Re: [TLS] Media types "application/tls" and "application/ssl", and URIs for schemes "tls" and "ssl"
"Salz, Rich" <rsalz@akamai.com> Wed, 27 December 2023 18:19 UTC
Return-Path: <rsalz@akamai.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F590C14F6A3; Wed, 27 Dec 2023 10:19:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.806
X-Spam-Level:
X-Spam-Status: No, score=-2.806 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ip5d-sfN2a0h; Wed, 27 Dec 2023 10:19:32 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7002CC14F5E3; Wed, 27 Dec 2023 10:19:32 -0800 (PST)
Received: from pps.filterd (m0050093.ppops.net [127.0.0.1]) by m0050093.ppops.net-00190b01. (8.17.1.22/8.17.1.22) with ESMTP id 3BRHl5M5029979; Wed, 27 Dec 2023 18:19:31 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h= from:to:cc:subject:date:message-id:references:in-reply-to :content-type:content-id:content-transfer-encoding:mime-version; s=jan2016.eng; bh=aUZ8d9/F/KLn/1couoCgwESZHW7GxQyTiMyCij572Ik=; b= QqfZ7IxnNM7/N82toh6ntAlENtFdp6730ugYOtJq7+vNXIAlA1ffdDrA47APfTWP IK5WU9DaEsO+iRAAoX4MMGq7FC2RbeJpwPknhm29tSwyqBRQpYaMeES33mf/r+fY 6V9Zn0cnPgdNxzOTt+LFtDHBM29//eIJaxyL9V8xTf4xVguKtvMJCYe+bDtna4Cg 0H5J9dF9GhQBo+PNdOu58pBDTcTTWmVPwKDHNzTB2gL5qiugTYghu7AgmYViXDkt ctq51Onmh0ZQd6RE2GlBsrYj3qERlEv+HmEDTUbvgiMLgtB5rE48ocWDwon22yv0 84KV58M5kgDnk3iK8mulYA==
Received: from prod-mail-ppoint4 (a72-247-45-32.deploy.static.akamaitechnologies.com [72.247.45.32] (may be forged)) by m0050093.ppops.net-00190b01. (PPS) with ESMTPS id 3v5qqbc1p9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 27 Dec 2023 18:19:31 +0000 (GMT)
Received: from pps.filterd (prod-mail-ppoint4.akamai.com [127.0.0.1]) by prod-mail-ppoint4.akamai.com (8.17.1.19/8.17.1.19) with ESMTP id 3BRFqKjw015205; Wed, 27 Dec 2023 13:19:30 -0500
Received: from email.msg.corp.akamai.com ([172.27.50.204]) by prod-mail-ppoint4.akamai.com (PPS) with ESMTPS id 3v5us2fk8x-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 27 Dec 2023 13:19:30 -0500
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) by ustx2ex-dag4mb5.msg.corp.akamai.com (172.27.50.204) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.28; Wed, 27 Dec 2023 10:19:29 -0800
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) by ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) with mapi id 15.02.1258.028; Wed, 27 Dec 2023 10:19:29 -0800
From: "Salz, Rich" <rsalz@akamai.com>
To: arkiver <arkiver=40protonmail.com@dmarc.ietf.org>, Eric Rescorla <ekr@rtfm.com>
CC: "tls@ietf.org" <tls@ietf.org>, "JustAnotherArchivist (JAA)" <justanotherarchivist@riseup.net>
Thread-Topic: [TLS] Media types "application/tls" and "application/ssl", and URIs for schemes "tls" and "ssl"
Thread-Index: AQHaM4GVxtkMwJrO90i2BBZfPZnJ0rCzMH0A///AiYCABwiHgIADtC8A
Date: Wed, 27 Dec 2023 18:19:29 +0000
Message-ID: <1A3A30C7-9680-44ED-AD5E-46F9A90EFF95@akamai.com>
References: <xzQs7kZTf4a-ip-6hpfaXV4RGdaIkCJah_dWW900efvQTUuywS4xe4bJiVL7iOk4poXg44IR5aH9aRe9H52F4Ko-2Xql9GPIY1kVtzfV6NI=@protonmail.com> <CABcZeBM_5yZ2Y9Rw7EOvvvVGDL8+Z4-8ZyHSPN1bvPKKxf0Uaw@mail.gmail.com> <2DFA835E-39C1-4644-859A-EC035BB7DF81@akamai.com> <GoRB3Tc8-MqNpGDGjtIW8q2tTvOsv_iceh7tIzsC7ovInjwEnrJpTKJ5WJdWCQyZEnq0Mx9zAZZViCrutnJ31or1zN1g1w8oTt0SvnywD78=@protonmail.com>
In-Reply-To: <GoRB3Tc8-MqNpGDGjtIW8q2tTvOsv_iceh7tIzsC7ovInjwEnrJpTKJ5WJdWCQyZEnq0Mx9zAZZViCrutnJ31or1zN1g1w8oTt0SvnywD78=@protonmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.80.23121017
x-originating-ip: [172.27.164.43]
Content-Type: text/plain; charset="utf-8"
Content-ID: <477020FDD9B9F04C87689D2AD52230AC@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.997,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-12-27_12,2023-12-27_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxlogscore=569 adultscore=0 phishscore=0 mlxscore=0 bulkscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2311290000 definitions=main-2312270134
X-Proofpoint-GUID: yskwpqWf9YMyXOh9FXmQCVXoGGmevMS9
X-Proofpoint-ORIG-GUID: yskwpqWf9YMyXOh9FXmQCVXoGGmevMS9
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.997,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-12-27_12,2023-12-27_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 mlxlogscore=558 adultscore=0 suspectscore=0 malwarescore=0 priorityscore=1501 impostorscore=0 lowpriorityscore=0 clxscore=1015 phishscore=0 bulkscore=0 spamscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2311290000 definitions=main-2312270135
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/k83aty1zw_hLb-ybksyxXSxsBdU>
Subject: Re: [TLS] Media types "application/tls" and "application/ssl", and URIs for schemes "tls" and "ssl"
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Dec 2023 18:19:36 -0000
> Next to this we would want to record TLS/SSL details that are not clear from the above WARC record with HTTP response. We could certainly store an abstraction or interpretation of these details, but we risk losing information if we do (similar to how we store the raw HTTP response without alterations). From my initial message, an example TLS record may look like (with fake digest and length, copied from the HTTP WARC record example): Again, think carefully about the data you are recording. Also, TLS1.2 allows renegotiation in an active connection to do things like change the cipher algorithm, ask the client to send its certificate, and so on. Are you going to record those? Client authentication seems like something important. And which part are you recording". The client or server side or both? You said "outgoing TLS record" but that's not clear to me. Renegotiation can be initiated by either side FYI. > The handshake messages hold interesting data, for example they could be used for fingerprinting and in that way affect the HTTP responses. These message are on the TLS level layer. We would want to store these as they are received so as to not risk losing any information, as we do for the HTTP level layer. Are you going to support session resumption, session tickets, pre-shared keys? Are you going to ensure your client doesn't do any of those? Merging the thread this early didn't help this conversation. I am sure I have missed replying to some of my points that you responded to. I read RFC 7595 and looked at the IANA registry. I am fairly confident that you will never get the "tls" scheme, so you might want to re-think things a bit.
- Re: [TLS] Media types "application/tls" and "appl… Eric Rescorla
- [TLS] Media types "application/tls" and "applicat… arkiver
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich
- Re: [TLS] Media types "application/tls" and "appl… Eric Rescorla
- Re: [TLS] Media types "application/tls" and "appl… arkiver
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich
- Re: [TLS] Media types "application/tls" and "appl… JustAnotherArchivist
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich
- Re: [TLS] Media types "application/tls" and "appl… arkiver
- Re: [TLS] Media types "application/tls" and "appl… JustAnotherArchivist
- Re: [TLS] Media types "application/tls" and "appl… Eric Rescorla
- Re: [TLS] Media types "application/tls" and "appl… arkiver
- Re: [TLS] Media types "application/tls" and "appl… Salz, Rich