[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Comments on TLS identity protection



Hi Pasi,

Pasi.Eronen@xxxxxxxxx a écrit :
If the extra computations occur only in very rare situations, it's perfectly reasonable not to care about it

I disagree. Anybody can connect to your server at any time and doing uncompleted double handshake. It is not a rare situation.


(at least sufficiently to spend the $$$ for designing, implementing, testing, deploying, etc. a new mechanism).

How much :). The proposed changes are minimal.

My point was that we *already* have one mechanism for client privacy
in TLS. Thus IMHO the right question to ask is *NOT* which one is more efficient and preferred, but rather is the existing mechanism so bad that we should spend effort in adding *another* one?


I tried to explain why double handshake is not good in terms of optimization and security consideration.

Well, I know your opinion regarding the double handshake since Montreal's meeting when you said "it would the same end result as adding a couple of roundtrips". Note that double handshake at this time was not described in draft-simon-emu-rfc2716bis-03 and it has been added by August 2006, one month after Montreal meeting and three months after draft-urien-badra-eap-tls-identity-protection :)

I think deployment-wise, double handshake has the advantage that
it's already specified and implemented.

Any link to test the implementation, please?

Best regards,
Badra


_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls