Re: [TLS] TLS Suite Naming Conventions

2024-01-07 Thread Rob Sayre
On Sat, Jan 6, 2024 at 10:07 AM Orie Steele wrote: > Thanks for your detailed response! > Even TLS 1.3 is not super clear on this one. I read: https://datatracker.ietf.org/doc/html/rfc8446#appendix-B.4 And I was a little bit confused. So, you get some all caps with underscores. These do all w

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread Orie Steele
Thanks for your detailed response! I agree with everything you wrote, but especially these parts: > A key is a thing you get out of a signature scheme, not the other way around. And this part: > As far as we're concerned, these are just names that conform to the signature scheme interface (KeyG

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread David Benjamin
On Sat, Jan 6, 2024 at 12:23 PM David Benjamin wrote: > I think this thread stems from a misunderstanding of what TLS is doing, > and what "Ed25519" means. > > > In the thread, Neil said that it is better to negotiate for key > (representations), instead of algorithms, and that TLS has been movin

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread David Benjamin
I think this thread stems from a misunderstanding of what TLS is doing, and what "Ed25519" means. > In the thread, Neil said that it is better to negotiate for key (representations), instead of algorithms, and that TLS has been moving away from fully specifying things. This is the exact opposite

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread Orie Steele
On Sat, Jan 6, 2024 at 9:16 AM Hannes Tschofenig wrote: > Hi Orie, > > > I am not sure whether the comparison between JOSE/COSE and TLS is > appropriate when the latter uses a handshake and the former is a one-shot > message (or a payload). > > In a TLS handshake there are so many things that get

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread Salz, Rich
* Hence, I am not sure what the benefit of aligning the registries are. To me, this entire ciphersuite vs. à la carte discussion is largely a matter of taste. Strongly agree. TLS is an online protocol; the others are not. Perhaps the LAMPS (neé spasm) working has opinions, since JOSE at al

Re: [TLS] TLS Suite Naming Conventions

2024-01-06 Thread Hannes Tschofenig
Hi Orie, I am not sure whether the comparison between JOSE/COSE and TLS is appropriate when the latter uses a handshake and the former is a one-shot message (or a payload). In a TLS handshake there are so many things that get negotiated, such as the algorithms and parameters for protecting the

[TLS] TLS Suite Naming Conventions

2024-01-06 Thread Orie Steele
Hello, Apologies in advance for starting a thread about the proper way to name things. We've been discussing the TLS naming conventions in relation to JOSE and COSE naming conventions for suites. Here is the start of the full thread: https://mailarchive.ietf.org/arch/msg/jose/66xvb1EgD-bf7V-XyAg