Re: [TLS] ETSI releases standards for enterprise security and data centre management

2018-12-12 Thread Arnaud.Taddei.IETF
I appreciate this answer, thank you Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Friday 7 December 2018 23:48, Sean Turner wrote: > There is no WG consensus to adopt this draft as no WG adoption call has been > made. draft-dkg-tls-reject-static-dh is an individual dr

[TLS] Further TLS 1.3 deployment updates

2018-12-12 Thread David Benjamin
Hi folks, We have one more update for you all on TLS 1.3 deployment issues. Over the course of deploying TLS 1.3 to Google servers, we found that JDK 11 unfortunately implemented TLS 1.3 incorrectly. On resumption, it fails to send the SNI extension. This means that the first connection from a JDK

Re: [TLS] draft-dkg-tls-reject-static-dh

2018-12-12 Thread Peter Gutmann
Tony Arcieri writes: >I think these concerns can largely be addressed by ECDHE with e.g. X25519: Sure, and they could be addressed even better with LoRaWAN security, which is even more efficient, however given that the current common denominator for the user base appears to be TLS 1.0, the fact