Re: [TLS] Remove 0-RTT client auth

Martin Thomson <martin.thomson@gmail.com> Mon, 22 February 2016 07:18 UTC

Return-Path: <martin.thomson@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 790911B3645 for <tls@ietfa.amsl.com>; Sun, 21 Feb 2016 23:18:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lns8dFPg7-gM for <tls@ietfa.amsl.com>; Sun, 21 Feb 2016 23:18:49 -0800 (PST)
Received: from mail-ig0-x22c.google.com (mail-ig0-x22c.google.com [IPv6:2607:f8b0:4001:c05::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22CE81B33C7 for <tls@ietf.org>; Sun, 21 Feb 2016 23:18:49 -0800 (PST)
Received: by mail-ig0-x22c.google.com with SMTP id y8so80312594igp.0 for <tls@ietf.org>; Sun, 21 Feb 2016 23:18:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=0+Hk09V3855586ndIvbSswpU5ulMNTfHehUjK2sr83s=; b=0Fuzf5bfLq6aJYe8ClujPXvvMPTYm123i65B7wb9z7qIQZl1O0ioe8tCQJmTzKffYT TLY0seGhudz240kwEmBfx0wwJLD4kAUHGPb5FCjroXgRWqPrEAumdlFDwze1QelDoa2p K5IgvtOm4f9OKExxSpxV9angvYddxAKEfqkD/HCHZtKCqT4gN6C6hpiu0ToW0g5vY6iP RVECTRJZSYZoXn4qoWPBDHOb6iSTcZgyrn/14DYmScMZvAYpPGNgRos1J56vXoqnqNxe bXxcCJB1n57Rc+hRqbmNRrOX8WgeKLrGb1Jgb7TOKc7Qny0dxoVZOjgDVkgpycaq5HnK 53Xg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=0+Hk09V3855586ndIvbSswpU5ulMNTfHehUjK2sr83s=; b=luMumuWlpkjwEIiuAKlR0XWCatNnD282GlNQgJtD5a5i0OqUn8dB304heEJbRMRvLm z0K28CgxexTqeq5KGslyI/WToj0Ddu+qwGvlyNvTZOZzF31SZ9xvU5apuBNfIsitwVeS Z4B7Zq7y7oFLG1ra0NRaovzgYf4gM6HH0ZJ1n3utB31Ah7QGDqIQy8v4D1fJEiO+tuG1 wiUmj4LnfmGqopapqivVg0hBvRqBiCqg9y7UfczH/d4SG87fXe5CUdwEhAnO19KwOiOO oBnQa3fpKE/qtaUKjvHTSCi8/106UIZ1cFQykEToRlerZlOqOPukIXiYHBohWOvBf6n3 Hd3g==
X-Gm-Message-State: AG10YOR78Wxd7kRf9IYqSE6J/mneksqQ/SfFL1buLLfbPnSZjz+D5YCbl6D1a6TuprEWEOR3aieKX/Q8cxXNEw==
MIME-Version: 1.0
X-Received: by 10.50.131.227 with SMTP id op3mr3239972igb.94.1456125528515; Sun, 21 Feb 2016 23:18:48 -0800 (PST)
Received: by 10.36.53.79 with HTTP; Sun, 21 Feb 2016 23:18:48 -0800 (PST)
In-Reply-To: <20160222054609.GA20873@LK-Perkele-V2.elisa-laajakaista.fi>
References: <CABkgnnWy3anGeLZ2a=EH+O2f4PnScJPGdBdEOkA7EmE+jgZ1pg@mail.gmail.com> <20160222054609.GA20873@LK-Perkele-V2.elisa-laajakaista.fi>
Date: Sun, 21 Feb 2016 23:18:48 -0800
Message-ID: <CABkgnnU311W0SnDA_VxVCqvQD3hC_FstrMoaGjWq-3h+765mvA@mail.gmail.com>
From: Martin Thomson <martin.thomson@gmail.com>
To: Ilari Liusvaara <ilariliusvaara@welho.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/jt95g6wABWTr9q7Jpucp4tTanxA>
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Remove 0-RTT client auth
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Feb 2016 07:18:50 -0000

On 21 February 2016 at 21:46, Ilari Liusvaara <ilariliusvaara@welho.com> wrote:
>> We originally thought that we might want to do this for
>> WebRTC/real-time.  As it so happens, we have an alternative design
>> that doesn't need this, so...
>
> Got mailarchive or draft link?

No, this was a realization that we could just stuff the ClientHello
into the signaling (the SDP offer to be precise) and continue the
handshake later.  There were all sorts of ideas floating around about
using offline configs, but those are all just more complex.