Re: [Emu] I-D Action: draft-ietf-emu-rfc7170bis-00.txt

2022-12-30 Thread John Mattsson
Hi,

>This document replaces RFC 7170.
Use the IETF term obsoletes and add that to the header.

- Use the new RFC 8174 text.

- I think we are past the time when it is acceptable to publish standards track 
based on the obsolete TLS 1.2. NIST is requiring TLS 1.3 support everywhere by 
January 2024. This document would be ready for deprecation before its even is 
published. The only reasonable thing for a 2023 document is to do TLS 1.3 only. 
If TLS 1.2 is supported at all the currently listed cipher suites needs to be 
forbidden and replaced with a profile like that in RFC 9113. I don't think the 
current document can be published as standard track in 2023.

Cheers,
John

From: Emu  on behalf of internet-dra...@ietf.org 

Date: Wednesday, 28 December 2022 at 17:28
To: i-d-annou...@ietf.org 
Cc: emu@ietf.org 
Subject: [Emu] I-D Action: draft-ietf-emu-rfc7170bis-00.txt

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the EAP Method Update WG of the IETF.

Title   : Tunnel Extensible Authentication Protocol (TEAP) 
Version 1
Authors : Alan DeKok
  Hao Zhou
  Joseph Salowey
  Nancy Cam-Winget
  Stephen Hanna
  Filename: draft-ietf-emu-rfc7170bis-00.txt
  Pages   : 98
  Date: 2022-12-28

Abstract:
   This document defines the Tunnel Extensible Authentication Protocol
   (TEAP) version 1.  TEAP is a tunnel-based EAP method that enables
   secure communication between a peer and a server by using the
   Transport Layer Security (TLS) protocol to establish a mutually
   authenticated tunnel.  Within the tunnel, TLV objects are used to
   convey authentication-related data between the EAP peer and the EAP
   server.  This document replaces RFC 7170.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-emu-rfc7170bis/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-emu-rfc7170bis-00.html


Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts


___
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu
___
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu


Re: [Emu] I-D Action: draft-ietf-emu-rfc7170bis-00.txt

2022-12-30 Thread Alan DeKok
On Dec 30, 2022, at 10:21 AM, John Mattsson 
 wrote:
> 
> Hi,
>  
> >This document replaces RFC 7170.
> Use the IETF term obsoletes and add that to the header.

  Done.

> - Use the new RFC 8174 text.

  Done.

>  
> - I think we are past the time when it is acceptable to publish standards 
> track based on the obsolete TLS 1.2. NIST is requiring TLS 1.3 support 
> everywhere by January 2024. This document would be ready for deprecation 
> before its even is published. The only reasonable thing for a 2023 document 
> is to do TLS 1.3 only. If TLS 1.2 is supported at all the currently listed 
> cipher suites needs to be forbidden and replaced with a profile like that in 
> RFC 9113. I don't think the current document can be published as standard 
> track in 2023.  

  If draft-ietf-emu-tls-eap-types is published in 2023, then I think it 
addresses your concerns.

  I have previously suggested bringing the text about TLS 1.3 from 
draft-ietf-emu-tls-eap-types into this document, and didn't get much feedback.  

  So I agree, if we're fixing TEAP, it does make sense to bring all of the TEAP 
issues into this document.  It's also important for implementors to write and 
test the TLS 1.3 key derivations.

  Alan DeKok.

___
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu


[Emu] Reminder EMU WG Virtual Interim 2023-01-04

2022-12-30 Thread Joseph Salowey
The EAP Method Update (emu) WG will hold a virtual interim meeting on
2023-01-04 from 09:00 to 10:00 America/Los_Angeles (17:00 to 18:00 UTC).

Upcoming interim meetings are listed here -
https://datatracker.ietf.org/meeting/upcoming

Agenda:
1. TEAP Errata
a. https://www.rfc-editor.org/errata/rfc7170
b. some Proposed resolutions - https://github.com/emu-wg/teap-errata
2. TEAP Revision
a. https://datatracker.ietf.org/doc/draft-ietf-emu-rfc7170bis/
b. https://github.com/alandekok/rfc7170-bis

Information about remote participation:
https://meetings.conf.meetecho.com/interim/?short=1756daa0-b496-469f-aed3-1a61158f90b6
___
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu


Re: [Emu] Reminder EMU WG Virtual Interim 2023-01-04

2022-12-30 Thread Alan DeKok
  The TEAP document is now hosted in the EMU WG repository:

https://github.com/emu-wg/rfc7170bis

> On Dec 30, 2022, at 11:02 AM, Joseph Salowey  wrote:
> 
> The EAP Method Update (emu) WG will hold a virtual interim meeting on 
> 2023-01-04 from 09:00 to 10:00 America/Los_Angeles (17:00 to 18:00 UTC).
> 
> Upcoming interim meetings are listed here - 
> https://datatracker.ietf.org/meeting/upcoming
> 
> Agenda:
> 1. TEAP Errata
> a. https://www.rfc-editor.org/errata/rfc7170
> b. some Proposed resolutions - https://github.com/emu-wg/teap-errata
> 2. TEAP Revision
> a. https://datatracker.ietf.org/doc/draft-ietf-emu-rfc7170bis/
> b. https://github.com/alandekok/rfc7170-bis
> 
> Information about remote participation:
> https://meetings.conf.meetecho.com/interim/?short=1756daa0-b496-469f-aed3-1a61158f90b6
> ___
> Emu mailing list
> Emu@ietf.org
> https://www.ietf.org/mailman/listinfo/emu

___
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu