Re: [TLS] Unifying tickets and sessions

Aaron Zauner <azet@azet.org> Thu, 23 October 2014 14:35 UTC

Return-Path: <azet@azet.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 326F81A9041 for <tls@ietfa.amsl.com>; Thu, 23 Oct 2014 07:35:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EntNNhTNOf5P for <tls@ietfa.amsl.com>; Thu, 23 Oct 2014 07:35:30 -0700 (PDT)
Received: from mail-ig0-f171.google.com (mail-ig0-f171.google.com [209.85.213.171]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E70E1A9023 for <tls@ietf.org>; Thu, 23 Oct 2014 07:35:30 -0700 (PDT)
Received: by mail-ig0-f171.google.com with SMTP id l13so1496217iga.10 for <tls@ietf.org>; Thu, 23 Oct 2014 07:35:29 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:references:from:content-type:in-reply-to :message-id:date:to:content-transfer-encoding:mime-version; bh=fcNInVWP+rMrviRPNQgkZA1j2XumDWYyPDj+pUF8eJc=; b=XQybO2+UAgdvN4qIPPn9osD6uFPM6U6xZHOMhcngLFj5t8hc/dKwv+oOl+N+7fyxAD TogSjcku88g83V+p5yUgp7fgfHdGGplxoiCAxm+vZHeVCFin0bDho+S2b0lWevYx+qnS IWnxULJ9derrmZn8CBLJyQr7VdQ4X/O0kG5+HUEpcbpQXqEzlDzYB+5nnjW2GceLncgt G+VJp+aap6R+mLcyu8QHCt3cOE1vn6XyA6uDP20E63iytbnAjtoo3tUJ+/hJOu2WwlvU jK7Au/q7hGaYYIkhxsplfSo2NDi93iC9RhCIoulj3tmxipZkxVw/adtV4PfoeT7ZGRED Aylg==
X-Gm-Message-State: ALoCoQkEG4KVTHyyZYJ3+kOMi1sldbnvNNIeRz757aFqKc1ZdzZ8dKVRiDhg4s0BLiBeojHiBIlM
X-Received: by 10.50.143.72 with SMTP id sc8mr12702520igb.38.1414074929661; Thu, 23 Oct 2014 07:35:29 -0700 (PDT)
Received: from [192.168.10.231] ([194.154.214.214]) by mx.google.com with ESMTPSA id y2sm1179278igl.8.2014.10.23.07.35.28 for <tls@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 23 Oct 2014 07:35:28 -0700 (PDT)
References: <2A0EFB9C05D0164E98F19BB0AF3708C71D3A8C48AF@USMBX1.msg.corp.akamai.com> <544606E5.2070807@fussenegger.info> <CAA7UWsVmxAmBtdCvpE_+c2e7brJNkPrQ5_69FDXzy2csg6EsyA@mail.gmail.com> <1659862.HPNNz8lRhl@pintsize.usersys.redhat.com> <CAA7UWsUbxDyh_yxn2t+tghHhLOhuBH+SqiLELJRFq9g=w=OAXw@mail.gmail.com> <28F97438-9D8D-40C4-9A99-AC8CF3183787@azet.org> <20141023142204.GN19158@mournblade.imrryr.org>
From: Aaron Zauner <azet@azet.org>
Content-Type: text/plain; charset="us-ascii"
X-Mailer: iPhone Mail (12A405)
In-Reply-To: <20141023142204.GN19158@mournblade.imrryr.org>
Message-Id: <30A14E39-177E-4299-B49D-334AAAFAE4FA@azet.org>
Date: Thu, 23 Oct 2014 16:35:27 +0200
To: "tls@ietf.org" <tls@ietf.org>
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (1.0)
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/ehc202bvxPhHSx4xP7hTLYOAcxs
Subject: Re: [TLS] Unifying tickets and sessions
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Oct 2014 14:35:32 -0000




> On 23.10.2014, at 16:22, Viktor Dukhovni <ietf-dane@dukhovni.org> wrote:
> 
> On Thu, Oct 23, 2014 at 03:34:01PM +0200, Aaron Zauner wrote:
> 
>>> Right now, RFC 5077 recommends: AES-128 with a 128-bit key and
>>> HMAC-SHA256 with a 256-bit key
>> 
>> hash functions have n/2 security.
> 
> The n/2 is collision resistance.  Here the hash function is used
> in an HMAC construction.  I don't believe that n/2 applies for
> HMAC-SHA2-256.

oh. that's true.

thanks for pointing that out.

Aaron
> 
> -- 
>    Viktor.
> 
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls