[TLS] Weekly github digest (TLS Working Group Drafts)

2020-12-05 Thread Repository Activity Summary Bot
Issues -- * tlswg/draft-ietf-tls-esni (+0/-0/3) 1 issues received 3 new comments: - #369 Potential SNI leak via cross-ECH resumption (3 by cjpatton, davidben, kjacobs-moz) https://github.com/tlswg/draft-ietf-tls-esni/issues/369 * tlswg/draft-ietf-tls-external-psk-importer

Re: [TLS] TLS Flags Open Question

2020-12-05 Thread Eric Rescorla
On Sat, Dec 5, 2020 at 7:05 AM Yoav Nir wrote: > Hi. > > At IETF 108 a question was raised about The TLS Flags extension. What > payloads on the server side can include this extension? > > The “candidates” are ServerHello, EncryptedExtensions, Certificate, and > NewSessionTicket. > > The only

[TLS] TLS Flags Open Question

2020-12-05 Thread Yoav Nir
Hi. At IETF 108 a question was raised about The TLS Flags extension. What payloads on the server side can include this extension? The “candidates” are ServerHello, EncryptedExtensions, Certificate, and NewSessionTicket. The only one that is controversial here (I think) is ServerHello,

Re: [TLS] [Last-Call] Last Call: (Deprecating TLSv1.0 and TLSv1.1) to Best Current Practice

2020-12-05 Thread Christian de Larrinaga
Nick Hilliard writes: > > What's relevant to the IETF is that it needs to make sound technical > recommendations about the usability and appropriateness of standards. > If organisations choose not to keep supporting some or all of their > product lines, this shouldn't impact the IETF's

Re: [TLS] [Last-Call] Last Call: (Deprecating TLSv1.0 and TLSv1.1) to Best Current Practice

2020-12-05 Thread Nick Hilliard
Ted Lemon wrote on 05/12/2020 01:32: Of course no product has infinite lifetime, but lots of iot stuff is expected to be in the walls for 30 years. Radiology equipment lasts decades. Etc. yip, this is one of the reasons that medical and other certified equipment (e.g. military, industrial, etc)