Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)

"Roland Dobbins" <rdobbins@arbor.net> Mon, 17 July 2017 17:01 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F2D7129B5B for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 10:01:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level:
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NaCAoHEA40V7 for <tls@ietfa.amsl.com>; Mon, 17 Jul 2017 10:01:44 -0700 (PDT)
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (mail-sn1nam02on0117.outbound.protection.outlook.com [104.47.36.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C3BA7131668 for <tls@ietf.org>; Mon, 17 Jul 2017 10:01:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=t1DfJHcDQIj+thTCHqDI2xbsk5YdSawU1uMYdcqwBy8=; b=fGjV+2geEkZk/FDj494DET90mMTl6ZeBzTR0s3I0jUzo11ACYpFa9kvQsPb12hLSjE5z6Ez8vFuMRtdUoSmIxxrx7E+feuWfTK4U9Yi1beniDJ+Nbm4JHgLBMHtUJBngSE2zFftxTeTX48h7P+a3KtjuhM/tSD1pU/HMtGEhq1c=
Authentication-Results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=arbor.net;
Received: from [172.16.1.3] (88.208.89.131) by CY1PR0101MB1036.prod.exchangelabs.com (10.160.225.140) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1261.13; Mon, 17 Jul 2017 17:01:29 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: Watson Ladd <watsonbladd@gmail.com>
Cc: Simon Friedberger <simon.tls@a-oben.org>, tls@ietf.org
Date: Mon, 17 Jul 2017 19:01:18 +0200
Message-ID: <88AD564A-B299-44EB-A825-D20717119AC8@arbor.net>
In-Reply-To: <CACsn0cmmrGd1Q4-GmbJ2VNXUUgKyX18_MsBQmuA2e86bPcLxMQ@mail.gmail.com>
References: <CABkgnnU8ho7OZpeF=BfEZWYkt1=3ULjny8hcwvp3nnaCBtbbhQ@mail.gmail.com> <2A9492F7-B5C5-49E5-A663-8255C968978D@arbor.net> <CABkgnnX7w0+iH=uV7LRKnsVokVWpCrF1ZpTNhSXsnZaStJw2cQ@mail.gmail.com> <FDDB46BC-876C-49FC-9DAE-05C61BB5EFC9@vigilsec.com> <9C81BE7B-7C21-4504-B60D-96BA95C3D2FD@arbor.net> <CAEa9xj55jzch-v0mysbRSryNM0Y7Bdtevmrc3+FVxMO8EP5zWA@mail.gmail.com> <CC3CE5F8-C8C2-4A70-829D-483E26D20733@arbor.net> <CAEa9xj5eR6b_+CsSDArMWWr-u8hx5B81kDVEMEX8sgfUeMUS8g@mail.gmail.com> <C3B01C35-E3A2-4A8B-9DD7-D6E4153ED39F@arbor.net> <CAEa9xj6p0y9ZzxLJvtv9GDzzfs5s13nnLqm=4_fNDPGV+=Od8Q@mail.gmail.com> <BE4E8E4A-51FC-4211-A16F-EBA8B3F01757@arbor.net> <CAEa9xj7sVcGAR03f3pWsK7giFqmu7GRHN4gqh9Nb6uEAOM88Yw@mail.gmail.com> <637C97B3-DA63-4F61-8EB5-D938136D520C@arbor.net> <dfc93b70-0fa4-6cac-8c3d-5f2ff771f85d@a-oben.org> <64A2BAB5-5EAC-4608-9BF4-856CA0859042@arbor.net> <CACsn0cnXv_f_o4NEMMsYW7KQ8UqyEzhyYSAqyZpfsc4ddOr=eA@mail.gmail.com> <CACsn0ckBT29pqdrUk7DfcscmEmG8zoVn119gY+Y73FEuheJGTg@mail.gmail.com> <CACsn0cmmrGd1Q4-GmbJ2VNXUUgKyX18_MsBQmuA2e86bPcLxMQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [88.208.89.131]
X-ClientProxiedBy: DB6PR05CA0017.eurprd05.prod.outlook.com (10.170.218.30) To CY1PR0101MB1036.prod.exchangelabs.com (10.160.225.140)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: e5ea2db7-f4d6-4da1-b665-08d4cd357857
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(300000503095)(300135400095)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:CY1PR0101MB1036;
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 3:7IQT8gYLXEt1XiSiKN8cH+AvDhGMn48Nb5hqqBkkLO8UwI2JwBPd9YP6xn5HSu7yJ+WQ1LwcpFWux/0FdO5qputLi7f6Ood2oB1IeSfyYMW++eOBdb+NMDr5J9/tCsWfwpVhb/tW5cacsB3GG+ZInJcqJbqIJpOxk1OzwMDF/O02Hizb5Qtl/0Ny5qKEE25DrZR8uJSKR9Px6BQkyu94zl1f5ywi0pOL52/3iyAnsQvUWKsDcqNDcxspfmLcU/DPTpwOqlHcG5p9PlDOvkCPy/OLBF3zbF7N+gfWzWGEaVvyOfDl+Xb3eUtOGuF7pqN+EiqFe/EBj/8KMYBtXkZ4vaTn/M/PhX00aO3SA9lY/kUNUbch7JUvyU3lCmaZqI423d4UDdJsQPBb/1CqBAgydCaWXzDJLhtMSBEBJwqNDbeWf/O0xLk9oSTr/6VHfoX3wnFUyJZuDpqUs0/ejy8PVPn5qvjRe63G7FkUUvOh+S3Cgg0eiw+F9sREbMK3IMIimKdOhjwFujCkjIGvrw/M0hgIZGd4ubicK89H7/nxQSq2hk7E5NSjESpRRCTxxiQ1y/6QWTLLMFrGiVfR/9eXygtW/1Q7boi1jSD67vvy8hW07Wb3eePIAUEqVQdnTyOFNaumkZ4QCiGqun1NSc3Dr9FMk8Ml70S5dE90tY3R+vjfyXBOmB7xtUqcd3gU5yZGbdoppGJJ+Gra1C9kjx++//XUMvLlDzDs4Q0JI9PnkmA=
X-MS-TrafficTypeDiagnostic: CY1PR0101MB1036:
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 25:0QpvNN+Mrwoizv26tcUBBM8szfvQ4nYfwv2hgmysSZVuJTqH0c1TfNPPtk46X5E8LU8ZjLjQlToxyyENHr+mfxJGI+a+7jDo4cJauX9F+a1lbmbl9JP5bMbZ5/KsgapvazS0j94l2FMAol51VpxLzd/NrOuNSB9sGwaiVQGWhU3AKRuuoQfo6fgFDU9PEyQHSsvEhzTPCWmRVJiR16hfTBpI7v2qlTaWDT4VJq9R36y3g4ZqKU0xRfLS8d7GAc7MnaUo5c/uo5NgtYbkcDo5VcTbKI/R5hHEPmWLIvFK7hJkcNXs0JWOtqvc9kLOO7sBPA13xgVQKQHK8DGAUeVSm6e11dUG6j4Tzv5CKSUDSJc7kyhd0Oje63ldRxeQCuFiineaSO2M4UEba8Egm6i1RwCVNo2FlMPpzRZi779jg1CMM82lJN9DuVEBhuFu5fdVXhZv689HF60B0Ctw3MgNrFaOxmboTuVGjOID4CCZu+g6VFYre4VGdcC4Sm0+IIOIPbcinZDXYJQ3bpXSoqXBwrsZWbH4JJUDVoEh+LeWaAZg65pG4rjy/GgHoh9LTwENrcXO+lQoApgXExB+Fxuq+DA5+xylQckPVlx88olxmCDb1GmUyA0706jmxIzlvdIbOvv5MnhxcIsPYLhpamVTHihzeSyucM17zQ7S648/M/a1+HHtq/5Uq/MdkcaC93wCX78gTx+Oz6xDF6XIVNgB3ZfCizfzv6Gws4OpOV6cfD+l7KmOYdPgR3UF5pmRl2rcMLvd97/ndf1jtvEtCcdhNY3gF8GWSWFooTUkMZjmIaqcBtNqH+YxDV8F7b0kXILhOzsThra1MtFnW1n/gk3/jzzo8901a/BQy+R32iKMGm0/4yA71C/eqoWOgVLpoLcQo2mm9p5ek9dhC6NHS+cIMRv7/9ZhUaBwvfMX+f9Wnr4=
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 31:WZEQnoTWuhPhOePxSLGSW09nWTUOCOOUpoe+/8GpmFn/uEylP6EJJxkJD5jdcpXkaOzWks+rAWd/S13T3I6wPKNRVZyByF3GmhZHCv+yzg8T3uOSRlDShWL/ScRCvKdT6WzqqQVcUl7k+xjfhPDE5FcqH2leQzyOQYGGIVmTWbMAKq8GdG3xru5C/Ytiw+U929XA78Ov12gLX2JKWlWtQipJd+8awP6n4Hq+/vk+G8rP+nwDeDdxDx8Z/zapVwWuQphREpNISa/j9TrKO2bKpUi3Ku7yGxerVK/gznSuMK2fhkxJx8ckHRzcedtc6qC2Lg6D7nUmA2SRa+NrXSJzWn8TdVBvUvdQon9BdPL3YIsztE+g7yZKCveLvbo0/Ei7JZJhhLulkjQjbDkuc8AKVhXTWBaBHmJwH9ll3OGmqgX51344mvvsOVbuaDSMIWqkR1InD3IqgaK8Jb6GhDZRH9P5jbheX2BW2f5c3IMS+dgqKF+9voD2faMWN8Iuw3S5m+2XqbhQJTqYMjgQmekVYB4dWGFozcE2LuTfoRqB110MPZMIWEsvBt7ff+EdR2NgkaJ7Ae6BIioZA0dnrEO5g5zmbdds2OOkBXDmRsV84ARY9UAX0kiN9Ufjl01EmrhqKEX+W75003RbJsB+P9wI+wNTK8L6ZxY0EDcSL/X9+9eHiresKXZfXsuYHJXR+k4o0nkHr8k0tkCQMB6BCk+oqQ==
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 20:bM2zI93Yapmpy0JrGO8g7+vai/Ke//ycIm1twgUQNio/pQBCbvFZswCGtS/exuH1Pz1fo0N+9rwQABkP4MD0fgIvgbPs0uh/meTTgEcPWC0R2KcO81NegC2RwR6SKTNAeCQsF6QZJFhbMNDBcijYLz4oLDlZpB6MZkowyjfq9WhuScBwRvgxP+dE7fzv70dlrUrbFDQEmJD52ByuRQZDHNOqVAsWf91h+p4QREKk7Lhi1Pl9fxKyhsk/XhloR9Cr8/8ahpeRvI2QnFhY4tg+11oV3LdR6XGCz44V/h3SzN6KXM2Rq+khss6b3W94HsNfEAm9v8rx0kvYQY0LGIG7z936jmcX2INE3BnUQ0P8tEfbG3FBzkYfd0io0vaaXyyU60fGecm3lnMuNodwryFTySbQD+bEnlxIGU6xOJ6nJ/KgZ8hnYkBypoEkp5oxtBoWj9FZzm9kqGd/k2x6gIU/jtmucAejM716ycKfZ69xCWspNVKw1fgH3nOqY5zymrPY
X-Exchange-Antispam-Report-Test: UriScan:(236129657087228)(266576461109395);
X-Microsoft-Antispam-PRVS: <CY1PR0101MB1036B37DD09A7BD831C6BE3DCAA00@CY1PR0101MB1036.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(2017060910075)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123564025)(20161123562025)(20161123555025)(20161123560025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY1PR0101MB1036; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY1PR0101MB1036;
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 4:8ZQFt5uetfqrvUmm2mRMqmsawiGFbxv00JQGRZHBycY7EBDvYHMzKpsxFsh87GIPHSn2Wh2IzN7DPNqLzf3GxxNF3shNxAybZXK+v4Ox7GDuZapyP+73bR2fRiGiYMq9cg8es7w3fTY+O5Di0cH9S8lW2vSJ6nmtPcfS/jy2bFxVL53NfcxLvwB8oKx0dYag0tHmwxSJ2QjEgJ+DUZPQ7mralSw+l2nuuF74AqGBuiJ1EZhE9TtRhPYA1sKOyX2OpdcQc2hiJAq23e72gi/wUaXX1aHQtF0f99GbHQ8Mat1QP9OocJZUy6yLye+GGOhjR2cDDXKwMhJ7G2jPjhD07KcOCnMfhfvRptzNwGkj5vzo+8PifjPF9lgS+amAC5BwNz7qqsoLIZyaRwxgaU54NiBA+IF3deat1LvJXl1kdLTqp4xOU2pT/lHwv2XoxK4TG1DitxxsSBA8se0oA7o1QhZgklxjBytrFNrA+VE6eKPuHGz8uQgMGXGAnOkNvdtTBkN4ZqAmRTJMXY4srV3hvfCNctA662skdzzIYgp5ADKVrcr2YR8Z1aCqiUMQZevac5p5CJ0D+TjEvmKptDuZFQf9P89uPrgFb2HK4thPK7QoOuzjxPlxAe7lVYMFnbu/KOUHnMSJDWDCxPHvGzvdU9BoliOHwGkGs8NGHyRzlex8hdsPOdCr13VuP5L4doQZTcJDtXHuxvbC7+pzRNGrwQkh8k5lyaBOKAKeH+LGTM4/EILli/HPpAetNU4Oi/QFrRytOYNUeZtoC1U+6YMvdwCCOePggsZy0TKiS3bL/cVF7iqTXU7WCWCXLH5G7wlggAqauDDF60Rj4jzr/mr6BZimku4BDVNje+Y61YyiAq7zQ0jnyp2Kebqm9rzCbF0g42izdrWLbWZVAcupdDcI9WZhv6cWuMzBXQ9LxDafUbHGn4B1Jveb46SBUAJxHDIcnmu1gmsNkir5rkobosVw8sXmxn3P+J6YtcpHpZMiTJbjbeJErNkWr+xNvek5qwG6DkS70vYI1TY3YAzAY0sj7zneFP/EzwcEWzTz3KuEkNubOxttJOVeNav+eYcqiQ3J74RnIMjLhSAAxVoyrWK5SXy7hkkYilScnHEHH91gYptPXo8PTD9SdSQQdNX96mdjroZ4UVGrIgNum8tKBWW9TwMu70ipHohr8zij8HR7QOLTmXD/fbB3LRcmuo4fQQkaxRvapMrisXFYt88Y2dQO1p+RWlGRqJj/i1WgW7c0Os4=
X-Forefront-PRVS: 0371762FE7
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(7370300001)(6049001)(6009001)(39450400003)(39410400002)(39400400002)(39840400002)(39850400002)(24454002)(7350300001)(305945005)(6916009)(6116002)(5660300001)(3846002)(189998001)(6486002)(53936002)(77096006)(50466002)(50986999)(47776003)(76176999)(66066001)(6246003)(42186005)(478600001)(2950100002)(33656002)(86362001)(110136004)(6666003)(38730400002)(1411001)(7736002)(2906002)(93886004)(8676002)(90366009)(81166006)(50226002)(83716003)(25786009)(4326008)(230783001)(229853002)(53546010)(82746002)(36756003)(5003940100001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR0101MB1036; H:[172.16.1.3]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 23:lkB54IbrBdLWmzgpLgXee3pclIGp0GWylM81PKvMwlOUE3cw32s489vzE6hHdFQwVGZb8TZesa1WJPuRk7Z5U5AivhD6+uwO9shwjlAJDthyumzayjH/5mhVXRqHWnLcxNRrc+LehvrfTwZBSfjP7TuVruQZLrYQ1rWekbI8FcHhN1Ydu0/p8rOb8qA61k9bTcXZRnJmxf8hDm2MBEhPCEhDlbJef8jgr88wry8G3XUFvpEYYxoN3TmB/mSaDjI4/sDkmSfldNPEgOkPkmzjQpZcPfEjI+Ays7UvG732r6OCzJW3C6YzwlmKD0982/1BjJJ8QRdBLQj4Y9U/UFtuO79+7vSIVajh/Egj/B5HBTAS6vJfsnZPAVlEbG0khpE5IaJ4w2nfsPIkaQU6fDoDkFSruYKBmtpsIv5jzCRHJuTyznVM5esb3EgMf1DefMe+W3XhNTXnnLrH8x6JdssysjoY1kYa04j0U8N28M5QkDomIaQLTiAzAPICOYIAKRDycoL8VkC1GQFpjrZvBy7cPQqCo1tPydZbrtCsqU4JuxBvDjW+RUU/RMJD4PJmVn2NKEeYtZZ86Bt09R7YJylkPkcs3cUtTg/E6Sm9rRXULylDvyn25VIwVnEfr6vq2YeNALWPlTtP8qKnyJGYqfDkCKv4KchBQTKHxYILPJrmpQxJ4yTzFabu027XOk2zxbucpZrSmO1NPZji/9BwH+kqhRax2wHLcOROtWQviRWjwZ1FoaUlt4UKgihOycUkzOmalGfjdHtgvVtvdk+FfrUTsheznRh6DR5WT0fu00UAly6mGlRc/RkNgae/pP1CEU0P46jpdUJLj2T81XKnfHQ1iy2nlZx+C9vqv+m5BcXxEaLohTH4NDMWV+AyEc92ddgyfhkAH7bDlKYXIkj5wi+75EwmQdk3cxHMpKFmgJ/2h2zl5pfh8d5xClOMJunL73YRgQVAtQhIg2nZLAO6CbLlW2gvu150h7TzpbMejtyY8zOCRqMfb1yiHllOS5mUQelq5J8IX9goAHPVSVQK4dgRdX7UaMO7AqvyDGN08FJyD3RoWI9veNmzVy4FY81r7GTMMZGtGfSbNqb0We90RrQ/WF/sSM6xHFfe71jEYwzfuh4j/7i1Ik8OeCjlX2ubwUKg/XV/JTfDBb1lBX2Bq6EE4R2lxwmYzo5DbOW0SNk6dYeXHzpHZTJftkGyzksRgtnSB3L5QGE7s6OXjC+C9SOlDG/tZibuhTqZVm4/FsYdQMiQKy8yxPKun53pMSVX9+ll
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 6:R1hgVtW9N42C+TqqR+9Q2NKUgmqgGfpuoPqCZLMsw9v7B40m0Hx5Nj/5LYno0ZLG+fim6QHPP63ELPFKqFRLMNS61HTRFqWL3PiRN5VQkT1AhotLkPW9vhSlWHo3IFxZ3fwKYPQZmAbMSRVafAakViEA5sCqaswDGZ/uF3ch48A6T/NvMi2J9B2KXRijO3ylTE0ug1l/KnM5b5WUHqLDBFIIriBpR3YGAYK24MEloX9QO1OMwDal9gLceEnGeHn1MDJRIcDo1RA5rHR53dttKWFzLpNjjzKSbCwvEVhTgMlc7Pg4rRJmSIAvc8Fpta3w4oaEAYUlkvjwSGSJnu/LmiyIJ33CcAOonGY7xChwPJBXHAb5bDdXTSm22kKl8FlumMFH39XPYFI2NP5kLyzaQONwabC0CmHcO2qYdO2nMsXqtpGq2T3m3Hz9WeLLVDNiBDgJzafp04voIfeikyJ4PjAc84NH55dKcMLVJTctJtUEh16Ak+LVd0+E9cYiRACiabCjz/TViboAVb1bk9ZOhmC49dsR60mcvztYKicYv19O7T9QjsjvWWACuOSx2eqZDmrAqnyEXC/v27j7SSXQXNtRTPhCctMZxL2ecU5l5lHnIAZ3plSHXey72+3o+ko0lew7Vy3kSQ3jfSGllbGyYhZPUJDHBfV5+I17wP3y0Zd20hipezvHlAhJZDpUkSzVAt1fkkpMordByxBAup9YOSDWwXRP6KDXzBhLX5PmgCedAyO/m8mv1pCgdnhznCE6z8c+miWeD0wzEid2lK4DcoOiMUN/AjWJ26oblMqwkSJM2Vo1WL5k9Jl/a96keZ0qbvO7Svk3bernQ8/oLG53vghbqc5yJAcxMPG3bQgvvbBqNN3bNvZiby7Oi6wHUoCin0CGZPOwuhFANM3VTxM6+wN09uXPwBMsDuZUHMCdoNfhgA7kfgaAkLvmS04PTrynT/OeO7iWIR1HbkfsnCyfbMsT0Kxz/jXtk+Q/DDL1nXY=
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 5:KgQ/qGf5xPq0BCMm1KE3KFrHs6hQgFb28wgfzfFPsX3cE3/5YjDxN6MlholQF4QgpVT7rMgBdDX+1tcO8vLG35vHrPoqlIDLEsvS5wI74nb4SCKEjlkSjkNy5iYk1QFPbwL5F4y9LbZXomJculSPMk0eHN0SDSMSywFMTp9jMoEG+vJpbOGUKjR2SlWsgPQBBmu1f51vGNhgv6fNv1iK4P+IlA6zxduIz7/o18SrOuQWFA3wD1Num2jgMJ7Ir2ip8eVNRktHyKzmkVEGmFJqdlDYKFnQ4cdFdnCh/eiSuikGNR1bF9i1aTL+V5lTZNXsndMgYmuaJkKdL7n23mRVcHiHxCB4Hm/G0FW9vtPC/hqlnz62YZMYhc3CcPZ8L8QCKOWi8BHnXHMT+cf2FbQWO5pS/T+eQ9rvuN121Njwv6yQn+YJVkEerVWqbLYSh2ly7swNHHlcU9XF28LTTp1DBb1CeNRES9l40mVYmlbhs9O5+7bsjcTStyMMmqZIzOFQ; 24:b+i4sf9LWZldCwhg8rbrPFGF7JZFbNdDrKhIyVq0b9OJ077iP8y6bB00tyUofQZHaco6nez58LZIRX67rjx2U3KaUvjXziS3QrZps0gjjuo=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; CY1PR0101MB1036; 7:alOumZIieS8wDt+T5Vd1zAUKmDh7AOuv+/Tbl+rOxTiCLrusxsDvvw5EEM+SGwJCAvHZL0lWKcQfv7Mdl2xdMwLCB1891rR6p+tINVej3BDSkHCBj4UibsVwRVlZrwSx5wgnfACWuBRO+8ILOZ5iALj/IMdxw8Y7LsMqPos9VMSLyu2BDTPUIuA/BGl/4CWKcEHAXO6io1D1ef8zAcdRcVyogHeKfZe/VW3n2im2zfirEtkID2rEK1A+SRuLjQDZ79hubDlWcTMtYCrAqcWrRMtf6R+hPci4gwYxrTHwZSbovww+jvyLeEmUxNiHlwgy6k5BVtVJfS1cIpkMAYXC9LVmabsjxuvr+ny0Ag5ERkXaPsJBxOY9aD+qxoRUbQHDzhPDAngsYnoVoofgbVtD40nO59geFUAzFdrJQMh7+XQe0df8mLcRGnTTNAZvhjI6cb9AcwGtHMEQHpmdbVqVSoRzZOe6b75Ly1D8wI27lOsNbSjSPQUsFZIpGKTxeQU74/YomDGFyEC80GOjJ8JcfSjVvInZszYJeSTWC4ktJVjAvspXOGtVbFmKJxC3hbbxB5hLUICvLyXNX4fG5VBx3pTniYn2+Uej3O1dVyauwKiQoPFqUe4BwyrwqonLADmWF0DDqtQjl4xY7GD70r4OyA/sLazglDWUib68I3b1dbuz6c+1t+wNaCF6pof4Pa4fe9ojM/SLbHMijZTvWiqO5iJOwXS1fxliC6KTJjyowTUwep10ZhEE3coie6gfSB8pJybx98ih3dgx0p3e/2pJja4jtGlE+Fr/K4zRtZcJST0=
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2017 17:01:29.1509 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR0101MB1036
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/uPx1rAQjDx3XUNXKCzve4d9AmSY>
Subject: Re: [TLS] Malware (was Re: draft-green-tls-static-dh-in-tls13-01)
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 17:01:46 -0000

On 17 Jul 2017, at 18:55, Watson Ladd wrote:

> So FS has no impact on this, correct?

It's often desirable to be able to inspect closer to the internal user 
traffic sources/destinations, as well as at the proxy.  It can greatly 
reduce the scope of traffic which is to be analyzed in any given 
investigative context (and possibly groveled through), which is a 
genuine operational concern.  So, having the ability to look at this 
traffic prior to it reaching the proxy can be valuable.

Many organizations do this, today.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>