Re: [Uta] Adoption call for draft-sheffer-uta-rfc7525bis-00

Ralph Holz <ralph.holz@gmail.com> Mon, 27 April 2020 11:25 UTC

Return-Path: <ralph.holz@gmail.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34DAA3A08BE; Mon, 27 Apr 2020 04:25:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id asI8AcsLWco7; Mon, 27 Apr 2020 04:25:56 -0700 (PDT)
Received: from mail-ed1-x529.google.com (mail-ed1-x529.google.com [IPv6:2a00:1450:4864:20::529]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 55BA93A0890; Mon, 27 Apr 2020 04:25:56 -0700 (PDT)
Received: by mail-ed1-x529.google.com with SMTP id s10so13136632edy.9; Mon, 27 Apr 2020 04:25:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=eMbqXiWXrRsY2yZrGbKLgHpnCZU7nCBUTrX/2EePjqw=; b=N841seG1JQRkuMmfNSK4rTzxKTUgsox36NQ6iQabXuphD9q6P7O78dGGpFWchZQa5B dG7lV8ZKHV4CjADgnBIQ/6jLtvIT7Y1l7xWo9mwA97ig7z2EirmALAVBNPCuGSOKQB4V z5oKLIByNNf4nsD1EJTxN3spsB4pKqrVuKaPIY36axxwWYkWTcFTIkCvZcc/pldXShtY tg+mwmd2o34ptWRgf7qzadTAAdR+O841Opad/XIjgk1HoN8OfjzJNNv2w3IWy6K6q6/z 1CfAddqdnebJbA3LtSwW4875ia7gRsjo4QeXo5TW/ufrpt4cvKLpOH3qvlQb9cLPNlIZ 7HCg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=eMbqXiWXrRsY2yZrGbKLgHpnCZU7nCBUTrX/2EePjqw=; b=jS/DaRuf0xr0GyPgCNTUlyJYiFK2YRvOMBSIAiXTGnRh+n3eosNiarCGxt0sZ9nsfv 0/5lvJKQbA++6pxQNEjDwgvv0UYl7u9froCIlaQkSYo52FvE7iRZ6DfG4N6ISXANmzSg Y4mzMSRyfCNl4is2mGrtcxKrKXu8nqamAs8n4FB15T1GqXZZid69YtT5EQPS4RjXgvn5 tKTCD+3xobkmFLLD9oCpI47lX6YnyiFx1yap4LC3Ect2Qqj1SOLd9LSahnXU8cwA427s n/CasScPOSnxa/I4Pc932HcppPQX+gVg19UQ+HHWdpC59jR+SDqAE615bnewDnhNzWac jxmg==
X-Gm-Message-State: AGi0PuaTs3Qlc4s4t8mtaqgJlOZAFeSqAUtyRSa0Lnd03rWotA1qnjvM eG3AK6NjyNOqjZTP7uaN/kAdmjvar/6JTGfH0ZY=
X-Google-Smtp-Source: APiQypId9Vr7jhfaQfaOaSGuw3TBWDc1ZMixjvIi8dWjNVTVc1qk0fYzb59MIVfZuD8veqZMFjPbC7Xmg3yKrXrcTio=
X-Received: by 2002:a50:ee0e:: with SMTP id g14mr18372325eds.34.1587986754678; Mon, 27 Apr 2020 04:25:54 -0700 (PDT)
MIME-Version: 1.0
References: <004801d61bae$08a61590$19f240b0$@smyslov.net> <1UW7qWO4vA.17rUXhBMkf8@pc8xp>
In-Reply-To: <1UW7qWO4vA.17rUXhBMkf8@pc8xp>
From: Ralph Holz <ralph.holz@gmail.com>
Date: Mon, 27 Apr 2020 21:25:43 +1000
Message-ID: <CAEKAoHTJ4S5Wfkb4KB+ZWQN7JO_Q-DXDcEz5pqd7MPMhyj_CDQ@mail.gmail.com>
To: tom petch <daedulus@btconnect.com>
Cc: Valery Smyslov <valery@smyslov.net>, "uta@ietf.org" <uta@ietf.org>, Yaron Sheffer <yaronf.ietf@gmail.com>, "uta-chairs@ietf.org" <uta-chairs@ietf.org>, Peter Saint-Andre <stpeter@mozilla.com>
Content-Type: multipart/alternative; boundary="0000000000006bb40905a443fa63"
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/rVpouR-_8Bj4GSfpujIT_ig6V-M>
Subject: Re: [Uta] Adoption call for draft-sheffer-uta-rfc7525bis-00
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Apr 2020 11:25:59 -0000

Hi,

I am not sure which key requirement you are referring to, or why TLS 1.3
should not see widespread use. In fact, TLS 1.3 is getting much more
traction already than TLS 1.2 ever had in a comparable amount of time:
https://arxiv.org/abs/1907.12762. I am not sure why you speak of a
fragmentation of protocols here - if anything, we are seeing consolidation.

It seems weird to leave a BCP in a state that is not referring to the BP,
which is definitely TLS 1.3 - due to the many additions made. TLS 1.3 also
brings changes that are important for applications - 0-RTT, for example,
has no replay protection, and should only be used with idempotent requests.
While that is spelled out in the RFC, it's not where our audience would
look (or we would not need BCPs).

It's also worthwhile to deprecate < TLS 1.2, and discuss under which
circumstances TLS 1.3 is preferable to TLS 1.2 (that's more a business
question). Add to that a discussion of PSK. Plus a few new extensions, some
defined in separate RFCs (eSNI for example).

I am, of course, both an author on the old (and new) BCP, and also an
author of the study I cite - but I think there's enough to warrant the -bis.

Ralph

On Mon, 27 Apr 2020 at 19:03, tom petch <daedulus@btconnect.com> wrote:

> What is the point of rfc7525bis?  Why do we need it?
>
> It seems to me that RFC7525 is a good set of recommendations and little
> has changed, in practical terms, since it was produced, although
> cryptanalysts can find weaknesses therein
>
> ---
> New Outlook Express and Windows Live Mail replacement - get it here:
> https://www.oeclassic.com/
>
> .
>
> The one change I am aware of is that the TLS WG has produced TLS 1.3 - I
> follow the TLS WG mailing list - but so what?  TLS 1.3 failed to meet one
> key requirement and I am unclear whether or not TLS 1.3 will gain
> widespread use in the Internet, with HTTP, SMTP and such like.  I see TLS
> 1.2 as being adequate for most purposes for some time to come so my concern
> is that rfc5575bis will simply be an endorsement of the work of the TLS WG
> - 1.3 is great, ditch everything else - leading to further fragmentation of
> the protocols.
>
> So, I am against adoption until it is clear that the I-D will endorse TLS
> 1.2 as adequate for most purposes.  After all, the TLS WG has yet to
> propose an I-D 'TLS 1.2 - Die, Die, Die'
>
> Tom Petch
>
>
> ----- Original Message -----
> From: Valery Smyslov <valery@smyslov.net>
> To: <uta@ietf.org>
> Cc: 'Yaron Sheffer' <yaronf.ietf@gmail.com>, <uta-chairs@ietf.org>,
> 'Ralph Holz' <ralph.holz@gmail.com>, 'Peter Saint-Andre' <
> stpeter@mozilla.com>
> Sent: 26/04/2020 10:35:30
> Subject: [Uta] Adoption call for draft-sheffer-uta-rfc7525bis-00
>
> ________________________________________________________________________________
>
> Hi,
>
> during the last  virtual interim meeting the draft
> draft-sheffer-uta-bcp195bis-00 was presented and the authors asked for its
> adoption.
> The general feeling in the room was in favor of the adoption, however
> the authors were asked to rename it to *-rfc7525-bis.
> The authors have renamed the draft and asked the chairs for its adoption.
> Since our responsible AD thinks agrees that this work is within the charter
> of the WG, the chairs are issuing a formal call for adoption
> to confirm the results we had at the meeting.
>
> This message starts a two weeks call for adoption of the
> draft-sheffer-uta-rfc7525bis-00 draft.
> The call will end up 10 May 2020. Please send your opinions to the list
> before this date.
>
> Please if possible include any reasons supporting your opinion. If you
> support this adoption,
> please indicate whether you are ready to review this draft if it becomes a
> WG document.
>
> Regards,
> Leif & Valery.
>
>
> _______________________________________________
> Uta mailing list
> Uta@ietf.org
> https://www.ietf.org/mailman/listinfo/uta
>