Re: [TLS] Transport Issues in DTLS 1.3

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Tue, 30 March 2021 19:24 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF95B3A1F40; Tue, 30 Mar 2021 12:24:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=m+Ja49+P; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=m+Ja49+P
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Om3KV1C3cpiN; Tue, 30 Mar 2021 12:24:34 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-eopbgr70054.outbound.protection.outlook.com [40.107.7.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 27A583A1F48; Tue, 30 Mar 2021 12:24:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vsf5Qad4Fs1tCbpcoBeic8WzyWmGh2CI5mSj1f5Wr5M=; b=m+Ja49+Pl3E5kvAbWPN7gmkUZEj/jbqSCPjBDbxrhwoziG7+3qwRdSp9VFXRZ3uozqZojJ3dww3fSWnsO34gTQ52is87O/r+OFE3iblijaSsGEK/Le2M3O8O7mwDcWIGG2St8MXneIWWMZfXnWQUbi1+yxZImhk0ebi6A6tUZoI=
Received: from AM6P193CA0129.EURP193.PROD.OUTLOOK.COM (2603:10a6:209:85::34) by AM5PR0802MB2401.eurprd08.prod.outlook.com (2603:10a6:203:9d::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.24; Tue, 30 Mar 2021 19:24:25 +0000
Received: from AM5EUR03FT056.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:85:cafe::85) by AM6P193CA0129.outlook.office365.com (2603:10a6:209:85::34) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.25 via Frontend Transport; Tue, 30 Mar 2021 19:24:24 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT056.mail.protection.outlook.com (10.152.17.224) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.29 via Frontend Transport; Tue, 30 Mar 2021 19:24:24 +0000
Received: ("Tessian outbound 001a76fead4a:v89"); Tue, 30 Mar 2021 19:24:23 +0000
X-CR-MTA-TID: 64aa7808
Received: from 51bfcef75a37.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 4E6DE981-F75F-41B3-9321-FEBC0A348336.1; Tue, 30 Mar 2021 19:24:18 +0000
Received: from EUR05-VI1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 51bfcef75a37.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Tue, 30 Mar 2021 19:24:18 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=MfN651Fj7+fTe/ixeNIItVPxAlj1HeD0st8XzLUo5B2/aiU5SPPIpS+/1pvzZSbmw/ffddr5lfd4yJGvED4ZcQT5nC+jeFICbaFwRqGXclIQuC8WYQvJxCR9ddiCgA8PiKuyErjGGBDKfq7fTHZuq/9uA1xSV6dI71161R5TLSUgYQGpMat1QwAp635noveD1Jg1F1XRAy8ES9uoBt4UEUookhGDa5+vkkxP5CjypYRbrtk3+WCxa9stHbXyRJDpJzUticxDSOelgO6cGrpR18XAmb3rnY2Wx2XeHi4R8lB64ayTWMBwY0h865aSvvlz3R3r/fu06QNNKW2ZewNVsg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vsf5Qad4Fs1tCbpcoBeic8WzyWmGh2CI5mSj1f5Wr5M=; b=cD/6nkfraHFT0Ctor88Rb4ns9XDkJlWmaBrfuQmuDvtXunzj+Sd6ImoKGOTQLZWYk64NCVZzp57sCEGcPeHX2r6dCFCjJ3bzQ3PJf83ZoSt0nOceEWv7iJVFyubxISSqtUt/xk+NzZz4OdRKfJwawrui0w/6i6O88Yqcmyb1KeRaXPFJlEECuF54fkY0V1XNnOiwgT5nvRC91xPhmw77HvD4nupxe4bPKCz4cfXqqKU12SeA/5SXO77XrmocxFyIum/GV5ut87c1G3ToqT6TOwy2kyPtJp5jZHHqoEAyWltoGETHEPtwQ0E+vjUqalmxtZh22T4m9jppiBybRyoQ2w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vsf5Qad4Fs1tCbpcoBeic8WzyWmGh2CI5mSj1f5Wr5M=; b=m+Ja49+Pl3E5kvAbWPN7gmkUZEj/jbqSCPjBDbxrhwoziG7+3qwRdSp9VFXRZ3uozqZojJ3dww3fSWnsO34gTQ52is87O/r+OFE3iblijaSsGEK/Le2M3O8O7mwDcWIGG2St8MXneIWWMZfXnWQUbi1+yxZImhk0ebi6A6tUZoI=
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com (2603:10a6:802:25::13) by VI1PR0801MB1903.eurprd08.prod.outlook.com (2603:10a6:800:89::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.25; Tue, 30 Mar 2021 19:24:16 +0000
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e]) by VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e%7]) with mapi id 15.20.3977.033; Tue, 30 Mar 2021 19:24:16 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Martin Duke <martin.h.duke@gmail.com>, Mark Allman <mallman@icsi.berkeley.edu>
CC: Eric Rescorla <ekr@rtfm.com>, "draft-ietf-tls-dtls13.all@ietf.org" <draft-ietf-tls-dtls13.all@ietf.org>, Lars Eggert <lars@eggert.org>, Gorry Fairhurst <gorry@erg.abdn.ac.uk>, "<tls@ietf.org>" <tls@ietf.org>
Thread-Topic: Transport Issues in DTLS 1.3
Thread-Index: AQHXIZcqf28Z7hfMOUOFn2z/tyGB36qW1cqAgAYAy4CAABCXgIAACbJg
Date: Tue, 30 Mar 2021 19:24:15 +0000
Message-ID: <VI1PR08MB2639961B79A47404423AC371FA7D9@VI1PR08MB2639.eurprd08.prod.outlook.com>
References: <CAM4esxR3YPoWaxU9B--oaT9r2bh_QBNH=tt0FsiUKaAT=M6_fg@mail.gmail.com> <CABcZeBMS5fUej0q5XhbxM5sMLQwAAyCgyAfbkTORQjvMM+jb7A@mail.gmail.com> <E43A7F98-6AE3-402B-B166-077B6D74B97A@icsi.berkeley.edu> <CAM4esxR+4NWHW6PadAVUsnwMZzE+yw75fdk2m2s3jV7V3inuQw@mail.gmail.com>
In-Reply-To: <CAM4esxR+4NWHW6PadAVUsnwMZzE+yw75fdk2m2s3jV7V3inuQw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 9F578B0A58111648826DCB7910F94AE1.0
x-checkrecipientchecked: true
Authentication-Results-Original: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=arm.com;
x-originating-ip: [195.149.223.198]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: b66bc3b8-a797-452a-71ed-08d8f3b16d82
x-ms-traffictypediagnostic: VI1PR0801MB1903:|AM5PR0802MB2401:
X-Microsoft-Antispam-PRVS: <AM5PR0802MB24012AA26FC16F45B550082AFA7D9@AM5PR0802MB2401.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:10000;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: onC8UomoIhLI9bnPRXNnAqVmnTDJImaC3uZm+7Lp4j/ezeWxVBXmjgkMQR47LiV4skaiXMAfHWkFBzxiTSMSSetA0QVGzhklDiJZAe/fsq3uHNPtzsBE0Iucl1xDeN6LL074owzOEvuEpRkMbLKOA2AEv+Q06A9z4taq+g78PFEOKx/0OfOGC1WdZKE9jKg8mi41zyP2ocPLpapFGTkEawIqFpcK+qwN9WeoqPZUl+6PPRzbHk0bHbkeYbtS9+veK/vSGbUmSNh9yN6UC/IFt8Gl6bSKoPLEwu/zU9xHdLPgVkOfCHhy7fTD1L3XdjhIbYj/XAET2Xb9Irf97gC3q5ow9/gpv2w9FRn3quAnyyIpmL8Wca3wa1Q3XXH+HavHcraucseWFbaW1o0lUIDNBk0uE38tNg8GJ57oih9HjHN2LQ63MLXZn52C2Huk+QkDFqiZmVPxv87NquIqGKgQWXWGRkMCRpwAdCsR0lV/OpZxXwNWykT5Y+xTOerY6G+sMlbOezGk7SFEqKndbvaSXhQIbj49bPE2Ir9ebjgES9IGO3zJOyLJcLJk6h0V1oGJPgMjM/rMZGD8GUzAlJQ81LvrJWnPhy+74Ws4c0xFfvWvF0tQ/vZnOTW/HC782+al/E6v13F9sdXlX3Fz6xT8TONn9f1hfiWWw0MiZ0cUGgw=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR08MB2639.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(346002)(136003)(396003)(376002)(39860400002)(33656002)(316002)(7696005)(8936002)(110136005)(71200400001)(8676002)(5660300002)(4326008)(76116006)(186003)(83380400001)(38100700001)(478600001)(53546011)(26005)(6506007)(66946007)(9686003)(66476007)(64756008)(66574015)(66556008)(66446008)(55016002)(54906003)(52536014)(86362001)(2906002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: /vxdHJ/LUthonl3TL0Pz17BbZfjZUzJfRAlBqN5s/hklnLh0jcGllVnn7reZXjnuIyvIGTTrCbsSeMKmgdmTw/9++9DFr8EKFvw3OyIWf3Py3fuyjxlmkaxzRSgUrYkaMN+pKF3hqFgd4DOb47x4ixFDGb8aebXM6wt+Jr7/p/ICXoEq5r4cgIw+opdLeOcle8+oxTYVXeChiOQrPlWNbo8TwrGYovn5PeleoIc8oXAdhqil1cx1/H1nzPEskzMROx9U1aycA7d2Xzbay0UxG1i82Xz84GEpYpzc6fcw5KTRqNk1niD83CRHYI3217V47WFwNZnCtxaNwiGQM6B85vWyaVByQcrCm7xwTDu/fBtEg5QcZEFWXG/UqMH7ApbtNytrKlWj15LSi7gTF/g/fuhXHKNRL4LIgpo9fuoN/s7Nz9HbrfvgHWIDidWjK18ee9TSoif9EzMSGhd4GdgMEM/M3zRv3B4NPRXHf+F7rXWvq6aM/L5c3S+7eaE2FxW2z2IuuDH+/GyBF1Q032QBXOMx/UbM5IdrvOH5fiQaJ+wkBU37ZlgTXtm7fXml6p+e2F/6+Y1/TMrJKCHL2F/XqNDJZyKdSecyvDjG8XsTUAFNJS+TV/VYqcw72czerKk85UGYKJaeIdaY4/T1ba7XLAY28rvnW8aKE2xZvHUrgJQqeGM6eSTcsPVArVaJ7OyivPKRXzExdjpg+32P/VXYsTZtjI2L6ueREFW2DSz3o7sVo5FFd2LnVYnsxVAgliPjfOvp1Y8in+txxBbtul485ZY29+Bp09FOGEpspayAYGE+ZtCkxBv0hG6tt61v6+AZW+BjEIXPqPib0pFSkU6Xl2fUPX7LFhIQhrLcmmeG29FVB5DLSpXshCq0khk5SzdJzskh4DTfIt6PUSNITELcQL/potGUnK1bxPt76f7VhGJBTK+WUGnqVauisG0SU/gAIEdGdhHYKYZ/fMmxTNko+sXSY/jBAaXVIgEHOqB/U/WRS+GFSvuHYfpeka1aV2lUjFb5Kt6JvhbDxQ0hYLEzUsUbtUrQT+flyt/9iitx2p2jlDRD9JysKa2v0WQhrgpjV8qC4DX07pXf6pAa//kxIQrS7olws1pvvRTgzUwi+BOS7hD0tPmr/2AFwTICW8oa8ODyYM8GiIqfrhS1AlWJ1TkkwAtzLuGGc72DUvzOgy3AekBfSEIpYdzFwvo+E2u2wu3rUpEA9Rw4l6aykKUmzndlNiXW2fw4nA+n1g8hS6tY4CMzTZuUK4Er4RflAzb4gh3D3GmKHrFyUsRBG88Yf6mlEuDNYVOiJ6mlTPF5MBA9YjLnTNiA794HNWdETa9T
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0801MB1903
Original-Authentication-Results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT056.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 06e487c8-e79d-402f-a421-08d8f3b1687d
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 5jEEbFs/DPamCZaSw+jY9sAK99kB4TGMuxbcV8Ai+B7QGvzCLHP/hJD9gPqt3XqyVDGFwQ6R835RLXRGsYGTtJsdBJ49Neiei/N3hnenHG7zhR99758aNYIRkoQoRdwjx1em5V1dYjWE+mk1GuISywqR/wcC9l4sICJNLJxGM62k68oW/QogJ9j9cj/yVN9MitEHpZcGd3KFbpu0hQgmKeBpHH7Q1ZAT1z3aIzfetUAPw607MSiCo41Shaia2znrL8fhFXy/9To74lSR3SlVV6V1On27kzMbVgCdMRJHobcyahqe9FIdwG304Z2A+6yMPk/Z2Vkawm3Co/PL/IDCKOFMiesoaVDzQIchqObjybzB0liOhakloN1+7DuzCky7L5o6PMQDlTFHt6tDotb3GAzes5ArpL6iB4l8aToI9lbEByK4/fuCF+6aNZbOqNXukg70K21kOZgzKHcdt5mw+jsMbPUiGiVW167NQPI8CwRzbOX4IzYXZ+VkvxN4IX/TBJaUNzjpEt4RKkJL4V8sAnEm1fmCRThyTojKG/l7Zn7bpmdoSATFT7yffSJUxTKiNPIQMd94mPCc2pOyYIQGJj/uJCwd7imO3SWzTwcbbWO6Kvwg9aqBWCxnO00DQCniEniRThupxM9o45XaMlMLYA==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(136003)(39860400002)(396003)(346002)(376002)(46966006)(36840700001)(82310400003)(47076005)(55016002)(336012)(81166007)(36860700001)(8936002)(478600001)(8676002)(54906003)(4326008)(6506007)(53546011)(7696005)(5660300002)(26005)(82740400003)(70586007)(186003)(70206006)(83380400001)(66574015)(450100002)(52536014)(356005)(9686003)(86362001)(110136005)(33656002)(2906002)(316002); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Mar 2021 19:24:24.4221 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b66bc3b8-a797-452a-71ed-08d8f3b16d82
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT056.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5PR0802MB2401
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/rwXMlUbOh6JiufZatbDXbfCFClo>
Subject: Re: [TLS] Transport Issues in DTLS 1.3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Mar 2021 19:24:39 -0000

Hi Martin,

the main issue Ekr is bringing up is that the DTLS handshake happens infrequently and it is small in size.
The use of DTLS for protecting application traffic is not impacted by this timeout.

Ciao
Hannes

-----Original Message-----
From: Martin Duke <martin.h.duke@gmail.com>
Sent: Tuesday, March 30, 2021 8:48 PM
To: Mark Allman <mallman@icsi.berkeley.edu>
Cc: Eric Rescorla <ekr@rtfm.com>; draft-ietf-tls-dtls13.all@ietf.org; Lars Eggert <lars@eggert.org>; Gorry Fairhurst <gorry@erg.abdn.ac.uk>; <tls@ietf.org> <tls@ietf.org>
Subject: Re: Transport Issues in DTLS 1.3

 Thank you Eric (and Mark).

To reiterate, I believe introducing latency regressions with respect to DTLS 1.2 would be bad for the internet. So what's new in the area under discussion is (a) lowering the timeout from 1s to 100ms, and (b) the introduction of ACKs.

I would characterize ekr's reply as making the following points:

(1) *DTLS practice at Mozilla and elsewhere already uses timeouts << 1 sec*
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.