Re: [TLS] consensus call: (not precluding ticket request evolution)

2020-03-06 Thread Viktor Dukhovni
On Fri, Mar 06, 2020 at 07:24:01PM -0800, Benjamin Kaduk wrote: > > > It seems like this would avoid the trap of alternating full and resumption > > > handshakes that was discussed downthread for the case where client > > > supports > > > reuse but server does not. > > > > Yes, there is some wig

Re: [TLS] consensus call: (not precluding ticket request evolution)

2020-03-06 Thread Benjamin Kaduk
On Thu, Mar 05, 2020 at 09:27:47PM -0500, Viktor Dukhovni wrote: > On Thu, Mar 05, 2020 at 05:30:04PM -0800, Benjamin Kaduk wrote: > > > > No it does not, because he specifically emphasised treating 0 in the > > > resumption count as issue no tickets, whereas PR#18 says that that that > > > don't

[TLS] [Editorial Errata Reported] RFC8447 (6009)

2020-03-06 Thread RFC Errata System
The following errata report has been submitted for RFC8447, "IANA Registry Updates for TLS and DTLS". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid6009 -- Type: Editorial Reported by: Benjam

[TLS] [Errata Verified] RFC8446 (5976)

2020-03-06 Thread RFC Errata System
The following errata report has been verified for RFC8446, "The Transport Layer Security (TLS) Protocol Version 1.3". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid5976 -- Status: Verified T

Re: [TLS] 3GPP forbids support of MD5, SHA-1, non-AEAD, and non-PFS in TLS

2020-03-06 Thread Eric Rescorla
This is great news. Thanks for helping make it happen! -Ekr On Fri, Mar 6, 2020 at 4:03 PM John Mattsson wrote: > Hi, > > I am happy to report that 3GPP just took the decision to forbid support of > MD5 and SHA-1, as well as all non-AEAD and non-PFS cipher suites in TLS. > The changes apply to

[TLS] FW: New Version Notification for draft-friel-tls-eap-dpp-00.txt

2020-03-06 Thread Owen Friel (ofriel)
All, Dan and I have a new draft that describes how a mechanism similar to the Wi-Fi Alliance Device Provisioning Profile can be used on wired networks via proposed new TLS extensions, with those extensions being leveraged in an EAP transaction. Importantly, the DPP bootstrap key format, and thu

[TLS] 3GPP forbids support of MD5, SHA-1, non-AEAD, and non-PFS in TLS

2020-03-06 Thread John Mattsson
Hi, I am happy to report that 3GPP just took the decision to forbid support of MD5 and SHA-1, as well as all non-AEAD and non-PFS cipher suites in TLS. The changes apply to all Rel-16 3GPP systems that use TLS and DTLS, which are quite many. 3GPP had already mandaded support of TLS 1.3, forbid

[TLS] WG Review: Transport Layer Security (tls)

2020-03-06 Thread The IESG
The Transport Layer Security (tls) WG in the Security Area of the IETF is undergoing rechartering. The IESG has not made any determination yet. The following draft charter was submitted, and is provided for informational purposes only. Please send your comments to the IESG mailing list (i...@ietf.o

Re: [TLS] TLS@IETF017: Agenda Topics

2020-03-06 Thread Sean Turner
Hi! Just aa gentle reminder for agenda topic request. Also, if you are planning to be a remote presenter please let us know. spt > On Feb 18, 2020, at 20:05, Sean Turner wrote: > > The TLS WG will be meeting @ IETF 107 in Vancouver. To help the chairs get a > better handle on how arrange our