Re: [TLS] Record version (was Re: Salsa20 stream cipher in TLS)

Wan-Teh Chang <wtc@google.com> Fri, 22 March 2013 17:49 UTC

Return-Path: <wtc@google.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D278D21F8F9F for <tls@ietfa.amsl.com>; Fri, 22 Mar 2013 10:49:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.978
X-Spam-Level:
X-Spam-Status: No, score=-101.978 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5iVaXWolXOGR for <tls@ietfa.amsl.com>; Fri, 22 Mar 2013 10:49:55 -0700 (PDT)
Received: from mail-ia0-x22b.google.com (mail-ia0-x22b.google.com [IPv6:2607:f8b0:4001:c02::22b]) by ietfa.amsl.com (Postfix) with ESMTP id 2B57221F8F81 for <tls@ietf.org>; Fri, 22 Mar 2013 10:49:55 -0700 (PDT)
Received: by mail-ia0-f171.google.com with SMTP id z13so3801909iaz.30 for <tls@ietf.org>; Fri, 22 Mar 2013 10:49:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=VdzcTG5b350k70Vhefu5NOL8q8F/srC4OX1Tx3jKsuI=; b=Ps+snFkXEmaULm9jfcQxcASI/a1BYMDM47NsR0DIYmg4yPl3RU0sIUnoWfClQmb98C Z99LWAxf6xXulPolEy1RbqTFXLEyLs3HFpsGHBDc6FBkYnhRUiRaBVY5bTkwTa5Ss5mv TGHY5ms1Y0hV48ZjQXGeDbpqac7mJpJeOtEm1bPdNrEl0e9XGTkmqwh2aA3ADr6RBld5 nbG0HHjbduK5g5jOwNJUnYvcp09+7kjgHWscFmfTlWqbFUD4e4kIuiN5YwwsRj5Q1BEG uGh6GFPOoqKLZxuoHjgO5JIm/LeqR/pd9EDnAGTp9hmNACPVpgbVd1NJmqGJcONFIZrZ 9pnw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type:x-gm-message-state; bh=VdzcTG5b350k70Vhefu5NOL8q8F/srC4OX1Tx3jKsuI=; b=g0Am2jOQg3sE923NEZN5wWCaojLLWGMwH9X4nEGrgbMGYXppaECT040O6T/bLukdxn Bb1Mx0ig4iffGVLEnATyke/NbVt0+JOvroSXhsLSAQ9s1KkE4Jx2Eu8nCWl3xVCgp42c q3B0SSlDJanOPFmR9tTvGVKekctV/aOIRc8MnkXzpeyYp0+ZH5VvLwUocUQZxxPypRCO rR5PqZUCfNzjjuQxKpH8xqqIABUhn76aAv7ZzAR/X+G4LMR9v4bMqvsCwFznLs831XWi edgf4Tbo3DEwl1r1Og6B+0eoegwF/12BSGentQmvI6Ulh8iAW3pUpc4TENXOr4y4ldmf Eorg==
MIME-Version: 1.0
X-Received: by 10.50.70.34 with SMTP id j2mr1822820igu.7.1363974594799; Fri, 22 Mar 2013 10:49:54 -0700 (PDT)
Received: by 10.231.112.2 with HTTP; Fri, 22 Mar 2013 10:49:54 -0700 (PDT)
In-Reply-To: <514C9538.7030401@pobox.com>
References: <20130322052312.1ADD51A65B@ld9781.wdf.sap.corp> <514C9538.7030401@pobox.com>
Date: Fri, 22 Mar 2013 10:49:54 -0700
Message-ID: <CALTJjxEV_zYJ9_igbAR9ynRGdbXhmwBux552NAAgSdbJ6_3-bA@mail.gmail.com>
From: Wan-Teh Chang <wtc@google.com>
To: Michael D'Errico <mike-list@pobox.com>
Content-Type: text/plain; charset="ISO-8859-1"
X-Gm-Message-State: ALoCoQkd/P77iWDE5+V95IzkfNyDSELPc3RTXaF9MkKSzlW3tcYkMxri+oOBNbha1uHVKBXMHFjqCzTRt3nYViykDcYOsBGaaPh0woAhBngRDELnnz/m8+POEcFX5XeHkGLJHPBJAFxJ8f/tP/nKASP6L7/QKFR/7SjUTOhDqHOTgwl0h48H5Bzzuof0r7FxaxBRR1VPREhU
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Record version (was Re: Salsa20 stream cipher in TLS)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Mar 2013 17:49:56 -0000

On Fri, Mar 22, 2013 at 10:30 AM, Michael D'Errico <mike-list@pobox.com> wrote:
>
> Perhaps some better advice should be added next time ("use the client's
> lowest supported version") and placed in the main document instead of
> an appendix....

As RFC 5246 Appendix E says, this is a complex topic.

We encountered one server that supports SSL 3.0 and TLS 1.0 and
chooses the version in the record layer, ignoring ClientHello.client_version:
http://bonsai.mozilla.org/cvsblame.cgi?file=mozilla/security/nss/lib/ssl/ssl3con.c&rev=1.207&mark=2379-2386#2379

If you put the lowest version number supported by the client,
which is typically SSL 3.0 {03, 00}, in the record layer, this
server will pick SSL 3.0, even though it can also do TLS 1.0.

In our experience with the Google Chrome browser, putting
TLS 1.0 {03, 01} in the record layer of the initial ClientHello
has worked well. (ClientHello.client_version is TLS 1.1 {03, 02}
for Google Chrome.)

Wan-Teh