Re: [TLS] draft-ietf-tls-record-limit-01

2017-09-25 Thread Martin Thomson
On Mon, Sep 25, 2017 at 9:01 PM, Hubert Kario wrote: > my understanding of this draft was that the TLS1.3 ContentType is included in > the record limit while it is not included in the TLS 1.3 maximum payload size That's right, I forgot this detail. I subtract 1 for TLS 1.3

Re: [TLS] TLS specification clarification in case of client authentication: different CA with DN different only in case

2017-09-25 Thread Geoffrey Keating
devzero2000 writes: > Hello everyone > > >From the tls 1.2 specification, speaking of client authentication, > https://tools.ietf.org/html/rfc5246#section-7.4.4 par 7.4.4 (but it is the > same for the last tls draft 1.3 par. 4.2.4.) > > when he says: > >

[TLS] TLS specification clarification in case of client authentication: different CA with DN different only in case

2017-09-25 Thread devzero2000
Hello everyone >From the tls 1.2 specification, speaking of client authentication, https://tools.ietf.org/html/rfc5246#section-7.4.4 par 7.4.4 (but it is the same for the last tls draft 1.3 par. 4.2.4.) when he says: certificate_authorities A list of the distinguished names [X501] of

Re: [TLS] draft-ietf-tls-record-limit-01

2017-09-25 Thread Hubert Kario
On Monday, 25 September 2017 04:12:09 CEST Martin Thomson wrote: > Hi Hannes, > > I appreciate that the way that you calculate the available space is > difficult, but I did think very long and hard about this. > > The current approach makes it easier for someone to *comply* with the > size limit