Re: [TLS] [certid] [secdir] secdir review of draft-saintandre-tls-server-id-check-09

"Steingruebl, Andy" <asteingruebl@paypal-inc.com> Wed, 22 September 2010 21:45 UTC

Return-Path: <asteingruebl@paypal-inc.com>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 990E428C127 for <tls@core3.amsl.com>; Wed, 22 Sep 2010 14:45:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.944
X-Spam-Level:
X-Spam-Status: No, score=-4.944 tagged_above=-999 required=5 tests=[AWL=0.173, BAYES_00=-2.599, DNS_FROM_RFC_BOGUSMX=1.482, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0Bh0wmDvuri5 for <tls@core3.amsl.com>; Wed, 22 Sep 2010 14:45:40 -0700 (PDT)
Received: from den-mipot-001.corp.ebay.com (den-mipot-001.corp.ebay.com [216.113.175.152]) by core3.amsl.com (Postfix) with ESMTP id 0276F28C135 for <tls@ietf.org>; Wed, 22 Sep 2010 14:45:39 -0700 (PDT)
DomainKey-Signature: s=ppinc; d=paypal-inc.com; c=nofws; q=dns; h=X-EBay-Corp:X-IronPort-AV:Received:Received:From:To:CC: Date:Subject:Thread-Topic:Thread-Index:Message-ID: References:In-Reply-To:Accept-Language:Content-Language: X-MS-Has-Attach:X-MS-TNEF-Correlator:acceptlanguage: Content-Type:Content-Transfer-Encoding:MIME-Version: X-CFilter; b=e9MDsWtPmS/l1MY1s3ibuQFvEorX2oJw34IEhqmVgK40V6hg9CGervFQ G4rWWsTTaN4PeDbftp/fIIvJoa35yO/zKwQDsRV5/zE01R4ufa4VXafn3 2X59YUk0joBVo3t;
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=paypal-inc.com; i=asteingruebl@paypal-inc.com; q=dns/txt; s=ppinc; t=1285191968; x=1316727968; h=from:to:cc:date:subject:message-id:references: in-reply-to:content-transfer-encoding:mime-version; z=From:=20"Steingruebl,=20Andy"=20<asteingruebl@paypal-inc .com>|To:=20Marsh=20Ray=20<marsh@extendedsubset.com>,=20N asko=20Oskov=20<noskov@microsoft.com>|CC:=20ArkanoiD=20<a rk@eltex.net>,=20Barry=20Leiba=0D=0A=09<barryleiba.mailin g.lists@gmail.com>,=20"tls@ietf.org"=20<tls@ietf.org>,=20 Jeffrey=0D=0A=20Hutzelman=20<jhutz@cmu.edu>|Date:=20Wed, =2022=20Sep=202010=2015:46:05=20-0600|Subject:=20RE:=20[T LS]=20[certid]=20[secdir]=09secdir=09review=09of=0D=0A=09 draft-saintandre-tls-server-id-check-09|Message-ID:=20<5E E049BA3C6538409BBE6F1760F328ABEAF8CAE654@DEN-MEXMS-001.co rp.ebay.com>|References:=20<AANLkTin6qXBOEJheaG8+SU=3D3k6 3Ed+3qXvoLHF5_hb6x@mail.gmail.com>=0D=0A=09<4C9A27D0.7030 909@stpeter.im>=0D=0A=09<17472_1285173298_o8MGYvUB005723_ AANLkTinAdE0qVxqUEBNe3ZWCry856bresv+x2Ga7Urju@mail.gmail. com>=0D=0A=09<86E28295D464B450ECA5B1D5@lysithea.fac.cs.cm u.edu>=0D=0A=09<20100922183143.GA23200@eltex.net>=09<4C9A 5B13.1040802@extendedsubset.com>=0D=0A=09<4C9A5FA8.705060 5@extendedsubset.com>=0D=0A=09<B197003731D4874CA41DE7B446 BBA3E86B133F95@TK5EX14MBXW652.wingroup.windeploy.ntdev.mi crosoft.com>=0D=0A=20<4C9A7330.3090001@extendedsubset.com >|In-Reply-To:=20<4C9A7330.3090001@extendedsubset.com> |Content-Transfer-Encoding:=20quoted-printable |MIME-Version:=201.0; bh=JY+eDyH5z1oaJp8fhl80Lv1kvSKs+8O5HtT6vQrd6FA=; b=ctMulPJiqA4Gwui7MhAX/LPNwXg4RQ9KbteH42b8joZtSIxUuh5aj0in /sOOykzIjWAhS7ioy/O0gKGY8o+3wQu43cfGkEGTRv8Am3JhkpH0YEss1 MW0QeK7FAm/KPW2;
X-EBay-Corp: Yes
X-IronPort-AV: E=Sophos;i="4.57,220,1283756400"; d="scan'208";a="72217458"
Received: from den-vtenf-002.corp.ebay.com (HELO DEN-MEXHT-003.corp.ebay.com) ([10.101.112.213]) by den-mipot-001.corp.ebay.com with ESMTP; 22 Sep 2010 14:46:07 -0700
Received: from DEN-MEXMS-001.corp.ebay.com ([10.241.16.228]) by DEN-MEXHT-003.corp.ebay.com ([10.241.17.54]) with mapi; Wed, 22 Sep 2010 15:46:06 -0600
From: "Steingruebl, Andy" <asteingruebl@paypal-inc.com>
To: Marsh Ray <marsh@extendedsubset.com>, Nasko Oskov <noskov@microsoft.com>
Date: Wed, 22 Sep 2010 15:46:05 -0600
Thread-Topic: [TLS] [certid] [secdir] secdir review of draft-saintandre-tls-server-id-check-09
Thread-Index: ActanBJvRBGFN9V1RBS/pSEYQryekgAAvevw
Message-ID: <5EE049BA3C6538409BBE6F1760F328ABEAF8CAE654@DEN-MEXMS-001.corp.ebay.com>
References: <AANLkTin6qXBOEJheaG8+SU=3k63Ed+3qXvoLHF5_hb6x@mail.gmail.com> <4C9A27D0.7030909@stpeter.im> <17472_1285173298_o8MGYvUB005723_AANLkTinAdE0qVxqUEBNe3ZWCry856bresv+x2Ga7Urju@mail.gmail.com> <86E28295D464B450ECA5B1D5@lysithea.fac.cs.cmu.edu> <20100922183143.GA23200@eltex.net> <4C9A5B13.1040802@extendedsubset.com> <4C9A5FA8.7050605@extendedsubset.com> <B197003731D4874CA41DE7B446BBA3E86B133F95@TK5EX14MBXW652.wingroup.windeploy.ntdev.microsoft.com> <4C9A7330.3090001@extendedsubset.com>
In-Reply-To: <4C9A7330.3090001@extendedsubset.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter: Scanned
Cc: ArkanoiD <ark@eltex.net>, Jeffrey, Barry Leiba <barryleiba.mailing.lists@gmail.com>, "tls@ietf.org" <tls@ietf.org>, Hutzelman <jhutz@cmu.edu>
Subject: Re: [TLS] [certid] [secdir] secdir review of draft-saintandre-tls-server-id-check-09
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Sep 2010 21:45:41 -0000

> -----Original Message-----
> From: tls-bounces@ietf.org [mailto:tls-bounces@ietf.org] On Behalf Of
> Marsh Ray
> On 09/22/2010 04:17 PM, Martin Rex wrote:
>  > I'm confused about the IE8 vs. IE9 behaviour that you report--  > could it be
> that for your IE8 is running on a platform that  > does not implement TLS
> extensions (XP,2003) or has the  > TLSv1.x protocols disabled for some
> reason?

The IE team has written about this exact situation.  XP doesn't support SNI.  Newer operating systems do.

http://blogs.msdn.com/b/ieinternals/archive/2009/12/07/certificate-name-mismatch-warnings-and-server-name-indication.aspx
http://blogs.msdn.com/b/ie/archive/2005/10/22/483795.aspx

- Andy