If it's true that the only use of this indication is client auth, then option 1 
makes the most sense to me.

-----Original Message-----
From: TLS [mailto:tls-boun...@ietf.org] On Behalf Of Martin Thomson
Sent: Wednesday, October 21, 2015 5:01 PM
To: Eric Rescorla <e...@rtfm.com>
Cc: tls@ietf.org
Subject: Re: [TLS] Allow NamedGroups from the server?

2b. encrypted extensions over ServerHello

If we make this like signature_algorithms, then I think that I prefer option 1. 
 I don't like that signature_algorithms is built that way, I think that it's 
repulsive, but there are some advantages to doing it that way, especially if we 
accept the fact that the client can authenticate multiple times, so I'm willing 
to live with that.

On 21 October 2015 at 16:56, Eric Rescorla <e...@rtfm.com> wrote:
> https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fgithu
> b.com%2ftlswg%2ftls13-spec%2fissues%2f292&data=01%7c01%7cAndrei.Popov%
> 40microsoft.com%7c6625ee4cf40f4f52917108d2da73ea39%7c72f988bf86f141af9
> 1ab2d7cd011db47%7c1&sdata=qOVO5xpSgVIXG6%2fiMyP3zQSbeFwZlrDW1kcqvONCRD
> Y%3d
>
> Presently, RFC 4492 only specifies the EC points it can support in 
> ServerHello, but does not let the server indicate which EC curves it 
> supports. Unless I'm missing something, this means that there's no way 
> for the server to indicate what groups it would support.
>
> That seems less than ideal. There seem like three options here:
>
> 1. Put it in CertificateRequest
> 2. Send it in ServerHello
> 3. Do nothing.
>
> Thoughts?
> -Ekr
>
>
>
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fwww.i
> etf.org%2fmailman%2flistinfo%2ftls&data=01%7c01%7cAndrei.Popov%40micro
> soft.com%7c6625ee4cf40f4f52917108d2da73ea39%7c72f988bf86f141af91ab2d7c
> d011db47%7c1&sdata=%2f612ldpCER8pXNtxSxUfQjhuYcMAIZ2S3o1ozmxqqWI%3d
>

_______________________________________________
TLS mailing list
TLS@ietf.org
https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fwww.ietf.org%2fmailman%2flistinfo%2ftls&data=01%7c01%7cAndrei.Popov%40microsoft.com%7c6625ee4cf40f4f52917108d2da73ea39%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=%2f612ldpCER8pXNtxSxUfQjhuYcMAIZ2S3o1ozmxqqWI%3d

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to