Re: [TLS] Re-chartering TLS

2020-01-18 Thread Salz, Rich
I'd remove "With these goals in mind" from the last sentence, but the new 
charter (with the "resources" edit) even if my suggestion isn't accepted.


___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls


Re: [TLS] Re-chartering TLS

2020-01-18 Thread Benjamin Beurdouche
LGTM, I agree with using “resource" instead of “size”…
My understanding is that “security” is broad enough to cover new authentication 
mechanisms
and that “privacy" will be broad enough to cover “metadata protection” if 
needed, correct?
B.

> On Jan 17, 2020, at 4:31 AM, Christopher Wood  wrote:
> 
> Hi folks,
> 
> As discussed in Singapore, it's time to re-charter the working group to 
> reflect ongoing (e.g., Exported Authenticators and Encrypted SNI/CH) and 
> future work (e.g., cTLS). For reference, the current charter is available 
> here: 
> 
>   https://datatracker.ietf.org/doc/charter-ietf-tls/
> 
> A draft of the new charter is below, and also available on GitHub [1]. Please 
> have a look and and send comments, either here on the mailing list or in the 
> GitHub repo, by 2359 UTC on 30 January 2020. Any and all feedback is welcome! 
> We would like to complete this in advance of IETF 107 so we can move forward 
> with items such as cTLS. 
> 
> ~~~
> The TLS (Transport Layer Security) working group was established in 1996 to 
> standardize a 'transport layer' security protocol. The basis for the work was 
> SSL (Secure Socket Layer) v3.0 [RFC6101]. The TLS working group has completed 
> a series of specifications that describe the TLS protocol v1.0 [RFC2246], 
> v1.1 [RFC4346], v1.2 [RFC5346], and v1.3 [RFC8446], and DTLS (Datagram TLS) 
> v1.0 [RFC4347], v1.2 [RFC6347], and v1.3 [draft-ietf-tls-dtls13], as well as 
> extensions to the protocols and ciphersuites.
> 
> The working group aims to achieve three goals. First, improve the 
> applicability and suitability of the TLS family of protocols for use in 
> emerging protocols and use cases. This includes extensions or changes that 
> help protocols better use TLS as an authenticated key exchange protocol, or 
> extensions that help protocols better leverage TLS security properties, such 
> as Exported Authenticators. Extensions that focus specifically on protocol 
> extensibility are also in scope. This goal also includes protocol changes 
> that reduce the size of TLS without affecting security. Extensions that help 
> reduce TLS handshake size meet this criteria. 
> 
> The second working group goal is to improve security, privacy, and 
> deployability. This includes, for example, Delegated Credentials, Encrypted 
> SNI, and GREASE. Security and privacy goals will place emphasis on the 
> following:
> 
> - Encrypt the ClientHello SNI (Server Name Indication) and other 
> application-sensitive extensions, such as ALPN (Application-Layer Protocol 
> Negotiation).
> - Identify and mitigate other (long-term) user tracking or fingerprinting 
> vectors enabled by TLS deployments and implementations.
> 
> The third goal is to maintain current and previous version of the (D)TLS 
> protocol as well as to specify general best practices for use of (D)TLS, 
> extensions to (D)TLS, and cipher suites. This includes recommendations as to 
> when a particular version should be deprecated. Changes or additions to older 
> versions of (D)TLS whether via extensions or ciphersuites are discouraged and 
> require significant justification to be taken on as work items.
> 
> With these goals in mind, the working group will also place a priority in 
> minimizing gratuitous changes to (D)TLS.
> ~~~
> 
> Best,
> Chris, on behalf of the chairs
> 
> [1] https://github.com/tlswg/wg-materials/blob/master/charter/charter.md
> 
> ___
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls

___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls


Re: [TLS] Re-chartering TLS

2020-01-18 Thread Christopher Wood
On Sat, Jan 18, 2020, at 9:19 AM, Salz, Rich wrote:
> I'd remove "With these goals in mind" from the last sentence, but the 
> new charter (with the "resources" edit) even if my suggestion isn't 
> accepted.

To confirm, you'd replace this:

 "With these goals in mind, the working group will also place a priority in 
minimizing gratuitous changes to (D)TLS."

with this:

  "The working group will also place a priority in minimizing gratuitous 
changes to (D)TLS."

Right? That seems fine to me!

Thanks,
Chris

___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls


Re: [TLS] Re-chartering TLS

2020-01-18 Thread Christopher Wood
On Sat, Jan 18, 2020, at 9:29 AM, Benjamin Beurdouche wrote:
> LGTM, I agree with using “resource" instead of “size”…
> My understanding is that “security” is broad enough to cover new 
> authentication mechanisms
> and that “privacy" will be broad enough to cover “metadata protection” 
> if needed, correct?

Indeed -- that's the intent! 

Best,
Chris

___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls


Re: [TLS] Re-chartering TLS

2020-01-18 Thread Salz, Rich
>  "The working group will also place a priority in minimizing gratuitous 
> changes to (D)TLS."

>Right? That seems fine to me!
  
Great, thanks.

___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls


[TLS] Weekly github digest (TLS Working Group Drafts)

2020-01-18 Thread Repository Activity Summary Bot




Issues
--
* tlswg/tls-subcerts (+0/-1/💬2)
 2 issues received 2 new comments:
 - #43 Add support for advertising supported signature schemes (1 by chris-wood)
   https://github.com/tlswg/tls-subcerts/issues/43 
 - #41 Assign codepoint for delegated_credentials extension (1 by chris-wood)
   https://github.com/tlswg/tls-subcerts/issues/41 


 1 issues closed:
 - Add support for advertising supported signature schemes https://github.com/tlswg/tls-subcerts/issues/43 




Pull requests
-
* tlswg/tls-subcerts (+0/-1/💬1)
 1 pull requests received 1 new comments:
 - #46 Address Issue #43 (1 by chris-wood)
   https://github.com/tlswg/tls-subcerts/pull/46 


 1 pull requests merged:
 - Address Issue #43
   https://github.com/tlswg/tls-subcerts/pull/46 



Repositories tracked by this digest:
---
* https://github.com/tlswg/draft-ietf-tls-esni
* https://github.com/tlswg/certificate-compression
* https://github.com/tlswg/draft-ietf-tls-external-psk-importer
* https://github.com/tlswg/draft-ietf-tls-ticketrequest
* https://github.com/tlswg/tls-flags
* https://github.com/tlswg/dtls13-spec
* https://github.com/tlswg/dtls-conn-id
* https://github.com/tlswg/tls-subcerts
* https://github.com/tlswg/oldversions-deprecate
* https://github.com/tlswg/sniencryption
* https://github.com/tlswg/tls-exported-authenticator
* https://github.com/tlswg/draft-ietf-tls-grease
___
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls