Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

"Salz, Rich" <rsalz@akamai.com> Fri, 22 November 2019 00:35 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C64C1200B7 for <tls@ietfa.amsl.com>; Thu, 21 Nov 2019 16:35:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F0eI6SIeWr3l for <tls@ietfa.amsl.com>; Thu, 21 Nov 2019 16:35:02 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 065CF12082C for <tls@ietf.org>; Thu, 21 Nov 2019 16:34:37 -0800 (PST)
Received: from pps.filterd (m0122332.ppops.net [127.0.0.1]) by mx0a-00190b01.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id xAM0XKLF004745; Fri, 22 Nov 2019 00:34:36 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=9UqUvzoLV6nnu0Q2uPn62PspK+7AR7wBXjRxIFBivVE=; b=Y+vuarrNo7KXGOn536+2IQi/Hb4sniPI7WhmAyU+iYmlRnFGc6JiBdFdcAeJfJP6vz9d /mjgk0yWGS38qMh+jcMmnSP0su2WY1pm1iq+uYE4LGgVz/ffEIansMxInjXA6FWpoci6 eM66IFQiXBV2qwcfzMUK7iOJOhGVOhDTDFnyR3585kRnibMUMenYUAyfpbIT0Kwxz0lB iUx5ji5lIDSuYqFcy3BKAP4W7qpJlQjYJvb8lH11gnoGCl0s+owMk7zaSmvRZ7f2X5C2 97PYUSUKlxMZTEDl+d3V9Gl0KqJEoyhB8K2Bs9q2238NYTH2cC+Crcuaymbc1NAv7CG4 4Q==
Received: from prod-mail-ppoint3 (prod-mail-ppoint3.akamai.com [96.6.114.86] (may be forged)) by mx0a-00190b01.pphosted.com with ESMTP id 2we3j2res5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 22 Nov 2019 00:34:36 +0000
Received: from pps.filterd (prod-mail-ppoint3.akamai.com [127.0.0.1]) by prod-mail-ppoint3.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xAM0Vd20024891; Thu, 21 Nov 2019 19:34:35 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.31]) by prod-mail-ppoint3.akamai.com with ESMTP id 2wadb30gs3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Thu, 21 Nov 2019 19:34:34 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb3.msg.corp.akamai.com (172.27.123.103) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 21 Nov 2019 19:34:14 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Thu, 21 Nov 2019 19:34:14 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Sean Turner <sean@sn3rd.com>, TLS List <tls@ietf.org>
Thread-Topic: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate
Thread-Index: AQHVoLzgvZaYJ6m0nUODILOyuUxBJaeXMZMA
Date: Fri, 22 Nov 2019 00:34:13 +0000
Message-ID: <315F2BCF-11E0-4FBD-8420-865F29A66AD1@akamai.com>
References: <508EEDF7-73D2-4BE6-AFBA-710E5A5AB41F@sn3rd.com>
In-Reply-To: <508EEDF7-73D2-4BE6-AFBA-710E5A5AB41F@sn3rd.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1f.0.191110
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.216.139]
Content-Type: text/plain; charset="utf-8"
Content-ID: <5DE5BBD093BE3A4DAE1ACE30863B7BD4@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-21_07:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=790 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1911140001 definitions=main-1911220001
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-21_07:2019-11-21,2019-11-21 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 impostorscore=0 bulkscore=0 mlxlogscore=755 spamscore=0 clxscore=1015 suspectscore=0 phishscore=0 adultscore=0 mlxscore=0 lowpriorityscore=0 malwarescore=0 priorityscore=1501 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911220001
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ywCjSI0YWLmgrAhftpipww3FwTU>
Subject: Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Nov 2019 00:35:05 -0000

>    This is the working group last call for the "Deprecating MD5 and SHA-1 signature hashes in TLS 1.2" draft available https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/.  Please review the document and send your comments to the list by 2359 UTC on 13 December 2019.
  
I just re-read this.  Looks good. Perhaps a sentence of rationale in section 2 and 3 explaining why its SHOULD NOT and not MUST NOT would help explain things to some?