[TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-12 Thread Simon Mangel
Dear all, tl;dr: We plan on updating RFC 7924 for TLS 1.3 and would like to check whether there is interest in the TLS wg. The TLS Cached Information extension [RFC7924] has not seen significant adoption since its specification. However, we still believe it to be an interesting candidate in upcom

Re: [TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-15 Thread Simon Mangel
Hi Dennis, > Can you expand more on the intended use case? When would it make sense > to use a RFC7924-like mechanism over TLS 1.3's session resumption? > > I skimmed RFC 7924 and session resumption seems strictly better as it's > already widely deployed, allows for the DH handshake to be optio

Re: [TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-25 Thread Simon Mangel
Hi Dennis, Am Dienstag, dem 15.08.2023 um 13:20 +0100 schrieb Dennis Jackson: > > Two observations:  > > > > 1. The reason ticket lifetimes are often shorter than 7 days is > > because they can be used to track user visits. Caching end-entity > > certificates as in RFC 7924 over a long period

Re: [TLS] RFC7924 (Cached Information Extension) Update for TLS 1.3

2023-08-25 Thread Simon Mangel
Please ignore that weird German part in the unformatted mail, my mail client strangely hid it from me in the HTML version. Best, Simon Am Freitag, dem 25.08.2023 um 16:18 +0200 schrieb Simon Mangel: > Hi Dennis, > > Am Dienstag, dem 15.08.2023 um 13:20 +0100 schrieb Denni