Security concerns around co-locating TLS and non-secure on same port (WGLC: draft-ietf-tsvwg-iana-ports-08)

Magnus Westerlund <magnus.westerlund@ericsson.com> Mon, 08 November 2010 03:14 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: tsvwg@core3.amsl.com
Delivered-To: tsvwg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BCB373A695E; Sun, 7 Nov 2010 19:14:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.643
X-Spam-Level:
X-Spam-Status: No, score=-106.643 tagged_above=-999 required=5 tests=[AWL=-0.044, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rk21zc48anV8; Sun, 7 Nov 2010 19:14:25 -0800 (PST)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by core3.amsl.com (Postfix) with ESMTP id 684AE3A6956; Sun, 7 Nov 2010 19:14:25 -0800 (PST)
X-AuditID: c1b4fb3d-b7b28ae00000135b-eb-4cd76b24a2d4
Received: from esealmw128.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id 45.2A.04955.42B67DC4; Mon, 8 Nov 2010 04:14:44 +0100 (CET)
Received: from esealmw126.eemea.ericsson.se ([153.88.254.170]) by esealmw128.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Mon, 8 Nov 2010 04:14:39 +0100
Received: from [153.88.17.45] ([153.88.17.45]) by esealmw126.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Mon, 8 Nov 2010 04:14:38 +0100
Message-ID: <4CD76B1B.5030308@ericsson.com>
Date: Mon, 08 Nov 2010 11:14:35 +0800
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; sv-SE; rv:1.9.2.12) Gecko/20101027 Thunderbird/3.1.6
MIME-Version: 1.0
To: tls@ietf.org
Subject: Security concerns around co-locating TLS and non-secure on same port (WGLC: draft-ietf-tsvwg-iana-ports-08)
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-OriginalArrivalTime: 08 Nov 2010 03:14:38.0909 (UTC) FILETIME=[141256D0:01CB7EF3]
X-Brightmail-Tracker: AAAAAA==
Cc: tsvwg <tsvwg@ietf.org>, Paul Hoffman <paul.hoffman@vpnc.org>
X-BeenThere: tsvwg@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Transport Area Working Group <tsvwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tsvwg>
List-Post: <mailto:tsvwg@ietf.org>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Nov 2010 03:14:26 -0000

TLS experts,

There currently a WG last call ongoing in on the IANA Procedures for the
Management of the Service Name and Transport Protocol Port Number
Registry update document.
https://datatracker.ietf.org/doc/draft-ietf-tsvwg-iana-ports/

A WG last call comment on this document was raised by Paul Hoffman:
http://www.ietf.org/mail-archive/web/tsvwg/current/msg10305.html

My summary of that comment is that STARTTLS for SMTP (RFC 3207) has
shown to have some security issues, be complexer to implement than using
two ports and thus less popular. Thus the registration rules should be
less restrictive in assigning an additional port for TLS version of
services/applications/protocols.

The downside of less restrictive port allocation rules is that the port
space will be consumed at a higher rate. Thus there is need to determine
what is the most suitable trade-off here.

Clearly if the security issues are serious when one multiplex TLS and
non-secured version of the protocol on the same port we must allow such
port allocations. However if the issues are minor and the primarily
issue is implementation complexity then saving the limited port space is
probably more important.

Your input into these questions would be very appreciated.

Thanks

Magnus Westerlund

----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB                | Phone  +46 10 7148287
Färögatan 6                | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------