Re: [TLS] TLS Export Channel Binding

Sam Whited <sam@samwhited.com> Fri, 01 May 2020 16:17 UTC

Return-Path: <sam@samwhited.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 109563A1683 for <tls@ietfa.amsl.com>; Fri, 1 May 2020 09:17:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=samwhited.com header.b=rl5UEHcA; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=hj0/w8S8
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZSndAiqkf-Oj for <tls@ietfa.amsl.com>; Fri, 1 May 2020 09:17:11 -0700 (PDT)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0ADB53A1675 for <tls@ietf.org>; Fri, 1 May 2020 09:08:49 -0700 (PDT)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.west.internal (Postfix) with ESMTP id 4C58164D; Fri, 1 May 2020 12:08:48 -0400 (EDT)
Received: from imap34 ([10.202.2.84]) by compute7.internal (MEProxy); Fri, 01 May 2020 12:08:48 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samwhited.com; h=mime-version:message-id:in-reply-to:references:date:from:to :cc:subject:content-type:content-transfer-encoding; s=fm2; bh=vD l2zzIvMPyAJnH1YosiOH5Y/xwm654jEnFVChMnkNk=; b=rl5UEHcAGp1J96QyOq BiuF5fRhMxl+9EAS7Me9vnJ+hrKBcXTHh1ZsZ3FHIizg0IF4GMaeXwZvdsqOGZZJ f9v5WWsymGwa4giugmeJ9LLUUvaQJTNnn8z4je9u5hlgghsgi2SH4cKjYwWLF10K uMjmafT0Cb3InXIk/3/6h/TZohX8okOYnxOMMNFJaioORdtoyjDCpUxvUXk4R1Fg iFh0Z3L3PZ2/FvzYOdHpI2Q1vlV0T1+f0k9aQ1ejoErCCO0T2e0aSb76eTC7yojR RsqApi+tX4PSU03KeMI6QkS1QyxPj+w/ManLygdEVO194X//ena/y6d++qZgRACZ AtxA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=vDl2zzIvMPyAJnH1YosiOH5Y/xwm654jEnFVChMnk Nk=; b=hj0/w8S8tv/aJNuwPYqQwXSF/h3ABiSM4FsFUWc7mCgswyYbm/PUlasne M6vbC96sTAEseRj7vfewRi/ucJ87aHXTQSHpDWd5DuaDs+lc+gyHcKMbH77Dvsbz 6y2lzKsGIMPwxR54XMbTJJwtiGxM9mV/J5WcvIpmw8wuwJxOq/G6U88NZ8yZDVnP g5VbN50liyRApcR1ZuVr2jrHWKbFXXnefpI2+4w52h6ICJqxaVb3HcpUSnHvC5Wl E0Q/O9Dxp1XTQpIRgfpBRwws7yx/rKNXTYmsQHB6u0u6m3GdAduVOqhPNYoqCuoP rAQDb8g+G/sKNQ+slptH4W/mhqjog==
X-ME-Sender: <xms:j0msXvmtJ4sEbcU4_6dkLxOt7wL47Z9kSlB1qdim1pT_8EYLJHqEFw>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduhedrieejgdelhecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpefofgggkfgjfhffhffvufgtgfesthhqredtreerjeenucfhrhhomhepfdfurghm ucghhhhithgvugdfuceoshgrmhesshgrmhifhhhithgvugdrtghomheqnecuggftrfgrth htvghrnhepleejvdehgeefhfeitddtfefhudettdffvdegueejkeevudetiefgjeehgfeh leehnecuffhomhgrihhnpehrfhgtqdgvughithhorhdrohhrghdpihgvthhfrdhorhhgne cuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepshgrmhes shgrmhifhhhithgvugdrtghomh
X-ME-Proxy: <xmx:j0msXiEBdVrgetan-sYm3hhOx7G6_U6LxWOzYEr8ThifhvGmaIQrtA> <xmx:j0msXocVoGV3Cnf0c0k_TaZL1KUHxrFUjFZdb7acWP0MfaWgIaDy7Q> <xmx:j0msXvFLxn8QhFjdvshCxcbMc84Ol-f0zKZFAQL1NKwjYM9Drxva3g> <xmx:j0msXgNZ3C_NadNWaxYgVqzhbMsjS4g6Dut37fjcbBSvEvSp_QwJAQ>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id A37D01460061; Fri, 1 May 2020 12:08:47 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.3.0-dev0-351-g9981f4f-fmstable-20200421v1
Mime-Version: 1.0
Message-Id: <13c2ff5e-f68e-45b5-bd64-085b9bdaf17e@www.fastmail.com>
In-Reply-To: <CACykbs3WDk7a0+0vCSDfCuib1Bex8SUJ-kvtZhjchvvm+5xc0g@mail.gmail.com>
References: <0f20d1f6-56c1-4e01-813f-f8b3c57a5c9b@www.fastmail.com> <CACykbs3WDk7a0+0vCSDfCuib1Bex8SUJ-kvtZhjchvvm+5xc0g@mail.gmail.com>
Date: Fri, 01 May 2020 12:08:27 -0400
From: Sam Whited <sam@samwhited.com>
To: Jonathan Hoyland <jonathan.hoyland@gmail.com>
Cc: "<tls@ietf.org>" <tls@ietf.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/grvWCgxFsC5zNii9JCJm5NLReWA>
Subject: Re: [TLS] TLS Export Channel Binding
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 May 2020 16:17:14 -0000

Hi Jonathan,

On Fri, May 1, 2020, at 12:00, Jonathan Hoyland wrote:
> I believe TLS Exporters are what you are looking for.
> https://www.rfc-editor.org/rfc/rfc8446.html#section-7.5

Thanks for the follow up. That is indeed what the channel binding type
I've created uses. Would the TLS working group be interested in
standardizing such a document?

I've gone ahead and uploaded my initial draft that I threw together here
in case you're interested:

https://datatracker.ietf.org/doc/draft-whited-tls-channel-bindings-for-tls13/

—Sam