Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

Julien ÉLIE <julien@trigofacile.com> Fri, 08 March 2019 21:43 UTC

Return-Path: <julien@trigofacile.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C470F126C87 for <tls@ietfa.amsl.com>; Fri, 8 Mar 2019 13:43:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.121
X-Spam-Level:
X-Spam-Status: No, score=-1.121 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NEUTRAL=0.779] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YHxmxToTm5Dw for <tls@ietfa.amsl.com>; Fri, 8 Mar 2019 13:43:47 -0800 (PST)
Received: from denver.dinauz.org (denver.dinauz.org [37.59.56.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 541141224E8 for <tls@ietf.org>; Fri, 8 Mar 2019 13:43:47 -0800 (PST)
Received: from localhost (localhost.localdomain [127.0.0.1]) by denver.dinauz.org (Postfix) with ESMTP id 9105E6046B; Fri, 8 Mar 2019 22:43:45 +0100 (CET)
Received: from denver.dinauz.org ([127.0.0.1]) by localhost (denver.dinauz.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nCr5BFWjpeYd; Fri, 8 Mar 2019 22:43:45 +0100 (CET)
Received: from macbook-pro-de-julien-elie.home (2a01cb0800a77500e55ee6b556e83842.ipv6.abo.wanadoo.fr [IPv6:2a01:cb08:a7:7500:e55e:e6b5:56e8:3842]) by denver.dinauz.org (Postfix) with ESMTPSA id 569046046A; Fri, 8 Mar 2019 22:43:45 +0100 (CET)
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, tls@ietf.org
References: <154165491176.26419.11906807559515385277@ietfa.amsl.com> <62386296-c674-44ef-65b0-e3ced823eb92@cs.tcd.ie> <b5a4aa40-d169-cc26-afa5-2600274fdbcb@trigofacile.com> <80e995af-6fbc-fd96-6aec-586ac6b91e87@cs.tcd.ie> <82df11e9-d689-1a70-66c2-63b15b1fdc62@trigofacile.com> <03e56e20-9d47-7136-5810-a407ae22f79f@cs.tcd.ie>
From: Julien ÉLIE <julien@trigofacile.com>
Organization: TrigoFACILE -- http://www.trigofacile.com/
Message-ID: <b52d7fc6-0499-597b-6187-db0d392cd1b1@trigofacile.com>
Date: Fri, 08 Mar 2019 22:43:45 +0100
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:60.0) Gecko/20100101 Thunderbird/60.5.3
MIME-Version: 1.0
In-Reply-To: <03e56e20-9d47-7136-5810-a407ae22f79f@cs.tcd.ie>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: fr
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/YyjL6osmsIWl343sNKUaYipWyiI>
Subject: Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Mar 2019 21:43:50 -0000

Hi Stephen,
>> And RFC 7525 (belonging to BCP 195) states in Section 3.1.1:
>>
>>     o  Implementations SHOULD NOT negotiate TLS version 1.1
>> [...]
>>     o  Implementations MUST support TLS 1.2 [RFC5246] and MUST prefer to
>>        negotiate TLS version 1.2 over earlier versions of TLS.
>>
>> That's why I thought RFC 8143 was already requiring not to use TLS 1.1.
> 
> SHOULD NOT != MUST NOT though:-) And in any case, an additional
> unnecessary update would be no harm in this case, so I figure it's
> best to leave it as-is.

Sure.


> (Unless I'm missing some reason why that
> UPDATE would do damage, in which case, we should chat more.)

No damage at all.
You can leave it as-is.


> So, yes, I've added 7525 to the list of UPDATEd stuff in my copy
> and made a change of intended status to BCP. (I bet a beer we'll
> change that again >1 time:-)

:)

-- 
Julien ÉLIE

« Si l'art n'a pas de patrie, les artistes en ont une. » (Camille
   Saint-Saëns)