Re: [TLS] draft-ietf-tls-rfc8446bis - Security propterites - Protection of endpoint identities

John Mattsson <john.mattsson@ericsson.com> Thu, 11 February 2021 09:07 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A36593A13E6 for <tls@ietfa.amsl.com>; Thu, 11 Feb 2021 01:07:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.35
X-Spam-Level:
X-Spam-Status: No, score=-2.35 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.25, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rGL--Qhj14FK for <tls@ietfa.amsl.com>; Thu, 11 Feb 2021 01:07:56 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2081.outbound.protection.outlook.com [40.107.20.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA8A93A13DD for <TLS@ietf.org>; Thu, 11 Feb 2021 01:07:55 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EQTvi5P0J4KYHyDgFIizZW4SUovclPnAb4pQhmZmuY2309rRmJ+HrARW6WjY9EHkLwEuHCfFmMH7r1yoVbb9QU/F1IxuHtjVE+9rHiV+fD6Emya6xugSwIa5kLK7IboTyQymiOGejJ60ZoXqyqp9iIrAckN8CJECpybXxi9iRyUjF0lJV3tadigRg4H6gtyesZvSKkPEmR8vXJ1gnwRNP/v3sS18dV9vD0xYVRi8+jI9hcUvx6GnBcnFliYfJyiMkW0shkJo+vzoPXE5EJHBOWjkq5OAIo1u4dkXAJIqfnwfcbnXmq9srsa2E3DDKAt67yo29dImRoQZCcBvfZfrBg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8zdEht4ZctkxPCC8wg5lxocluAH+oTF9a/IcoQhhv5s=; b=V1VS599OtkAU6bJc5b53dqw7L7DYd6t9At0nTMOK58TJIx1o5ZvuX+Od/9pptlkW1Gjoljibf7mKokeRa6Dgk/WW4Gs2ZkEazq5+BzpE5TsZum7RN3lGgYKwyWqWBW6fdFG4kWwWLK9szP1sH4n+nObg/FANWk47kdehBpbxH1DUPuQaxwcOwLKcgmT77d/ifckAOyxgRc/eF2E9xJBggkYjAL5PRG6vg28w/97yElbIOqXsHoOjyjj98KmkzmTCr5wWLYM4k5IuB4MyL3UM3Nu+qRH9LHrTz1qP0Tcb+0v4n7MSBFRkNK5Hcdpz0FudopkLg6CLoCUt/hWxLERsLQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8zdEht4ZctkxPCC8wg5lxocluAH+oTF9a/IcoQhhv5s=; b=dwDFKN4982CMgzznKJPY8qcIddcg+rQ2Hj5XrQUrLvIGvLPRtBwT3YK63lJKy/PBGalMVcxLcHatazrFqug4Pu+G3J80TQTWfqE3FPpdPMndUb/FKJVizn0fSGtD/wRVJgif5OZV9zqTPw6Mfn/jrGrIb6sPSDt1hqsyzV7Sam8=
Received: from (2603:10a6:3:4b::8) by HE1PR0702MB3564.eurprd07.prod.outlook.com (2603:10a6:7:8c::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3846.25; Thu, 11 Feb 2021 09:07:44 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::c555:6e47:970c:1268]) by HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::c555:6e47:970c:1268%11]) with mapi id 15.20.3846.027; Thu, 11 Feb 2021 09:07:44 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Eric Rescorla <ekr@rtfm.com>, "Salz, Rich" <rsalz@akamai.com>
CC: "research@bensmyth.com" <research@bensmyth.com>, "<tls@ietf.org>" <TLS@ietf.org>
Thread-Topic: [TLS] draft-ietf-tls-rfc8446bis - Security propterites - Protection of endpoint identities
Thread-Index: AQHW/43NdDjKffLd90a2SEyd7cXv76pROzWAgAAvyYCAACR0gIAAEqkAgAEaRAA=
Date: Thu, 11 Feb 2021 09:07:44 +0000
Message-ID: <03C7384D-4FE9-4978-A6E1-40348F02E194@ericsson.com>
References: <2CBD606F-E391-47DD-AEBB-1673D57752D3@ericsson.com> <CA+_8xu06Aq=bGuP6iJ9g=wVoA-L2aW-3HLfMJctbKpLBw9Ou_w@mail.gmail.com> <CA+_8xu19_ZpYheMh0RQipEFw0-z5ZxBwFCZRgerBX7gLGx9gaw@mail.gmail.com> <59192368-E39E-43B5-A369-A4CE65609752@akamai.com> <CABcZeBM9NEDXiWrFcc5yH6bvrQBTVJDw6HNkytKELqze+-W1tg@mail.gmail.com>
In-Reply-To: <CABcZeBM9NEDXiWrFcc5yH6bvrQBTVJDw6HNkytKELqze+-W1tg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.45.21011103
authentication-results: rtfm.com; dkim=none (message not signed) header.d=none;rtfm.com; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [81.225.97.222]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 8e8b0b94-9e5c-4a5a-093b-08d8ce6c7e7b
x-ms-traffictypediagnostic: HE1PR0702MB3564:
x-microsoft-antispam-prvs: <HE1PR0702MB3564923602AEB2DC7B70A031898C9@HE1PR0702MB3564.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:6108;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: InNQN6Uc5bAGUZC7oHDhVz5F8SRiBJADv1m1Nww5DQMYZsygPEZeRaImzDtJKXKM2RBdP0gL3iHnbJxL8ut32WsOW04rgka8ILz0Jnn5/ZhzawfG0xeK+84m3oxk+hq7m063du6KOgQDWkG3KjxQPYuPrS/NVfPQJeoPaJIWy1BK3nG1ImcX8cNGb7wirg6cZM9zTRxykij6tBwpnKMbdh9kntEBB8jHGxulvi6UiY4fJM9mv7Rwe5J9kFKyo6XX3jmu6sJbehOEOU5PpTpY/7qaug8PlLw7GWxAyL2PFQsBBDGwTqmhd4z915eoi12OM+cjTeFhyjawjyKCYwXoQrBlZnl+ditkQilXudWYNCNNDr3lrGdjBdNdzlNCCBEKOFvzvVgPR1m+IeIW2ig5B9n7elO3VGkdsirKHwXmE4zSCF7b4gdc11ejU0FdlmcLcyDmYKaBWIIlTw8gQsx38z0O718cAR4LhVEeyBb4X5XsgNuGIMTttMEhk0WS4W28xrTBF4IZAiaheYoyatIpQMPdig+ZN2sMZ7SS3xEtEQqx1268NM1XfTf7xdp/tStR0EFXzpOecJi3Irbt9FJmyHLZwfZTP1oArjtZ8Qv1P6S9CfC8SqQ3cV9aWIMlZtJjIC9Dnzc93ezEf0aNn8cMvA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(396003)(366004)(39860400002)(136003)(376002)(36756003)(86362001)(66946007)(76116006)(478600001)(5660300002)(83380400001)(4326008)(33656002)(71200400001)(166002)(316002)(44832011)(110136005)(66476007)(8936002)(966005)(66446008)(64756008)(66556008)(15650500001)(2906002)(2616005)(53546011)(6506007)(186003)(26005)(54906003)(6512007)(8676002)(6486002)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: Uri8tHNALn8zk/+1q2h9rPowvoDZweNP8WMKTa28IwKaEHbdZe5HaDvnK26A6mg1hsL9sVdz+5T1fVhj+SsrCWw/v3PvuVz1RTAd48U6ZbYjBiJ3IBAz403t1MZbHbnmjFDfjRRwzGEt/Q+jluEfa30KZwAlQ+EdeRsHlITZXS4aYG6CqChsDw+IEHsO1h133ImSVFDqpQuOdqzr5D8LKJDEqrDb8rq2GvibnD6sakdNGksjlUFuQxCOpYG2vPTi52e4u61OTKRQkJ7ePLRon2wcanvt7zRLAuw1gTiJYq9FDWdt2MXkBlwXy6bIJi94WHZuV0EvKaVC6UWBT9AQ8sIPPAySMWCO0vNgrkz5GDkGiKxjizRJWmEi8XqWK7SNvuUUiqVQFoq28a7XwJu/Ut3hrPcSXq1lFlDyodZ7KWKAGVWfutFUQy336GJQKtuCMQGjoVm25Ian2UYyorj+9VK5FFpcaMEtjnEMq+Uh5p2yGRPUIEEi+82GFIBqg/vuKs9bQLm5WlZQVn/IqSmQ/bJH+ZnAwnxxeyVzlAkZSXoj+O6LsyfI+AEX3jyk9Q4qp9IMjB62LYcVE15vICxj/Mv4Dxk2bJyqbPjtHOHVXuxlRSAwMlIC20hXoKM5Q0JGmSqZgBaW3IT9mlXyDkbDo4nEjTOayJMsig7PinW24TMPAWUXL0hLmZVSzJrE2ejkqO5Ndkn9cJYsEAcicRAyQrN8AVWq7eMXGmtbPs+zp7NAObvZIfUmnEM2+I6aqdEqVQb77KPXr6crkcQD3hTSjS+orIS7Rpc60gWEP3Okx8QFfoZ/BOaN04xN934FvPIDubyIPX7uik09YTL+RkziJWCVu4r108qBnZ0+QQ/Wou/6cdhzqEnWrkhCHbtCBongTCqi83IKEbeOOSKqvVS23AAFmLFgNqU8I0vZ0o/AVUqqBqebRa1bi6kan9t/u0IC++AEqTu2yIi59QhbKa3I/9RoZ+1Aq6AMAPdeRtEDU6nLPcuBEfNVimdjpCL518NIc1MYQxc1lWgaK5GOKRgMDlO2p/11gPOvsCVirASgFs73SiyvkcaPmM5YhCDMhBFNwjdnKbh/TDP5zwQoVp8wz8j098RE3LcPvRwg/rDYABlCmWaDlxCMughsAQ6DZJb0M8kUh119QoUv9hwPjBnFmirJfGHNHRiGCIFMBZYXUv+f8sXDt8/hyzE0xqvcVxbfXymDvTic6uMxK3O6ceJoK6YQrRp/f8rgkpn3BhAkI7mw938lvgcWbCu2/ZkrylOf6qjZ5bZt6eApPPeMoxMdEyX54uGu//fIbL609uMkE9ZOVqxgCPV6paVKn3RFcBok
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_03C7384D4FE94978A6E140348F02E194ericssoncom_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8e8b0b94-9e5c-4a5a-093b-08d8ce6c7e7b
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Feb 2021 09:07:44.5538 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: EfSopFIztZdCEbkETUasqtuu7o5NAWGouGfFLzdkcHcLbb0ss+5P8v7ehega47HZOXauazmUdFw4VwZweyOP9DPK1DTjIvM8blvQ1IQK824=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0702MB3564
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/X8_vvN7o1GvKn0v3zEbN40LxtO8>
Subject: Re: [TLS] draft-ietf-tls-rfc8446bis - Security propterites - Protection of endpoint identities
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Feb 2021 09:07:59 -0000

Sure

https://github.com/tlswg/tls13-spec/pull/1210

John

From: Eric Rescorla <ekr@rtfm.com>
Date: Wednesday, 10 February 2021 at 18:18
To: "Salz, Rich" <rsalz@akamai.com>
Cc: "research@bensmyth.com" <research@bensmyth.com>, John Mattsson <john.mattsson@ericsson.com>, "TLS@ietf.org" <TLS@ietf.org>
Subject: Re: [TLS] draft-ietf-tls-rfc8446bis - Security propterites - Protection of endpoint identities

Agreed. With that said, I don't think it would hurt to add some text. John, would you like to provide a PR?

-Ekr


On Wed, Feb 10, 2021 at 8:11 AM Salz, Rich <rsalz=40akamai.com@dmarc.ietf.org<mailto:40akamai.com@dmarc.ietf.org>> wrote:

· Previous versions of TLS explicitly offered a null cipher (wherein encryption consists of the identity operation, i.e., the data is not encrypted). These modes have been deprecated in TLS 1.3.

These modes have been *removed* in TLS 1.3  Further, the only ciphers in the RFC provide authenticated encryption. I think anything that doesn’t provide that is going to get an “N” in the recommended column FWIW.  I’m one of three experts for that registry.
                /r$





_______________________________________________
TLS mailing list
TLS@ietf.org<mailto:TLS@ietf.org>
https://www.ietf.org/mailman/listinfo/tls