Re: [TLS] [FORGED] Re: no fallbacks please [was: Downgrade protection, fallbacks, and server time]

2016-06-09 Thread Hubert Kario
On Thursday 09 June 2016 05:48:15 Peter Gutmann wrote: > Hubert Kario writes: > >The first one is: > >https://github.com/tomato42/tlsfuzzer > >and aims to be a comprehensive test suite > > Very nice, just setting it up now. One minor request, it'd be useful > to have a run-evening wrapper script

Re: [TLS] Adoption of TLS-LTS

2016-06-09 Thread Hubert Kario
On Wednesday 08 June 2016 19:29:07 Peter Gutmann wrote: > Russ Housley writes: > >I do not think the TLS WG should take on any document that makes > >changes to the TLS 1.2 protocol. > > So how is that different from any number of other TLS standards-track > RFCs, say, RFC 7627 (one of the ones r

Re: [TLS] Closing on keys used for handshake and data messages

2016-06-09 Thread Daniel Kahn Gillmor
On Fri 2016-06-03 17:54:53 -0400, Joseph Salowey wrote: >Trial decryption has serious implementation problems >- >Double-encrypting handshake messages in both the handshake key and the >application key does not actually provide the required key separation >- >Separately encr