[TLS] Weekly github digest (TLS Working Group Drafts)

Repository Activity Summary Bot <do_not_reply@mnot.net> Sun, 18 February 2024 07:38 UTC

Return-Path: <do_not_reply@mnot.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4E3CC14F5F2 for <tls@ietfa.amsl.com>; Sat, 17 Feb 2024 23:38:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.406
X-Spam-Level:
X-Spam-Status: No, score=-2.406 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="DfkxzWPX"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="GYmC6x5j"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DO9NxV3zZo2X for <tls@ietfa.amsl.com>; Sat, 17 Feb 2024 23:38:28 -0800 (PST)
Received: from wfhigh8-smtp.messagingengine.com (wfhigh8-smtp.messagingengine.com [64.147.123.159]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F004C14F5E8 for <tls@ietf.org>; Sat, 17 Feb 2024 23:38:28 -0800 (PST)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailfhigh.west.internal (Postfix) with ESMTP id B34F41800087 for <tls@ietf.org>; Sun, 18 Feb 2024 02:38:27 -0500 (EST)
Received: from mailfrontend1 ([10.202.2.162]) by compute6.internal (MEProxy); Sun, 18 Feb 2024 02:38:27 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to :mime-version:reply-to:subject:subject:to:to; s=fm2; t= 1708241907; x=1708328307; bh=b2P/YEMIF/i9BQkJXo3nJkJmGyydjYRflMj iB0J7Sww=; b=DfkxzWPXLDMaa3OsCmXEj8wzYSY6bSnqKKgDcc/3U57zKGESBG4 avKcWFggQ4gBgeojp0uTlwkxm8nQZ6NzJajqn8yXLMTWmifOG2mG5o/VUFo11g3N H588idaQPcFloh3h6QCHX5WMpEY9CRA3R2WdTGO4B2M49Xl0NE2rpkG0Br9Q37Xc H/qmfHn1A9Ky3/wNta9QSFCL6MpQC9aFjHSUna8IJKgVWs6qCXpKw3DHuMya5mr8 v8z3FhGiEHzjIHWJU6noq0mcgEqmkVHT+VA2xVyyst+6gSd8LA8Mp47MCgLjNgNW ogxDTuan0ANarr5R7IsUN8JItr4pDpDoURw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:mime-version :reply-to:subject:subject:to:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t=1708241907; x= 1708328307; bh=b2P/YEMIF/i9BQkJXo3nJkJmGyydjYRflMjiB0J7Sww=; b=G YmC6x5j0YZ1BhZ8yozmHZoIL/azdLQFJAI7JoVxxo67jWlIHnpwstEDPoSP2mSqC 60e8Zt2u9NVogdRGkeoH8Nj63vfxTodB3sSC1bV4ecnIxdsFZkIqO9ccmAbrDJ1e oytQKRL8Pvfq39MOdr4UcuKZ3T5Zm26Vf8fg9Rm9h6Sqbm7wqvDgQZDQZgN4kf+t xsu7Ea1ENZD1MPqxwhO9iaVcsNrC8YnLHSRE4e2uhERH0jSivHZOzs+dxQyCT3ee GlC1876ObW5Z9njUwTWG4eWjHVMCOCdtbRAfjtZ+wtM8qOhdf2yHc7KBAnSgHldf R3rLbY0zMzg9iUxZayWoQ==
X-ME-Sender: <xms:87PRZZ2hCWJPpid1iXpMQB-eBVlNYmkqJJ2bVOFwBpmqnPQVSGpLuA> <xme:87PRZQH6_s8Bt-ozVr6wy-H1867hz3OG8kZJufPt4zmwLRq53FiHq_WJhMfxJ8rS7 AIip70P978vgN3Ong>
X-ME-Received: <xmr:87PRZZ6wefKazMRdQcvFQG02TO85WdH-AuPU1ueMEW7QO8gCpv80xg4pp7Ne_0Jb1aJ839tUidsf9GyXkrMVtLwotRASHTc7eyoK0O8mr-ZvRds_dOAzdDT3QdDIMQN5g_8>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvledrvdehgdduuddvucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucfpohcuuggrthgvuchfihgvlhguucdlgeelmdenuc fjughrpegtggfhvffusegrtddtredttdejnecuhfhrohhmpeftvghpohhsihhtohhrhicu tegtthhivhhithihucfuuhhmmhgrrhihuceuohhtuceoughopghnohhtpghrvghplhihse hmnhhothdrnhgvtheqnecuggftrfgrthhtvghrnhepkeefvdduteejvdefkeehieevuefg fefhteetveegffekffefteffvdelheduieetnecuffhomhgrihhnpehgihhthhhusgdrtg homhenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpegu ohgpnhhothgprhgvphhlhiesmhhnohhtrdhnvght
X-ME-Proxy: <xmx:87PRZW2TCa14tXinMWJKz9-1CMKE_uT_wHr9j61e9G9zIGIanpabAA> <xmx:87PRZcF3R_IkcDqysM24xQnvtMWUxSG90wyLpDiy40zCtYNpcScgRQ> <xmx:87PRZX__16KmWebQouDGPCD09qhsnY0QSLyQFLezqp7QCYXyVw1NrA> <xmx:87PRZWO_5F3zrN3OzDM1GRE8LXntd_7o2TDNq2S6NlLTJD9JBdP976iZS4s>
Feedback-ID: i1c3946f2:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <tls@ietf.org>; Sun, 18 Feb 2024 02:38:26 -0500 (EST)
Content-Type: multipart/alternative; boundary="===============0776144886868951955=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: tls@ietf.org
Message-Id: <20240218073828.3F004C14F5E8@ietfa.amsl.com>
Date: Sat, 17 Feb 2024 23:38:28 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/l7IKyUaU9_Q2uQvR0iXbkcNgJ88>
Subject: [TLS] Weekly github digest (TLS Working Group Drafts)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 18 Feb 2024 07:38:32 -0000



Issues
------
* tlswg/draft-ietf-tls-esni (+2/-2/💬10)
  2 issues created:
  - Use Session ID and/or PSK in Client Hello to transfer enctypred SNI (by 0x391F)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/605 
  - Memory for ECH rejection (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/604 

  6 issues received 10 new comments:
  - #605 Use Session ID and/or PSK in Client Hello to transfer enctypred SNI (4 by 0x391F, ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/605 
  - #604 Memory for ECH rejection (1 by davidben)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/604 
  - #595 Will we loosen the ECHConfig.version == ECH-extension-codepoint requirement in the longer term? (2 by ekr, sftcd)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/595 [propose to close] 
  - #591 Can we clarify the Misconfiguration section? (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/591 
  - #586 Server retry flow, section 7.1 (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/586 
  - #585 s11.1 item 2: include "TLS 1.3" column values (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/issues/585 

  2 issues closed:
  - Will we loosen the ECHConfig.version == ECH-extension-codepoint requirement in the longer term? https://github.com/tlswg/draft-ietf-tls-esni/issues/595 [propose to close] 
  - s11.1 item 2: include "TLS 1.3" column values https://github.com/tlswg/draft-ietf-tls-esni/issues/585 

* tlswg/tls13-spec (+0/-2/💬7)
  4 issues received 7 new comments:
  - #1339 illegal_parameter vs protocol_version (1 by ekr)
    https://github.com/tlswg/tls13-spec/issues/1339 [propose-close] 
  - #1338 client_early_traffic_secret  and alert (4 by davidben, ekr)
    https://github.com/tlswg/tls13-spec/issues/1338 [propose-close] 
  - #1332 AES CCM and AES CCM 8 key usage limits (1 by ekr)
    https://github.com/tlswg/tls13-spec/issues/1332 
  - #1330 Say even more clearly that you can't trust the client to send their most preferred shares (1 by ekr)
    https://github.com/tlswg/tls13-spec/issues/1330 

  2 issues closed:
  - Say even more clearly that you can't trust the client to send their most preferred shares https://github.com/tlswg/tls13-spec/issues/1330 
  - AES CCM and AES CCM 8 key usage limits https://github.com/tlswg/tls13-spec/issues/1332 



Pull requests
-------------
* tlswg/draft-ietf-tls-esni (+5/-4/💬9)
  5 pull requests submitted:
  - Clarify that you can fall back by providing no ECH in EE (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/603 
  - More explanatory text.. Fixes #587. Fixes #591 (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/602 
  - Expand overview to clarify the topologies. Fixes #588 (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/601 
  - Ech compatibility middleboxes (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/600 
  - Fix the metadata fields (by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/599 

  9 pull requests received 9 new comments:
  - #603 Clarify that you can fall back by providing no ECH in EE (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/603 
  - #602 More explanatory text.. Fixes #587. Fixes #591 (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/602 
  - #601 Expand overview to clarify the topologies. Fixes #588 (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/601 
  - #594 A first proposal to fix the no-sni section. (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/594 
  - #592 Deployment considerations: Improving the compatibility middlebox sect… (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/592 
  - #590 Experimental proposal to add an Abbreviation section ommitting 'well … (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/590 
  - #589 Minor editorial issues and fixing metadata to stop annoying make errors. (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/589 
  - #588 Ech proposed definitions (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/588 [propose to close] 
  - #587 Proposed changes to the overview section to give better justice to ECH. (1 by ekr)
    https://github.com/tlswg/draft-ietf-tls-esni/pull/587 

  4 pull requests merged:
  - Ech compatibility middleboxes
    https://github.com/tlswg/draft-ietf-tls-esni/pull/600 
  - Fix the metadata fields
    https://github.com/tlswg/draft-ietf-tls-esni/pull/599 
  - Figure 5: figure spacing
    https://github.com/tlswg/draft-ietf-tls-esni/pull/596 
  - ech_outer_extensions: TLS 1.3 column change
    https://github.com/tlswg/draft-ietf-tls-esni/pull/597 

* tlswg/tls13-spec (+0/-2/💬3)
  2 pull requests received 3 new comments:
  - #1334 Tracking by replaying a flight of 0-RTT data (2 by ekr, emanjon)
    https://github.com/tlswg/tls13-spec/pull/1334 [propose-close] 
  - #1333 Privacy and PSK identifiers (1 by ekr)
    https://github.com/tlswg/tls13-spec/pull/1333 

  2 pull requests merged:
  - Privacy and PSK identifiers
    https://github.com/tlswg/tls13-spec/pull/1333 
  - not-same might be greater, this is less
    https://github.com/tlswg/tls13-spec/pull/1336 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/tlswg/draft-ietf-tls-semistatic-dh
* https://github.com/tlswg/draft-ietf-tls-md5-sha1-deprecate
* https://github.com/tlswg/draft-ietf-tls-esni
* https://github.com/tlswg/certificate-compression
* https://github.com/tlswg/draft-ietf-tls-external-psk-importer
* https://github.com/tlswg/draft-ietf-tls-ticketrequest
* https://github.com/tlswg/tls13-spec
* https://github.com/tlswg/tls-flags
* https://github.com/tlswg/dtls13-spec
* https://github.com/tlswg/dtls-conn-id
* https://github.com/tlswg/tls-subcerts
* https://github.com/tlswg/oldversions-deprecate
* https://github.com/tlswg/sniencryption
* https://github.com/tlswg/tls-exported-authenticator
* https://github.com/tlswg/draft-ietf-tls-ctls
* https://github.com/tlswg/external-psk-design-team