Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-18 Thread Ilari Liusvaara
On Tue, Dec 18, 2018 at 03:01:07PM -0600, David Benjamin wrote: > On Tue, Dec 18, 2018 at 1:27 AM Viktor Dukhovni > wrote: > > > Also connection re-establishment has considerable cost, additional > > TCP roundtrips on top of the extra TLS roundtrips. > > > > Agreed. The other cost is that it can

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-18 Thread David Benjamin
(Hit send too early) On Tue, Dec 18, 2018 at 3:32 PM David Benjamin wrote: > On Tue, Dec 18, 2018 at 3:06 PM Ilari Liusvaara > wrote: > >> On Tue, Dec 18, 2018 at 02:27:10PM -0600, David Benjamin wrote: >> > On Tue, Dec 18, 2018 at 3:00 AM Ilari Liusvaara < >> ilariliusva...@welho.com> >> > wro

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-18 Thread David Benjamin
On Tue, Dec 18, 2018 at 3:06 PM Ilari Liusvaara wrote: > On Tue, Dec 18, 2018 at 02:27:10PM -0600, David Benjamin wrote: > > On Tue, Dec 18, 2018 at 3:00 AM Ilari Liusvaara < > ilariliusva...@welho.com> > > wrote: > > > > > On Mon, Dec 17, 2018 at 05:17:37PM -0600, David Benjamin wrote: > > > > H

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-18 Thread Ilari Liusvaara
On Tue, Dec 18, 2018 at 02:27:10PM -0600, David Benjamin wrote: > On Tue, Dec 18, 2018 at 3:00 AM Ilari Liusvaara > wrote: > > > On Mon, Dec 17, 2018 at 05:17:37PM -0600, David Benjamin wrote: > > > Hi folks, > > > > > > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd > > l

Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-18 Thread David Benjamin
On Tue, Dec 18, 2018 at 1:27 AM Viktor Dukhovni wrote: > On Tue, Dec 18, 2018 at 12:45:22AM -0600, David Benjamin wrote: > > > An earlier iteration even placed the retry on the same connection, which > > makes the analog clearer. (Doing it in the same connection is rather a > > mess, so we bounc

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-18 Thread David Benjamin
On Tue, Dec 18, 2018 at 3:00 AM Ilari Liusvaara wrote: > On Mon, Dec 17, 2018 at 05:17:37PM -0600, David Benjamin wrote: > > Hi folks, > > > > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd > like > > the group's thoughts on. The goal is to make ESNI more robust and > elim

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-18 Thread Ilari Liusvaara
On Mon, Dec 17, 2018 at 05:17:37PM -0600, David Benjamin wrote: > Hi folks, > > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd like > the group's thoughts on. The goal is to make ESNI more robust and eliminate > a bunch of deployment risks. The PRs are linked below: > > ht

Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-17 Thread Viktor Dukhovni
On Tue, Dec 18, 2018 at 12:45:22AM -0600, David Benjamin wrote: > An earlier iteration even placed the retry on the same connection, which > makes the analog clearer. (Doing it in the same connection is rather a > mess, so we bounce to a new one.) Any concern about the possibility that the reaso

Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-17 Thread David Fifield
On Tue, Dec 18, 2018 at 12:45:22AM -0600, David Benjamin wrote: > Thanks for the comment! The PR did try to touch on this, but perhaps I did a > poor job of wording it: > https://github.com/tlswg/draft-ietf-tls-esni/pull/124/files#diff-4d2dc9df336bea8e17f5eb4ed7cb1107R511 > > The intent is you use

Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-17 Thread David Benjamin
Thanks for the comment! The PR did try to touch on this, but perhaps I did a poor job of wording it: https://github.com/tlswg/draft-ietf-tls-esni/pull/124/files#diff-4d2dc9df336bea8e17f5eb4ed7cb1107R511 The intent is you use the retry keys just for that one retry. Subsequent connection attempts re

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-17 Thread Kazuho Oku
Hi David and others involved in the work, Thank you for the PR. 2018年12月18日(火) 8:18 David Benjamin : > > Hi folks, > > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd like > the group's thoughts on. The goal is to make ESNI more robust and eliminate a > bunch of deploymen

Re: [TLS] ESNI robustness and GREASE PRs - client tracking concerns?

2018-12-17 Thread David Fifield
On Mon, Dec 17, 2018 at 05:17:37PM -0600, David Benjamin wrote: > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd like > the > group's thoughts on. The goal is to make ESNI more robust and eliminate a > bunch > of deployment risks. The PRs are linked below: > > https://git

Re: [TLS] ESNI robustness and GREASE PRs

2018-12-17 Thread Stephen Farrell
Hiya, On 17/12/2018 23:17, David Benjamin wrote: > Hi folks, > > We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd like > the group's thoughts on. The goal is to make ESNI more robust and eliminate > a bunch of deployment risks. The PRs are linked below: > > https://github.

[TLS] ESNI robustness and GREASE PRs

2018-12-17 Thread David Benjamin
Hi folks, We[*] wrote up some proposed changes for draft-ietf-tls-esni that we'd like the group's thoughts on. The goal is to make ESNI more robust and eliminate a bunch of deployment risks. The PRs are linked below: https://github.com/tlswg/draft-ietf-tls-esni/pull/124 https://github.com/tlswg/d