[TLS] Proposed changes to the "feature freeze" draft

2024-04-22 Thread Salz, Rich
I just made a set of proposed changes to the “use-tls13” draft [1] and taking a look at the “frozen” draft [2]. I wanted to remove the duplication of text between the two documents. This means * Remove the bullet list from the introduction * Remove the security considerations because i

Re: [TLS] [EXT] Re: Deprecating Static DH certificates in the obsolete key exchange document

2024-04-22 Thread Filippo Valsorda
2024-04-21 23:26 GMT+02:00 Blumenthal, Uri - 0553 - MITLL : > I see two possibilities: > > 1. Nobody in the real world employs static DH anymore – in which case this > draft is useless/pointless; or > 2. On private networks people employ static DH to implicitly authenticate > their peers (a-l

Re: [TLS] [EXT] Deprecating Static DH certificates in the obsolete key exchange document

2024-04-22 Thread Hubert Kario
On Sunday, 21 April 2024 23:26:56 CEST, Blumenthal, Uri - 0553 - MITLL wrote: I see two possibilities: 1. Nobody in the real world employs static DH anymore – in which case this draft is useless/pointless; or even if everybody agreed, making official, public statement on a particular top

Re: [TLS] IANA Recommendations for Obsolete Key Exchange

2024-04-22 Thread Hubert Kario
On Monday, 15 April 2024 19:30:29 CEST, Joseph Salowey wrote: At IETF 119 we had discussion on how to mark the ciphersuites deprecated by draft-ietf-tls-deprecate-obsolete-kex in the IANA Registry. At the meeting there was support for ('D' means discouraged): RSA ciphersuites should be marked