Re: [TLS] TLS 1.3 Authentication using ETSI TS 103 097 and IEEE 1609.2 certificates

2018-09-26 Thread Mounira Msahli
Hi all, Please find attached a new version of the draft. We took account of pevious TLS group comments. William, editor of 1609.2, proposes to add the section certificate verify (section 4.3 in the draft). It concerns the addition of IEEE 1609.2 signature for the the Certificate verify. We

Re: [TLS] TLS 1.3 Authentication using ETSI TS 103 097 and IEEE 1609.2 certificates

2018-09-26 Thread Ilari Liusvaara
On Wed, Sep 26, 2018 at 05:57:28PM +0200, Mounira Msahli wrote: > Hi all, > > Please find attached a new version of the draft. We took account of > pevious TLS group comments. William, editor of 1609.2, proposes to > add the section certificate verify (section 4.3 in the draft). > It concerns t

[TLS] I-D Action: draft-housley-tls-tls13-cert-with-extern-psk-02.txt

2018-09-26 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Transport Layer Security WG of the IETF. Title : TLS 1.3 Extension for Certificate-based Authentication with an External Pre-Shared Key Author : Ru

Re: [TLS] I-D Action: draft-housley-tls-tls13-cert-with-extern-psk-02.txt

2018-09-26 Thread Russ Housley
I believe that this version resolves all of the issues that were raised during the Montreal meeting and the mail list. The biggest change: This version allows external PSKs and resumption PSKs to be used withe certificates. Russ > A New Internet-Draft is available from the on-line Internet-D

Re: [TLS] I-D Action: draft-housley-tls-tls13-cert-with-extern-psk-02.txt

2018-09-26 Thread David Benjamin
The resumption flow in this draft looks odd to me. While the handshake flow is the same, the use cases differ between which identity should be in play and when to use it. Separate extensions and documents may be better. (I suppose saying the semantics change completely between resumption and extern