Re: [TLS] [Technical Errata Reported] RFC5246 (6572)

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Thu, 06 May 2021 08:53 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81ED63A18E1 for <tls@ietfa.amsl.com>; Thu, 6 May 2021 01:53:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=LDkl4kPS; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=LDkl4kPS
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WkasmepXWhlM for <tls@ietfa.amsl.com>; Thu, 6 May 2021 01:53:49 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-eopbgr70087.outbound.protection.outlook.com [40.107.7.87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 760D73A18DB for <tls@ietf.org>; Thu, 6 May 2021 01:53:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b5C1c5mDszWjcLsZqpGrekrcCx4GwD32g/Nh5X4AO6E=; b=LDkl4kPSXVUXczsNKxYqVoKHECopEmxkG6jy77jKk/MbAsMYJcx+l9Nhwg/cnKKCslqEdDl8LZp8Ls/WLFVbLe0HTA6JlCay8Jn1QjSLrskRsQLBRrSwerZfxwlsw8Xr3POTuL8vW53HrGoToq39ukBRAs8qy5TqMItIs0HX8tU=
Received: from AM4PR0501CA0045.eurprd05.prod.outlook.com (2603:10a6:200:68::13) by VI1PR08MB3597.eurprd08.prod.outlook.com (2603:10a6:803:84::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25; Thu, 6 May 2021 08:53:45 +0000
Received: from AM5EUR03FT045.eop-EUR03.prod.protection.outlook.com (2603:10a6:200:68:cafe::e2) by AM4PR0501CA0045.outlook.office365.com (2603:10a6:200:68::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.24 via Frontend Transport; Thu, 6 May 2021 08:53:45 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT045.mail.protection.outlook.com (10.152.17.105) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25 via Frontend Transport; Thu, 6 May 2021 08:53:45 +0000
Received: ("Tessian outbound 9a5bb9d11315:v91"); Thu, 06 May 2021 08:53:45 +0000
X-CR-MTA-TID: 64aa7808
Received: from 494132943c8e.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 8F715825-4B17-4008-8DA0-4BFA95B90616.1; Thu, 06 May 2021 08:53:38 +0000
Received: from EUR05-VI1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 494132943c8e.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 06 May 2021 08:53:38 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=e+7Zx9tA79m/035v9+MNptRTPwzv9cnLU/LSGxSln2H6SIOluQ3i2l+97z0hGOucERGczOP0Q7OBcgi94knkPAlwEEv11s8jZctaJ9jGGd5OkLohDh2NVOIehIEJ/aLLujJXvDlq9oYy1k+nNYUk6w6KEbwA8mAY+asiNZWDq0odLi7D1Vl0rTHzSkAbIxKrE3SVPsXxYBc+ImI5IB0NO7olSMTVAsEPd6epT6XdvaCDo2WQr7ZtMlv1C4v/hvGNLqbf8iPfO4TDTIxlJeb50Bag4IJ4DbIF/Crx2tSYz7hLqnPOesJBGKoaB5pea1pX1LB87bSwN71TSkTNk7WxJg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b5C1c5mDszWjcLsZqpGrekrcCx4GwD32g/Nh5X4AO6E=; b=U9XXdFxJYJkRgcx6GdBOGJByFfpVjyYXpv+i+PYX0EXbiPprcrm4mi8Jno6rytv5OnnHzCqDtmGQOshiyH41/1UnTbLEijDM+Y3DoHmFIm5I0BMXVTOKRlnq2t/Ws1kR/tN+mJgczRFzWOn/fbQQ9OrOzPK2oJhKld1alUDmiOhiS2KWawqpiF25n/1JpIVqz+ZtIFa1UDzKNYybNZNgtvr5CTtEDSGDq6eAalbCwCsrwjb2W4Y2Hq4yI35aEFz3qsqYGspDjxWZpbZeTt/d1F6NylF9RgUDUqj6NZL3WRw6tSXA4M6zGYKkKJG+CogyxcA4bCDcNe35bODzuuGpnw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b5C1c5mDszWjcLsZqpGrekrcCx4GwD32g/Nh5X4AO6E=; b=LDkl4kPSXVUXczsNKxYqVoKHECopEmxkG6jy77jKk/MbAsMYJcx+l9Nhwg/cnKKCslqEdDl8LZp8Ls/WLFVbLe0HTA6JlCay8Jn1QjSLrskRsQLBRrSwerZfxwlsw8Xr3POTuL8vW53HrGoToq39ukBRAs8qy5TqMItIs0HX8tU=
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com (2603:10a6:802:25::13) by VI1PR08MB4301.eurprd08.prod.outlook.com (2603:10a6:803:f7::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25; Thu, 6 May 2021 08:53:37 +0000
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e]) by VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e%7]) with mapi id 15.20.4108.027; Thu, 6 May 2021 08:53:37 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "tls@ietf.org" <tls@ietf.org>, "johannes.goerlich@siemens.com" <johannes.goerlich@siemens.com>
Thread-Topic: [TLS] [Technical Errata Reported] RFC5246 (6572)
Thread-Index: AQHXQZiNkonFSTWUOEuOMqk9TyZItqrWJokQ
Date: Thu, 06 May 2021 08:53:36 +0000
Message-ID: <VI1PR08MB2639FA09A6BC4A2C61FE2549FA589@VI1PR08MB2639.eurprd08.prod.outlook.com>
References: <20210505102116.813D5F407AA@rfc-editor.org>
In-Reply-To: <20210505102116.813D5F407AA@rfc-editor.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 743EF311570F9047843D351D05ADEE80.0
x-checkrecipientchecked: true
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.114.2]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: df797ca3-cf49-4d3c-7d70-08d9106c74f8
x-ms-traffictypediagnostic: VI1PR08MB4301:|VI1PR08MB3597:
X-Microsoft-Antispam-PRVS: <VI1PR08MB35976F7F65EA796C29248E24FA589@VI1PR08MB3597.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:10000;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: JmiPvuQ5N2TJMYRF3hkE8JfnlkqwbSZ0CxJd8NLPf9kWu03WLWMuqnf96IilYfLNRDrgN35GFgm42sc6sqd24v/8IKeWwM9kPEll02GXuvcSbEWIwow6i1sCjVZUjk4geLFRMHVqcqb1Oj3BTfavvTgAjzJVyHb04ELiP3KbObx5k7a+VduNlEF+UEgVNQFXZ0VYfl3kj6gNvDRfgCjGE0UhlgfW2K+n1YNxB/ar3jjYUGpJQMLLpFiviz1euoiOx9D6RRvJ8OKUOy12cnE91jgt1wkrDb/47AZkWlbB6YO+Xz+YlO52LzvWQNgMRw//fwGTAk/VBvftGZa9SiAP4TbcmgyV+kHYANJTkFYMDB8Z1zV5iTqDV76lJwdH36wtLuKb/tPCg2LfX5izZIiT1bp8lvCbGIr+YIU9teUgTc9GXhcd6E3s16nKiYfWHUlH01jW7YOmwa1oBHjQ7wyYHbTHlstcP7iAtmA+YGFKsiWdp0AjLbjKgt9p4lXY27CR82tSvDaxYnpA1z6E6nCYDvTGL7pvPY5v6k0xoTiOJFxIRX2xjsi9Y3gOJjWK/Hwt4nDSHXxJtJ6OPtDVL//BxSDGygGlBs234QcQPWgD9zIZ5QadCn/tY1PFdjmnb+9KVM/AMCsAvtuv6oAIPDyYb6jHq4lna+VShJB5UhA0Po6aqvngfiK9bNp+QuEDUXgN
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR08MB2639.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(39860400002)(396003)(376002)(366004)(136003)(76116006)(66946007)(38100700002)(186003)(9686003)(26005)(8676002)(64756008)(966005)(8936002)(478600001)(6506007)(33656002)(66476007)(71200400001)(7696005)(66556008)(55016002)(316002)(66446008)(122000001)(5660300002)(110136005)(83380400001)(52536014)(66574015)(86362001)(2906002)(53546011); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: OKZIRj/uNQ5cS8J+EGekxoSxJbRd2HXnN05HT5qFIh/YlmSd7PwY3bqsfDm20qmWscVvS2fQDkfL1YQ5vn0CEiwo9hDNA7sCiI/ypdTh8bMNRvrLKEt0QNYjGzr5A9vADyUsoOitSghXV+nT9ReKp5lT5Kqn5hD57N/SYDFEJQ7XauE3scCInR9tTc6qb+FxRWBlXwLaN/5PpOPUdlSU+AXHR+wPBKCTZzlbTirRpdt5nl5MNm7alJh4m4FvP0p/o+c2GtOVwpMCO5tGi/zLFGqlW2L0twvhOrxixF6C4v8VT7prCTzb/xDCwfiTQjLXVWJQ5zaA9BV/wA2mdb+LqGtkDB4v2cO241BPThPEFSbVfVKNGKWlGvmRHOqPbJT/a3V58oY1PN6s7ZYQ1mYHK7pnj5iO0bSjtEu+I/+5zJbfy2ATKzpCaWezU9jpStGg5yiN7LtPRaonH3UNuaZ0AQlKg/rSY0yeJ7TBTp2NWDTkWPWIZHrTfoT0fdiQR1ey1b2gjNPZuWqvlRVtA8elG00DyuOQ55oSVnK65FgAnJOwZ8QCAFhmzKonXqRlbFf+FFwxt5rzgjSNrTUq6ii4lTltLOtMN7SAwIMr4mwSbmksVqZU1Es9/qa70Ub4w1FeKlf+4zv17hJRj3elFvPZaUndYWFs0E+ApfP0SPJM5tzehjqXFEhfKJYzaNzRUO1I+Lw0p1l3bFzCMDImy7VIBidyx4BSuaSBQaLBB34Di89gVM7SknZ4jsilcOj+W3P2Tq/aPj6d0ITrbqoxuuDxGnLW91Qd3SB0J+JmpQoHg58p5sQlWss3CAUaSsVoY9OfHgCpkjiJeS9I0/L5RUbdMU/Nq3in9OoG+orbnf5g3mRH4lHsH25G8R1ik7u1EoeRxhuNg4GZ7n9X6v/f9jEmjwQ85B6GrJU6qAIf4mBsyX07hoFOZ9e8FPbFQYHUz6++my00e5rDhvDLoz863aR+vD1WqoW1ygfb7bXp4v3ZEiEhlKMaCmhVoMuAXVZzJkvqO9U4OExbdReOSJlu2tRXzzMsO5yfTZ67sb7RhFcsOU0i7JNdDNGLdlvK2YeruJXETvEFXkSz2Zes9ah9N/ryUsbeQI0GoB7DuNFCRhGePnl8Gkjo7+paTX+JbqvlQVyGdGL3m1x1Ft/JIJg1vpC8nfj080+5xA7A4bnDMS4ELoW14E3iaEQP5B9hagfoHdr17kk17h1Z9sdUlcbzY2KgDiEM1RfnX6S9d9pHD5Wajli63VYBzhRHLrGd/LLB72F6vJtKsSlaTiqTMnXFc6BLdg4QXNkw9448kYqOsmRssbk=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB4301
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT045.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: a1295bd6-0739-4122-5b87-08d9106c6ffd
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: XlaHIFiti2krH7rMVKoWQG58RNeI5wNKy5KgxF+R6ePdmOpCateBJrByi22/aIOlGVh4Rcq8XA2o1/etyNo3eOsloi41w3n6UeF3OT6USy2XQdo7I3SRExWLwDSgTlQwFLgRvPTY7+TJjKZq7pAYlbhG0oO6UfHpYUrDSDjp1jqTfW+sHNWD7NSPtD0z3CBNaUoEUoaPHUSvMcHc5yJ8lyeQzeY2YMQn1sMYuT/1X8PS7vjrVXq+A5I0WbdOMeP/cv2fq5Vi3gRYSsgt0EmldiyKFR68/b1+hi6d2qLXpU5cbFcZ4zoSjQ9YkJHD7J6f6uTZ8hAgR9SUx0+yKuL9HyQSyenY5W0icZd06J0jUfLP6HmKCH0J4QGhUeAf4rfF89msMysNFIZE5Gk+bCSzQ3Qq96f2qfxBPNnR+JYdRIl8agWIusoGHBMXXvgIOJ1wcsO3l+5IusXOYdU6NP9RnTfQBmOpDKPMHSJEiCVZEjWCpATeo1aUPKovAkR5D8ck++EKyoyAVrZcVmRFZsYNK1yCcN7R0pSfjT8iclMnZgzByU/bLLixVn2GYxAYxnQSOZ0I3x4yTvb/SdRoi/W341Ef2bPhDHoUs70LNPlYUaCcFOTHurHKoocuCtuhrG4QiJba7kQujbM1DhMhbZc3abkq28JlQIxCWeJ6gpM3hS7+p6fYXVYc1IRlA9IbShLDDBSNUqw10nswSoPZqUqrakHr81cIM8EdNi9aD6vPQDA=
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(396003)(39860400002)(346002)(136003)(376002)(36840700001)(46966006)(8676002)(9686003)(83380400001)(86362001)(33656002)(66574015)(110136005)(82310400003)(47076005)(55016002)(81166007)(53546011)(186003)(36860700001)(336012)(5660300002)(356005)(2906002)(26005)(82740400003)(316002)(7696005)(478600001)(70206006)(966005)(52536014)(8936002)(70586007)(6506007); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 May 2021 08:53:45.3790 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: df797ca3-cf49-4d3c-7d70-08d9106c74f8
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT045.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB3597
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/n-eSaRnnAQM_ObkfEiR01p89Qh0>
Subject: Re: [TLS] [Technical Errata Reported] RFC5246 (6572)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 May 2021 08:53:56 -0000

Hi Johannes,

TLS 1.2 has been obsoleted by TLS 1.3. Prior to this, other specifications have profiles the algorithm choice (see RFC 7525 and RFC 7925).

Ciao
Hannes

-----Original Message-----
From: TLS <tls-bounces@ietf.org> On Behalf Of RFC Errata System
Sent: Wednesday, May 5, 2021 12:21 PM
To: tim@dierks.org; ekr@rtfm.com; rdd@cert.org; kaduk@mit.edu; caw@heapingbits.net; joe@salowey.net; sean+ietf@sn3rd.com
Cc: rfc-editor@rfc-editor.org; tls@ietf.org; johannes.goerlich@siemens.com
Subject: [TLS] [Technical Errata Reported] RFC5246 (6572)

The following errata report has been submitted for RFC5246, "The Transport Layer Security (TLS) Protocol Version 1.2".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid6572

--------------------------------------
Type: Technical
Reported by: Johannes Görlich <johannes.goerlich@siemens.com>

Section: 9

Original Text
-------------
In the absence of an application profile standard specifying otherwise, a TLS-compliant application MUST implement the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA (see Appendix A.5 for the definition).

Corrected Text
--------------
In the absence of an application profile standard specifying otherwise, a TLS-compliant application MUST implement the cipher suite TLS_RSA_WITH_AES_128_GCM_SHA256 (see Appendix A.5 for the definition).

Notes
-----
A must-be-implement cipher suite should not relay on a bulk encryption algorithm which is vulnerable to plain-text attacks or on a secure hash algorithm which has been proven to be insecure.

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party can log in to change the status and edit the report, if necessary.

--------------------------------------
RFC5246 (draft-ietf-tls-rfc4346-bis-10)
--------------------------------------
Title               : The Transport Layer Security (TLS) Protocol Version 1.2
Publication Date    : August 2008
Author(s)           : T. Dierks, E. Rescorla
Category            : PROPOSED STANDARD
Source              : Transport Layer Security
Area                : Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.