[TLS] New drafts: adding input to the TLS master secret

Paul Hoffman <paul.hoffman@vpnc.org> Sat, 30 January 2010 00:11 UTC

Date: Fri, 29 Jan 2010 15:42:26 -0800
From: Paul Hoffman <paul.hoffman@vpnc.org>
Subject: [TLS] New drafts: adding input to the TLS master secret
Greetings again. I have submitted two drafts that are probably of interest to some people in the TLS WG. I intend to submit them as individual submissions, not through the WG, but getting input from the WG before I do so would be great.

The first document changes the TLS/DTLS master secret calculation when there are particular kinds of extensions present. Of course, it does not change the calculation when those extensions are not present, and there are no extensions yet that would kick in the change.

The second document is an extension that is similar to the one that Ekr proposed over a year ago. It allows one or both parties to add more random input to the master secret calculation. This is desired by some organizations who want to match the guaranteed amount of randomness in the master secret calculation with the strength of the encryption and authentication functions.

Both documents are (purposely) short and hopefully easy to read. If you have any comments, send them to me or, if you think they pertain to the WG, maybe send them here. Again, these are not meant to be WG work items; I doubt that the effort to recharter and so on would be worth the value.

--Paul Hoffman

	Title		: Additional Master Secret Inputs for TLS
	Author(s)	: P. Hoffman
	Filename	: draft-hoffman-tls-master-secret-input-00.txt
	Pages		: 4
	Date		: 2010-1-29
   This document describes a mechanism for using additional master
   secret inputs with Transport Layer Security (TLS) and Datagram TLS

A URL for this Internet-Draft is:

	Title		: Additional Random Extension to TLS
	Author(s)	: P. Hoffman
	Filename	: draft-hoffman-tls-additional-random-ext-00.txt
	Pages		: 3
	Date		: 2010-1-29
   This document specifies a TLS/DTLS extension that uses the additional
   master secret inputs to achieve useful security properties.

A URL for this Internet-Draft is:

--Paul Hoffman, Director
--VPN Consortium