[TLS] Re: Adoption call for TLS 1.2 Update for Long-term Support

2024-11-07 Thread Peter Gutmann
David A. Cooper writes: >It would also be inappropriate to adopt it as a WG document, especially as a >standards track document, I was thinking more informational. Actually I'm not too fussed over what category it's in, as long as it gets out of its current limbo. >It would be contrary to the

[TLS] Re: FATT process update

2024-11-07 Thread Muhammad Usama Sardar
Thank you for clearly writing down the process and continuing to improve it. I particularly like the "understood" part, which is IMO a key benefit of formal methods. Also, thanks for clearly mentioning the current members in FATT process. I do notice that current FATT is slightly different fro

[TLS] Re: [TLS]Consensus call for RFC8773bis Formal Analysis Requirement

2024-11-07 Thread Muhammad Usama Sardar
Dear chairs, I had a short meeting with Russ today and we don't understand /precisely/ what the FATT is worried about and therefore why a formal analysis is required at all. Extending CH and SH to negotiate external PSK follows the best current practice for extending TLS. Moreover, external

[TLS] Bytes server -> client

2024-11-07 Thread Bas Westerbaan
Hi all, Just wanted to highlight a blog post we just published. https://blog.cloudflare.com/another-look-at-pq-signatures/ At the end we share some statistics that may be of interest: On average, around 15 million TLS connections are established with > Cloudflare per second. Upgrading each to ML

[TLS] Re: Bytes server -> client

2024-11-07 Thread Kampanakis, Panos
Hi Bas, That is interesting and surprising, thank you. I am mostly interested in the ~63% of non-resumed sessions that would be affected by 10-15KB of auth data. It looks like your data showed that each QUIC conn transfers about 4.7KB which is very surprising to me. It seems very low. In exper

[TLS] Re: Adoption call for TLS 1.2 Update for Long-term Support

2024-11-07 Thread Alicja Kario
On Thursday, 7 November 2024 14:58:02 CET, Peter Gutmann wrote: The current late-to-the-party response seems to be mostly a chorus of "I haven't read it but I know I don't like it". There is no need for personal attacks. -- Regards, Alicja (nee Hubert) Kario Principal Quality Engineer, RHEL Cry

[TLS] Re: DTLS 1.3 replay protection of post-handshake messages?

2024-11-07 Thread John Mattsson
 Hi Eric, Martin, You suggested writing an RFC require replay protection in DTLS 1.3. I was just planning to start writing such a -00 draft but now I see there is “DTLS Clarifications - David Benjamin (15 min)” on the agenda. If that means RFC9147bis, it might be better to have it there. But b

[TLS] Re: Bytes server -> client

2024-11-07 Thread Raghu Saxena
Dear Bas, Thanks for sharing. I'm quite curious about this bit in particular: On 11/7/24 10:06 PM, Bas Westerbaan wrote: On average, around 15 million TLS connections are established with Cloudflare per second. Upgrading each to ML-DSA, would take 1.8Tbps, which is 0.6% of our curr