[TLS] [Technical Errata Reported] RFC9147 (8108)

2024-09-18 Thread RFC Errata System
The following errata report has been submitted for RFC9147, "The Datagram Transport Layer Security (DTLS) Protocol Version 1.3". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid8108 -- Type: Te

[TLS] DTLS 1.3 and the 0-RTT <-> 1-RTT transition

2024-09-18 Thread David Benjamin
Another issue with RFC 9147: when does the client switch from sending 0-RTT to 1-RTT app data, and when does the server start processing 1-RTT app data from the client? This is less of an open question (I think we match how we already resolved this for QUIC), but is something we should have writte

[TLS] Re: DTLS 1.3 ACKs near the version transition

2024-09-18 Thread David Benjamin
One more wriggle if we wish to allow unencrypted ACKs, though it is fixable. Section 7, says: > During the handshake, ACK records MUST be sent with an epoch which is equal to or higher than the record which is being acknowledged. [...] Implementations SHOULD simply use the highest current sending

[TLS] [Technical Errata Reported] RFC9147 (8107)

2024-09-18 Thread RFC Errata System
The following errata report has been submitted for RFC9147, "The Datagram Transport Layer Security (DTLS) Protocol Version 1.3". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid8107 -- Type: Te