Re: [TLS] 2nd WG Last Call for draft-ietf-tls-dtls-rrc

"Salz, Rich" <rsalz@akamai.com> Mon, 02 October 2023 13:20 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD4CDC1527A0 for <tls@ietfa.amsl.com>; Mon, 2 Oct 2023 06:20:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.805
X-Spam-Level:
X-Spam-Status: No, score=-2.805 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 21RFVqvy5rOw for <tls@ietfa.amsl.com>; Mon, 2 Oct 2023 06:20:11 -0700 (PDT)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D52AC151073 for <tls@ietf.org>; Mon, 2 Oct 2023 06:20:11 -0700 (PDT)
Received: from pps.filterd (m0050096.ppops.net [127.0.0.1]) by m0050096.ppops.net-00190b01. (8.17.1.22/8.17.1.22) with ESMTP id 392A8qiJ031878; Mon, 2 Oct 2023 14:20:09 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h= from:to:subject:date:message-id:references:in-reply-to :content-type:content-id:content-transfer-encoding:mime-version; s=jan2016.eng; bh=8NAxkbUjxu8vlQaEQXc0Oixr3FDEbF1908gyzfgD4dw=; b= g4dPBfUefNuy3fyBUJDkFHsdYVJ0VaGUxUZZTW1hLZgCu6M6DpBVHUlG3r1Nwzuc e6YfqkdlW1fnlBFwNCyZgOZ3+Gu4EZFcJKDiOYcZv6clsdD7pn+SQVmchzVQTv5K +XVC3ByupbbMOWkMxdO246v6BO95+Sldvglo+d/Ak5bJI0YZzsvxTM4r/xhaWE5u FCmN6kpS45XU135k3gvCfzsPnFnN2RcWou6VSTMJwQArbGImC+Vq3zy826q977Jl T0o5okjzPMa2iRVRQs6M8YqggKdsXCyPF4jCwTGkGk5s6S0j2H9OeLwQgRyEMAL4 vtC7u7VNDUedym/NLXTJDw==
Received: from prod-mail-ppoint8 (a72-247-45-34.deploy.static.akamaitechnologies.com [72.247.45.34] (may be forged)) by m0050096.ppops.net-00190b01. (PPS) with ESMTPS id 3tec3feqwj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 02 Oct 2023 14:20:09 +0100 (BST)
Received: from pps.filterd (prod-mail-ppoint8.akamai.com [127.0.0.1]) by prod-mail-ppoint8.akamai.com (8.17.1.19/8.17.1.19) with ESMTP id 392CZJhV022318; Mon, 2 Oct 2023 09:20:09 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.206]) by prod-mail-ppoint8.akamai.com (PPS) with ESMTPS id 3tef0wbqwy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 02 Oct 2023 09:20:09 -0400
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) by ustx2ex-dag4mb7.msg.corp.akamai.com (172.27.50.206) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.25; Mon, 2 Oct 2023 06:20:08 -0700
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) by ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) with mapi id 15.02.1258.025; Mon, 2 Oct 2023 06:20:08 -0700
From: "Salz, Rich" <rsalz@akamai.com>
To: Sean Turner <sean@sn3rd.com>, TLS List <tls@ietf.org>
Thread-Topic: [TLS] 2nd WG Last Call for draft-ietf-tls-dtls-rrc
Thread-Index: AQHZ6nOs8P0D/GO+HkuH/4A1F0lTprAw0yuAgAXwioA=
Date: Mon, 02 Oct 2023 13:20:08 +0000
Message-ID: <B0EAD2AB-66D1-4DF1-8437-3C6D83104538@akamai.com>
References: <50990212-57EB-4228-A259-BB8FEA6AC364@sn3rd.com> <D53F6EE6-AE87-422C-9241-010D13380992@sn3rd.com>
In-Reply-To: <D53F6EE6-AE87-422C-9241-010D13380992@sn3rd.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.77.23091003
x-originating-ip: [172.27.118.139]
Content-Type: text/plain; charset="utf-8"
Content-ID: <7DCE931F5BDB5D46A9F9F57B7D883255@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.267,Aquarius:18.0.980,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-10-02_07,2023-10-02_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 bulkscore=0 mlxscore=0 mlxlogscore=516 phishscore=0 suspectscore=0 adultscore=0 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2309180000 definitions=main-2310020100
X-Proofpoint-ORIG-GUID: BdcO0qPNkCp_r-WUa5lXjoxC0BoYJmj4
X-Proofpoint-GUID: BdcO0qPNkCp_r-WUa5lXjoxC0BoYJmj4
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.267,Aquarius:18.0.980,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-10-02_07,2023-10-02_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 priorityscore=1501 mlxlogscore=554 impostorscore=0 spamscore=0 bulkscore=0 malwarescore=0 phishscore=0 mlxscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2309180000 definitions=main-2310020100
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/oEQT88RJ-30-wRuXfFiAwlvyuuM>
Subject: Re: [TLS] 2nd WG Last Call for draft-ietf-tls-dtls-rrc
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Oct 2023 13:20:14 -0000

> https://datatracker.ietf.org/doc/draft-ietf-tls-dtls-rrc/ <https://datatracker.ietf.org/doc/draft-ietf-tls-dtls-rrc/>
> 
> The WG Last Call will end 3 October 2023 @ 2359 UTC.

I read the draft over the weekend.  I am not a DTLS person, but I think this is a good document.  It highlights both the security issues and a way to approach the problem.  I couldn't find anything wrong, but see disclaimer :)

Ship it.