[Uta] Fwd: Last Call: <draft-ietf-tls-external-psk-guidance-03.txt> (Guidance for External PSK Usage in TLS) to Informational RFC

Sean Turner <sean@sn3rd.com> Tue, 16 November 2021 14:35 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 77F9C3A0141 for <uta@ietfa.amsl.com>; Tue, 16 Nov 2021 06:35:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hi5bWiblTDNp for <uta@ietfa.amsl.com>; Tue, 16 Nov 2021 06:35:16 -0800 (PST)
Received: from mail-qk1-x72d.google.com (mail-qk1-x72d.google.com [IPv6:2607:f8b0:4864:20::72d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2C39F3A0147 for <uta@ietf.org>; Tue, 16 Nov 2021 06:35:16 -0800 (PST)
Received: by mail-qk1-x72d.google.com with SMTP id 193so20670366qkh.10 for <uta@ietf.org>; Tue, 16 Nov 2021 06:35:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=from:mime-version:subject:message-id:references:to:date; bh=uECjOVGA1g7In5mKHJvcsuOu7qWLxSoKktKsEXwoDJ0=; b=VpINAIEpMiuCzVWc/1Kc96ChvNckDG/ZFWsbjkmxUNvfN5yg+5jizWyEYz871dcz3A LMbyHGPVpVem2F06QxAwL1o2hlQiYHxfqoY20WFxtFYv59D8WY+e5JAxI79MGWD1CvEG wH2PeP4vi0O2D7imzOCXQ6ctO5e98BLy5VcNk=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:mime-version:subject:message-id:references :to:date; bh=uECjOVGA1g7In5mKHJvcsuOu7qWLxSoKktKsEXwoDJ0=; b=dbbHxuOgVhcxUptjCH+jA3aiXpAOBSTfRugX1mfU5W52qIM41Sb8udnFTF7loFxovj M7NSQCEqjyNRc602cend2Zcycv3nSVOoeDZP8rVY4Cb7bPcBPzzJKAjKnFyafiQtldO0 geX9XjLwTSYhLrXX++77d7qW4n1w2bezE2cqXlZPjrBoDWtmTTIy9iMgvrxWyFE4yT/t gMKAXJ75GDexep3FeqBkukJWTSnqVGqVqNJ7QUTyMVchtybDI7CtpDUOZf44qtusV/Xn z6kwytVM3OWtno/AjkSfO/vs7GuyT+0bky7G3VnMz3OxBUd6MkEmR6u7lWNo0Vj1bdkW 7pNg==
X-Gm-Message-State: AOAM5325vOg90QHDw87sDP/Sus5IYRqtCvky5fuoNqinaSCcRzjkkQfd 7Bb4sY9522uHXUHR3XOzQBPIAww9pBb9mQ==
X-Google-Smtp-Source: ABdhPJyWaRPFTeX6rv6BMinn1W8bVLhejoxBWRhe/h68DgMcXb6jJJoacnoutUWyvHYp8gTlgesKQg==
X-Received: by 2002:a05:620a:298e:: with SMTP id r14mr6422116qkp.509.1637073313575; Tue, 16 Nov 2021 06:35:13 -0800 (PST)
Received: from smtpclient.apple (pool-71-178-177-131.washdc.fios.verizon.net. [71.178.177.131]) by smtp.gmail.com with ESMTPSA id bs7sm3857870qkb.79.2021.11.16.06.35.12 for <uta@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 16 Nov 2021 06:35:12 -0800 (PST)
From: Sean Turner <sean@sn3rd.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_3C978920-CE97-44E8-AA6D-FB4D2A446E7F"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
Message-Id: <C8F2F42C-D186-4749-A757-92D6C8CEB809@sn3rd.com>
References: <163552419830.4698.11840592589716354497@ietfa.amsl.com>
To: UTA List <uta@ietf.org>
Date: Tue, 16 Nov 2021 09:35:12 -0500
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/EbjBe5lQSTfKM8Pqr0ItpBFfaFo>
Subject: [Uta] Fwd: Last Call: <draft-ietf-tls-external-psk-guidance-03.txt> (Guidance for External PSK Usage in TLS) to Informational RFC
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Nov 2021 14:35:22 -0000

Apologies, I maybe should have sent this earlier, but Rich Salz’s secdir reminded me to forward this IETF LC due to the application-focused nature of this I-D.

Cheers,
spt

> Begin forwarded message:
> 
> From: The IESG <iesg-secretary@ietf.org>
> Subject: Last Call: <draft-ietf-tls-external-psk-guidance-03.txt> (Guidance for External PSK Usage in TLS) to Informational RFC
> Date: October 29, 2021 at 12:16:38 EDT
> To: "IETF-Announce" <ietf-announce@ietf.org>
> Cc: draft-ietf-tls-external-psk-guidance@ietf.org, kaduk@mit.edu, sean@sn3rd.com, tls-chairs@ietf.org, tls@ietf.org
> Reply-To: last-call@ietf.org
> 
> 
> The IESG has received a request from the Transport Layer Security WG (tls) to
> consider the following document: - 'Guidance for External PSK Usage in TLS'
>  <draft-ietf-tls-external-psk-guidance-03.txt> as Informational RFC
> 
> The IESG plans to make a decision in the next few weeks, and solicits final
> comments on this action. Please send substantive comments to the
> last-call@ietf.org mailing lists by 2021-11-19. Exceptionally, comments may
> be sent to iesg@ietf.org instead. In either case, please retain the beginning
> of the Subject line to allow automated sorting.
> 
> Abstract
> 
> 
>   This document provides usage guidance for external Pre-Shared Keys
>   (PSKs) in Transport Layer Security (TLS) 1.3 as defined in RFC 8446.
>   This document lists TLS security properties provided by PSKs under
>   certain assumptions, and then demonstrates how violations of these
>   assumptions lead to attacks.  This document discusses PSK use cases
>   and provisioning processes.  This document provides advice for
>   applications to help meet these assumptions.  This document also
>   lists the privacy and security properties that are not provided by
>   TLS 1.3 when external PSKs are used.
> 
> 
> 
> 
> The file can be obtained via
> https://datatracker.ietf.org/doc/draft-ietf-tls-external-psk-guidance/
> 
> 
> 
> No IPR declarations have been submitted directly on this I-D.
> 
> 
> 
> 
>