Re: [TLS] [ECH] Reverting the config ID change

Christopher Wood <caw@heapingbits.net> Tue, 16 February 2021 13:43 UTC

Return-Path: <caw@heapingbits.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 764CE3A0CC3 for <tls@ietfa.amsl.com>; Tue, 16 Feb 2021 05:43:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=heapingbits.net header.b=eypIr28C; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=ivzp97xg
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JH8N8KWzB_SH for <tls@ietfa.amsl.com>; Tue, 16 Feb 2021 05:43:54 -0800 (PST)
Received: from out1-smtp.messagingengine.com (out1-smtp.messagingengine.com [66.111.4.25]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A9A063A0CC1 for <tls@ietf.org>; Tue, 16 Feb 2021 05:43:54 -0800 (PST)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 578795C00DB for <tls@ietf.org>; Tue, 16 Feb 2021 08:43:53 -0500 (EST)
Received: from imap4 ([10.202.2.54]) by compute4.internal (MEProxy); Tue, 16 Feb 2021 08:43:53 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=heapingbits.net; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type; s=fm3; bh=GEQ1/TFRMgqMbPyyFIlKBtioLcUzZK4 UrBD2c0qciyU=; b=eypIr28CWcX5Jrp6qFB3+I4N/GNxuMxCAZY9VJ8GFx93wDy HC9HkzAeEEBz58JeQ/h4H7GII+l7Cek3lDmBQfr3jJhkWEj2KGbMurq+2RyKOoyU Xn3j8+8ikeZgfz2R2lWLE6C9eq/x9lc2xJlpN3u2oK6261ALYrV0urY7zJQbMKql qSiufKwm03ZPdR0FVkdMQTaKlD2VtU1UH0cTnfnbz2BtDzzD3BjdhwdedprHy3wK nhE1IglsyDK53H5qK4ejZzd/5yAfofOsvNz8CgBprixLqICSSWAfgLLr4tfFQ0K0 7PZ+XYr5PBogTPvFQWWzXXoi1DdprGOf4mSt2sg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=GEQ1/T FRMgqMbPyyFIlKBtioLcUzZK4UrBD2c0qciyU=; b=ivzp97xgEgQWYsYVKjxACC 9mD+ZYu3+p7lcYauyPcMrtCyWPT4VMPl72+FTGPGTRzcGYknaZSs4gDcagjhCBFz +agShGhbhtto5J9+KvBfiq+1uSVO3hbVkXKCECGcAx7TJKImoTOhKTz/gthBDzOm TpYJBBffojFdVb1G8UaUwVlyJV5LqGvu8bVTL0Lk63wwCxxK9c2khtMCc13aI5QB RmA7CfjPC0lbXMNTmkFUAPd/39OQYPV1enW3XRpN9ptm5kSGTMZ48EyeAF9tWiSC wkkXiIn7kWYKSGR1DHVeEd+SNKpmbs33GmWkxG2ldQ6S2DpmAb7gxzanTabQ6zjw ==
X-ME-Sender: <xms:GMwrYMc9QnSWbkfkT0OGiUF9uaBNIt9uq5h0d8LMyWrNU2TfC3dctg> <xme:GMwrYOMzH9FBoDIpiDxiC5F7cYdQZF4RMFO-qA3qcZHJG8e2vgo-kfsHO_sFWyv9r CMpkeczdYbHffcCUac>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrjedtgdehhecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecunecujfgurhepofgfggfkjghffffhvffutgesthdtre dtreertdenucfhrhhomhepfdevhhhrihhsthhophhhvghrucghohhougdfuceotggrfies hhgvrghpihhnghgsihhtshdrnhgvtheqnecuggftrfgrthhtvghrnheptdffueelveefle ehlefffffgleffjefhkeetudfhueelheetjeehvdffgffhueelnecuffhomhgrihhnpehg ihhthhhusgdrtghomhdpihgvthhfrdhorhhgnecuvehluhhsthgvrhfuihiivgeptdenuc frrghrrghmpehmrghilhhfrhhomheptggrfieshhgvrghpihhnghgsihhtshdrnhgvth
X-ME-Proxy: <xmx:GMwrYNhhi7kTkiPxcGY2w3Ira1M9cTW__wmGZw-TngtZzM-CAPDgoA> <xmx:GMwrYB8lRAJpRAY5MEk4ZHoXq1jLMkfoaEEVKduDztJo1buQKSTqaw> <xmx:GMwrYItsNYdbM6iXSHqPAXSkmakPq3Tf-uz_vz53zj4QH2zyUQ5kBA> <xmx:GcwrYG76-zP6Diz6J3Nxrk-YfNF1ZWOcf_qptuf3GdJmpWhUUrwmxw>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id D4BCF16005E; Tue, 16 Feb 2021 08:43:52 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-141-gf094924a34-fm-20210210.001-gf094924a
Mime-Version: 1.0
Message-Id: <7925717a-bcba-4b29-b12b-b47e622c62b3@www.fastmail.com>
In-Reply-To: <e44be9d1-bd0a-4e99-b092-b1b21c517b0e@www.fastmail.com>
References: <e44be9d1-bd0a-4e99-b092-b1b21c517b0e@www.fastmail.com>
Date: Tue, 16 Feb 2021 05:43:32 -0800
From: Christopher Wood <caw@heapingbits.net>
To: "TLS@ietf.org" <tls@ietf.org>
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/WIPySmyzfvOEZbGFWu8KeMRUYb8>
Subject: Re: [TLS] [ECH] Reverting the config ID change
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Feb 2021 13:43:56 -0000

On the heels of this change, here's another PR that I'd folks to weigh in on:

   https://github.com/tlswg/draft-ietf-tls-esni/pull/381

Thanks,
Chris

On Mon, Feb 8, 2021, at 2:29 PM, Christopher Wood wrote:
> We previously had a server-selected label for the ECHConfig, but that 
> has since been replaced with a client-computed identifier. There are a 
> couple of problems with this change in practice (see [1]), so the 
> following PR proposes reverting back to the old behavior: 
> 
>    https://github.com/tlswg/draft-ietf-tls-esni/pull/376
> 
> There is a separate issue [2] regarding the length of this identifier, 
> but we can address that separately.
> 
> Please have a look at the PR and provide feedback. We'd like to merge 
> this soon. 
> 
> Thanks,
> Chris
> 
> [1] https://github.com/tlswg/draft-ietf-tls-esni/issues/375
> [2] https://github.com/tlswg/draft-ietf-tls-esni/issues/379
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>