Re: [TLS] Binding imported PSKs to KDFs rather than hash functions

2019-09-17 Thread Christopher Wood
Hi Martin, Thanks for the reply! Please see inline below. On Mon, Sep 16, 2019, at 6:26 PM, Martin Thomson wrote: > There are two points here to consider: > > 1. Whether the key that we are feeding into this process is going to be > used exclusively for that purpose, or whether it might be used

[TLS] Éric Vyncke's No Objection on draft-ietf-tls-sni-encryption-05: (with COMMENT)

2019-09-17 Thread Éric Vyncke via Datatracker
Éric Vyncke has entered the following ballot position for draft-ietf-tls-sni-encryption-05: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to

Re: [TLS] Éric Vyncke's No Objection on draft-ietf-tls-sni-encryption-05: (with COMMENT)

2019-09-17 Thread Barry Leiba
> --Section 3.3 -- > Probably worth expanding "DOS" at first use. Actually, "DoS" (with the small "o") is in the RFC Editor's list of abbreviations that do not need to be expanded. That, of course, doesn't mean that it *shouldn't* be expanded. But it should be spelled with the small "o", in any

Re: [TLS] Binding imported PSKs to KDFs rather than hash functions

2019-09-17 Thread Martin Thomson
On Wed, Sep 18, 2019, at 00:56, Christopher Wood wrote: > > In thinking about the first point, we might want to consider whether > > the KDF that is used in the importer might need to be used in other > > ways. > > To be clear, you're referring to HKDF and its role in deriving ipsk > from eps

[TLS] Adam Roach's Yes on draft-ietf-tls-sni-encryption-05: (with COMMENT)

2019-09-17 Thread Adam Roach via Datatracker
Adam Roach has entered the following ballot position for draft-ietf-tls-sni-encryption-05: Yes When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://w