Re: [TLS] TLS 1.3 - method to request uncached shared secrets

2015-07-19 Thread Ilari Liusvaara
On Sat, Jul 18, 2015 at 02:28:40PM -0400, Dave Garrett wrote: On Saturday, July 18, 2015 01:06:33 am Brian Smith wrote: This is not really what I was intending when I suggested the feature. I was intending for their to be an indication, in the ClientHello, that the server should not do any

Re: [TLS] TLS 1.3 - method to request uncached shared secrets

2015-07-19 Thread Dave Garrett
On Sunday, July 19, 2015 05:03:56 pm Viktor Dukhovni wrote: In the current 1.3 draft, there is indeed no client signal. [...] The fix would be for the client to send an empty extension of some sort to signal its desire to elicit a session ticket. Why is the SessionTicket TLS Extension being

Re: [TLS] TLS 1.3 - method to request uncached shared secrets

2015-07-19 Thread Viktor Dukhovni
On Sun, Jul 19, 2015 at 02:56:22PM +0200, Eric Rescorla wrote: I'm not seeing a lot of value here. Remember that servers are not required (and have never been required) to do session resumption, but much of the overhead of doing it (having to have a database, session ticket machinery) is

Re: [TLS] TLS 1.3 - method to request uncached shared secrets

2015-07-19 Thread Eric Rescorla
On Sun, Jul 19, 2015 at 10:17 PM, Brian Smith br...@briansmith.org wrote: On Sun, Jul 19, 2015 at 1:16 PM, Viktor Dukhovni ietf-d...@dukhovni.org wrote: On Sun, Jul 19, 2015 at 02:56:22PM +0200, Eric Rescorla wrote: I'm not seeing a lot of value here. Remember that servers are not