Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-12 Thread Terry Burton
On Wed, 12 Aug 2020 at 07:17, Mohit Sethi M wrote: > Thank you again for the feedback. I have updated the text in github: > https://emu-wg.github.io/draft-ietf-emu-eap-tls13/draft-ietf-emu-eap-tls13.html#rfc.section.5.7 > > Here is the diff for your convenience: >

Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-12 Thread Mohit Sethi M
Hi Alan and Terry, Thank you again for the feedback. I have updated the text in github: https://emu-wg.github.io/draft-ietf-emu-eap-tls13/draft-ietf-emu-eap-tls13.html#rfc.section.5.7 Here is the diff for your convenience:

Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-11 Thread Alan DeKok
On Aug 11, 2020, at 8:40 AM, Terry Burton wrote: > > On Tue, 11 Aug 2020 at 09:11, Mohit Sethi M > wrote: >> >> Section 5.7 "Resumption" says: >> >>> When resumption occurs, it is based on cached information at the TLS >>> layer. To perform resumption in a secure way, the EAP-TLS peer

Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-11 Thread Terry Burton
On Tue, 11 Aug 2020 at 09:11, Mohit Sethi M wrote: > > Section 5.7 "Resumption" says: > > > When resumption occurs, it is based on cached information at the TLS > >layer. To perform resumption in a secure way, the EAP-TLS peer and > >EAP-TLS server need to be able to securely retrieve

Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-11 Thread Mohit Sethi M
Hi Terry, Section 5.7  "Resumption" says: > When resumption occurs, it is based on cached information at the TLS >    layer.  To perform resumption in a secure way, the EAP-TLS peer and >    EAP-TLS server need to be able to securely retrieve authorization >    information such as certificate

Re: [Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-10 Thread Alan DeKok
On Aug 10, 2020, at 11:58 AM, Terry Burton wrote: > Reading "Using EAP-TLS with TLS 1.3" I find the text potentially > misleading when it comes to resumption within TLS 1.3, specifically > for the case where the peer wishes to re-validate the certificate > originally provided by the server during

[Emu] draft-ietf-emu-eap-tls13: Client re-validation of server authority information during resumption

2020-08-10 Thread Terry Burton
Hi, Reading "Using EAP-TLS with TLS 1.3" I find the text potentially misleading when it comes to resumption within TLS 1.3, specifically for the case where the peer wishes to re-validate the certificate originally provided by the server during the initial handshake using only its locally cached