[TLS] Re: I-D Action: draft-ietf-tls-8773bis-08.txt

Russ Housley <housley@vigilsec.com> Mon, 02 June 2025 16:06 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2DA172FCA540 for <tls@mail2.ietf.org>; Mon, 2 Jun 2025 09:06:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vigilsec.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eR-BhO_L08KI for <tls@mail2.ietf.org>; Mon, 2 Jun 2025 09:06:28 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9668D2FCA53B for <tls@ietf.org>; Mon, 2 Jun 2025 09:06:28 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 75F951A1BBB for <tls@ietf.org>; Mon, 2 Jun 2025 12:06:28 -0400 (EDT)
Received: from smtpclient.apple (pfs.iad.rg.net [198.180.150.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 6A51F1A2B34 for <tls@ietf.org>; Mon, 2 Jun 2025 12:06:28 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.600.51.1.1\))
Date: Mon, 02 Jun 2025 12:06:18 -0400
References: <174888002912.2583484.1581276047944401119@dt-datatracker-59b84fc74f-84jsl>
To: IETF TLS <tls@ietf.org>
In-Reply-To: <174888002912.2583484.1581276047944401119@dt-datatracker-59b84fc74f-84jsl>
Message-Id: <C11980B0-5542-4E2F-9A44-93B021FFF23B@vigilsec.com>
X-Mailer: Apple Mail (2.3826.600.51.1.1)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com; h=from:content-type:content-transfer-encoding:mime-version:subject:date:references:to:in-reply-to:message-id; s=pair-202402141609; bh=kLzLb6gzyQ7+mgAen9UhYVcCMp10opiEQv9EMhHhLWc=; b=J1Idq8qOZQ/pDbR8a5S7bLp+FS7cZEZYTsglgOIV3NJzBvNkjjlvMhoTZoOS0XL//YXRD0hD+2eJNQvpJOfAKCgq+cBFVThYIW68Jfykg8cDDHVPZmyxJGddTENHfkV7/wreHsWA0UgNrrMi2RB1LzG6hTAM+f4TagNx+qeOuIQySxyGUUpYA7CD0NQeWT60pLI5Rv8NM1Sdn2Cd5LEnfr2pGTAGxWyu1uSCZPvqoRUOX2a/Ux/IMNVfr1NEDxDdmS8ws1qvfJZaytCdVyoYWK4HJc0YrFYGGDxjMSD2WFHzg3X8T6FZ752tY7z/dHI1kRleKo1IkWbq1jGnLMCizw==
X-Scanned-By: mailmunge 3.09 on 66.39.134.11
Message-ID-Hash: X6KSP6WTYFJBV7MJONIVEBOA3N75WKXS
X-Message-ID-Hash: X6KSP6WTYFJBV7MJONIVEBOA3N75WKXS
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: I-D Action: draft-ietf-tls-8773bis-08.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/iflpI1u3JAUHYir2-BtaBdu5v4c>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Correcting a typo in the version that was posted two days ago.  Tanks to Usama for spotting it.

Russ


> On Jun 2, 2025, at 12:00 PM, internet-drafts@ietf.org wrote:
> 
> Internet-Draft draft-ietf-tls-8773bis-08.txt is now available. It is a work
> item of the Transport Layer Security (TLS) WG of the IETF.
> 
>   Title:   TLS 1.3 Extension for Using Certificates with an External Pre-Shared Key
>   Author:  Russ Housley
>   Name:    draft-ietf-tls-8773bis-08.txt
>   Pages:   16
>   Dates:   2025-06-02
> 
> Abstract:
> 
>   This document specifies a TLS 1.3 extension that allows TLS clients
>   and servers to authenticate with certificates and provide
>   confidentiality based on encryption with a symmetric key from the
>   usual key agreement algorithm and an external pre-shared key (PSK).
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-tls-8773bis/
> 
> There is also an HTMLized version available at:
> https://datatracker.ietf.org/doc/html/draft-ietf-tls-8773bis-08
> 
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-tls-8773bis-08
> 
> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts