Re: [TLS] OpenSSL now at draft-20

2017-05-08 Thread Richard Barnes
On Wed, May 3, 2017 at 6:48 PM, Martin Thomson wrote: > On 4 May 2017 at 02:29, Matt Caswell wrote: > > FYI, I have just made the necessary updates to bring the OpenSSL > > master branch up to draft-20 compatibility. Please test!! > > > That's timely. I just landed -20 support in NSS. It's on

Re: [TLS] The case for a single stream of data

2017-05-08 Thread Benjamin Kaduk
On 05/06/2017 04:58 AM, Ilari Liusvaara wrote: > On Fri, May 05, 2017 at 09:28:07AM -0700, Colm MacCárthaigh wrote: >> I wanted to start a separate thread on this, just to make some small >> aspects of replay mitigating clear, because I'd like to make a case for TLS >> providing a single-stream, wh

Re: [TLS] The case for a single stream of data

2017-05-08 Thread Ilari Liusvaara
On Mon, May 08, 2017 at 09:33:27PM -0500, Benjamin Kaduk wrote: > On 05/06/2017 04:58 AM, Ilari Liusvaara wrote: > > On Fri, May 05, 2017 at 09:28:07AM -0700, Colm MacCárthaigh wrote: > >> I wanted to start a separate thread on this, just to make some small > >> aspects of replay mitigating clear,

Re: [TLS] The case for a single stream of data

2017-05-08 Thread Benjamin Kaduk
On 05/08/2017 11:45 PM, Ilari Liusvaara wrote: > On Mon, May 08, 2017 at 09:33:27PM -0500, Benjamin Kaduk wrote: >> On 05/06/2017 04:58 AM, Ilari Liusvaara wrote: >> >>> - That automatic wait on 0-RTT failure seems just the kind of feature >>> that gets disabled. Furthermore, 10 second idle on co