[TLS] I-D Action: draft-ietf-tls-session-hash-03.txt

internet-drafts@ietf.org Wed, 12 November 2014 09:00 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com []) by ietfa.amsl.com (Postfix) with ESMTP id 24CAD1A8AC3; Wed, 12 Nov 2014 01:00:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id 8Wn1JklnvOcw; Wed, 12 Nov 2014 01:00:00 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D29811A0451; Wed, 12 Nov 2014 01:00:00 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.7.2.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20141112090000.29696.26200.idtracker@ietfa.amsl.com>
Date: Wed, 12 Nov 2014 01:00:00 -0800
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/zPHURG5qwjhSbv-kmMw8tgB1El4
Cc: tls@ietf.org
Subject: [TLS] I-D Action: draft-ietf-tls-session-hash-03.txt
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Nov 2014 09:00:02 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Transport Layer Security Working Group of the IETF.

        Title           : Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension
        Authors         : Karthikeyan Bhargavan
                          Antoine Delignat-Lavaud
                          Alfredo Pironti
                          Adam Langley
                          Marsh Ray
	Filename        : draft-ietf-tls-session-hash-03.txt
	Pages           : 11
	Date            : 2014-11-12

   The Transport Layer Security (TLS) master secret is not
   cryptographically bound to important session parameters.
   Consequently, it is possible for an active attacker to set up two
   sessions, one with a client and another with a server, such that the
   master secrets on the two sessions are the same.  Thereafter, any
   mechanism that relies on the master secret for authentication,
   including session resumption, becomes vulnerable to a man-in-the-
   middle attack, where the attacker can simply forward messages back
   and forth between the client and server.  This specification defines
   a TLS extension that contextually binds the master secret to a log of
   the full handshake that computes it, thus preventing such attacks.

The IETF datatracker status page for this draft is:

There's also a htmlized version available at:

A diff from the previous version is available at:

Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at: