[TLS] Re: 2nd Working Group Last Call for The SSLKEYLOGFILE Formatfor TLS
Ilari Liusvaara <ilariliusvaara@welho.com> Wed, 26 February 2025 08:53 UTC
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0DC4D1A9314 for <tls@mail2.ietf.org>; Wed, 26 Feb 2025 00:53:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietfa.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jCLejRMS-ToY for <tls@mail2.ietf.org>; Wed, 26 Feb 2025 00:53:37 -0800 (PST)
Received: from smtp.dnamail.fi (sender001.dnamail.fi [83.102.40.178]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 918FB1A92F9 for <tls@ietf.org>; Wed, 26 Feb 2025 00:53:37 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id 979782113E11 for <tls@ietf.org>; Wed, 26 Feb 2025 10:53:36 +0200 (EET)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.178]) by localhost (dmail-psmtp01.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id BdXNiq2Nauju for <tls@ietf.org>; Wed, 26 Feb 2025 10:53:36 +0200 (EET)
Received: from LK-Perkele-VII2 (87-92-153-79.rev.dnainternet.fi [87.92.153.79]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id 24FFE2113E10 for <tls@ietf.org>; Wed, 26 Feb 2025 10:53:36 +0200 (EET)
Date: Wed, 26 Feb 2025 10:53:35 +0200
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: tls@ietf.org
Message-ID: <Z77Wj18Vh74F0xmd@LK-Perkele-VII2.locald>
References: <6a27cae41645539b3fa90b5f83a8973c73cdd6a0.camel@aisec.fraunhofer.de> <CA+_8xu1nDDHuqRbh2OvRVkvxPyLcJS==rumo3sxPC56NsWLCMw@mail.gmail.com> <93eb1e78c7348459fc92ff874c7e691baf4a0bf0.camel@aisec.fraunhofer.de> <ee908b7b-da13-4840-b70a-84dd66d4bc1f@redhat.com> <2e57a347-cbfc-487c-8b3e-7ee240913ed2@tu-dresden.de> <8fb60e2e-5103-4511-9c97-6b59bae1c5dc@redhat.com> <CAN8NK9HvfsoePrW9ft_krVtiAV7aYrf4suD52=pQUmG543W-0Q@mail.gmail.com> <e2b73144-8ccb-4ff8-a32c-2c7aefefc7d1@betaapp.fastmail.com> <955e3b1a-0baf-4483-b741-eb17ecce18ba@cs.tcd.ie>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <955e3b1a-0baf-4483-b741-eb17ecce18ba@cs.tcd.ie>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: E3THYAXT67ZQZZPFE5MHOAQ7YLDK6ZZ7
X-Message-ID-Hash: E3THYAXT67ZQZZPFE5MHOAQ7YLDK6ZZ7
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: 2nd Working Group Last Call for The SSLKEYLOGFILE Formatfor TLS
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/u3SVOa0pU3cLstmzdOLgcDYE18g>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Tue, Feb 25, 2025 at 12:01:00PM +0000, Stephen Farrell wrote: > > Hiya, > > On 24/02/2025 21:54, Martin Thomson wrote: > > but > > this is a case where that interoperation already exists. > I think the above was true of your initial draft Martin, > but is significantly less true of the current draft that > includes an IANA registry setup with the specification > required procedure - that, in addition to the addition of > ECH exfiltration, means that publishing this implies that > the TLS WG approve of whatever methods of exfiltration a > DE approves of, and that we approve of every new thing we > add to TLS (ECH in the current case) having an exfiltration > method defined for it, without WG oversight. This is an application debugging tool. ECH adds new keys that need to be exported for application debugging purposes (as the ECH may contain application-specific extensions). TLS extensions are already specification required. Bad extensions can do stuff that is absolutely fatal to security (way beyond any even remotely reasonable SSLKEYLOG key type). And moreover, those extensions may introduce new keys that need to be exported for application debugging (just like ECH does). And extensions are not the only specification required registry where bad stuff can be absolutely fatal (cipher suites and supported groups are the most obvious examples). Moreover, the very purpose of Specification Required / DE is to not have WG approval of every thing added. So if WG oversight is needed for actions with major potential security impact, those three registeries need to have policies changed. RFC 8447 explicitly states that changing extensions and ciphersuites to Specification Required was WG consensus. -Ilari
- [TLS] 2nd Working Group Last Call for The SSLKEYL… Sean Turner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… David Benjamin
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… David Benjamin
- [TLS] Re: 2nd Working Group Last Call for The SSL… David Benjamin
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… Sean Turner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… David Benjamin
- [TLS] Re: 2nd Working Group Last Call for The SSL… Stephen Farrell
- [TLS] Re: 2nd Working Group Last Call for The SSL… Bellebaum, Thomas
- [TLS] Re: 2nd Working Group Last Call for The SSL… Ben Smyth
- [TLS] Re: 2nd Working Group Last Call for The SSL… Bellebaum, Thomas
- [TLS] Re: 2nd Working Group Last Call for The SSL… Stephen Farrell
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… Bellebaum, Thomas
- [TLS] Re: 2nd Working Group Last Call for The SSL… Ben Smyth
- [TLS] Re: 2nd Working Group Last Call for The SSL… Bellebaum, Thomas
- [TLS] Re: 2nd Working Group Last Call for The SSL… Andrei Popov
- [TLS] Re: 2nd Working Group Last Call for The SSL… _ _
- [TLS] Re: 2nd Working Group Last Call for The SSL… Martin Thomson
- [TLS] Re: 2nd Working Group Last Call for The SSL… Stephen Farrell
- [TLS] Re: 2nd Working Group Last Call for The SSL… David Adrian
- [TLS] Re: 2nd Working Group Last Call for The SSL… Alicja Kario
- [TLS] Re: 2nd Working Group Last Call for The SSL… Muhammad Usama Sardar
- [TLS] Re: 2nd Working Group Last Call for The SSL… Aaron Zauner (azet)
- [TLS] Re: 2nd Working Group Last Call for The SSL… Arnaud Taddei
- [TLS] Re: 2nd Working Group Last Call for The SSL… Achim Kraus
- [TLS] Re: 2nd Working Group Last Call for The SSL… S Moonesamy
- [TLS] Re: 2nd Working Group Last Call for The SSL… Alicja Kario
- [TLS] Re: 2nd Working Group Last Call for The SSL… Alicja Kario
- [TLS] Re: 2nd Working Group Last Call for The SSL… Aaron Zauner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Arnaud Taddei
- [TLS] Re: 2nd Working Group Last Call for The SSL… Stephen Farrell
- [TLS] Re: 2nd Working Group Last Call for The SSL… Arnaud Taddei
- [TLS] Re: 2nd Working Group Last Call for The SSL… Ben Smyth
- [TLS] Re: 2nd Working Group Last Call for The SSL… Sean Turner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Christian Huitema
- [TLS] Re: 2nd Working Group Last Call for The SSL… Bellebaum, Thomas
- [TLS] Re: 2nd Working Group Last Call for The SSL… Aaron Zauner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Martin Thomson
- [TLS] Re: 2nd Working Group Last Call for The SSL… Aaron Zauner
- [TLS] Re: 2nd Working Group Last Call for The SSL… Arnaud Taddei
- [TLS] Re: [EXTERNAL] Re: 2nd Working Group Last C… Yaakov Stein
- [TLS] Re: [EXTERNAL] Re: 2nd Working Group Last C… Andrei Popov
- [TLS] Re: [EXTERNAL] 2nd Working Group Last Call … Alicja Kario
- [TLS] Re: 2nd Working Group Last Call for The SSL… Salz, Rich
- [TLS] Re: 2nd Working Group Last Call for The SSL… Ilari Liusvaara