Re: [TLS] 2nd WGLC for Delegated Credentials for TLS

Jonathan Hoyland <jonathan.hoyland@gmail.com> Fri, 24 July 2020 16:12 UTC

Return-Path: <jonathan.hoyland@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71C623A0ECF for <tls@ietfa.amsl.com>; Fri, 24 Jul 2020 09:12:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qb1O57i8AwCl for <tls@ietfa.amsl.com>; Fri, 24 Jul 2020 09:12:04 -0700 (PDT)
Received: from mail-vs1-xe29.google.com (mail-vs1-xe29.google.com [IPv6:2607:f8b0:4864:20::e29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 771843A0ECC for <tls@ietf.org>; Fri, 24 Jul 2020 09:12:04 -0700 (PDT)
Received: by mail-vs1-xe29.google.com with SMTP id o184so5205139vsc.0 for <tls@ietf.org>; Fri, 24 Jul 2020 09:12:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=6d2J8lpCgIZ5jxjqXOSrx98cTjD12zH9HOhHMgxPmsc=; b=jQt5ef8ocPS1MyX4iKD2XUndRfOXBvMM76jRGtEHj6Klfwo68dBug14Sn7mA1tRdep P5AntQcWGK40hiW7PX7JX2w4lMgI0+ZF1bxj4gnHY7s8oZw4mnMCaWOjj6baHP4NyzGX erOK/2q46Wp8YjFb6XtVITiO4LLXGvEtNKGBbDP3wlYFXMOyM2+BWzo0rNlOMocisCDM Lx0OgpYNkhBvC3VjATwQeM3VkhYgkEEB8CKaweGiSpxMfJnyojMYj6PlB3mNFkOY5R6y hxfMFLP1f7xcRVjVS1H7Fw4kA6kLVzougneiPd548l9GXa05WelgwQUcQGclSHEQj7IT /o8Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=6d2J8lpCgIZ5jxjqXOSrx98cTjD12zH9HOhHMgxPmsc=; b=fEjAWPZt/Z9TsHd9YUnWnS+2u37tYcL2v4KvbbSpNMpse15TGMRq0h5bRoB5AXCnOz Za6e0lA31xfOzGwlEfRD4Cw1ua9WYWOkX0K9GBCNS7jR2dmHw7/9qePeY8QglkVCrCWO ieMJGCb7h0sgvHDu5GcQWEOed7zrBjCs8nOZ7svgdVebx54wImtUpHS3dzKH1tzvcCpf VfqqpDzS8XOpeSpq3QsYMwRTvn6Ez36/jEfVtlE8YkcPy8mlqUYhJUuR3plS2CstE96P jy9YaopTmgVJHHqRvJRXlYjI48LyGQMGfEDKIsQLzN4S9+DeD6shaeSMj58O7MuuJpb2 OmyA==
X-Gm-Message-State: AOAM5333ULMuxhn6oVCAyeiHee+qkwVNriJR2vJVCH1SUq6N1fvUoWvo G0MiGZw/8Vcr32qpB1upgamc5y8zYPrDxhmNZgMvVzVr
X-Google-Smtp-Source: ABdhPJxQ21Ec0z5gpFJ/EUG8VfaU4du7lPws+uqD9Dz2Bm5CfPuhMxE3r35/mcKz879CUqfatBVmjWI2dZhESOMScUo=
X-Received: by 2002:a67:ec54:: with SMTP id z20mr1156629vso.143.1595607123120; Fri, 24 Jul 2020 09:12:03 -0700 (PDT)
MIME-Version: 1.0
References: <CAOgPGoB3LDZ2uMJkMyDxMbbWy6yScYuURVB7GqTiwVS0f2UkTw@mail.gmail.com> <CACykbs1zgLW5RS3pH34DjBDz8ap14AmAb4NL1NMrpWc6Octq1A@mail.gmail.com>
In-Reply-To: <CACykbs1zgLW5RS3pH34DjBDz8ap14AmAb4NL1NMrpWc6Octq1A@mail.gmail.com>
From: Jonathan Hoyland <jonathan.hoyland@gmail.com>
Date: Fri, 24 Jul 2020 17:11:57 +0100
Message-ID: <CACykbs1A9juWuWHBoJc_hMS8a+zC+1aUXYQAvThsM_ppgrYcAg@mail.gmail.com>
To: Joseph Salowey <joe@salowey.net>
Cc: "<tls@ietf.org>" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c661b905ab323bfb"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/vSweLT6yZX42i0VGKbN5eZzLi8s>
Subject: Re: [TLS] 2nd WGLC for Delegated Credentials for TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Jul 2020 16:12:07 -0000

Just as a follow up to this, the proof files are now available here
<https://github.com/kmilner/TLS13Tamarin/commit/06f0c2a96e46444675573cfd0979f68d9661b3ab>.


These results are under the stronger model of a Dolev-Yao attacker with the
ability to reveal long term keys (for certificates).

Stronger results and write-up are still works-in-progress.

Regards,

Jonathan

On Thu, 2 Jul 2020 at 15:20, Jonathan Hoyland <jonathan.hoyland@gmail.com>
wrote:

> Hi All,
>
> For those interested, I've been working on a formal analysis of DCs the
> results of which should appear online in the next few days.
> I'll post to the list when it's up.
>
> In summary I managed to prove a server only version of DCs secure (i.e.
> does not violate any of the properties in Appendix E.1) under the Dolev-Yao
> model without resumption, and work on a more general result is ongoing.
>
> Regards,
>
> Jonathan
>
> On Mon, 29 Jun 2020 at 16:59, Joseph Salowey <joe@salowey.net> wrote:
>
>> This is the second working group last call for Delegated Credentials for
>> TLS.  The latest draft can be found here:
>> https://tools.ietf.org/html/draft-ietf-tls-subcerts-09.  There have been
>> 2 revisions since the last review.  Draft 8 contains changes that were not
>> committed in time for draft 7 and draft 9 contains revisions from the
>> previous WGLC.  Links to the Diffs between the draft 9 and draft 7 can be
>> found at the end of this message.   Please focus your review on the changes
>> between draft 7 and draft 9.  Please send your comments to the list by July
>> 13, 2020.
>>
>> Thanks,
>>
>> Sean and Joe
>>
>> [Inline Diff]
>> https://tools.ietf.org/rfcdiff?difftype=--hwdiff&url2=draft-ietf-tls-subcerts-09.txt&url1=draft-ietf-tls-subcerts-07.txt
>> [Side-by-side Diff]
>> https://tools.ietf.org/rfcdiff?url2=draft-ietf-tls-subcerts-09.txt&url1=draft-ietf-tls-subcerts-07.txt
>>
>> _______________________________________________
>> TLS mailing list
>> TLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/tls
>>
>