Re: [TLS] Issue 471: Relax requirement to invalidate sessions on fatal errors

2016-05-24 Thread Benjamin Kaduk
Version -13 includes neither the word "stateful" nor "stateless", so if Yaron's proposal is taken, it would be better to explicitly refer to session tickets or ID-based resumption (with appropriate citations). That said, I'm not sure I see the need for a normative requirement on the server; we

Re: [TLS] Issue 471: Relax requirement to invalidate sessions on fatal errors

2016-05-22 Thread Yaron Sheffer
This still makes the *stateful* implementation much more deterministic and those implementations are common enough. So how about: Alert messages with a level of fatal result in the immediate termination of the connection. In this case, other connections corresponding to the session may

[TLS] Issue 471: Relax requirement to invalidate sessions on fatal errors

2016-05-21 Thread Eric Rescorla
https://github.com/tlswg/tls13-spec/issues/471 http://tlswg.github.io/tls13-spec/#alert-protocol says: "Alert messages with a level of fatal result in the immediate termination of the connection. In this case, other connections corresponding to the session may continue, but the session