Re: [TLS] Hybrid key exchange in TLS 1.3 and variable-length secrets

Benjamin Kaduk <bkaduk@akamai.com> Sun, 11 October 2020 18:00 UTC

Return-Path: <bkaduk@akamai.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B20E3A0F11 for <tls@ietfa.amsl.com>; Sun, 11 Oct 2020 11:00:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.299
X-Spam-Level:
X-Spam-Status: No, score=-3.299 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 83kt6kfVnwAW for <tls@ietfa.amsl.com>; Sun, 11 Oct 2020 11:00:30 -0700 (PDT)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8F8B3A0F10 for <tls@ietf.org>; Sun, 11 Oct 2020 11:00:29 -0700 (PDT)
Received: from pps.filterd (m0050102.ppops.net [127.0.0.1]) by m0050102.ppops.net-00190b01. (8.16.0.42/8.16.0.42) with SMTP id 09BHuv5O009943; Sun, 11 Oct 2020 19:00:27 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=date : from : to : cc : subject : message-id : references : mime-version : content-type : in-reply-to; s=jan2016.eng; bh=PG1CZXDyiZ+POlPv60UtRag5e4QAEMpissXqwiFE+E8=; b=jYachONy1fF+Py1QB1aIptOzw3WaGS4WlpwX6detMlaHO/33GshNXeJCJM3h8DQp18cv MCuS6Ax7AOR1p84a/QfzFmTtCfNV+X2U9znU4rYtD/OpeD9AFN+Flgq6IT0OWRNVCR05 ZSAIbuxkET6rjHjp+3ht9MKz/0Li8ZYitCsFwaYrGs3/b8mJdrJ7NHk9Kk9ISlfHNvG7 hRSqFjJjH9st+FCWPKfQE8BCbPlygBfxZJocjxi8G2Aw8T4efaR3d4koukusfy9AVC8G TimNjUIweHaZFtdFa6e0/oscWEF/Vj3lUHMFxOhSczfI2/m4pobv06jexLFx9is3aWm3 VQ==
Received: from prod-mail-ppoint6 (prod-mail-ppoint6.akamai.com [184.51.33.61] (may be forged)) by m0050102.ppops.net-00190b01. with ESMTP id 343522uhcr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 11 Oct 2020 19:00:27 +0100
Received: from pps.filterd (prod-mail-ppoint6.akamai.com [127.0.0.1]) by prod-mail-ppoint6.akamai.com (8.16.0.42/8.16.0.42) with SMTP id 09BHo5xY028803; Sun, 11 Oct 2020 14:00:18 -0400
Received: from prod-mail-relay10.akamai.com ([172.27.118.251]) by prod-mail-ppoint6.akamai.com with ESMTP id 34389xjeun-1; Sun, 11 Oct 2020 14:00:18 -0400
Received: from akamai.com (sea-lp9yo.kendall.corp.akamai.com [172.19.16.134]) by prod-mail-relay10.akamai.com (Postfix) with ESMTP id 59DBC3D145; Sun, 11 Oct 2020 18:00:18 +0000 (GMT)
Date: Sun, 11 Oct 2020 11:00:17 -0700
From: Benjamin Kaduk <bkaduk@akamai.com>
To: Douglas Stebila <douglas@stebila.ca>
Cc: Nimrod Aviram <nimrod.aviram@gmail.com>, "<tls@ietf.org>" <tls@ietf.org>
Message-ID: <20201011180016.GB20623@akamai.com>
References: <CABiKAoSGpodvQAegOhDxKxvDWoUsZBZL2JFWbtyseH+19cj6VQ@mail.gmail.com> <CAFBh+SQmzEyoFZS70W3btSS41yr4H4+vMV24fBBwsQsi5G0pbA@mail.gmail.com> <CABiKAoRixi6pEZFJGMUt=k+wo8qvY3c_1QD=fZ18f+ghKNyxng@mail.gmail.com> <CABiKAoRAD4pRio9CFdfwEujQFHWi3SVVTbTLCh2wmmdxRux7ig@mail.gmail.com> <CAFBh+STCnhB0f1DSmvrxc+1HvTxpRfgKYSTSOzq_LQVaCaQVnw@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <CAFBh+STCnhB0f1DSmvrxc+1HvTxpRfgKYSTSOzq_LQVaCaQVnw@mail.gmail.com>
User-Agent: Mutt/1.9.4 (2018-02-28)
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.235, 18.0.687 definitions=2020-10-11_12:2020-10-09, 2020-10-11 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxlogscore=595 adultscore=0 bulkscore=0 phishscore=0 mlxscore=0 suspectscore=0 spamscore=0 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2010110168
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.235, 18.0.687 definitions=2020-10-11_12:2020-10-09, 2020-10-11 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 suspectscore=0 priorityscore=1501 malwarescore=0 bulkscore=0 impostorscore=0 clxscore=1011 lowpriorityscore=0 spamscore=0 mlxscore=0 mlxlogscore=523 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2010110169
X-Agari-Authentication-Results: mx.akamai.com; spf=${SPFResult} (sender IP is 184.51.33.61) smtp.mailfrom=bkaduk@akamai.com smtp.helo=prod-mail-ppoint6
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/yOpujEPz8GNhhUr7sNTSh1F4Q28>
Subject: Re: [TLS] Hybrid key exchange in TLS 1.3 and variable-length secrets
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 Oct 2020 18:00:32 -0000

Might as well publish a new revision of the I-D in the datatracker, too, since
the current one is approaching its expiry.

-Ben

On Fri, Sep 25, 2020 at 10:16:01AM -0400, Douglas Stebila wrote:
> Thanks!  I've merged it in.
> 
> On Fri, Sep 25, 2020 at 4:48 AM Nimrod Aviram <nimrod.aviram@gmail.com> wrote:
> >
> > Thanks!
> > The PR is here, happy to hear comments and corrections:
> > https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_dstebila_draft-2Dietf-2Dtls-2Dhybrid-2Ddesign_pull_1&d=DwICAg&c=96ZbZZcaMF4w0F4jpN6LZg&r=sssDLkeEEBWNIXmTsdpw8TZ3tAJx-Job4p1unc7rOhM&m=scN8KVeFpWVHjq0xefZ-MgaFkz3Dur3X0b6_ev41lZE&s=uEgApPwG25neG5tcewrPfJxk6KO-9aot8ZysgPeA-Bw&e= 
> >
> > best,
> > Nimrod
> >
> >
> > On Fri, 18 Sep 2020 at 12:04, Nimrod Aviram <nimrod.aviram@gmail.com> wrote:
> >>
> >> Sounds good to me.
> >> I'm happy to send a PR making these changes, but couldn't find the repository for the document.
> >> Could you please point me to it?