Re: [TLS] FW: New Version Notification for draft-rsalz-tls-tls12-frozen-00.txt

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 17 May 2023 15:34 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A4854C1522CB for <tls@ietfa.amsl.com>; Wed, 17 May 2023 08:34:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.998
X-Spam-Level:
X-Spam-Status: No, score=-6.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zzqyyjcP69ns for <tls@ietfa.amsl.com>; Wed, 17 May 2023 08:34:24 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04on070d.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0d::70d]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F27B7C1524DB for <tls@ietf.org>; Wed, 17 May 2023 08:34:23 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=XvfsBxHhCFsEwYHMF5CFk4g3e3pMjiiw/TukouX/fh/Gjow38zdGhLgb1HIqZngEUfPn0dEMqABbpqaTYvDDWap+xYFqQo5m2xR/jRZZ+NyIidj/92ncDjL8/Fn+QSSf+G5HRGYtBHBV+TZjLXx/SyyE23V63/ZwvdPe+BVx4tpD3aEoC3bH5w/UqT7vht2cXuHX2MJu4M7gmIvdCosOGYtDIh8Iuap2QBWv94gOQU7t7j2FmoQtSByZLd7BPnTu5U2btOjnFagvnB11T7FORCeaxXwDHzc4E9jl7G+cBuaoelLhlEJJd17/7NnJnxbrZk+JEyo9/QeMLRgjtEuQFg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=lrLVGJO7K4dpLIRqoEMCSgYaCrgjBOvCtjk88FvUGZ0=; b=bOZfutN5AC061wEhaArxWv+bTC4yLbIUC3BAGsZrKUYCcpUHPZwENBA/TbxXAv0/G86MUmkJYtU8edd93IImHeucPA6RoYN7ywNcjTX3ZM/MswmLzOkpBLg0Gqa/dj3KuRqMeTEYrG1rFfgrFilrEVhsIm5RRpeyLiHVpSo1EoidVsz6qLbsHwUoPvj2l4YLB22YOy6pqWUwLVvx4sIyg0zapB4zZd824HZao1w1d8HdKfsWxLR+earfCofssj2P7pph0zGTlESf17eLKLxXjy9KJbwwSZAJIAhJ/o+9GvytYOTJIZhKAYDjTeg4pA0XaBSFkbDjd99B/O1KRH5K1w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lrLVGJO7K4dpLIRqoEMCSgYaCrgjBOvCtjk88FvUGZ0=; b=Zcy0zoqVu4xiLOy++Tx4mUt3APIspQyAeFEFSpQausDNMobMA3PO5ulTTRjXK2X6XsZRHwNZ3NrY8kO6DjpzBNABe4kxEPdcYLc5I2HhOUXQJZ2Og6TdckHFHvULvdnsmNQccBLogURuIZRLNxOAQXNrb7k1DA9WzNyv67WE3/PNng0MaZp7NAn7OXvafCr1A0Vann/WI6lBsrb/oqegotaq+7R+V3bp5hr+zNOmj/eqnSn+wYNZ9yKVJ2WcTMhQWSncy9OvH7KB9Z+wEbQOukLsHwH/L1DsUEKLEVng3B56bshphbwg6cWX98obu28C/j81zCZx9nzW1aJxx63rcA==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by AS8PR02MB7304.eurprd02.prod.outlook.com (2603:10a6:20b:3f7::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6387.33; Wed, 17 May 2023 15:34:17 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::579a:c872:9936:8fd5]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::579a:c872:9936:8fd5%6]) with mapi id 15.20.6387.033; Wed, 17 May 2023 15:34:17 +0000
Message-ID: <4926ef9d-c70c-6ed2-5424-511cc5c32009@cs.tcd.ie>
Date: Wed, 17 May 2023 16:34:15 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Content-Language: en-US
To: "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>, "tls@ietf.org" <tls@ietf.org>
References: <168433253177.21166.7087521084356529375@ietfa.amsl.com> <2EE32FD9-2F71-49A1-8F8E-36AA16644D41@akamai.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <2EE32FD9-2F71-49A1-8F8E-36AA16644D41@akamai.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------S1AEc8zlEsHfgX7COZ06ilEv"
X-ClientProxiedBy: DB6P195CA0018.EURP195.PROD.OUTLOOK.COM (2603:10a6:4:cb::28) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB7PR02MB5113:EE_|AS8PR02MB7304:EE_
X-MS-Office365-Filtering-Correlation-Id: f6008c11-d281-4df3-2a2b-08db56ec2ccf
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: R6/R/krc1K29iBvW7yeP5+vdVpyJ6Z/+dI/mgssWJ6femI4J4LVFihKkdgPvXKcoc7/fEJmXoq4kMiJsKAKHhqts4DAI8UUQcPJkP0zNP1szIHealrwaDs7Wv/SfIwRY2f17ZzaQ6AuY++HVSKOmK6NOnvv+RCvnJ6YnfQqzJ77lVMOkdVSn/TaWpVNoPQ/JqVG1ANivMWO57CwHckhG6Khjm4UkzuLJLIsr4q/4pf8ZmOdDR2ycTP3Y/kLX4SMuoRX196ohgBX5287iR19eFOl7sVHhglO3jUEHROWb3V0ixfMSgyj4HGimN1RksjrSqFjNaVBIV+BACN2FDU+xc+TI7FGjKos6Fn66lP5cS4BQrnV4u9bJhO11PTr4SleZml4aCsNcHjaMZbZihiyvMSvjZXKdqZ4/iZDvO8stIF2WoenhIY2oRzL1x/l646PZFCzzaF/p4nnEsVZHXJPNtFCMIoG3djPeGg8nmDa/tDtdVMoAXRtWtSqnXJ0JczEyuxDohiGbPsc74qBEIwtNAYm31V+BFLZNo4ZniraplGVc/CCQRXmG1etFlY5U7Lbp0bl3R8m1orGSrU4LgDSGMK+0erXYGIfcaiA1szj8ol6UAx1NGh9pzQJvWZVPpJh3PCr46ubUwPyrigtol8nDnWUTO8B6WCjLcPwq3N5DSN+p2ZOpkeQwFv1tfwOcaM7T
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(396003)(376002)(346002)(366004)(136003)(39860400002)(451199021)(966005)(36756003)(33964004)(6486002)(21480400003)(83380400001)(6506007)(6512007)(66574015)(186003)(2616005)(53546011)(235185007)(5660300002)(44832011)(66476007)(15650500001)(86362001)(41300700001)(41320700001)(31696002)(31686004)(786003)(38100700002)(316002)(110136005)(8936002)(66556008)(66946007)(8676002)(478600001)(2906002)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: FvGYf+OsV/jbRvyx/jeMsXRRIRFvrGrdtBkXav+Bfisl1ha4usxbwn+n98hDotEsXaHZRgj8axfNrcYpMD52Pt790syGK3aAXGhic7Cq3kzwNJrQLRCOR05aqbgDhjgyFapODS7IXuGTV9ChWkSBtDpEsqfGk6wQfoHzeeP28wvIus2fFJdZUuGA40dgM6ftwFwD/8uA0UfoqFIutBT6RA+nSIEMPr0qfxJlseCcIIEojXUH5BUZ69n89HfoPV7OWHVe4wygxvwigLCk3GU74PtjepGFoT8IUNs2QlIW4GNxX2DzKikJ5vVi7pXX4/p7xIqqIdPh+FWaE6Uq1XXkLK7mO1JIlT98/sMCniLgh3N3iJC2S0se0ZEyaeB5J8mmAjRKxR320hQEpqlonlTdUo3fctitUytdwrbOhweMJuVosJuMeetOSmukPBbGl0RHtV1dubJxqfEgKt/n9SPU/l7QDY7DOmka65NaB8YTEyWQvn9wDnEZB3KKIbcKVXb6cEihctWYXjHRq3buzi/Phv8JqXMS3xnwB/faU2yydn4teeQqBz0TUdSHy+8ZkJuQzd4Mw2rdUQfQC/oMXiLZQio8O/saKip/lAHjA1qPSOWckRoU/eexXxeDomQM1IYNGJBdNC6vbvTFlAFBiXPGPXTM337e+C0yg7y5Fw1KG16l2fIZ8GOEA0JrHE6da/Od+SzL23xNXuW3YnY36WqUJK4UzPpXmJ4Kz12QwqrLwezd4kF7DXtGA01LosFWUlC+Rel+x0rerNHQHQpHg9Vd8i+L1zUARGaTfG7SdD5aa/Rw+UDfSsbQX+yTvZg9A+y4hRFfXnO2oYv69k0GG/IdcaVfvgOFu+49yvshZfqp9wKUpXn/zSAFaUHsfxIfFLkxle79vsLtbWPd9tdfzGoM+CHLp5bvolmmTx2cZI2c0BCD0wG7m5o9zzXguxdfEV+wd8OSC+aykzfsVoiwxb3cVfgTFCezj4UcRHx8Y2Sq2jTChSAZ3cmtY4Jgz1PwBx2k2AwI7TMjBxBh2mo/9o87mgOXdTjYy/4WXJSBFPTa64d8za3ahTwPQRLmuUIGqQffeiI5BgeaO+7nEnd0VLqgglbUuve5gutl9QQVGptjd49uih5xlWgDxLpid5dz+mCjkZSIaV1lAvQc/muDYXbALVqdevmytp2cJaHQZSzRPSd6Lj3DHH61lDuFFkpvEcaHjV8M1LcI3hUTBn4V3Kf5xzMILauUF4qL5+hOzmbEeVxkvyCZreni5l7MVSmDt0avoH+DjYrj4XGtm7M0DYL+/TQh8Q8MujglxMwA5BGE/iPzuiepIWXJFMwHWoDVl9/T928LmKeK5yDikOXgF9AyVTgswqHsQ+VjspHzouygpBB9T+beNauQ0oK2vDnxtPm4CtOHju1kMqSONL08JGIYhALtfTxwwy7sPBLfsFlcZ9VCTEcpjuO8QS34InnIbFqGSe/mYGQCuc+IaJc9tNIkDO7x64y2BAYA209vaKZ1/s7BeJnRnztKTGGcM7k8zVeTb8IR7vQGQhVkFr3D8pQALUJbLWv/kqn0AtAfNy4+SjXr888gfNfqHuRzAlPNoTo0UG/R227MXK4HqJanwkau14bzIQqRC7tB4yIDfQTHjKs9KTfctfUEMwuhiNzBFTFn
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: f6008c11-d281-4df3-2a2b-08db56ec2ccf
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 May 2023 15:34:17.0195 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: +un2eoE1PaGGyryt0+CjEDWsdYgJ7RS64RS9H7ygYcyYeSHRsQc3JPydMGaceYbP
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR02MB7304
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/kk_rjYAdsPJCHa_iRV4PeWhpnEY>
Subject: Re: [TLS] FW: New Version Notification for draft-rsalz-tls-tls12-frozen-00.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 May 2023 15:34:29 -0000

Hiya,

On 17/05/2023 15:11, Salz, Rich wrote:
> This is the "TLS 1.2 is frozen" draft promised in Yokohama.  I am
> pleased to have Nimrod as co-author.  We think this is ready for
> adoption :)

I'd be supportive of adoption. I think the draft could
do with a clearer statement to the effect that this one
will likely be "held" in the WG until there's rough
consensus that it's timely to make it an RFC, but
otherwise it seems good enough to adopt.

I'd guess this probably ought be a BCP too though, but
don't care that much.

I don't know if there'll need to be more exceptions
carved out for IANA registries or not, but that is
probably better debated after adoption.

Cheers,
S.


> 
> On 5/17/23, 10:08 AM, "internet-drafts@ietf.org
> <mailto:internet-drafts@ietf.org>" <internet-drafts@ietf.org
> <mailto:internet-drafts@ietf.org>> wrote:
> 
> 
> 
> 
> A new version of I-D, draft-rsalz-tls-tls12-frozen-00.txt has been
> successfully submitted by Rich Salz and posted to the IETF
> repository.
> 
> 
> Name: draft-rsalz-tls-tls12-frozen Revision: 00 Title: TLS 1.2 is
> Frozen Document date: 2023-05-17 Group: Individual Submission Pages:
> 8 URL:
> https://www.ietf.org/archive/id/draft-rsalz-tls-tls12-frozen-00.txt 
> Status:
> https://datatracker.ietf.org/doc/draft-rsalz-tls-tls12-frozen/ Html:
> https://www.ietf.org/archive/id/draft-rsalz-tls-tls12-frozen-00.html 
> Htmlized:
> https://datatracker.ietf.org/doc/html/draft-rsalz-tls-tls12-frozen
> 
> 
> 
> 
> Abstract: TLS 1.2 is in widespread use and can be configured such
> that it provides good security properties. TLS 1.3 is also in
> widespread use and fixes some known deficiencies with TLS 1.2, such
> as removing error-prone cryptographic primitives and encrypting more
> of the traffic so that it is not readable by outsiders.
> 
> 
> Both versions have several extension points, so items like new 
> cryptographic algorithms, new supported groups (formerly "named 
> curves"), etc., can be added without defining a new protocol. This 
> document specifies that TLS 1.2 is frozen: no new algorithms or 
> extensions will be approved.
> 
> 
> Further, TLS 1.3 use is widespread, and new protocols should require 
> and assume its existence.
> 
> 
> 
> 
> 
> 
> 
> 
> The IETF Secretariat
> 
> 
> 
> 
> 
> 
> 
> _______________________________________________ TLS mailing list 
> TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls