Re: [TLS] Connection ID in TLS

John Mattsson <john.mattsson@ericsson.com> Tue, 20 March 2018 23:29 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A24491205F0 for <tls@ietfa.amsl.com>; Tue, 20 Mar 2018 16:29:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.32
X-Spam-Level:
X-Spam-Status: No, score=-4.32 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com header.b=WYK9gaSD; dkim=pass (1024-bit key) header.d=ericsson.com header.b=jgr51kPp
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5Ol9uEY58AtX for <tls@ietfa.amsl.com>; Tue, 20 Mar 2018 16:29:18 -0700 (PDT)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7C9D1200B9 for <TLS@ietf.org>; Tue, 20 Mar 2018 16:29:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=ericsson.com; s=mailgw201801; c=relaxed/simple; q=dns/txt; i=@ericsson.com; t=1521588551; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:CC:MIME-Version:Content-Type: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=lRch99IsX7VUrfC0UB6Ru4zBsn94iO7i8fzBAdSWG8M=; b=WYK9gaSDsd9mA21MnXdmxmJV+yvXhSXdX+ul1vS9Vr2dHskrFwlesQNaRCg9laz4 XsvpH0+Z7AsuUysejde6As39+D74seLag70sNBp7s1ddjfOo5f4TyzlOZP9EJSmN 4zSwB9/XpH0hByr9Sh05ublhsUR9vY2NaqWY6Qlvapw=;
X-AuditID: c1b4fb25-669ff70000006222-af-5ab199471df2
Received: from ESESSHC023.ericsson.se (Unknown_Domain [153.88.183.87]) by sesbmg23.ericsson.net (Symantec Mail Security) with SMTP id 2D.4E.25122.74991BA5; Wed, 21 Mar 2018 00:29:11 +0100 (CET)
Received: from ESESBMB504.ericsson.se (153.88.183.171) by ESESSHC023.ericsson.se (153.88.183.87) with Microsoft SMTP Server (TLS) id 14.3.382.0; Wed, 21 Mar 2018 00:29:11 +0100
Received: from ESESBMB501.ericsson.se (153.88.183.168) by ESESBMB504.ericsson.se (153.88.183.171) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1034.26; Wed, 21 Mar 2018 00:29:11 +0100
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (153.88.183.157) by ESESBMB501.ericsson.se (153.88.183.168) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1034.26 via Frontend Transport; Wed, 21 Mar 2018 00:29:11 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=lRch99IsX7VUrfC0UB6Ru4zBsn94iO7i8fzBAdSWG8M=; b=jgr51kPpSDnBFcIC/YMeAhh4gje3qK/m7+hCOwR+FWoOq3sErhkZO3mS053yZ6FDDGuT7rLbbpPIypGvdQwBG9qIIwq+wi/NDLZgk9kiyKtlBMiAp9oym0r9b2lDptXM5vanBiJKSO9vCAXNtEBXi/g1S7XhSfdrsB+EPtBgfFY=
Received: from HE1PR0701MB2011.eurprd07.prod.outlook.com (10.167.189.149) by HE1PR0701MB2860.eurprd07.prod.outlook.com (10.168.91.150) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.609.6; Tue, 20 Mar 2018 23:29:09 +0000
Received: from HE1PR0701MB2011.eurprd07.prod.outlook.com ([fe80::7d80:1860:283c:5ef2]) by HE1PR0701MB2011.eurprd07.prod.outlook.com ([fe80::7d80:1860:283c:5ef2%3]) with mapi id 15.20.0609.010; Tue, 20 Mar 2018 23:29:09 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Richard Barnes <rlb@ipv.sx>, "Fossati, Thomas (Nokia - GB/Cambridge)" <thomas.fossati@nokia.com>
CC: "TLS@ietf.org" <TLS@ietf.org>
Thread-Topic: [TLS] Connection ID in TLS
Thread-Index: AQHTwG76506ybveZD0qR37g9lZTLFqPZYz2AgABzI4A=
Date: Tue, 20 Mar 2018 23:29:09 +0000
Message-ID: <EC1CBB7D-6B07-4288-A1E2-841AD3EB9BE1@ericsson.com>
References: <A32E0C44-51E8-4D2D-AF1C-A55A5065E143@nokia.com> <CAL02cgRLdOBTWECGP9rSWVAO0nRHbDAjnFi62ZLr-5xqnbXJ7g@mail.gmail.com>
In-Reply-To: <CAL02cgRLdOBTWECGP9rSWVAO0nRHbDAjnFi62ZLr-5xqnbXJ7g@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.a.0.180210
authentication-results: spf=none (sender IP is ) smtp.mailfrom=john.mattsson@ericsson.com;
x-originating-ip: [80.5.95.90]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; HE1PR0701MB2860; 7:4bwXOKTsJYUS1w3WVKqDZcH+7opzTygsRB24MdB4DaSNn0S1jii8RElw5sGLM0CW5blDsTZncxVTlfk8hYTnF9VAK5NLZdiHco+CrwYsj09k86ra5/yt+D8pnsx6DvBz2S89671TB+bknTyowhntAxQGDiSbdtzmPphfqdmtsU0FOiB7r1T9UgiysnZ+41LmonWEiyuA5Sg4nVNvSwm39FXBfJuZtkTk1GnBQmbmQ6Gu9516kIttuqXFyzfmfdmj
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: 533a8a98-9f0f-430f-430c-08d58eba61a1
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:HE1PR0701MB2860;
x-ms-traffictypediagnostic: HE1PR0701MB2860:
x-microsoft-antispam-prvs: <HE1PR0701MB2860C9BD23E422C3CF39860189AB0@HE1PR0701MB2860.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(37575265505322)(28532068793085)(120809045254105)(82608151540597)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(3002001)(93006095)(93001095)(3231221)(944501244)(52105095)(10201501046)(6041310)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123562045)(20161123560045)(20161123558120)(6072148)(201708071742011); SRVR:HE1PR0701MB2860; BCL:0; PCL:0; RULEID:; SRVR:HE1PR0701MB2860;
x-forefront-prvs: 061725F016
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(346002)(39380400002)(376002)(39860400002)(366004)(396003)(189003)(199004)(53936002)(97736004)(5660300001)(86362001)(8676002)(6306002)(54896002)(3660700001)(6506007)(53546011)(2950100002)(478600001)(81156014)(81166006)(966005)(606006)(6436002)(5250100002)(8936002)(68736007)(186003)(102836004)(26005)(316002)(6486002)(14454004)(36756003)(33656002)(110136005)(58126008)(8656006)(6246003)(83716003)(229853002)(106356001)(2900100001)(4326008)(82746002)(99286004)(25786009)(2906002)(66066001)(3846002)(790700001)(6116002)(76176011)(3280700002)(236005)(7736002)(6512007)(105586002); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR0701MB2860; H:HE1PR0701MB2011.eurprd07.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: j1N5mhzkQP41qrgJ0LURrfctwKBf4gqf/ITkOHllvV9AfFQyneu4D//EyE5yf/RT2t57DtJKb+1bW6r8FKOJbZIM+DesbBZKmifB9rQI/i4KdA+fhrUD5f40VlfbmBLg9fVNHksO4X1WgKy29AzaC4wxTH8l8jTJ3yatRJ5MVlwEpuq6ByeoT18B/MkQPN5d+aWZkqgdy6oXge6ykIC7aLGlC2ZcqsFYuvY6iLfy/+HcBCM66TEAPcidb2OHfg2dYFbnFE4bHfAc3JLjAYkFrYc+8ueeUZ+9xGsbjw1pGIG4Q312Y9Pk4vx9HK7kwSZNA9FikTmkp4VLjyQ5jWFhRA==
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_EC1CBB7D6B074288A1E2841AD3EB9BE1ericssoncom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 533a8a98-9f0f-430f-430c-08d58eba61a1
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Mar 2018 23:29:09.4250 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2860
X-OriginatorOrg: ericsson.com
X-Brightmail-Tracker: H4sIAAAAAAAAA02SaUhUURTHu+/N8hwauo3bQS1oyLTFZaoPkmn2SYOEhEIbbBn1ueDaPJWs cMEVFbV0tBncoLHUKXLCpWRCHanUEsNWzSBJJdHQxkRMW2bmTuC33znnf875n8tlaImB78Ik pKSzyhRFklQg4qkjesK9gtV6ua+hV+anqgjwK1gxCfxMY6UoiA7RatepkGq9hhfyeXKcOkPL Rcdj2KSETFbpE3hZFF/c2o/SitirP2fn+bnoTlQpsmMAHwV90xhVikSMBA8iGJqYoUnQiWBc 9YlPgjUEk/1/hSRooeBX57jQ0s/DJgrU7y6SQi0Ffa+/24bNIah69tGqEmBfaDDkCizsgGOh vHGab2Ea7wFD97BVY489YMqYKyQaTxhaUNGEj8FCXblZz5i3uYOuP9GSFuMToOvtsO3KR/C7 RMuzaOxwGHROuFk0CDvB2sh9iqxyhsmZJoocjUFrGKMJO8L81z9WO47YG/JNH4Sk9wIUFtbx iWY3jM7eEhDeBeNNZYhwNwWV1T6EvWBZpbLNDAV13YjA4g3wCILlhmkeKRyCL6vNVp+AU6Gm TVqFZJot9ghHw6tRFV9jPXMnDKtneBpzB433w8NeH43t4WrKpoWEPaGwvsHGIfDEUEVt1TQj ph05ciwXlRx3+Ig3q0yI5rjUFO8UNv0RMv+pgc4N98fozeJJI8IMkm4XD5bo5RK+IpPLSjYi YGipg9gYYU6JYxRZ11hl6iVlRhLLGZErw5M6i+vti+USHKdIZxNZNo1V/q9SjJ1LLnKq65vT 9drrA88u2xdob7q1DC91Xc/PuBGrW2l9IDrvwSQ1x7TV9nS5vjwYHNsWkSM/7eu9wyPMf9td fuMVzw3FvZJ9UVPZvpHZ7U557zsyivpEQXkDguen0kKZ9SVu4vbij82nAZkF32R5/i/O5VRW DG+uhkdmbe6VMY09ya5vp6U8Ll4hO0ArOcU/8hNG+08DAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/k01qh7BpMOoaMwsVZldHjGE3HJ0>
Subject: Re: [TLS] Connection ID in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Mar 2018 23:29:31 -0000

I don’t think it is required either, the mechanisms in draft-schmertmann-dice-codtls and draft-friel-tls-over-http clearly wotks, but Hannes Tschofenig brought it up as a new mechanism that can be used to simplify things in ATLS, I tend to agree. I don’t think we should invent new mechanism for ATLS if we can use Connection ID.

From: "rlb@ipv.sx"; <rlb@ipv.sx>;
Date: Tuesday, 20 March 2018 at 17:37
To: "Fossati, Thomas (Nokia - GB/Cambridge)" <thomas.fossati@nokia.com>;
Cc: John Mattsson <john.mattsson@ericsson.com>;, "TLS@ietf.org"; <TLS@ietf.org>;
Subject: Re: [TLS] Connection ID in TLS

I don't think Connection-ID is really required for ATLS.  As Carsten and Owen mentioned in the side meeting, there are a few ways to use HTTP to correlate the relevant messages.

On Tue, Mar 20, 2018 at 5:15 PM, Fossati, Thomas (Nokia - GB/Cambridge) <thomas.fossati@nokia.com<mailto:thomas.fossati@nokia.com>> wrote:
On 20/03/2018, 16:38, "TLS on behalf of John Mattsson" <tls-bounces@ietf.org<mailto:tls-bounces@ietf.org> on behalf of john.mattsson@ericsson.com<mailto:john.mattsson@ericsson.com>> wrote:
> At the Monday afternoon TLS session, it was stated that Connection ID
> in TLS was unemployable in the wild due to middleboxes. Couldn't that
> be solved by placing the cid field after the length field?

Are you referring to slide 13 of [1]?

If so, the problem is not CID-specific.  It's more generally what
could happen if we try and reuse the top bit of the length field
for other purposes.

Yoav brought up the case of an intercepting middlebox - one that needs to
pretend to be a fully-fledged TLS server.  That kind of box might
either:
- let the extension that enables repurposing the length's MSB pass
  through, and subsequently choke on the invalid length [HARD FAIL];
- eat up the unknown extension and therefore break the feature
  negotiation [SOFT FAIL].

Cheers


[1] https://datatracker.ietf.org/meeting/101/materials/slides-101-tls-sessb-record-header-extensions-for-dtls-00

_______________________________________________
TLS mailing list
TLS@ietf.org<mailto:TLS@ietf.org>
https://www.ietf.org/mailman/listinfo/tls