Re: [TLS] TLS 1.2 Long-term Support Profile vs HTTP/2.0

2016-04-03 Thread Yoav Nir
> On 3 Apr 2016, at 8:44 AM, Martin Thomson wrote: > > On 3 April 2016 at 18:18, Peter Gutmann wrote: >> I think the reason why there's no rationale is because there's no rational >> explanation for lumping TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 in with the likes >> of TLS_RSA_EXPORT_WITH_RC4_40_M

Re: [TLS] TLS 1.2 Long-term Support Profile vs HTTP/2.0

2016-04-03 Thread Martin Thomson
On 3 April 2016 at 18:18, Peter Gutmann wrote: > I think the reason why there's no rationale is because there's no rational > explanation for lumping TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 in with the likes > of TLS_RSA_EXPORT_WITH_RC4_40_MD5. You evidently believe that a decision to move to AEAD on

Re: [TLS] TLS 1.2 Long-term Support Profile vs HTTP/2.0

2016-04-03 Thread Peter Gutmann
Nikos Mavrogiannopoulos writes: >I liked the idea of an LTS profile for TLS 1.2, however I just realized that >RFC7540 [0] blacklists (with no rationale) 3 out of the 4 LTS ciphersuites >and I'm wondering how practically useful will be that profile. I chose the two sets of algorithms that were s

Re: [TLS] TLS 1.2 Long-term Support Profile vs HTTP/2.0

2016-04-01 Thread Dave Garrett
On Friday, April 01, 2016 03:54:51 am Nikos Mavrogiannopoulos wrote: > On Wed, 2016-03-16 at 12:36 +, Peter Gutmann wrote: > > After a number of, uh, gentle reminders from people who have been > > waiting for > > this, I've finally got around to posting the TLS-LTS draft I > > mentioned a while

[TLS] TLS 1.2 Long-term Support Profile vs HTTP/2.0

2016-04-01 Thread Nikos Mavrogiannopoulos
On Wed, 2016-03-16 at 12:36 +, Peter Gutmann wrote: > After a number of, uh, gentle reminders from people who have been > waiting for > this, I've finally got around to posting the TLS-LTS draft I > mentioned a while > back.  It's now available as: > > > http://www.ietf.org/id/draft-gutmann-tl