[TLS] PKI dynamics and trust anchor negotiation

2025-02-06 Thread David Benjamin
Hi all, There's been a lot said about root store divergence and fragmentation. We discussed this quite a bit in the interim, but with the continued interest in the topic, and some arguments being brought up on repeat, I wanted to clear some misconceptions, in a separate thread to avoid cluttering

[TLS] I-D Action: draft-ietf-tls-keylogfile-03.txt

2025-02-06 Thread internet-drafts
Internet-Draft draft-ietf-tls-keylogfile-03.txt is now available. It is a work item of the Transport Layer Security (TLS) WG of the IETF. Title: The SSLKEYLOGFILE Format for TLS Authors: Martin Thomson Yaroslav Rosomakho Hannes Tschofenig Name:draft-ietf-tls-

[TLS] Re: PKI dynamics and trust anchor negotiation

2025-02-06 Thread Salz, Rich
First, to correct a misrepresentation: this draft is not a veiled attempt to completely diverge from the Web PKI and fragment the ecosystem. I never said that the draft is such a veiled attempt, and I don’t recall any other postings saying that. I am concerned that the fragmentation is a hi

[TLS] Re: Adoption Call for Trust Anchor IDs

2025-02-06 Thread David Schinazi
I support adoption. I personally agree with the consensus from the trust tussle interim - I do think we should work on the problem as described. Not that that opinion is particularly relevant, because the consensus has already been declared by the chairs anyway. On that note, I haven't seen new in

[TLS] Re: PKI dynamics and trust anchor negotiation

2025-02-06 Thread Watson Ladd
Dear David, I have to start by apologizing. It's not until now on reading your email that I've come to the realization of what the issues were with at least the early negotiation proposals in a way that makes them clearly articulateable, and I think earlier on it would have been more fruitful for

[TLS] Re: PKI dynamics and trust anchor negotiation

2025-02-06 Thread David Benjamin
On Thu, Feb 6, 2025 at 4:40 PM Salz, Rich wrote: > > > First, to correct a misrepresentation: this draft is not a veiled attempt > to completely diverge from the Web PKI and fragment the ecosystem. > > > > I never said that the draft is such a veiled attempt, and I don’t recall > any other postin

[TLS] Re: Adoption Call for Trust Anchor IDs

2025-02-06 Thread Salz, Rich
I've thought about this for a while, and had intended to not say anything, although I (doubtless because of my employer :) have been lobbied by advocates on both sides. I am opposed to adoption. While I can believe that there are real-world issues that this solves, I feel the risk of fragmentin