Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Eric Rescorla
Document: draft-jackson-tls-cert-abridge-00.txt Hi Dennis, Thanks for sending this. This seems like great work and a big improvement. I have a number of comments below, mostly minor. S 1.1. The existing compression schemes used in [TLSCertCompress] have been shown to deliver a substantial

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Salz, Rich
> I would love to get feedback from the working group on whether the draft is worth developing further. I read your document [1] and found it very interesting. I found the handling of extensions complicated, although I admit to reading that part very quickly. How much simpler would things b

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Dennis Jackson
On 07/07/2023 17:42, Salz, Rich wrote: I would love to get feedback from the working group on whether the draft is worth developing further. I read your document [1] and found it very interesting. Thanks Rich! I found the handling of extensions complicated, although I admit to reading tha

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Dennis Jackson
Thank you for the comments. I'll fix most of them - responses inline for the rest: On 07/07/2023 17:38, Eric Rescorla wrote: S 3.1.2.    7.  Order the list by the date each certificate was included in the        CCADB, breaking ties with the lexicographic ordering of the        SHA256 certific

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Salz, Rich
> I don't follow your comment about the handling of extensions, the code doing the compression and decompression isn't aware of what an extension is or handling them specially, its just swapping strings. In order to compress the larger strings which issuers add to end entity certificates So, yo

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Eric Rescorla
On Fri, Jul 7, 2023 at 1:21 PM Dennis Jackson wrote: > Thank you for the comments. I'll fix most of them - responses inline for > the rest: > > On 07/07/2023 17:38, Eric Rescorla wrote: > > S 3.1.2. > >7. Order the list by the date each certificate was included in the >CCADB, breakin

[TLS] I-D Action: draft-ietf-tls-rfc8446bis-08.txt

2023-07-07 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This Internet-Draft is a work item of the Transport Layer Security (TLS) WG of the IETF. Title : The Transport Layer Security (TLS) Protocol Version 1.3 Author : Eric Rescorla Filename

[TLS] I-D Action: draft-ietf-tls-rfc8446bis-09.txt

2023-07-07 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This Internet-Draft is a work item of the Transport Layer Security (TLS) WG of the IETF. Title : The Transport Layer Security (TLS) Protocol Version 1.3 Author : Eric Rescorla Filename

Re: [TLS] Abridged Certificate Compression

2023-07-07 Thread Kampanakis, Panos
Hi Dennis, This is an interesting draft. The versioned dictionary idea for ICA and Root CAs especially was something I was considering for the ICA Suppression draft [1] given the challenges brought up before about outages with stale dictionary caches. As you point out in the draft, cTLS uses s