Re: [TLS] 0-RTT & resumption

2015-08-07 Thread Ilari Liusvaara
On Fri, Aug 07, 2015 at 02:50:14PM -0700, Eric Rescorla wrote: > I've updated the PR based on feedback from Dave, Ilari, and Martin. > > https://github.com/tlswg/tls13-spec/pull/211 > > I'll merge this PR on 8/11 unless there are serious objections. As usual > please send minor changes as github

Re: [TLS] 0-RTT & resumption

2015-08-07 Thread Eric Rescorla
I've updated the PR based on feedback from Dave, Ilari, and Martin. https://github.com/tlswg/tls13-spec/pull/211 I'll merge this PR on 8/11 unless there are serious objections. As usual please send minor changes as github comments and/or PRs. -Ekr On Tue, Aug 4, 2015 at 5:40 AM, Eric Rescorla

Re: [TLS] 0-RTT & resumption

2015-08-04 Thread Eric Rescorla
On Mon, Aug 3, 2015 at 11:51 PM, Ilari Liusvaara < ilari.liusva...@elisanet.fi> wrote: > On Sat, Jul 25, 2015 at 09:07:49PM +0200, Eric Rescorla wrote: > > > > > > We agreed on how to do this in Prague. The sticking point was > establishing > > the cipher suite. I have WIP text on my machine for b

Re: [TLS] 0-RTT & resumption

2015-08-03 Thread Ilari Liusvaara
On Sat, Jul 25, 2015 at 09:07:49PM +0200, Eric Rescorla wrote: > > > We agreed on how to do this in Prague. The sticking point was establishing > the cipher suite. I have WIP text on my machine for both of these which I > will be > sending early next week, once I get enough sleep to be able to cl

Re: [TLS] 0-RTT & resumption

2015-07-25 Thread Eric Rescorla
On Sat, Jul 25, 2015 at 8:53 PM, Dave Garrett wrote: > I'm pretty sure some/all of this was likely mentioned elsewhere, but I > don't see any discussion on-list. (it was mentioned in part of the IETF 93 > recording I watched as this whole topic needing to go to the list, as well) > There's also r

Re: [TLS] 0-RTT & resumption

2015-07-25 Thread Viktor Dukhovni
On Sat, Jul 25, 2015 at 02:53:17PM -0400, Dave Garrett wrote: > 3) Just to state the obvious: If a client is going to do PSK resumption > with a non-PFS suite, it needs to offer a non-PFS suite. Forward-secrecy is not about doing or not doing DHE/ECDHE those are just means to an end. Forward-sec

[TLS] 0-RTT & resumption

2015-07-25 Thread Dave Garrett
I'm pretty sure some/all of this was likely mentioned elsewhere, but I don't see any discussion on-list. (it was mentioned in part of the IETF 93 recording I watched as this whole topic needing to go to the list, as well) There's also related TODOs in the draft on this topic. Here's a start to t