Re: [TLS] Epochs for ACKs

2020-04-20 Thread Hanno Becker
Hi Ekr, Great, thanks, I left comments on that PR. Cheers, Hano From: Eric Rescorla Sent: Sunday, April 19, 2020 10:39 PM To: Hanno Becker Cc: tls@ietf.org Subject: Re: [TLS] Epochs for ACKs I have posted a PR to clarify this: https://github.com/tlswg/dtls13-

[TLS] Comments on draft-dt-tls-external-psk-guidance-01

2020-04-20 Thread Hollenbeck, Scott
Here are a few comments gathered from Verisign Labs on draft-dt-tls-external-psk-guidance-01: 1. Sec. 6, requirement 1 states "Low entropy keys are only secure against active attack if a Password Authenticated Key Exchange (PAKE) is used with TLS." "only secure ... if" may be too strong a st

Re: [TLS] [Uta] CBOR Certificate Compression of RFC 7925 certificates suitable for cTLS

2020-04-20 Thread John Mattsson
Hi Sean, The documents (planned to be replaced with a single document) specifies a new compression algorithm and makes an IANA registration of that new compression algorithm for use with draft-ietf-tls-certificate-compression. The difference compared to the already registered algorithms (zlib,

Re: [TLS] Ticket request PR#20

2020-04-20 Thread Viktor Dukhovni
On Mon, Apr 20, 2020 at 12:18:28PM -0700, Nick Harper wrote: > > That precludes clients from soliciting 0 *only* from servers that > > support some future specification, and otherwise getting 1 from > > servers that support only the current specification. > > > > That's not true. Suppose there's