[TLS] Weekly github digest (TLS Working Group Drafts)

2020-04-26 Thread Repository Activity Summary Bot
Issues -- * tlswg/draft-ietf-tls-esni (+1/-0/💬8) 1 issues created: - Restrict ECHO inner/outer variance for interop purposes (by sftcd) https://github.com/tlswg/draft-ietf-tls-esni/issues/223 5 issues received 8 new comments: - #223 Restrict ECHO inner/outer variance for interop p

Re: [TLS] DTLS 1.3 AEAD additional data

2020-04-26 Thread Thomas Fossati
On 25/04/2020, 11:43, "Thomas Fossati" wrote: > On 25/04/2020, 11:11, "Thomas Fossati" wrote: > > On 25/04/2020, 01:30, "Christopher Wood" > > wrote: > > > On Thu, Apr 23, 2020, at 2:17 PM, Eric Rescorla wrote: > > > > 1. Allowing implicit CIDs is very recent (it was introduced in > > > > -34) >

Re: [TLS] Choice of Additional Data Computation

2020-04-26 Thread Hanno Becker
Hi, Thanks Chris for your thoughts. Yes, it seems that specific formal analysis is needed, since we're dealing with the new situation that - in contrast to TLS 1.3 - shortened or omitted fields in the DTLS 1.3 headers (e.g. epoch, length, CID) introduce a notion of implicit context to a record

Re: [TLS] DTLS 1.3 AEAD additional data

2020-04-26 Thread Christopher Wood
On Sun, Apr 26, 2020, at 2:37 AM, Thomas Fossati wrote: > On 25/04/2020, 11:43, "Thomas Fossati" wrote: > > On 25/04/2020, 11:11, "Thomas Fossati" wrote: > > > On 25/04/2020, 01:30, "Christopher Wood" > > > wrote: > > > > On Thu, Apr 23, 2020, at 2:17 PM, Eric Rescorla wrote: > > > > > 1. Allowi

Re: [TLS] Choice of Additional Data Computation

2020-04-26 Thread Eric Rescorla
On Sun, Apr 26, 2020 at 2:43 AM Hanno Becker wrote: > Hi, > > Thanks Chris for your thoughts. > > Yes, it seems that specific formal analysis is needed, since we're > dealing with the new > situation that - in contrast to TLS 1.3 - shortened or omitted fields in > the DTLS 1.3 headers > (e.g. epo

[TLS] I-D Action: draft-ietf-tls-ctls-00.txt

2020-04-26 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Transport Layer Security WG of the IETF. Title : Compact TLS 1.3 Authors : Eric Rescorla Richard Barnes

Re: [TLS] Choice of Additional Data Computation

2020-04-26 Thread Martin Thomson
On Sat, Apr 25, 2020, at 01:56, chris - wrote: > However, the formal > models of [1,2] assume reliable transport (i.e., TCP): failure to > deliver packets in order is deemed an attack. Therefore, the > definitions would need to be changed in order to account for the case > of DTLS. (I'm not sur