Re: [TLS] proposal to encrypt ContentType for TLS 1.3

Colm MacCárthaigh <colm@allcosts.net> Sat, 05 July 2014 01:19 UTC

Return-Path: <colm@allcosts.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A11231A0011 for <tls@ietfa.amsl.com>; Fri, 4 Jul 2014 18:19:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.678
X-Spam-Level:
X-Spam-Status: No, score=-1.678 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-0.7] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6jIV2FIpZSRa for <tls@ietfa.amsl.com>; Fri, 4 Jul 2014 18:19:19 -0700 (PDT)
Received: from mail-ob0-f180.google.com (mail-ob0-f180.google.com [209.85.214.180]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D0B31A00FE for <tls@ietf.org>; Fri, 4 Jul 2014 18:19:19 -0700 (PDT)
Received: by mail-ob0-f180.google.com with SMTP id vb8so2409888obc.11 for <tls@ietf.org>; Fri, 04 Jul 2014 18:19:18 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=agmlHhHJB65/gnAymlM17Vc9FlMr7MZZUCz9MRsA0ZQ=; b=LYYNYRWGInsVR5hYey17IJSGC1GSfOb35Amgrc9+YnHGqBaFp8d7qg/WUsIYxGCsKb AoRYBkWrqW047EWTLJMHkzsumjQeC3H8YRq9Mi9rsw6jX9UXlIFcLWMQcKHqmAbpHEy3 4lC/LxPeUzIG8xfNR7DFIu5KqiiRB8SGavYZ42jrnKdXppaMGcODa0vllHck1G2rK4pf eFB2EKBADsw2mZUNLU/KHKkUkK9NUs94PnhDZ47UoiqqkRM5onbmNEijgBA8TjUOCdYE Ti2++GkK/faDr5zJ1erO5yFiH/xqxHwZv44zv/k+KlYp03Q9+mf4Q2FziA9vg4xbDLv7 Kp1g==
X-Gm-Message-State: ALoCoQlAjtRI0W0IIpK1B956Wn4b37kLlGFmz1X1ddoporBGAQKzIs3NZpe52MCIJBnU8Y49uJ+j
MIME-Version: 1.0
X-Received: by 10.60.45.130 with SMTP id n2mr15921764oem.12.1404523158778; Fri, 04 Jul 2014 18:19:18 -0700 (PDT)
Received: by 10.76.10.198 with HTTP; Fri, 4 Jul 2014 18:19:18 -0700 (PDT)
In-Reply-To: <CABcZeBNnL8S2+OgUgg0LagWdA_aom5Qfsm0Da=ypJGhUwoepYQ@mail.gmail.com>
References: <53B331A5.2040908@fifthhorseman.net> <CABcZeBNnL8S2+OgUgg0LagWdA_aom5Qfsm0Da=ypJGhUwoepYQ@mail.gmail.com>
Date: Fri, 4 Jul 2014 18:19:18 -0700
Message-ID: <CAAF6GDe71ANQ2cGRb68i=2sjgX47KdCBF_DJsFCJWyTHhra3yA@mail.gmail.com>
From: =?UTF-8?Q?Colm_MacC=C3=A1rthaigh?= <colm@allcosts.net>
To: Eric Rescorla <ekr@rtfm.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/bIgLCuzhYJaSLwchOs6JN3WeTiQ
Cc: IETF TLS WG <tls@ietf.org>
Subject: Re: [TLS] proposal to encrypt ContentType for TLS 1.3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 05 Jul 2014 01:19:20 -0000

On Fri, Jul 4, 2014 at 5:11 PM, Eric Rescorla <ekr@rtfm.com> wrote:
> This seems like an idea with a fair bit of merit, but if I understand
> correctly, it's going to result in a stream of data which cannot be
> parsed into TLS records by existing network elements.

I don't think that it does. As long as the length field remains
unencrypted, it's possible or a stream processor to figure out where
each record starts and end. Processors already need to do this as new
record types can always be introduced.

-- 
Colm