Re: [TLS] Abridged Certificate Compression

2023-07-10 Thread Dennis Jackson
Hi Panos, On 08/07/2023 02:49, Kampanakis, Panos wrote: Hi Dennis, This is an interesting draft. Thanks! The versioned dictionary idea for ICA and Root CAs especially was something I was considering for the ICA Suppression draft [1] given the challenges brought up before about outages with

Re: [TLS] Abridged Certificate Compression

2023-07-10 Thread Dennis Jackson
On 07/07/2023 21:28, Eric Rescorla wrote: S 3.2.1 How much value are you getting from the CT logs? It seems like additional complexity. I agree with your comment about having this submitted to CCADB. It seemed the fairest repeatable way to check whether a CA was offer

Re: [TLS] Abridged Certificate Compression

2023-07-10 Thread Ilari Liusvaara
On Thu, Jul 06, 2023 at 11:18:01PM +0100, Dennis Jackson wrote: > Hi all, > > I've submitted the draft below that describes a new TLS certificate > compression scheme that I'm calling 'Abridged Certs' for now. The aim is to > deliver excellent compression for existing classical certificate chains

Re: [TLS] Abridged Certificate Compression

2023-07-10 Thread Eric Rescorla
On Mon, Jul 10, 2023 at 10:54 AM Dennis Jackson wrote: > > On 07/07/2023 21:28, Eric Rescorla wrote: > > S 3.2.1 >> How much value are you getting from the CT logs? It seems like >> additional complexity. I agree with your comment about having >> this submitted to CCADB. >> >> It seemed the faire

[TLS] Hybrid Key Exchange in TLS 1.3 section 5

2023-07-10 Thread David Finnie
Hi folks, Nice work on the draft by all so far. I had some comments/questions on section 5: * A very minor issue: Section 5.1 has 3 instances of the misspelling "varient". * Section 5.2: The last sentence: "Both sides uses their copy of the shared secret as a component within the hybrid