The following errata report has been submitted for RFC8446,
"The Transport Layer Security (TLS) Protocol Version 1.3".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid8803

--------------------------------------
Type: Technical
Reported by: Loïc Ferreira <[email protected]>

Section: E.1

Original Text
-------------
The PSK binder value forms a binding between a PSK and the current handshake, 
as well as between the session where the PSK was established and the current 
session. This binding transitively includes the original handshake transcript, 
because that transcript is digested into the values which produce the 
resumption master secret.

Corrected Text
--------------
The PSK binder value forms a binding between a PSK and the current handshake, 
as well as between the session where the PSK was established (if established 
via a NewSessionTicket message) and the current session. This binding 
transitively includes the original handshake transcript, because that 
transcript is digested into the values which produce the resumption master 
secret.

Notes
-----
The last sentence is not correct since it does not hold for an external PSK 
(computed independently from the resumption master secret).

NB: section 4.2.11.2 adds this precision: "The PSK binder value forms a binding 
between a PSK and the current handshake, as well as a binding between the 
handshake in which the PSK was generated (if via a NewSessionTicket message) 
and the current handshake."

Instructions:
-------------
This erratum is currently posted as "Reported". (If it is spam, it 
will be removed shortly by the RFC Production Center.) Please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
will log in to change the status and edit the report, if necessary.

--------------------------------------
RFC8446 (draft-ietf-tls-tls13-28)
--------------------------------------
Title               : The Transport Layer Security (TLS) Protocol Version 1.3
Publication Date    : August 2018
Author(s)           : E. Rescorla
Category            : PROPOSED STANDARD
Source              : Transport Layer Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to