[TLS]Re: Working Group Last Call for Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings

2024-06-27 Thread Christopher Patton
This looks good to me, modulo Rich's points and one more minor thing. "Use of ECH yields an anonymity set of cardinality equal to the number of ECH-enabled server domains supported by a given client-facing server" ( https://www.ietf.org/id/draft-ietf-tls-svcb-ech-02.html#section-5.1-2). This is on

[TLS]Re: Working Group Last Call for Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings

2024-06-27 Thread Stephen Farrell
Hiya, On 25/06/2024 16:30, Mike Bishop wrote: Responses to some of these in-line below. More generally, I think several of these arise from the question of whether requirements on "publishers" apply specifically to a tool which is automatically generating these records or generally to the opera