Re: [TLS] TLS 1.3 draft-07 sneak peek

Eric Rescorla <ekr@rtfm.com> Fri, 03 July 2015 17:35 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 43FDF1A0171 for <tls@ietfa.amsl.com>; Fri, 3 Jul 2015 10:35:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level:
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qsp4vOkIrXkl for <tls@ietfa.amsl.com>; Fri, 3 Jul 2015 10:35:22 -0700 (PDT)
Received: from mail-wg0-f50.google.com (mail-wg0-f50.google.com [74.125.82.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EAD811A016B for <tls@ietf.org>; Fri, 3 Jul 2015 10:35:21 -0700 (PDT)
Received: by wguu7 with SMTP id u7so93443166wgu.3 for <tls@ietf.org>; Fri, 03 Jul 2015 10:35:20 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=waCGZ3pYKuSSOcrGopmJ9HbcRGFVkO7BokxSKm0mbT4=; b=KKZDGaVyP5/lPMeFMDNVo+H3uL3X8z3vVl/ClsGXvOuNWHUdaxlNyj74uc5ha9dkTY Rc2TumvSAq7mpY9FPH4tWMS9pVP0MI1P5ZIYy+sOIsJDxzOq/ZK8/9udEaZBnMAA1bZi ljGmwlpjOZZ0JKbzHpvRtv6hxaZrf25IsAO+HXgAVTc9xAgA026U13QTK3c9POGTczyu u9ZrvMZtZ3pksi+v4NiCjSKPGWvmzb8lnBIwfm5iza1Yzm7waFVvMulkiJa/ATR8ev4B Vl2UWBPcRBOH9m/0ZG3U0xXvSAjQ5wB+w3AQY+YWub1bQKHYKmth1YEc3/4PvRBMhzpF Hmkg==
X-Gm-Message-State: ALoCoQkTdwc3b/rDtN1AtCC9GLMnjTKxXBSQHmdHMnA+M7jurkzdWEazaZ5qj8dyDPD1Q32LyWi0
X-Received: by 10.194.79.225 with SMTP id m1mr23290281wjx.8.1435944920679; Fri, 03 Jul 2015 10:35:20 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.27.95.211 with HTTP; Fri, 3 Jul 2015 10:34:41 -0700 (PDT)
In-Reply-To: <4069375.XY312j7rEL@pintsize.usersys.redhat.com>
References: <CABcZeBOWK_WnHAefsZUBr4UyEkyiZqi1mhoZH8ZeGFftdOqTTw@mail.gmail.com> <4069375.XY312j7rEL@pintsize.usersys.redhat.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 03 Jul 2015 10:34:41 -0700
Message-ID: <CABcZeBPmyZ7Hvb2KDPfNw7Ov-AQwzi9Ww6vL-PY-2yst4pEEHw@mail.gmail.com>
To: Hubert Kario <hkario@redhat.com>
Content-Type: multipart/alternative; boundary="047d7b10c903ea1de40519fbfa58"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/tkLj26pwPXdvJkk0T4QUOkMAToI>
Cc: "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] TLS 1.3 draft-07 sneak peek
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Jul 2015 17:35:23 -0000

On Fri, Jul 3, 2015 at 10:23 AM, Hubert Kario <hkario@redhat.com> wrote:

> On Tuesday 30 June 2015 15:23:18 Eric Rescorla wrote:
> > Folks,
> >
> > Yesterday, I posted the -06 draft which snapshots the consensus changes
> > made since -05, specifically:
> >
> > - Prohibit RC4 negotiation for backwards compatibility.
> > - Freeze & deprecate record layer version field.
> > - Update format of signatures with context.
> > - Remove explicit IV.
>
> I've noticed that the default values in case the client didn't use
> signature
> algorithms extensions is to use SHA1+RSA, SHA1+DSA and SHA1+ECDSA.
>
> As we all know, those are not considered secure now.
>
> Maybe we should update it to SHA256 for all three?


I would welcome a PR for that.

-Ekr