Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2020-05-09 Thread Christopher Wood
FYI: This PR has been merged. Best, Chris, on behalf of the chairs On Mon, May 4, 2020, at 10:08 AM, Christopher Wood wrote: > Thanks, Alessandro! We'll aim to merge this PR on Friday. We ask that > folks review it before then. > >https://github.com/tlswg/draft-ietf-tls-md5-sha1-deprecate/

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2020-05-04 Thread Christopher Wood
Thanks, Alessandro! We'll aim to merge this PR on Friday. We ask that folks review it before then. https://github.com/tlswg/draft-ietf-tls-md5-sha1-deprecate/pull/5 Thanks, Chris, on behalf of the chairs On Thu, Apr 23, 2020, at 10:45 AM, Alessandro Ghedini wrote: > On Sun, Nov 24, 2019 at

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2020-04-23 Thread Alessandro Ghedini
On Sat, Nov 23, 2019 at 05:32:36PM +0100, Karthik Bhargavan wrote: > This is a bit of a shameless plug, but I think it is important to cite papers > that show that the use of weak hash functions for TLS signatures is actually > exploitable. > > As far as I know, the last round of deprecating MD5

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2020-04-23 Thread Alessandro Ghedini
On Sun, Nov 24, 2019 at 11:27:26AM -0500, David Benjamin wrote: > On Sat, Nov 23, 2019 at 8:40 AM Ilari Liusvaara > wrote: > > > On Fri, Nov 22, 2019 at 08:18:47PM +0100, Hubert Kario wrote: > > > On Friday, 22 November 2019 03:25:24 CET, David Benjamin wrote: > > > > On Fri, Nov 22, 2019 at 8:35

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-12-18 Thread Kathleen Moriarty
On Wed, Dec 18, 2019 at 1:20 PM Russ Housley wrote: > I support the progress of this document, but I have one tardy comment. > > I think that Section 6 should have some introductory text similar to the > text at the beginning of Section 7. > Thank you, Russ. > > Russ > > > > On Dec 17, 2019, at

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-12-18 Thread Russ Housley
I support the progress of this document, but I have one tardy comment. I think that Section 6 should have some introductory text similar to the text at the beginning of Section 7. Russ > On Dec 17, 2019, at 3:21 PM, Sean Turner wrote: > > The WGLC ended on Friday. A couple of comments were

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-12-17 Thread Sean Turner
The WGLC ended on Friday. A couple of comments were received and need to be addressed prior to progressing the draft to Ben. We will put the document in the “Revised I-D Needed” state. Thanks, spt > On Nov 21, 2019, at 17:41, Sean Turner wrote: > > All, > > This is the working group last

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-24 Thread David Benjamin
On Sat, Nov 23, 2019 at 8:40 AM Ilari Liusvaara wrote: > On Fri, Nov 22, 2019 at 08:18:47PM +0100, Hubert Kario wrote: > > On Friday, 22 November 2019 03:25:24 CET, David Benjamin wrote: > > > On Fri, Nov 22, 2019 at 8:35 AM Salz, Rich wrote: > > > > > > > > ... > > > > SHA-1 signature hashes in

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-23 Thread Karthik Bhargavan
This is a bit of a shameless plug, but I think it is important to cite papers that show that the use of weak hash functions for TLS signatures is actually exploitable. As far as I know, the last round of deprecating MD5 in TLS signatures was triggered by the SLOTH attack: https://www.mitls.org

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-23 Thread Ilari Liusvaara
On Fri, Nov 22, 2019 at 08:18:47PM +0100, Hubert Kario wrote: > On Friday, 22 November 2019 03:25:24 CET, David Benjamin wrote: > > On Fri, Nov 22, 2019 at 8:35 AM Salz, Rich wrote: > > > > > > ... > > > SHA-1 signature hashes in TLS 1.2" draft available > > > https://datatracker.ietf.org/doc/dra

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-22 Thread Hubert Kario
On Thursday, 21 November 2019 23:41:36 CET, Sean Turner wrote: All, This is the working group last call for the "Deprecating MD5 and SHA-1 signature hashes in TLS 1.2" draft available https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/. Please review the document and send you

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-22 Thread Hubert Kario
On Friday, 22 November 2019 03:25:24 CET, David Benjamin wrote: On Fri, Nov 22, 2019 at 8:35 AM Salz, Rich wrote: ... SHA-1 signature hashes in TLS 1.2" draft available https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/. Please review the document and send your comments to th

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-21 Thread David Benjamin
On Fri, Nov 22, 2019 at 8:35 AM Salz, Rich wrote: > >This is the working group last call for the "Deprecating MD5 and > SHA-1 signature hashes in TLS 1.2" draft available > https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/. > Please review the document and send your comments

Re: [TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-21 Thread Salz, Rich
>This is the working group last call for the "Deprecating MD5 and SHA-1 > signature hashes in TLS 1.2" draft available > https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/. Please > review the document and send your comments to the list by 2359 UTC on 13 > December 2019.

[TLS] WGLC for draft-ietf-tls-md5-sha1-deprecate

2019-11-21 Thread Sean Turner
All, This is the working group last call for the "Deprecating MD5 and SHA-1 signature hashes in TLS 1.2" draft available https://datatracker.ietf.org/doc/draft-ietf-tls-md5-sha1-deprecate/. Please review the document and send your comments to the list by 2359 UTC on 13 December 2019. Note th