[TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-tls12-frozen-07: (with COMMENT)
"Arano, Edward" <edward.arano@bofa.com> Fri, 06 June 2025 13:02 UTC
Return-Path: <edward.arano@bofa.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1328F31C2C8A; Fri, 6 Jun 2025 06:02:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.292
X-Spam-Level:
X-Spam-Status: No, score=-4.292 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=bofa.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XZbC-VOq_uew; Fri, 6 Jun 2025 06:02:31 -0700 (PDT)
Received: from bankofamerica.com (ltwemail.bankofamerica.com [171.161.41.178]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 56B1C31C2B46; Fri, 6 Jun 2025 06:01:32 -0700 (PDT)
Received: from lltwa05mxepmx03.bankofamerica.com ([171.180.36.246]) by lltwa05hxepmx02.bankofamerica.com (8.17.1/8.17.1) with ESMTPS id 556D1SST041437 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL); Fri, 6 Jun 2025 13:01:29 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bofa.com; s=corp2202; t=1749214889; bh=ZjG+BdtLmdCkViuDtyxlcTdz629DEfmQU1JMGRUoYFc=; h=Date:From:Subject:In-reply-to:To:References; b=2M2jRpFeVa64e7nMW9anlKtNb1yKUGM4B3v0Px9UhZKvf4okrTl1zzDJRy75EMS7c DOWIWX6ckpK7S+XhbPwI1ef6tvnqQYpyjkZJfzpZNTQO6bINqT3fSt+EGmUOqxdjqM cRn9fpVypYKCKOmaUoZPSCGOOA/dNurXojakAQnUmJLLL9+4xRJQ5jvi2j6NBAua8q przF9rGWo9ZBSz8Zd2w2JKPjXFvc3s1x2Nz7L5lLpXuoAtRjRpQQs2FeWnrxKfH6ra ZuWGS8I3bZ37jAYWYFF7e78oQZ89vv7kcnjUOliaUmwv6JRaz9Vsv80Y+ahzIgn3PC DZkMiujvnSumQ==
Received: from rtxppra01.sdi.corp.bankofamerica.com (rtxppra01.sdi.corp.bankofamerica.com [30.157.160.36]) by lltwa05mxepmx03.bankofamerica.com (8.17.1/8.17.1) with ESMTPS id 556D1SQC005121 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NO); Fri, 6 Jun 2025 13:01:28 GMT
Received: from pps.filterd (rtxppra01.sdi.corp.bankofamerica.com [127.0.0.1]) by rtxppra01.sdi.corp.bankofamerica.com (8.18.1.2/8.18.1.2) with ESMTP id 556BoiNF026381; Fri, 6 Jun 2025 13:01:28 GMT
Received: from ahp-cmta-rdn-02.sdi.corp.bankofamerica.com (ahp-cmta-rdn-02.sdi.corp.bankofamerica.com [30.28.208.25]) by rtxppra01.sdi.corp.bankofamerica.com (PPS) with ESMTPS id 46yr2x29r8-8 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Fri, 06 Jun 2025 13:01:28 +0000
Date: Fri, 06 Jun 2025 13:01:25 +0000
From: "Arano, Edward" <edward.arano@bofa.com>
In-reply-to: <BYAPR17MB29511FAC8530A019AB95A325CD6FA@BYAPR17MB2951.namprd17.prod.outlook.com>
X-Originating-IP: [30.91.45.31]
To: "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>, "tls@ietf.org" <tls@ietf.org>, Paul Wouters <paul.wouters@aiven.io>
Message-id: <d5d11ff8dfc5429d816fa1ff2486589e@bofa.com>
MIME-version: 1.0
Content-type: multipart/alternative; boundary="Boundary_(ID_Cnh6u+Y5QE2E9a8NzInya3)"
Content-language: en-US
X-MS-Has-Attach:
Accept-Language: en-US
Thread-topic: [TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-tls12-frozen-07: (with COMMENT)
Thread-index: AQHb1krq+jCT7dtL9kGkMEwATQZuW7P2FptA
X-MS-TNEF-Correlator:
x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0Jhbmsgb2YgQW1lcmljYSIsImlkIjoiODQ1ZmVkM2UtMzY2My00Y2Q5LTg3MWItNDg4OTUzZjAyNTVmIiwicHJvcHMiOlt7Im4iOiJDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiUHVibGljIn1dfSx7Im4iOiJFbmNyeXB0aW9uWWVzIiwidmFscyI6W119LHsibiI6IkVuY3J5cHRpb25ObyIsInZhbHMiOltdfSx7Im4iOiJDb25maWRlbnRpYWxUeXBlIiwidmFscyI6W119XX0sIlN1YmplY3RMYWJlbHMiOltdLCJUTUNWZXJzaW9uIjoiMTguOC4xOTQ4LjIiLCJUcnVzdGVkTGFiZWxIYXNoIjoiK3lYakh5M2pyNDlaVE1DdDZXV1wvekpkdnNyN3B3bFJFSEFhTStKTTVyWlZjMHJscnJ1ZzhoYjIrTDZqTXVNTHEifQ==
x-bac-client-sensitivity: X2
x-tm-as-product-ver: SMEX-14.0.0.3197-9.1.2019-29238.004
x-tm-as-result: No-10--26.127500-8.000000
x-tmase-matchedrid: Rwud/WFcGwLQMpaZX+MyZNzhlBQC4vHlMnOFtznwUJ4/k6lPgmzEC7DQ N+uXSQvr8NQlTV1CgBW/pOXG1Igi1DpZ7hy2zJoFKW3AcPTjclLg0I8K3NSDhbeLtl6MhxoBHY/ XeJlZKEUtzM8wdlz5DiTG1CpdES1k3Zvca1xCHnhEKZlqWQag3kOBQVcKGV65r5yskCAo7Z1JXh 06B6i7TMZ/nnR6UersOsROPjsAqC6Hc1byTKI/B0D+2bGa0Ty0ilc6sJYLhXGrCTO4GiKE2o00P ILgpqtbo4iCakRRMU0zgRR/MnDxnoeQz99GL8Vo6foKe4Q8CvJYIT2WfbFdzwA8UbTSfKQpF9Kv E0VU/hPqxdiKkAStbCgT8GKLxcZAUUwCnWPDd6W07MHUzrduCAfzbupO+dPjz5ZT39uyf/3IUO/ tqmZnK9VRbHgTqRNXlL4HXNbRhCYauK3TCjnujg2jSkq0A6AqIhg63Ta4ijCRM8KDVl3qBTt2PQ RPfn+RH9y2iTR/ycUw29xwmsxYyXT8fEYWbsTC2vfEgFTynI0t448A6vPPH9AEcVVIRUblju2Xl cEx9HSPRZL2qqfMbWmtbMnX9yEapLUFVhkFi6H2p6beZo8PuEs/y+hHxbP4izDl1LnYNFi5i32n QDua+xKaKt6PUx41YmWy0eh3/x4jTcKyra4x3dD6xLvX4M4In4/eUoqfaGBMLBAAoJ2ehOTSopv UrOgHKJPv4wf7bHmzZHhGBmyWLqHGyscLVAjOUEI3FM/j03gxcZz1VY3hFsSughRPLRdG61+8Ko UtwFc=
x-tm-as-user-approved-sender: No
x-tm-as-user-blocked-sender: No
x-tmase-result: 10--26.127500-8.000000
x-tmase-version: SMEX-14.0.0.3197-9.1.2019-29238.004
x-tm-snts-smtp: 6A893D32F401B98E31C67CDACF516B92474EF199C540F316A6CF6772AF45A16D2000:8
References: <a6dfaeec1f3f412a9231fe0ad0d9881c@bofa.com> <BYAPR17MB29511FAC8530A019AB95A325CD6FA@BYAPR17MB2951.namprd17.prod.outlook.com>
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUwNjA2MDExOCBTYWx0ZWRfX+hvc7rin57E8 2Bct85ybmAx1eDD0wGlAfP97TV6O1mlxRn19bsyfMQygA6GTNAlp06hf0hMmqwEsumoHeyhI8sT 01tBNs84myDJxtDl2tD9+Tne/sq7zkhHtGT4K6qTxAgMMsqZLgWp4vsjSIX3C/iAR7kgom+Jx/p fZoAe7nk6AwZfFu3eT27FMbYzjhF8gRHqQBkTzarZnfr0sijxfnvPMZHw6tETXyhoNfKpWJuKq3 OCqTfqFqKzJrM93srEmgxHNobqEepn0/H9WFT2Ld2Gqqmzf677uQ==
X-Proofpoint-ORIG-GUID: ZSDx2Wfn9UOBe0GugE2Brj-v_kf2J6_m
X-Proofpoint-GUID: ZSDx2Wfn9UOBe0GugE2Brj-v_kf2J6_m
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1099,Hydra:6.0.736,FMLib:17.12.80.40 definitions=2025-06-06_04,2025-06-05_01,2025-03-28_01
Message-ID-Hash: HTEEW3MKWTN6U2BIGUJDR4MBQHXA5HQG
X-Message-ID-Hash: HTEEW3MKWTN6U2BIGUJDR4MBQHXA5HQG
X-MailFrom: edward.arano@bofa.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-tls12-frozen-07: (with COMMENT)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/g_gcQudujmp63zCYDsaovR_3Tt4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Dear Rich Salz Thank you kindly for your reply. I did not know that you had authored the drafts. Pleased to collaborate with you. I still think the IETF should reconsider. There are millions (im sure much more) of server OS’s in production around the world representative of many organizations (government/military and public) that cannot support TLS 1.3 natively. 😊 Is it reasonable to expect all organizations to upgrade all this infrastructure in a few years to a Server OS that supports TLS 1.3 when the new pqc algorithms can just be added to TLS 1.2? Respectfully Eddie From: Salz, Rich <rsalz=40akamai.com@dmarc.ietf.org> Sent: Thursday, June 5, 2025 2:52 PM To: Arano, Edward <edward.arano@bofa.com>; tls@ietf.org; Paul Wouters <paul.wouters@aiven.io> Subject: Re: [TLS] Re: Ketan Talaulikar's No Objection on draft-ietf-tls-tls12-frozen-07: (with COMMENT) ZjQcmQRYFpfptBannerEnd Hello Apologies and not sure if this is the right place to ask this question; but wondering if the IETF will reconsider adding PQC algorithms to TLS 1.2?? Yes, this is the right place to start a conversation. I expect it won’t get very far beyond strong consensus that the answer is no. There is a related draft, https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/<https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/__;!!I2XIyG2ANlwasLbx!RBC6R5rQGVN7u4Ja2ClWKbPcg4O1qAixwDIpl0kaf2599GvCokwCwGolidEO36ZzWnTdlxrrKlGWjHgl-U3UowUsojKIfRvd$> that encourages people to move to TLS 1.3. Both of these have been through the IETF approval process and are waiting for the AD to post a public notice. (Nudge, Paul :) Adding new algorithms to TLS 1.2 requires installing new software, of course. For a variety of reasons, if you must install new software, the IETF view is you should install TLS 1.3. Disclaimer: I’m the primary author of both of the drafts. /r$ PS: Your disclaimer – repeated twice! – is in violation of the IETF policy that list traffic can be seen by anyone. :) ---------------------------------------------------------------------- This message, and any attachment(s), is for the intended recipient(s) only, may contain information that is privileged, confidential and/or proprietary and subject to important terms and conditions available at http://www.bankofamerica.com/electronic-disclaimer. If you are not the intended recipient, please delete this message. For more information about how Bank of America protects your privacy, including specific rights that may apply, please visit the following pages: https://business.bofa.com/en-us/content/global-privacy-notices.html (which includes global privacy notices) and https://www.bankofamerica.com/security-center/privacy-overview/ (which includes US State specific privacy notices such as the http://www.bankofamerica.com/ccpa-notice)
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Ketan Talaulikar
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Deb Cooley
- [TLS] Ketan Talaulikar's No Objection on draft-ie… Ketan Talaulikar via Datatracker
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Arano, Edward
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Ketan Talaulikar
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Deb Cooley
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Ketan Talaulikar
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Eric Rescorla
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Arano, Edward
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Peter Gutmann
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Salz, Rich
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Watson Ladd
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Eric Rescorla
- [TLS] Re: Ketan Talaulikar's No Objection on draf… David Benjamin
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Peter Gutmann
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Eric Rescorla
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Eric Rescorla
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Peter Gutmann
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Kathleen Moriarty
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Watson Ladd
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Achim Kraus
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Martin Thomson
- [TLS] Re: Ketan Talaulikar's No Objection on draf… Kathleen Moriarty