Re: [TLS] consensus call: deprecate all FFDHE cipher suites

2022-12-14 Thread Nimrod Aviram
Let me clarify that the document also has RSA as a MUST NOT. So there will be no reason to read this document and switch from FFDHE to RSA. On Wed, 14 Dec 2022 at 06:09, Peter Gutmann wrote: > Blumenthal, Uri - 0553 - MITLL writes: > > >I do not support deprecation, because there will be deplo

Re: [TLS] consensus call: deprecate all FFDHE cipher suites

2022-12-14 Thread Peter Gutmann
Nimrod Aviram writes: >Let me clarify that the document also has RSA as a MUST NOT. > >So there will be no reason to read this document and switch from FFDHE to >RSA. If you tell people they can't have A but they can't have B either then they're going to have to choose one of the two in order to

Re: [TLS] consensus call: deprecate all FFDHE cipher suites

2022-12-14 Thread Ilari Liusvaara
On Tue, Dec 13, 2022 at 03:51:33PM +, Blumenthal, Uri - 0553 - MITLL wrote: > I do not support deprecation, because there will be deployed devices > (IoT, SCADA) that aren’t upgradable – and the new stuff will have to > access them. Any stuff that needs to access such devices already has to be

Re: [TLS] consensus call: deprecate all FFDHE cipher suites

2022-12-14 Thread Blumenthal, Uri - 0553 - MITLL
True - but, unfortunately, quite a few readers misunderstand that and use depreciation as an excuse to remove support of deprecated algorithms and protocols. Wouldn’t be the first case an RFC gets misinterpreted. Regards,UriOn Dec 14, 2022, at 02:30, Rob Sayre wrote:On Tue, Dec 13, 2022 at 8:14 P