Re: [Uta] FW: New Version Notification for draft-ietf-uta-rfc7525bis-05.txt

"Salz, Rich" <rsalz@akamai.com> Thu, 03 February 2022 19:47 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 83DD53A17BD for <uta@ietfa.amsl.com>; Thu, 3 Feb 2022 11:47:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.674
X-Spam-Level:
X-Spam-Status: No, score=-2.674 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.576, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JVnYzhIdJysZ for <uta@ietfa.amsl.com>; Thu, 3 Feb 2022 11:47:38 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14A1A3A17B9 for <uta@ietf.org>; Thu, 3 Feb 2022 11:47:37 -0800 (PST)
Received: from pps.filterd (m0122330.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.1.2/8.16.1.2) with ESMTP id 213HLjEW018207; Thu, 3 Feb 2022 19:47:34 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=6Iaxq71Z/hdGtlfqF+mhuZpNzl971prWy44B/+l+j3w=; b=eJxkUbku/xPbsEfsTv7E0xP2R0Zrxs0nWtPY2fGYNtWd3Bj/GKZgfxaw7hr6cbgnLVIH lrzrVdFErdlSRXMOZrXOmpkmPgI2kodRpFMoUYn3uK94aL/yxye0Pz/sbTjZOE86XYeB WiGTG3XI/jNrEtWEBRXSt6Zp2lFyC+1Ikf4A0DCQZFSFsSgnI0OgwP5GKYx8AfdXOr0x 889cPWTf/X6RKMgIZpzLQhW9hlKXB7p22evFlBCp9xu2Iz50TGc7rk3z/RpXEaZdSy8a RHDu25sXY6vNCNHf8eo9Qzo2nTaD5cyWo/72UkSJqFHSHdFrmq9/y1oe6eOc95YKdvlu 1w==
Received: from prod-mail-ppoint1 (prod-mail-ppoint1.akamai.com [184.51.33.18] (may be forged)) by mx0b-00190b01.pphosted.com (PPS) with ESMTPS id 3e0597x8ec-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 03 Feb 2022 19:47:34 +0000
Received: from pps.filterd (prod-mail-ppoint1.akamai.com [127.0.0.1]) by prod-mail-ppoint1.akamai.com (8.16.1.2/8.16.1.2) with SMTP id 213JKKLW003425; Thu, 3 Feb 2022 14:47:33 -0500
Received: from email.msg.corp.akamai.com ([172.27.91.21]) by prod-mail-ppoint1.akamai.com with ESMTP id 3e0gmardub-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 03 Feb 2022 14:47:33 -0500
Received: from USMA1EX-DAG1MB2.msg.corp.akamai.com (172.27.123.102) by usma1ex-dag4mb2.msg.corp.akamai.com (172.27.91.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.2.922.19; Thu, 3 Feb 2022 14:47:33 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com (172.27.123.101) by usma1ex-dag1mb2.msg.corp.akamai.com (172.27.123.102) with Microsoft SMTP Server (TLS) id 15.0.1497.28; Thu, 3 Feb 2022 14:47:33 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com ([172.27.123.101]) by usma1ex-dag1mb1.msg.corp.akamai.com ([172.27.123.101]) with mapi id 15.00.1497.028; Thu, 3 Feb 2022 14:47:33 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Yaron Sheffer <yaronf.ietf@gmail.com>, "uta@ietf.org" <uta@ietf.org>
Thread-Topic: [Uta] FW: New Version Notification for draft-ietf-uta-rfc7525bis-05.txt
Thread-Index: AQHYGTbiwY6xmhNazk2zDiBX0k7GmA==
Date: Thu, 03 Feb 2022 19:47:32 +0000
Message-ID: <C715D231-02EF-4062-AE7B-328B62532584@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.57.22011101
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.27.164.43]
Content-Type: text/plain; charset="utf-8"
Content-ID: <A4C281012B2AF0429836D23F1B62425B@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.425, 18.0.816 definitions=2022-02-03_06:2022-02-03, 2022-02-03 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 spamscore=0 bulkscore=0 suspectscore=0 adultscore=0 phishscore=0 malwarescore=0 mlxlogscore=804 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2201110000 definitions=main-2202030116
X-Proofpoint-GUID: _x7EM_z3Nsx96IWfR4JlsrdEWd3trF9F
X-Proofpoint-ORIG-GUID: _x7EM_z3Nsx96IWfR4JlsrdEWd3trF9F
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.816,Hydra:6.0.425,FMLib:17.11.62.513 definitions=2022-02-03_06,2022-02-03_01,2021-12-02_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 mlxscore=0 mlxlogscore=787 phishscore=0 suspectscore=0 priorityscore=1501 adultscore=0 impostorscore=0 malwarescore=0 spamscore=0 lowpriorityscore=0 clxscore=1015 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2201110000 definitions=main-2202030118
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/0xQw5vqd-2jvF07_ErBWfhQQwD0>
Subject: Re: [Uta] FW: New Version Notification for draft-ietf-uta-rfc7525bis-05.txt
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Feb 2022 19:47:43 -0000

I re-read the document.  It's very nice.  A few nits, I think all are editorial and can be fixed later. I support moving this doc forward.


I note that you say "use encrypted client hello when it's ready"  Do you want to make the same recommendation for DTLS 1.3?

Do you want to say anything about EdDSA and the kerfuffle going on in cfrg@ mailing list right now?  No is a good, and probably sane, answer.

4.3 needs a tweak to get {RFC8446, Section 9.1} right.

4.4, do you want to say why 2**24.5 is used for both?  Simpler and therefore easier to get right?

5. Should the applicability statement include things like QUIC and NTS?

5. Rather than refer to 2026, I think you should refer to the BCP whatever it is.

6.1 Should the references to RFC6125 be changed to the draft 6125bis?