Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-22 Thread tirumal reddy
On Thu, 17 Sep 2020 at 01:38, Nick Harper wrote: > > > On Wed, Sep 16, 2020 at 12:24 AM tirumal reddy wrote: > >> Hi Nick, >> >> Please see inline >> >> On Wed, 16 Sep 2020 at 06:00, Nick Harper wrote: >> >>> I agree with EKR, Ben Schwartz, and Watson Ladd's concerns on this draft. >>> >>> The

Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-22 Thread tirumal reddy
On Sun, 20 Sep 2020 at 14:05, Eliot Lear wrote: > > > > On 11 Sep 2020, at 12:40, Nick Lamb wrote: > > > > On Fri, 11 Sep 2020 12:32:03 +0530 > > tirumal reddy wrote: > > > >> The MUD URL is encrypted and shared only with the authorized > >> components in the network. An attacker cannot read t

Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-22 Thread Ben Schwartz
I'm not able to understand the new text in Section 6. Are you saying that clients MUST include all the listed extensions/features, but MAY also include extensions/features not listed in the MUD profile? So the MUD profile only acts as a "minimum" set of features? On Tue, Sep 22, 2020 at 7:34 AM