Re: [xmpp] Fwd: I-D Action: draft-saintandre-xmpp-tls-03.txt

Dave Cridland <dave@cridland.net> Wed, 18 December 2013 18:09 UTC

Return-Path: <dave@cridland.net>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2B71C1AE037 for <xmpp@ietfa.amsl.com>; Wed, 18 Dec 2013 10:09:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.378
X-Spam-Level:
X-Spam-Status: No, score=-1.378 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EDMG0vLwkPh4 for <xmpp@ietfa.amsl.com>; Wed, 18 Dec 2013 10:09:03 -0800 (PST)
Received: from mail-oa0-x231.google.com (mail-oa0-x231.google.com [IPv6:2607:f8b0:4003:c02::231]) by ietfa.amsl.com (Postfix) with ESMTP id 43DAB1AE006 for <xmpp@ietf.org>; Wed, 18 Dec 2013 10:09:03 -0800 (PST)
Received: by mail-oa0-f49.google.com with SMTP id i4so8601904oah.36 for <xmpp@ietf.org>; Wed, 18 Dec 2013 10:09:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cridland.net; s=google; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=jayJLS9Y3MzD46EvbaOxayO1KYUzI8Ko65ovl4ZeqEs=; b=HBNgf7v/eNtoKnJnqRnkqppZV6V5z9NAolzS0FIE+t808xF4wkjbkHQL8J9iJxN7Qx qRVTAO9W0COL0ttSEu43b9mmPmc3R76+DfbungqiWn0UQGRGiwd6hJZcRe0wZBaWIG3U rUAq7b3dNqAbIMDVlnZVTtKVXfwV1msYbgWoA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=jayJLS9Y3MzD46EvbaOxayO1KYUzI8Ko65ovl4ZeqEs=; b=HpjD7GdIA6gHy5N8IeMs3+W8YEpJvKv8+IiEibO0nhj0ARw1PSbnaIWdQtPsWS8OKX 074JZjYXycglkyBNJ+lVl2HFamvPhxW7AKcXH/zaN5ypEe7cLDzDejJW20JhKvrz+d4w PR4xu1WTu7ghcwj908RErAxJZMHEY/oH1GBtVgOaBTmUk572Clu60hitT5z8A5GAJQzF sr1v27eHz1W7ox0fr6LlYrq7ju+3Q13aWH5w9Myw2ER4GPvWQ5Tn0gYnlm3zcd7UMmMG y9ANy+UNbEeiW9tJqV+i2vJ4BWHulVd2jOFcNrSLmttvyiGiSu6vweHhSUBeDzAl+MJ2 lB/g==
X-Gm-Message-State: ALoCoQl/ibL0JVPKNen5pJGmGc+v1lLtMZALiyQ6yZ2PxlJJg8uB3DXt4583Cz4vVCS19wqnKMLM
MIME-Version: 1.0
X-Received: by 10.60.51.161 with SMTP id l1mr2837123oeo.69.1387390141701; Wed, 18 Dec 2013 10:09:01 -0800 (PST)
Received: by 10.60.144.38 with HTTP; Wed, 18 Dec 2013 10:09:01 -0800 (PST)
In-Reply-To: <52B0B323.5050805@stpeter.im>
References: <20131217202338.32484.54532.idtracker@ietfa.amsl.com> <52B0B323.5050805@stpeter.im>
Date: Wed, 18 Dec 2013 18:09:01 +0000
Message-ID: <CAKHUCzxoPnAOChhV+a1sFMJPa-k-aBYr_AtV2Eq1JAFjca7imQ@mail.gmail.com>
From: Dave Cridland <dave@cridland.net>
To: Peter Saint-Andre <stpeter@stpeter.im>
Content-Type: multipart/alternative; boundary="001a11c2f3ec8fb7b804edd2f0ef"
Cc: XMPP <xmpp@ietf.org>
Subject: Re: [xmpp] Fwd: I-D Action: draft-saintandre-xmpp-tls-03.txt
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp/>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Dec 2013 18:09:05 -0000

Some scattergun comments.

1) I think you're saying SHOULD support, MAY negotiate TLS 1.1. Are you?
Are we also saying SHOULD support later TLS versions, and SHOULD negotiate
them?

2) There was some interesting discussions on the use of long-lived DH
parameters and the resultant levels of perfection in the forward secrecy
over on (erm) one of the XSF lists. It'd be nice to get some
recommendations of longevity of the DH parameters - many implementations
either hard-code these or generate them once only.


On Tue, Dec 17, 2013 at 8:25 PM, Peter Saint-Andre <stpeter@stpeter.im>wrote:

> FYI.
>
>
> -------- Original Message --------
> Subject: I-D Action: draft-saintandre-xmpp-tls-03.txt
> Date: Tue, 17 Dec 2013 12:23:38 -0800
> From: internet-drafts@ietf.org
> Reply-To: internet-drafts@ietf.org
> To: i-d-announce@ietf.org
>
>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
>
>
>         Title           : Use of Transport Layer Security (TLS) in the
> Extensible Messaging and Presence Protocol (XMPP)
>         Author(s)       : Peter Saint-Andre
>         Filename        : draft-saintandre-xmpp-tls-03.txt
>         Pages           : 10
>         Date            : 2013-12-17
>
> Abstract:
>    This document provides recommendations for the use of Transport Layer
>    Security (TLS) in the Extensible Messaging and Presence Protocol
>    (XMPP).  This document updates RFC 6120.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-saintandre-xmpp-tls
>
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-saintandre-xmpp-tls-03
>
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-saintandre-xmpp-tls-03
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://www.ietf.org/mailman/listinfo/i-d-announce
> Internet-Draft directories: http://www.ietf.org/shadow.html
> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt
>
>
> _______________________________________________
> xmpp mailing list
> xmpp@ietf.org
> https://www.ietf.org/mailman/listinfo/xmpp
>