Re: [Uta] Proposed list of deliverables

"Orit Levin (LCA)" <oritl@microsoft.com> Mon, 03 February 2014 18:42 UTC

Return-Path: <oritl@microsoft.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F12AA1A01E1 for <uta@ietfa.amsl.com>; Mon, 3 Feb 2014 10:42:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.602
X-Spam-Level:
X-Spam-Status: No, score=-2.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KQ32iwtFcJVd for <uta@ietfa.amsl.com>; Mon, 3 Feb 2014 10:42:00 -0800 (PST)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2lp0204.outbound.protection.outlook.com [207.46.163.204]) by ietfa.amsl.com (Postfix) with ESMTP id CC7B11A01CE for <uta@ietf.org>; Mon, 3 Feb 2014 10:41:59 -0800 (PST)
Received: from BL2PR03MB290.namprd03.prod.outlook.com (10.141.68.19) by BL2PR03MB291.namprd03.prod.outlook.com (10.141.68.25) with Microsoft SMTP Server (TLS) id 15.0.873.10; Mon, 3 Feb 2014 18:41:52 +0000
Received: from BL2PR03MB290.namprd03.prod.outlook.com ([10.141.68.19]) by BL2PR03MB290.namprd03.prod.outlook.com ([10.141.68.19]) with mapi id 15.00.0873.009; Mon, 3 Feb 2014 18:41:52 +0000
From: "Orit Levin (LCA)" <oritl@microsoft.com>
To: Peter Saint-Andre <stpeter@stpeter.im>, "uta@ietf.org" <uta@ietf.org>
Thread-Topic: [Uta] Proposed list of deliverables
Thread-Index: Ac8UDfYmUjL7spWFRWi+szgpg2cFIgM+kacAAABVyMA=
Date: Mon, 03 Feb 2014 18:41:51 +0000
Message-ID: <0b0789ddea34437fbf26e9b66cb9dcaf@BL2PR03MB290.namprd03.prod.outlook.com>
References: <0bc674da169f4772b0fb2173ed679115@BY2PR03MB300.namprd03.prod.outlook.com> <52EFD694.5010405@stpeter.im>
In-Reply-To: <52EFD694.5010405@stpeter.im>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [98.247.123.117]
x-forefront-prvs: 01110342A5
x-forefront-antispam-report: SFV:NSPM; SFS:(10009001)(6009001)(199002)(189002)(24454002)(51704005)(479174003)(377454003)(13464003)(94316002)(15975445006)(56816005)(90146001)(81686001)(93136001)(80976001)(87266001)(47736001)(49866001)(2656002)(76786001)(19580395003)(76796001)(76576001)(83322001)(19580405001)(86362001)(92566001)(81542001)(94946001)(85852003)(93516002)(81816001)(81342001)(83072002)(51856001)(85306002)(33646001)(66066001)(69226001)(65816001)(63696002)(80022001)(79102001)(77982001)(59766001)(74706001)(74316001)(46102001)(74366001)(47446002)(74502001)(74662001)(74876001)(87936001)(47976001)(50986001)(4396001)(56776001)(54356001)(53806001)(76482001)(54316002)(31966008)(24736002); DIR:OUT; SFP:1101; SCL:1; SRVR:BL2PR03MB291; H:BL2PR03MB290.namprd03.prod.outlook.com; CLIP:98.247.123.117; FPR:AA4AC176.AC34E192.FDD1BF27.40695A91.20316; InfoNoRecordsA:1; MX:1; LANG:en;
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
Cc: Pete Resnick <presnick@qti.qualcomm.com>, Barry Leiba <barryleiba@computer.org>
Subject: Re: [Uta] Proposed list of deliverables
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Feb 2014 18:42:02 -0000

Peter,
This fits well with the spirit of the proposed deliverables (plus a few notes inline).
Orit.

> -----Original Message-----
> From: Uta [mailto:uta-bounces@ietf.org] On Behalf Of Peter Saint-Andre
> Sent: Monday, February 03, 2014 9:49 AM
> To: Orit Levin (LCA); uta@ietf.org
> Cc: Pete Resnick; Barry Leiba
> Subject: Re: [Uta] Proposed list of deliverables
> 
> On 1/17/14, 11:24 PM, Orit Levin (LCA) wrote:
> > Below is the list of deliverables for your consideration:
> >
> > 1. A threat analysis document containing a collection of known
> > security breaches to application protocols due to poor use of TLS
> > (Likely an Informational RFC)
> 
> I think this would be something like an expanded version of Section 2
> from draft-sheffer-tls-bcp.
> 
Yes.

> > 2. Applications' independent document recommending best existing and
> > future practices for using TLS (Likely a BCP or a Proposed Standard
> > RFC)
> 
> I think draft-sheffer-tls-bcp is a good starting point for this deliverable.
> 

More specifically, section 4 of this draft "enriched" with the recent discussion points and recommendations from the list.

> > 3. A set of documents, each describing best existing and future
> > practices for using TLS with a specific application protocol, i.e.,
> > SMTP, POP, IMAP, XMPP, HTTP 1.1, etc. (Case-by-case likely a BCP or a
> > Proposed Standard RFC)
> 
> I think we have some starting point documents toward documents about
> SMTP, POP/IMAP, and XMPP. It's not clear to me what we have for HTTP.

A question to explore would be how HTTP considerations differ from the generic considerations in #2.

> 
> > 4. A document discussing (and potentially defining) how to apply the
> > opportunistic encryption approach (preliminary outlined in
> > draft-farrelll-mpls-opportunistic-encrypt-00.txt) to TLS. (Category
> > TBD)
> 
> Personally I'm agnostic about the need for this one.

Broader discussion and agreement is needed before we know how to scope this in UTA.


> 
> Peter
> 
> --
> Peter Saint-Andre
> https://stpeter.im/
> _______________________________________________
> Uta mailing list
> Uta@ietf.org
> https://www.ietf.org/mailman/listinfo/uta