Re: [TLS] draft-green-tls-static-dh-in-tls13-01

"Roland Dobbins" <rdobbins@arbor.net> Mon, 17 July 2017 19:29 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 25EA7127B57 for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 12:29:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QJIMwswi0QfN for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 12:29:22 -0700 (PDT)
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (mail-dm3nam03on0126.outbound.protection.outlook.com [104.47.41.126]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28463120721 for <tls@ietf.org>; Mon, 17 Jul 2017 12:29:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Re4OsVuCmIc9qYkVxr/xXkQ1MPNNuCpSESu2roW9MOs=; b=PPSGVJ3yxiEjUEzYk0BWFFnNLlBGfksJoD0TNX8fZ5gMV6z7uCeX+bgwXHnwkL0VLfH1iSb3+jACsaOphC1bmDeZ0M8Wl+baG9kkzC5euqUowPAA1Aps+cF/EyvAt5AZCzHRPNufyQsJm4A2gxOsRKHN/l8hbb2GxcQapyMUV8k=
Authentication-Results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=arbor.net;
Received: from [172.16.1.3] (88.208.89.131) by DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 19:29:19 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: Watson Ladd <watsonbladd@gmail.com>
Cc: tls@ietf.org
Date: Mon, 17 Jul 2017 21:29:03 +0200
Message-ID: <E5BF12C2-B79A-444B-B4C2-90D28B40CCAC@arbor.net>
In-Reply-To: <CACsn0cmo0HXBj7MidTTwkgE+Hwed9SrEODSzN8oURzQHJTW1aQ@mail.gmail.com>
References: <CAPCANN-xgf3auqy+pFfL6VO5GpEsCCHYkROAwiB1u=8a4yj+Fg@mail.gmail.com> <CAOjisRxxN9QjCqmDpkBOsEhEc7XCpM9Hk9QSSAO65XDPNegy0w@mail.gmail.com> <CABtrr-XbJMYQ+FTQQiSw2gmDVjnpuhgJb3GTWXvLkNewwuJmUg@mail.gmail.com> <72BACCE6-CCB9-4DE9-84E6-0F942E8C7093@gmail.com> <a0a7b2ed-8017-9a54-fec0-6156c31bbbfa@nomountain.net> <6AF150DF-D3C8-4A4A-9D56-617C56539A6E@arbor.net> <CAN2QdAGRTLyucM1-JPmDU17kQgAv0bPZNASh54v=XoCW+qj48A@mail.gmail.com> <CACsn0cnc0X5++cOvTNsboda8J42qg3VDquZ4Va-X-YDcggnbvA@mail.gmail.com> <7423703D-5277-4F78-A2ED-1B7E152E7B08@arbor.net> <CACsn0cmo0HXBj7MidTTwkgE+Hwed9SrEODSzN8oURzQHJTW1aQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [88.208.89.131]
X-ClientProxiedBy: AM3PR04CA0144.eurprd04.prod.outlook.com (2603:10a6:207::28) To DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 90f48101-6756-4048-a7e5-08d4cd4a1f68
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(300000503095)(300135400095)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1039;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 3:a6wc/c4QhR4ooKdKkMNTKJKf4YaWcQf6fK8LzlrQNet4jYQ+WBs4sJEL3DvtGMBmJb9KmDtn73rpU8GvQqfR14m96wWy3NVqUn270DRWRPJUaWTb0pxs0VNS13kll4kXKsVCrv8gpglI9IuuqjQQY6yE05odV2a8/lGHKcKlGdlVfSoq/ICDSJd1ki7W9Gt6k4MkYROxX6maukKHK8EjLgZ2PI5AbK3oBZ3INwigT2ZbhTiqO3gygiV57mvFhC3Gplp/a0h7zjE/dNUsZaCWUocDhwGX2pQLmSCZGPZW8e95/jm/M8EQTaM5hXBFV5JABRzegcGp/3q5LPWSpteMKiC9IyTwfIHcfMko29mfDUiHHqFmSffxT1tPfYmMCh51SESiXuzjr1jWcFqFlDxr2c5qFvIk4QK/RiSLDhR/IVLDxJ9060FNjUxKFbM6WQR2C0Vi+NdrRe9QCy3ityIPXtnENx+OOvt5zmC6CD5q8JyCwB0VFF1YcnUUHHZFYojyLb4Jb8kRMKg8j/VFQLi3RIZPR43tMH3A1E8hlAB8hdyvkTR1PJWAuZ437MUIgstEUOfWOf5Sy3T7IgdkbcYw8hbgYuaTYWRYda034AGph3bCs3cMPDvkYcebGGtNX3sxTn8lAHjjt+NqH3FcBY0xuCHXmlDkbg10E4sMTiywV0ZOHHlKj/mRFafmOh13G1s2VRCs0HA+KdWndj2vnuIa70gXELYVIEMadNg3kDB4Q1Q=
X-MS-TrafficTypeDiagnostic: DM2PR0101MB1039:
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 25:NeABrQZxMieuSEzmg9NOxauz8dAcsUFUnxbBsT+tEXOm2ZI+jyPCDYV5IZrMaH36stbf5RC+M9QnFsN6vleLjpnarTQov05VBuYBHVoPXwOTm8RPtXAAnb5GoYJJNdr7mzqoQOsjPkz5+Hv9sciviyEhccSPouhSy2Lz0XhRy0iM90a+RGLHJg1kvWYdUXgAl4jxQgX/dQTXaAb8loTsvx7MEzGJePv0UZhwEOzYjUnGr2s6mknSlpdDof0wg1yesSOzpABCGY0q8sIHOgUR/HDaq7rvBJ/kTJioReKXJo5k9dFcCEZgsCyHHvTCm36aoKLqEze4SiG6G+pjDXxXKRy92Y6nBxGxIZ2TI0tRlORAx6TKS3BG2LV2UXTzkDqKOIiWxps1S9n4EL2ECZ6C2tvSlLTzPpkdfxPgL64xQNEe8XAqWx86Qvn1uQTugnPI1BAhV0FwPty8+yW+ZXF5PnVFJe0COomS79T6vTxtGIqbd4YohlafAefdCTDeV7edjLCHNV+IasC2uMuNjNn/R57KVEWcJjEdIQFfYV1o+bNArVNf9G5NgUVHYqTLun35HEL0ANE9SDlzV74HFVb7JxDTzKRxZ63vZmSCLdqZPuiMYvsyy+KL2EOKm5adBcjo+KcDzNnPz0xWq8bYDWv5wSCIg+ZDO6zKPZeZQAxyuumQOObSRXeUQGsNPdU3OiHxUAB2MaoBqqxqBxuN36f7zptNz75Neiy5YfM6jnkDt7JvO4dj0wyyr9GXKq9cZkNttYhxE9wpCn/9H7sh6W3QZwUgsyRwuszClzW4GJiI8/5S4liRP4EUHQFaa090cTiyRZHzOnPCptKJsT7v6STwgLFyNMdmLkEvR3owPNFqzhWzFstvgXb0lEwY8M0Ex8bVsci5sC3aTKDS6zS3M0iERgJ5SnIe9TTCdaJO0Uw146Y=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 31:5cCI+6gkRaELp9Hi6GbqFgVI3R0iGtFjrTBV4Fjh/7DVHfEOEfNf4DUkEXqAvsW0O814gP8Dxf3bWT07eBY7cXLCTQw5SHYqAc+F6UAsdRJP2hgXGDaZiAqQEMJLRfCfndSEs6m8/XqkaasSU+3q4B8HMJHN1C8bmYQX8AxDkZ1seiHOENtevoqTejIHAcLiDdvjzVOTdPhdZ1zyqdA8eKlwdzcoVdcx6kctaNDMzJaxEnMoS1pq7qwhFOLJZs0rYHXL1EIf7WFjKxi0btcpVzQfzpS9LeoXWGbTyxsWaETlUfw9UEIfPUIWyqiWo05bnplN5YO38N4WFqvmRSeMZnfPhFQaJfCxVrVseZA6Tm7FKaoveIDAwzbKO7Zw2Pj8UDm2/EjaU5gyxB4bYWNlwC6BgXoTxmt8UGIoMlcOT+p6gePBvMQEOc9boF8dNlQnIWxkfuhUutyGGDK7cLqYc2F9ptyM7bksxQ/N8Lv/PZMGKaMaxpmru0GHcwogI4zBqb3RnO3pngsbG1UkQtyLWrH8BEmkHxe5yNz3bQMxWds/jfo/4h4O4ayaIQ5VABx+f7FalgmAiEmSowB4k06CE1E1aTvvEJX2/ghfVhI/FiOZonBE55yjd5C9ap6LZgrWJgb5IehuRvTXGCRg0L2v5vaexBICyv9+m52Nuj0mVvySqa18ROwsIM3mDtCD0XykgCLwLphLouMXyWjajv+8dA==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 20:M42vhY6i/2cCUL2EjIbFXVpz4xiD05kZSwviDYxqWQE6csaWs+qIMfuUrjv0F7bIEKm9oSxdoez7xAvdcVCe/6a3WYSU6+W7H1qE0m4J8XRXb/QBYhrTF2/dEwfXZJgzdtO+xuMVrmK7AowYDCBFNRnSfeL9dD3jyBP1nav63CeirnCsPPHAEr6UFoMmiUFA9JFfuC92VTQxX5AXWeG9LK4J74XPQ7IoexFsnFPRjl/iMnShf4+mzLdm3GAEH3ZAr5SQE695IpW7AjC/6VZCJnClyp9AJtsWQdaorvUJ2/ESbkx/X53xwqO9E7u/WBqlWEZoAowgH1W6LCl9g2mdRMrFn1hfW6qKLNxUwIGGUsVp5KQ4Qub0edb076mjUmZNh2GHnHkJGa0ln7wX5++nA5vRfKnwYtMXW7s5TvbZFsGegfsOVaxsSgbSGWzoiLt3b6Gb1OAkhi9NQMY9jPdOiuLzEKfmB9RjepPKtjsVPBN2M35rOSUBFwH81YO9d1eN
X-Exchange-Antispam-Report-Test: UriScan:(158342451672863)(278428928389397)(236129657087228)(192374486261705)(48057245064654)(266576461109395)(247924648384137);
X-Microsoft-Antispam-PRVS: <DM2PR0101MB10396E1BDF564058BD94997FCAA00@DM2PR0101MB1039.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(2017060910075)(5005006)(8121501046)(3002001)(100000703101)(100105400095)(93006095)(93001095)(10201501046)(6041248)(20161123558100)(20161123564025)(20161123562025)(20161123555025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1039; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1039;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 4:vk6fktM+SanirFe4TA5LVbTVEQ9eOsujoDa3Zo+pEmoURYk7wLuVNEBnjcFo4yrnGI3ZIczI3F820cPzIPt+dn2PrwXsMLRaJ106AsN6KB1TY7aWulO5hcxWddgQHtnw8N6wF1ap9uwVfSNy7WdyxlhPTGuiP59vvRD/B1CLQ4boyC71LL9//J34tFanofbG3vAJ5NIErhiQ2Uw/myAWc8ZzdAJOpWpwUvgNiiTEvk53r6YC03x8HIoEeFbpGL8MROK9rAob67REdlKIBJrX8FdnQyY6GBXIcjHTf9ZmOgFhQCmmpw4A0xyLJow2X49uX8f/axvsfz5wKMh+RNi6+uF7sNwztM5O2BMI4ynnLXhHvhSN3AWsLxUj4jQlI6VOyXXnSX+2YzWXjDSw2PlBIesX3j+g/Ld7DhkX4E7NTNB8uDG9Xi2i80Oe3dZ1pXq4l1/NU/m5xgM98YBjWmZkz6BT09k+KXEVEFuTrhTO51W7jsjKJ/bm+9tS4qx67iARa4bMdFt/FWYutATOrLHaSyHK5eg/FfzhxbVEWZOxzezZXFIgqrGw8BY08+kCaVXJLkrTXiid6tqBXFL3mQFpuJKKjkcFxAvqhd/x26s1jrem889MFYf6NaK+eLaFSiEY2NzZO6CbnI4gnv0QCgcMm0wgwBDy31oSe5vyBu86pww9uoA/LB8oDR6S09KvQpYFPUqyk//J3VMsQRLs/WKjP4aZkd6SppAoX/YfgzbH1EddX5QCJqDXDGGNU83QBS4QHkH7ab4ldo9uq0ZHFEvN2XuBVEk//Kjui0EKeauTMUR6/Y9unzMbvZLDjUM/UqePUQ5M719cLAXVRn1iIF13OGbx8hfANsC3CSFDhGuoOoNIVhtih1KK2xF0agqvbUJ7WfNgCQ/NdMiMF/itwi1kqQ2k/5Jd1K7XS2gvzBigJJ4W/HJZbxOhGhBsZW2DPaVcSycUyyiyPVQ+ppUDpSEAlamdsPYSLibMh/DuEZfYWGZ78vi0qMeF0LzNKNBdlXa7pSwAVRnMm301W6hELl5JQWKpbBm306BGYGuj0lmwAs8FeVgtyLnKDQI+oZrPsh7C7m/dM4sISe6RRElxekt1TiyyHpDtoUYvOKccZuoxF6v7HL7KIu1s61iqKG2QMsrYvE49BR5cKfmg/IImaGp++Yq1eGfQhJr7qbX17kzeNuh7u45y7d/k0SxnlnLMmxl/+mCiMDWINzMulKRK+hsbCSHLVTvq5tXcPWGzvFNMxe5es6Y0eS5Dg9pw6L5fHFCkQ1fz0zWUskv5ykn4phHLH8XYlZ8FhozApGLXzENMPjUUXPHpG9/OCB6OdDddvJHNJ4JngrfsTH3+/K2ID/OVqhAED/UeO3gUVsIo2idltkHWIiCYKwRy/M+094RhSLge7Mf4LcSK/+hlPlZ7wGBneA==
X-Forefront-PRVS: 0371762FE7
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(7370300001)(4630300001)(6049001)(6009001)(39410400002)(39400400002)(39850400002)(39450400003)(39840400002)(24454002)(51444003)(7350300001)(86362001)(6246003)(25786009)(6916009)(81166006)(2950100002)(110136004)(38730400002)(36756003)(1411001)(3846002)(230783001)(93886004)(5660300001)(6116002)(83716003)(42186005)(5003940100001)(82746002)(50466002)(305945005)(53546010)(189998001)(478600001)(8676002)(7736002)(33656002)(4326008)(50226002)(53936002)(66066001)(6486002)(6666003)(229853002)(2906002)(77096006)(47776003)(50986999)(76176999); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1039; H:[172.16.1.3]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 23:zyeWOiB3a5BsfjYlDoM4xA70Vjh6wfch8VweifmYOu2yVhLeZw1NEibnDwOYVs7QoqVU4aXgXz2rOvXvYEUZV8Qb+CQBkDRH6xKNP9G+EwNymQguthBqVuIMGwGkquXXyRB7MlMCBG4w2nDfS7V/Onho1eGFprj7HIUhxS/m3feWP/VeJ//Z5UrV6JWJ8GZozYW/NUOrX1ow4Ffdk5MR4gMTKIT3IvWIkKpgAutHCtweQXh6zF26CG8vkPWwkZnWyMC3wshT1XvWByKdoAFCBUFGSmJogu1EAOLz9VEVuyl1NLntct1dxf7ISU2uSVRSrN1TuPIwLLBcQ/3AGCWimNFLvQCpZpTr8gKKhERTN5Fq8YfHf82njVDoYOACKUv/3JNj5gBLw+dBprSyGGuJHLPMMLUMyy08Som/aJfi+mmDYXFBT0g/aTGm2k55ioZYbyx0FYo1AnhFcVu6Mycmz9bKIdiDSCcyX0M+wrYAeDZLs3G8cbpxRMvq8IromEMoP4L2b265I6ScPAVRAm4Fzx3IHXFeMT/Fc0oLA4N3mb7JPaymHeBILgUWkZQylhtZ6nVJZ9jPzWnB945gC+RGhP8+k0+U2VXC8hjSu8Ra3hlC6iepyY8EjLOaJN5TfAi+xriOKBHmWVEZKSdfyqixCeAdpV+zWKujv1GNuTWXfQzi0ZlW04NdHIRfGRfU1gMZ6o359reuE5Ba8yNOENY6A1EFEcTVie/n+Mqe2bDjKmRZ/tkvCcRfCbnWYS+NyICX5jXAWUbh3ZDXMWQTAlu5e6ASrTQ32UwM+EHm2YlfLUh2cwFe9JuH3jcuziFDRj7gNxJ8Ch70FrYz10UQTaDtOqDC5tj2QM+s6AwdpVHlhWogiEo+P5uS9iWZ+TFgDn3SpMYW13xUmpornaghYTDmWZSnVQ6hrlGambE3UtzQOSRsb5mETO/9WEDOGipjx0dG0Qqde3gQ+PzKgkH//G7W5X+pO6I7QKkVHPfgY6XGMF2iRqfD+H5D6P3HwDO9Xg3JR14tZTQ5ngy3W4VgYvnndNL6pNHmagz6L795twXl4+Bgi3kwjYZWhJz7t9BpI91com4Tf+stK1IkPQju/G/54ZslZ2miDSUZIlYEb2UjQ8efIouhMIGDZLkU8n01O9enAypFFZJ510cByS3GzVwjZJjjY3+oxXXQrRoFIfoCeVzF75tUpdz6SK2fMgHJTcvzaO3S2aM71EpTQmzdfoHhsFAcUcyEuL1wnB2dR0R2hfS6njrAlGSWcJ6YCcH7jvAn
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 6:NOWjtEit/PaqIfT7S01ipcRy5/VHY2wv+ZDZI7D/H18gGFFOnbn4W1MOBEcvkrCU0pfm0psSE7JywZjevcUc3+q9QMeyTvVIscmoN9vIAEMlOQRuJ3k17nsRGmTFomQLSppKPtcT/yDEM2+gLn+JJGVuIPJkIljOoAkTWoky9o1gC4qHmnXBkQKlFZYYT5kvAXBBrSqQ+WUuXx8k4yWxOsskF1BNDaW1qkcotFLcmLyuHnR5gkCsmucWq9qwpsVfNyXfKUsim8VH4I9cun1u5GLrODVKNkZJ9wEdmlmG4u9iJDwTV5wCH/LAmi4EJ/RGLeZ8U8G/pD0s4tP/k73G/aQ14tqZ4ZNU5IoQ1Ec2kCHYdklYtZXhRAUDqqdJtdEVt52qsp0yFir4QTOnUMLec+1iIhEfsmZOmAkc/9KdAcMPd1mmQr+u5albwc4gee+TjS6MbYJrjP9zVwghXEiYIYYxsQ/Eag0mSLOxM4GM4UWQVEFlxyvNmgZ+ff8OPc/Aa4AuDtgHYgCqoajuQvmh/f2Mx118aMXqT+RkMigFtkvgcvptEy5BcrnS40/BFWDS3t3W+u+tr+m/gN+UQKCEDtTjG68XSA74qR+pzxr9uGsrUAIF+rKYTRqRREsTkq24r/lrlRup2SGHDuu9R0lHomuA+GnjsIEBKOdZ3boS+agyRkryuI+SQkPEtnFDtYLWVMXu5IdpZ/DoZd7/8c4lpwpfQyM6Zj/S28Ur2pA+n0qgDp+oui6AraBcWmM214g1n3h1xQ/KS19JrFd4juy5/6mcGkM1qCd6yMyL5DsJ3SnMgsnYtjchl+P2+dNbTQzhZ1U8TXFEOXjKN06NcY5KRJinU8eoWRCDF7iC1LWZB4gBFnpyd5C5GXWrLVReNHrZQ+t4ZKie5i66sMedyEMGgso2ZMSSkPa3NTWUC6nf180QtUNNd7+2w6LPsf1uyfyvzWhXv42VZE+auvWQFP1Fdkro3w4L3uE4J/famWomIGo=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 5:snHJYxvPW2j8ZY0ujfEE/oBVcGvF0Hfbxp7KKGHFOEB/VdMWFtFi3J3UyqIb5NnU/F9I4ekvdnph3EyhSPtbWcC+XpFDKRdUv0/tM/4Y3+pbNrjqUmmMCkrr6SlB5BBWtyhLhU0g+2etLp7JzwX6pHiGhxw/zf0zLMk2J1MNV2Y+LGtxitN4UHkmgHDursCUTkpLX+Y2Nk4h7NhCtqBVbQLfGaSee1CnWcjz4p3c9+IZ+6LwIkkezTbB+B+ma1zUvvlHNe8FOu+UUmrJjmqKmovTmuJB8lYwQmvAom3ZJcGeaf9nTIIWqYo6Ttc/vAxGyzuk6JEjEzLvqpLeFD5AOhXulofqbDYqV20/vXmISiJm8rJTtPXRTe9IpabBTi2K8P6dD8YWD6ZmmLGEhnnd6SNlO6ecH12tNKAd5SwgcF1NSbLmO6PuMKTiiEkyy+CzlNLsbGYbsTej9lFtv8XjXq6uTr9WMzBwIor1atqUtUwrXs8+H86pzVlTSOjUNoo0; 24:59qgwjrgEBwnpHFOFtwc5WoAy6rsODRnBM8GTckA4PM3XmZQiwA5SPrzvI9Mu1b71r33miFaYCJn/bbxqsNDH5oQQ+7v6xi29mHBQN3Qca4=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 7:kMfA7PLbVer9qNfcC8gxuv1YTkiHRYsJcXE59bvVlmbr8Swd58cVNE3RykeOiznP6QmlFDiQSFiamYymCR3zj3y4lk+GyiJO9vLjLb1lwtS1IRmGqDURCD4Av/bMbF3SWbp5oSC4RwoXmpr/zF9e/F126FfYILBR9v2/iaGyAK5XgTCu7XM6Fm7tee5hDKviCf50o5a6u/A4ttXw2AyLS9VGCZN1rZTZYrV2mhK1IhERBb5CId8T1Z6V3V1r22R8GgV6UpJ3f5jRgP4SzDvj0DLd9PXGHFLMhk/mVlJFdwIk16XmHFVNf0O4SF+A05/UJluFGjWfJcUAACoEnPS7so/ogV3h3piq2iK8QmpnslEUB/kcEtV2KH7zasmmUfE0AVwI1lVRFzKQZ2ormguZ69LR5ZVlnfyIsCSJ8snahe4oS3xMA4mLcMG4kAdsY8TTwbt3H2AI/FG392dVgocXEhrO1CPF3izlXmZwni9hj08RzRMWzCH6VD2M9odQZbAmQzaPekjJjW86JAQJb1hpA1RaEK+pmCXC7gqibQUfncL2vOshhEkBZVG0jVwoH2JwpBE4UzbTPjN5dFWaqX4pp5w96d91S6CsdnOflpyzM3JC6AhoqaVh8ofaVxecmPJN7ghrCCLqh6zpSRrGAgtVD5HkC3HX15oj8X6Zsk59v4Dv1Ng37/5BU+jydNTvq9B2NAuq4grRkmQ8FOjy+AWFkl6jC9IwPkclKGjdPUggypCBniRx0FTkRjRnVIZi6xI9Sri59UBl3y6NzXS8m9GxOpOUbOHTdty7v+dEtsYNemw=
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2017 19:29:19.7746 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1039
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/aEEgmllgxFYVYpzDGDHH56q6isU>
Subject: Re: [TLS] draft-green-tls-static-dh-in-tls13-01
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 19:29:24 -0000

On 17 Jul 2017, at 21:11, Watson Ladd wrote:

> How do you detect unauthorized access separate from knowing what
> authorization is?

I think we're talking at cross purposes, here.  Can you clarify?

> Yes, but you'll rot13 or rot 128 the file first. Why wouldn't you?

Many don't.  And being able to see rot(x) in the cryptostream has value.


> And the endpoints taking logs won't be?

Logs are no substitute for seeing the packets on the wire.


> Applications can rate-limited their own endpoints.

There's a lot more to DDoS defense than rate-limiting.  Rate-limiting 
often leads to gross overblocking.

> You're telling me a dedicated out of stream box can handle this but a 
> beefy server cannot?

Sadly, in all too many cases, yes.


> No one is taking away the ability to log the PMS to a file. That's the
> capacity which exists now.

But the capacity in question here is to see the packets on the wire.

> Alternatively it's because you've decided to run your networks in ways 
> very
> different from the public internet and used this as a way to avoid
> organizational battles over giving operations the tools they need to 
> work.

I think that some perceptions of how these things are done even on the 
public Internet may be a bit circumscribed.

The tools that network engineers and security personnel need analyze 
network traffic.  Logs are insufficient.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>