNPycnjXRF7hWOCbN1cgDNvqfFYP3t3syCpwhiv0UXIkL1PRoy9dMrJ1OgETDuFhKdBr3YM/vZmX+VgaDASYQopxcpPNjrE+m4BqF/uxYiKZ5R9AQQYyuvfb7SwGWj8GAGAbCJjRp3NORdC0jfcELIeshq6lWFA71EdjmtuGj/EPppj081zPuL3c79tvDoB2N6ybOwurSn+YdFgWAsTGxbXk0sECbFZI9AqUHa427G9eBzyV51UzXyDSKW0IwhdmPJNAeJTYUnRgrIQj066TE0woRgzDXXjfZfKj3gOLjKhO90tUrPE+zvlHRcJ/uUfU0JrUylIa66WNS/dTTFXtSEei3C1eZF+ErS1R17NwUEXoWK6QVeVbZAGJvKqurS0QhAot2cnD+uOHVJUX+eXD2dgAArle0/mbYSDFnNHam53hueb9ttzj4E4kGzLeV5yGUOUgrkOnHYkqeaRlTXPgD8I/A99/PPOOR+0+oLmeYnov/dHK/nySHmj/1IuauT2wh4/0irpr0B2bgWB+OnkT2PuzsbeFll8yYkK4vB5sxY2b7h6yOoIs/aouFuaoLYm7kIufPRgrC934bq+/1WlTPVFEfbe8bXKCYYnwxL6lcXnV/OdolMt+0YJJQq0Lg9L/CPiseHKBBCXF/Tzl2pUGqhYcaPnBaf1bXHo/OSM58wIdC5KcReXQw3HM3kfTinrHIPsgdwfbaTJYhFr66ZBtoZqrh19z4HYtivRB7zd/62u5u5yf9CrUkXuKE2O8zY6KOOTKRiYAnwAVj5UmvTEJ09HaQU/73dNJQNAlEcZaJXpEKCMHswcK5qHsT67B6nqYjOKJ0Inoo6Q5YyWLYNsTsGzi0+JMumisLicujJeyJxKWjjS//cOgK9GeG00BxBDSmegWbzUbuwjvYwLunSmhk42B3DlymOz/NxCVfaJgL95b4i4pb7xpJkutiSrCmRa87kLiNM2Dnrev0nFsurLEXe38mRCQ2HSfW710ITcs
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MN2PR17MB3901.namprd17.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(8096899003)(38070700018);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ++sjMownk3wfMnODo9yOLtfXQ9+/QqwMh5hWUZHK8EOcoh39muBmP6RQ0fxeBvKlHquUZoQayv8bz/N7ZHYaKeceACkFTXNlTQZWbh02S3+qgjUYBc92z0JRjfXNfBjNb8En0nAiJb1uQW3/wIF/sMcqY85dyQQtj2sVdtEHoSWGDPFTHIvyU7KN7ObSATy8n6yO868t6xSV7rDyCOHFjkqTS8XMOUqCFQ9+m44EKJgPrrwULf/yNg9jMfJwWyaNv9AgvObAXX8W4Il9/Kf4U1KjB61NiDSjXuxUfV6eguWXx5RYni9puIdGwfHr6sE+Nk93hG2tJA3G0MFJE8y6WMUr/UE8I8yObnXglINHgaa4/wZivp8xtC1KnOT9xFwJqy42hxAk3jPrh7eCIsk/ukXo1F1cDJBaVnoBTAlbIxDGudiBwVNconEWJAJzEnsigqoosIF/QYBnJA9MnyuDuRSkAILazQtKjzl/wTgwZKAUeMo5NnIk5Aboib1cK6d+sCi82ScNHTUllMeEdtLai4O+TuzbP53kJWekNxLCeq2QoyJCUAFSkFqCU9DAfYbO2ueFrW5fEAr624rCiXlo9dXXzRVKruBq+DNC02QBkVhKWQ5bbsvs/8iXVrx8K8xwSAQ9fklwoKYzfB94cq/1EZF00KRPJFM9yxBVyHLpYlL6XINRwI/IWM89UMGHLYPBxEIDj0iyyJ+iEXxIB0ca4Ar4grT0ZLeNMpsx6RpWH6/Nh6PjH9oaMBgeBjPaVtzQgKXKgkKIStyEMAJKkjMBQQD/L2L0Gs//veboNR+LDttkI75NmyAjL1yjdZFn2c1/vI/p12WgsQ0yxV7/J7ueTu3DFwFRU/gPxEm2923M4RcoJZ7GyqydRxsYLC23A+ITxSXh5EDtdUAkn413o7Gz6ZvS5i8iOgLtMey23cQHlHcGBeLmT081sLPLlq/wfyZ4vwK/w/nncdhtMES1i4+cvFDjFfgpkyo5WrDQzvkKqf7a+E4ERGO28DhiXR6KqjGDX+y1ZmDJv4gUHa0efekAocXI6FgV1PRgY9teuFFYUBjSmvLVMNbjrnexMLCl4O+IQyIfl8juM0KWnOWxD8GJL7VKiY+VEO3qXbKV9xSXBIlbMI/qpffRBcXPfbaYNOpM2Q7QypMy7T1MAgDWZtcKOl/RqF8q7oCOlfGpgSMvfJGCIEswZptMS5FIzKng4ofOPOnT/ItfmGZfeVsvfWagN2k3M7ICUgohzRMmH6M5LGXi/D2zQGQuQgwCTRNozmypjj4Xk24Ee7JPt6IGwJJP2r648yT9KL0FftYFFZz34AE5to+MTvAaSR5K97oINtW6qra4+W8GkiwqHd34PH9ozIupJK5r2gpq/eJSX76v05cuDQXGqqyAr8EkDSZLu8e5irz9XPR0s+8Ul09yUqe3JAN1mHpnGh71rGc8I//s0Uziq50PUvHkIYQi6OKbls3q7Q8GB48wTAPYH0SrPFwCIRxGqK9EeTcvnTLNoB+VP13lDxNLgMe2pk4qfa7GDlSl/CtylaqEMYYPfggM12EIC92cioDSq0FXfL3ZLcrOqL6rsJ+ShVz93dZuUf6Vs0/EhljtcAQsWxpjqPrU932F+A==
arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=I+8T4kNcoi4CJ4SR6G7CzyecrmFOE/k3QsaDdL2VO+YsBxOG2eiqogdqESS49XAmCVFIoMa80Fdd+DsG5FsBtFpZv8L8INjbS/AL2+ESee+GfG8yc2RGMVjRp65BmqAOXoIG4/cAWliCI8Xptb5ct/fS/WigmCQUVKtAVVPPTWe5aJMghospQDSOb7qeT8hMZhCNQlfbT3Z9JmooCRWFBpvm3tw0t+XiOaEHxfK98kiFLad2sDD6D6ZG0ap7NyjVZ+VMiN17mm11yr/i7gMIA6/KyxUqPDlryEV1jNpcbkxA6o0VGuFXjPgEchYYV7VUGoJk7rgSlYt4urpoON+xlA==
arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=826LQ+ZI058fLpWQbRlAYWJOmrotj8oHZWqT/Eciyc4=; b=ukf63cA7mEzF0cK8KWJR+GP6jAVvhmZ+/xmCSFx24xaOydQL78OLFJSJ6fLYDpfl3dVQDRGlflJjp5vrLT5SYeq+Ks1MyMmV00iQPzt4N51YIgbomvv89x5h/0YAl2iGaJ3Ql/qnEeQ2AICli9l/8r5GuYFo/p2/uA7gyPeNCfTHIoIESnAVh/slWQZrQRZ1TB6Pw/RSHlJDwr1dSDcFbWGkTf1MZmq52TCfn6K741cGNlehCCt1jKoHlR+sl7KUfXKcdFv3p7noTXBFumF34fYCvAJq9A11oedti5mnp6RQQa0L7VLzItVrDb8ICn1SvvYpVgnuzpu0GVf4z0DHSQ==
arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=akamai.com; dmarc=pass action=none header.from=akamai.com; dkim=pass header.d=akamai.com; arc=none
dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai365.onmicrosoft.com; s=selector1-akamai365-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=826LQ+ZI058fLpWQbRlAYWJOmrotj8oHZWqT/Eciyc4=; b=g+uQClTN96oASZTK24ldmT3NR0Yhyo3L0mG1iMpY9I577rrwTbiZ2TdXdpRI2yYo/OnOyUniv9s+W0yLDFbwSsSz3ceUcz8gWoDvBCngt2ky/iXHextcghCzPhHeqYrZEbBxUsPo7tzQp6cKQmH4aog3UrAtmrIMTYqbVUJrYpQ=
x-ms-exchange-crosstenant-authas: Internal
x-ms-exchange-crosstenant-authsource: MN2PR17MB3901.namprd17.prod.outlook.com
x-ms-exchange-crosstenant-network-message-id: 75b56939-4aec-42b2-1403-08dd65d8c3a7
x-ms-exchange-crosstenant-originalarrivaltime: 18 Mar 2025 04:53:02.5771 (UTC)
x-ms-exchange-crosstenant-fromentityheader: Hosted
x-ms-exchange-crosstenant-id: 514876bd-5965-4b40-b0c8-e336cf72c743
x-ms-exchange-crosstenant-mailboxtype: HOSTED
x-ms-exchange-crosstenant-userprincipalname: HB6eHm/tmeGnntHYUlRrgnJsBWjBrH+VRBzZB7p8D4vzpwqqCJ9KRPohe1LJwgDlAdfnMu9fTpMwJemEmEYxeQ==
x-ms-exchange-transport-crosstenantheadersstamped: MW4PR17MB4290
x-originatororg: akamai.com
Content-Type: multipart/alternative; boundary="_000_MN2PR17MB3901536C5B46BC0C10D681C5CDDE2MN2PR17MB3901namp_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1093,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-03-18_02,2025-03-17_03,2024-11-22_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 adultscore=0 bulkscore=0 malwarescore=0 suspectscore=0 spamscore=0 mlxlogscore=999 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2502280000 definitions=main-2503180032
X-Proofpoint-GUID: tj9BEph2sdcHomdrUMcZubrhhOJzSkQW
X-Proofpoint-ORIG-GUID: tj9BEph2sdcHomdrUMcZubrhhOJzSkQW
X-Authority-Analysis: v=2.4 cv=TMFFS0la c=1 sm=1 tr=0 ts=67d8fc38 cx=c_pps a=YfDTZII5gR69fLX6qI1EXA==:117 a=YfDTZII5gR69fLX6qI1EXA==:17 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=wKuvFiaSGQ0qltdbU6+NXLB8nM8=:19 a=Ol13hO9ccFRV9qXi2t6ftBPywas=:19 a=xqWC_Br6kY4A:10 a=Vs1iUdzkB0EA:10 a=g1y_e2JewP0A:10 a=IbRyc3QlGgXcGsZS864A:9 a=pILNOxqGKmIA:10 a=yMhMjlubAAAA:8 a=SSmOFEACAAAA:8 a=cKB1WfSZYh3G-N67:21 a=gKO2Hq4RSVkA:10 a=UiCQ7L4-1S4A:10 a=hTZeC7Yk6K0A:10 a=frz4AuCg-hUA:10
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1093,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-03-18_02,2025-03-17_03,2024-11-22_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 spamscore=0 lowpriorityscore=0 mlxscore=0 bulkscore=0 impostorscore=0 phishscore=0 mlxlogscore=855 priorityscore=1501 suspectscore=0 adultscore=0 clxscore=1011 classifier=spam authscore=0 authtc=n/a authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.19.0-2502280000 definitions=main-2503180033
Message-ID-Hash: ZRAEVI5VRQLMNJ74K26SZKAYBNXVIKLK
X-Message-ID-Hash: ZRAEVI5VRQLMNJ74K26SZKAYBNXVIKLK
X-MailFrom: rsalz@akamai.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "last-call@ietf.org" <last-call@ietf.org>, "draft-ietf-tls-rfc8447bis@ietf.org" <draft-ietf-tls-rfc8447bis@ietf.org>, "paul.wouters@aiven.io" <paul.wouters@aiven.io>, "tls-chairs@ietf.org" <tls-chairs@ietf.org>, "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [Last-Call] Re: Last Call: <draft-ietf-tls-rfc8447bis-11.txt> (IANA Registry Updates for TLS and DTLS) to Proposed Standard
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Ux7vYWtFhpijz9cB7Mc9uIIiMDI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

So, again: This draft should either be expanded to say what TLS clients and servers and configuration SHOULD / MUST do with D-level components, or tell readers why it is not. Telling developers "go look at every doc that is liked from a D-level spec" is likely to cause them to not do so, and the result will be insecure implementations and lack of interoperability.

I think it is good that the draft says “we discourage” and that’s good enough. The whole point of saying discouraged is that it doesn’t rise to the level of SHOULD NOT.