Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-27 Thread Watson Ladd
ectly retransmits the missing messages, the connection >>>> will perform suboptimally for a blip but still recover. >>>> >>>> David >>>> >>>> >>>> On Tue, Apr 16, 2024, 05:19 Tschofenig, Hannes < >>>> hannes.tscho

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-27 Thread David Benjamin
ing messages, the connection >>> will perform suboptimally for a blip but still recover. >>> >>> David >>> >>> >>> On Tue, Apr 16, 2024, 05:19 Tschofenig, Hannes < >>> hannes.tschofe...@siemens.com> wrote: >>> >>>&

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-17 Thread David Benjamin
> >>> >>> this is great feedback. Give me a few days to respond to this issue with >>> my suggestion for moving forward. >>> >>> >>> >>> Ciao >>> >>> Hannes >>> >>> >>> >>> *From:

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-17 Thread Marco Oliverio
oving forward. >> >> >> >> Ciao >> >> Hannes >> >> >> >> *From:* TLS *On Behalf Of *David Benjamin >> *Sent:* Saturday, April 13, 2024 7:59 PM >> *To:* >> *Cc:* Nick Harper >> *Subject:* Re: [TLS] Issues with buf

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-16 Thread David Benjamin
reat feedback. Give me a few days to respond to this issue with > my suggestion for moving forward. > > > > Ciao > > Hannes > > > > *From:* TLS *On Behalf Of *David Benjamin > *Sent:* Saturday, April 13, 2024 7:59 PM > *To:* > *Cc:* Nick Harper > *Subje

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-16 Thread Tschofenig, Hannes
Hi David, this is great feedback. Give me a few days to respond to this issue with my suggestion for moving forward. Ciao Hannes From: TLS On Behalf Of David Benjamin Sent: Saturday, April 13, 2024 7:59 PM To: Cc: Nick Harper Subject: Re: [TLS] Issues with buffered, ACKed KeyUpdates in

Re: [TLS] Issues with buffered, ACKed KeyUpdates in DTLS 1.3

2024-04-13 Thread David Benjamin
Another issues with DTLS 1.3's state machine duplication scheme: Section 8 says implementation must not send new KeyUpdate until the KeyUpdate is ACKed, but it says nothing about other post-handshake messages. Suppose KeyUpdate(5) in flight and the implementation decides to send NewSessionTicket.