Re: [TLS] Fwd: New Version Notification for draft-pettersen-tls-ext-multiple-ocsp-03.txt

"Yngve N. Pettersen (Developer Opera Software ASA)" <yngve@opera.com> Wed, 11 April 2012 15:40 UTC

Return-Path: <yngve@opera.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04D7811E807F for <tls@ietfa.amsl.com>; Wed, 11 Apr 2012 08:40:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ldp0oJiNOa6l for <tls@ietfa.amsl.com>; Wed, 11 Apr 2012 08:40:25 -0700 (PDT)
Received: from smtp.opera.com (smtp.opera.com [213.236.208.81]) by ietfa.amsl.com (Postfix) with ESMTP id DF79B11E8074 for <tls@ietf.org>; Wed, 11 Apr 2012 08:40:24 -0700 (PDT)
Received: from acorna.oslo.osa (pat-tdc.opera.com [213.236.208.22]) (authenticated bits=0) by smtp.opera.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id q3BFeFwN002335 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 11 Apr 2012 15:40:16 GMT
Content-Type: text/plain; charset="iso-8859-15"; format="flowed"; delsp="yes"
To: Rob Stradling <rob.stradling@comodo.com>
References: <20120306124950.6304.36237.idtracker@ietfa.amsl.com> <op.waq2hefjqrq7tp@acorna.invalid.invalid> <4F835685.5060103@ieca.com> <op.wclt30g0qrq7tp@acorna.oslo.osa> <4F859802.6080001@comodo.com>
Date: Wed, 11 Apr 2012 17:40:16 +0200
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: "Yngve N. Pettersen (Developer Opera Software ASA)" <yngve@opera.com>
Organization: Opera Software AS
Message-ID: <op.wclxtenoqrq7tp@acorna.oslo.osa>
In-Reply-To: <4F859802.6080001@comodo.com>
User-Agent: Opera Mail/10.63 (Win32)
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Fwd: New Version Notification for draft-pettersen-tls-ext-multiple-ocsp-03.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Apr 2012 15:40:26 -0000

On Wed, 11 Apr 2012 16:41:06 +0200, Rob Stradling  
<rob.stradling@comodo.com> wrote:

> On 11/04/12 15:20, Yngve N. Pettersen (Developer Opera Software ASA)  
> wrote:
> <snip>
>> <snip>
>>> 17. s2.2: So OCSP is definitely used a lot more than SCVP, but it is
>>> the other status protocol. Should we just add it now?
>>
>> Could be; I am, however, unfamiliar with SCVP, but if the WG wants it
>> added, and I am provided additional text as a starting point, then I can
>> include it. Adding SCVP will probably require some editorial
>> reorganization of section 2, splitting it into an overall format, an
>> OCSP, and a SVCP subsection.
>
> Hi Yngve.  Would an implementer be permitted to implement the OCSP  
> option but not the SCVP option (or vice versa)?

In the spec? It should be optional to implement it, so it should be  
prented as an additional method that may be sent.

AFAICT, OpenSSL 1.0.0 does not currently have any support for SCVP.

Adding the possibility would, however, improve testing of the  
extensibility of the extension.

> My suggestion: Implementations MUST support the OCSP option, and MAY  
> also support the SCVP option.

Agree.


-- 
Sincerely,
Yngve N. Pettersen
********************************************************************
Senior Developer		     Email: yngve@opera.com
Opera Software ASA                   http://www.opera.com/
Phone:  +47 23 69 32 60              Fax:    +47 23 69 24 01
********************************************************************