Re: [Uta] [Last-Call] Secdir telechat review of draft-ietf-uta-rfc7525bis-09

Peter Gutmann <pgut001@cs.auckland.ac.nz> Thu, 14 July 2022 03:08 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DD21C16ECE5 for <uta@ietfa.amsl.com>; Wed, 13 Jul 2022 20:08:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jmSVbUqS24tc for <uta@ietfa.amsl.com>; Wed, 13 Jul 2022 20:08:15 -0700 (PDT)
Received: from au-smtp-delivery-117.mimecast.com (au-smtp-delivery-117.mimecast.com [103.96.21.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D7B39C16ECC4 for <uta@ietf.org>; Wed, 13 Jul 2022 20:08:14 -0700 (PDT)
Received: from AUS01-ME3-obe.outbound.protection.outlook.com (mail-me3aus01lp2236.outbound.protection.outlook.com [104.47.71.236]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id au-mta-40-zZTFSIkbME-oic4Fr9Sbwg-2; Thu, 14 Jul 2022 13:07:06 +1000
X-MC-Unique: zZTFSIkbME-oic4Fr9Sbwg-2
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com (2603:10c6:10:10b::10) by MEXPR01MB1175.ausprd01.prod.outlook.com (2603:10c6:200:30::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.21; Thu, 14 Jul 2022 03:07:04 +0000
Received: from SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::64d6:2532:7a7e:561d]) by SY4PR01MB6251.ausprd01.prod.outlook.com ([fe80::64d6:2532:7a7e:561d%6]) with mapi id 15.20.5417.026; Thu, 14 Jul 2022 03:07:04 +0000
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Rob Sayre <sayrer@gmail.com>, Peter Saint-Andre <stpeter@stpeter.im>
CC: Benjamin Kaduk <kaduk@mit.edu>, "secdir@ietf.org" <secdir@ietf.org>, "draft-ietf-uta-rfc7525bis.all@ietf.org" <draft-ietf-uta-rfc7525bis.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "uta@ietf.org" <uta@ietf.org>
Thread-Topic: [Uta] [Last-Call] Secdir telechat review of draft-ietf-uta-rfc7525bis-09
Thread-Index: AQHYlunzWeaHHDs2rkWl2o6nLvuO+q18rMkAgACCzMA=
Date: Thu, 14 Jul 2022 03:07:04 +0000
Message-ID: <SY4PR01MB625186377F07976EFEF775F7EE889@SY4PR01MB6251.ausprd01.prod.outlook.com>
References: <165766858084.5251.12485129434316295805@ietfa.amsl.com> <b24e2934-200f-4f80-5261-aa2a977da39b@stpeter.im> <CAChr6Syq+uOTJsvqWuSustq_HdTaXCtDepyCuRWx+jGoEB06Fw@mail.gmail.com> <CAChr6SzkAmbjGK4XOwPkSwssLoG4NW1yG-6b2aFdFr43yF2zwQ@mail.gmail.com>
In-Reply-To: <CAChr6SzkAmbjGK4XOwPkSwssLoG4NW1yG-6b2aFdFr43yF2zwQ@mail.gmail.com>
Accept-Language: en-NZ, en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 98b1eef0-9d01-44c7-6f1d-08da6545edf1
x-ms-traffictypediagnostic: MEXPR01MB1175:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0
x-microsoft-antispam-message-info: ueeHjXl1YFCTdb560SClY3t/55PD5zbKh5uiWVVkgIuYvQg5Ho5+dxuD3pJzmy22kXCZgG7q/7XYVcAhiqvi/ATAHCRGsUtVjnYRtS8B8XgrOfreFNF8x8DvVPTrTFkAFttTqUK3fbAcIOMPHgvoipF+wZHIqXiKsuoCNWBoz7Q16UqmMQbxb8auMyCgaZyRt8efm2doAm4IYzsKvXlIGZJt7mQNI+c+ksO9jNSINAt5UsgaFXHy4bW36jTDJlcg2Gpmx1aF+y7gb5PDu5Rj3+ncCCSwX9y7p1UcxnGPgD+yESf30Zu8TfSXuW/+YyWInn24NSedupPKpYhFNLhrsnUSZpFbC4dYv1qKyT6h6flOOYsmSciYmx3N9BnkOewzC1bHA8+72du2wvRjVnLftGSa+o0KeDkuj8lzOCIBM8DtDs2zmTYtVhROZIkR0L1j5r9QSgsT/TwPiTnHOornWA4Mpz/RrNKWOUcuLPBgb+kzbcy4z04t7h1/LQngZ0bzBLTOEX4A3OR677Nkla30c6Dhystl7feWz08aDz5uDGGP4X0zhrgP92eibLdCIJyXKlQoCLh6nWfzBEkym8ku0v8OVDAHtAReyRahcVbigSToSQfX8yc8as00cM5VsfxiiCWDSgNH7BOJadflwFI6YV2p0d18JT0+lZcdgEyxW57UU7a7qCY+kd8fZayUe7eQA/8wzfvXbwwAiqzk0JOVoswUQOtQGz6M6hSWirPamYTR3T8GDCkkGbk5uI1PjZAwPS9EtQZktDpzPYh5GRFH1QSxfCu+zl2lZILkMFJHv634pFbLCvIC75NMs+b9vTYD
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SY4PR01MB6251.ausprd01.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(346002)(376002)(39860400002)(136003)(366004)(396003)(9686003)(76116006)(4744005)(26005)(8936002)(5660300002)(2906002)(41300700001)(478600001)(83380400001)(6506007)(33656002)(110136005)(7696005)(54906003)(186003)(786003)(71200400001)(316002)(55016003)(122000001)(38100700002)(38070700005)(52536014)(86362001)(64756008)(66476007)(8676002)(66556008)(66446008)(4326008)(66946007); DIR:OUT; SFP:1101
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: w4UQ5qqJy+Tn53oTHjZqxAURph6OPcc/X5x6RwNQKFLeLg5TwTWZjWUMy0qh91nZM0dKkcoq+vskXnZuu7XJOi4qj+8nO7zM+QDT/1LGSC1ioD+TuOIb0mjfYoSIddWNFYiuV/vcDwN7GY4IKckDudunUcrKXia725J1aLQlVZLEzEMc9V9LNJzmEaxWgzob3/qV6PYWRcI6Qv5C/KmZ1WxKMEFVRHyhKlIWXR3IyD1H01rrwFEAFPmv5RI/UUOMohyLVIdrkZ6ug5H0/ylaHBID/RI5dsrkENVtzgeEqWbW6fxVaCVcFJ7sOp3Gf0FbyiC8sa0DY4EJ+acwMSnpR3k2gYIQNHSEwZNPpmd316VN/FiXz6Wii4YQXr9J/noQhu3GnKYnqju/dzqTF4H319dzk38Mg3AERQHd2YNgsjYp7sqqLdM+lTllZVr5XKIuYbABHciangnq2JXnwOa78Gl0kE96utU4DTaji8kUvk00qXV8N/6syF/YVfUR59UanciYvDTHh7dnUWxiUA1H5Lp83HB6iQOoqie8/7od2l7ik+VDOlKhyH14B4AxuIZdFDGwU2DjT3duJdEbFx8e/9PkTDTi+YfNGMqbh01A1TCjGNb09qRI2kqKD3QWTD4TcxtQScxH2k2V22BIBahS3DFj7ASav/HIZc35q9SOgV/BEhXtpgbgrbKH+1piuUsbknKtLcMDcYCEtqPPptF4UqUBunsTODUofnaPObRxt0Co3KOjgGBuKT50F4vRNcv7FlBGRl96WSNWxLW8aQfzL7An71HbuR/uWNKnEcnWlxpL7vlm/4ubJPVUU8lMX/FCAFTvnqH7eCP2+6St0Bp/eWSzU2WNbq+d7m7Hi32Uf+qBicZGUP8KO3V5+4alqMiBLd4+txAQ6PxtIJfXLH5K0/phtHGjSoashTeyEWF7SedIYq1a3Z6ZpE5ndzJ4I7LWX7MnqgGXX/8RdILecCXpAowVBVT7b5qZvsplROLGT1IvzijpOpcl/pQ1Azn8PWq9gDHH2FugRyMPLykTm61dlds2ivLuzMxdVepvuKrMOXudOGDMSQl5fDiW2MPqjP++SL0A11YiJ8lz43tpwvQt5nRTO8kzqf9Wx2i9La643Rg8v3H5t7uAzdqOKXCCphfx1gh/lBxQEORZ7UgLQWe3epbNavWX2AvA8USbufYlJHefqSXTcUWeDdwNpN9ELIjM/34h8TRJ3XC1+7LekPgumqoE3s5KyOoA4mHn+ehHTpMIT5BijMWYJ83NmaS22UTrx169jtKOUWkorUgcxpk/s3p/6hgEP6RYdurS1c5OMS4XPItIo89ePQJM1wLwo61HYRlREv4DrnOb+5swfDstfX7ix7bFGHToSzkuZ0v3HmsAFZCXJhkgO48QRSzCzNQI+WDk6s+l6Ej80iAT0625sTZEb0QLzKr08l65aQbpoltMET/jaIW9JwX2DKf2KkInQJrvCWiAO0Bl19r7IQ9IudI+/JwyzGQlX9hdsZ6Gd76cYi2VopYYYqFqd1fiZdncMkChsYUpkXOq57SrHlUkLJnWqn2mDROFnn+mhGlqcaY0LKWnA3KaKE/ObQMrMcdKrnJHFa406HGs6EoPVf0FFw==
MIME-Version: 1.0
X-OriginatorOrg: cs.auckland.ac.nz
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SY4PR01MB6251.ausprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 98b1eef0-9d01-44c7-6f1d-08da6545edf1
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Jul 2022 03:07:04.5361 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: OqYbeOGTQRmdN6tWjeuUpxKHMEpCDZKpF+UJ7f786xuRJ/cvKq0HeOjxTif+tH8VrR93YZVJ4jO7aCzpRQWfhUvLVRTrjB2ISmbhB7fH97c=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MEXPR01MB1175
Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CAU17A13 smtp.mailfrom=pgut001@cs.auckland.ac.nz
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: cs.auckland.ac.nz
Content-Language: en-NZ
Content-Type: text/plain; charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/XFNVxZ4mlkWvAgCiU_R_G31JVNU>
Subject: Re: [Uta] [Last-Call] Secdir telechat review of draft-ietf-uta-rfc7525bis-09
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Jul 2022 03:08:16 -0000

Rob Sayre <sayrer@gmail.com> writes:

>Also, in the realm of opinion rather than correctness: mandating TLS 1.2
>support is misguided. Every TLS implementation maintains divided codebases
>for 1.2 vs 1.3.

On desktop PCs and servers perhaps, but in embedded the very fact that you
need two sets of codebases means many systems will stay with 1.2, possibly
forever when everything around them is also staying with 1.2.

>No one reads the TLS 1.2 code very closely these days, in my experience, so
>the BCP would be mandating support for something people don't really work on
>anymore.

Unless the only codebase you've got is 1.2.  However in the same embedded
systems you typically do it once, do it right, and skip the neverending flow
of bells and whistles that keep appearing, so there's no need to constantly
fiddle with the code as for PC/server use.

Peter.