[TLS] TLS1.3 clarification request

Jeremy Harris <jgh@wizmail.org> Mon, 15 March 2021 10:52 UTC

Return-Path: <jgh@wizmail.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A4D53A0BFF for <tls@ietfa.amsl.com>; Mon, 15 Mar 2021 03:52:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=wizmail.org header.b=3L2w5s34; dkim=pass (2048-bit key) header.d=wizmail.org header.b=Hyo1WiQb
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B-hD-SO2BH3f for <tls@ietfa.amsl.com>; Mon, 15 Mar 2021 03:52:53 -0700 (PDT)
Received: from wizmail.org (wizmail.org [IPv6:2a00:1940:107::2:0:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5DC1E3A0BFD for <tls@ietf.org>; Mon, 15 Mar 2021 03:52:53 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=wizmail.org; s=e202001; h=Content-Transfer-Encoding:Content-Type: MIME-Version:Date:Message-ID:Subject:From:To:From:Sender:Reply-To:Subject: Date:Message-ID:To:Cc:MIME-Version:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive: Autocrypt; bh=/+Q1cfMzQFvXGOixThaB1tpA+pnVN3/gUbYfzJL9Csw=; b=3L2w5s341cpx8HP 9M4uAVVCccpGC9/doJ2uQFGOZoIBWBBfokBRQF4xUIoDnNE6tJamRoOLOMrXO5WgFI0iZAg==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=wizmail.org ; s=r202001; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Date: Message-ID:Subject:From:To:From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc :MIME-Version:Content-Type:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive:Autocrypt; bh=/+Q1cfMzQFvXGOixThaB1tpA+pnVN3/gUbYfzJL9Csw=; b=Hyo1WiQbBQQQ5F1T1XVlooDw+h 8ZrPpvknID30XNXxcODhRs7BvL0qELJoApOtIe07VcprLfA3V/S8kx9QEPYeyW1XfwvZBr7HTD0FE 1FNr7rWU8pxnwqAQZmzIhsb9ufJTEG+O3s1DrLmFnRyy7ZagOsHpbkhqAVVfF6XG0aaou0y/789oF iM6sU23gQUI5W9iG/Qecq3apQ6fp8HLX2sgyQUvBHrSKyQAS/gcc4W+m///EsK6LWtNA+IMbV4fl8 6Aji6/bXgUkQwvCOsxMREpNpoLp6QwkHnmGbxfmyHCcw2j6AIyYcF15lPi9QERhekvCCqEBHxIpep 2VSRvzUQ==;
Authentication-Results: wizmail.org; iprev=fail smtp.remote-ip=46.33.133.68; auth=pass (PLAIN) smtp.auth=jgh@wizmail.org
Received: from [46.33.133.68] (helo=lap.dom.ain) (from_AS 51561) by wizmail.org (Exim 4.94.116) (TLS1.3) tls TLS_AES_128_GCM_SHA256 with esmtpsa id 1lLkq9-003anb-Kj for tls@ietf.org (return-path <jgh@wizmail.org>); Mon, 15 Mar 2021 10:52:49 +0000
To: "tls@ietf.org" <tls@ietf.org>
From: Jeremy Harris <jgh@wizmail.org>
Message-ID: <f9cd8547-566e-f9f5-fe95-b0abc952d62d@wizmail.org>
Date: Mon, 15 Mar 2021 10:52:49 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.8.0
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-GB
Content-Transfer-Encoding: 8bit
X-Pcms-Received-Sender: [46.33.133.68] (helo=lap.dom.ain) with esmtpsa
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/i8S0HsofF2fUKhDEYrt2AaPc56g>
Subject: [TLS] TLS1.3 clarification request
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Mar 2021 10:52:55 -0000

Hi,

Could people please confirm a detail of TLS 1.3 session
close behaviour?  Specifically, are half-closes supported
in similar fashion to TCP half-closes - in that it is
legitimate for one end to issue a Close Notify alert
and for the other end to receive that alert but continue
to transmit data after such reception and before sending
its own Close Notify?

Further, is it reasonable for the above first end to
expect the above second end to continue processing and
sending data that would have been sent in the absence of
such a first Close Alert?


I ask because of the observed actions of Google MTA servers.
When using a TLS1.3 connection, after STARTTLS on an ESMTP
connection with PIPELINING and CHUNKING - if the smtp client
pipelines a full set of MAIL, RCPT, BDAT nnnn LAST, QUIT
*and* follows those with a TLS Close Notify then the Google
server issues an immediate TCP FIN.  It does this without
sending any SMTP responses (even for the MAIL command)
and it does not send a TLS Alert of any kind.

If the full ESMTP sequence give is sent without the TLS
Close Notify, then SMTP responses are transmitted by the
SMTP server as expected.
-- 
Cheers,
   Jeremy

PS: I am aware that TLS1.2 does not support half-closes.