[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Status of IDEA and single-DES (ticket #64)
Paul and all,
I ad the same question Paul.
Regards,
Spokesman for INEGroup LLA. - (Over 277k members/stakeholders strong!)
"Obedience of the law is the greatest freedom" -
Abraham Lincoln
"Credit should go with the performance of duty and not with what is
very often the accident of glory" - Theodore Roosevelt
"If the probability be called P; the injury, L; and the burden, B;
liability depends upon whether B is less than L multiplied by
P: i.e., whether B is less than PL."
United States v. Carroll Towing (159 F.2d 169 [2d Cir. 1947]
===============================================================
Updated 1/26/04
CSO/DIR. Internet Network Eng. SR. Eng. Network data security IDNS.
div. of Information Network Eng. INEG. INC.
ABA member in good standing member ID 01257402 E-Mail
jwkckid1@xxxxxxxxxxxxx
My Phone: 214-244-4827
Paul Hoffman wrote:
> At 1:02 PM -0800 1/22/08, Nelson B Bolyard wrote:
> >Pasi.Eronen@xxxxxxxxx wrote, On 2008-01-22 00:41:
> >
> >> (2) Keep IDEA and single-DES in the TLS 1.2 main specification,
> >> but include a short advice along the lines described above.
> >
> >I strongly prefer that choice.
> >
> >If we say "MUST NOT" or even merely remove the definitions of those
> >suites from TLS 1.2, then interoperability problems will certainly
> >arise. Servers will be created that reject client hellos that contain
> >those cipher suite numbers, even if those hellos also include other
> >cipher suite numbers that are acceptable.
> >
> >I'd even go so far as to suggest that text be added stating that
> >compliant TLS 1.2 implementations MUST NOT reject client hellos simply
> >because those client hellos contain cipher suite numbers that are
> >deprecated, or undefined in TLS 1.2, or are "MUST NOT" (as in export
> >cipher suites) for TLS 1.2. If no acceptable cipher suite is found,
> >that's a problem but no server should ever reject a client hello simply
> >because it contains one or more cipher suite numbers that are unpopular.
> >
> >(Yes, I have seen servers that actually do that.)
>
> Yeesh. New levels of cluelessness among developers are discovered every day.
>
> If we add the text you want (which seems fine to me), would you then
> prefer #1 over #2?
>
> --Paul Hoffman, Director
> --VPN Consortium
>
> _______________________________________________
> TLS mailing list
> TLS@xxxxxxxxxxxxxx
> https://www1.ietf.org/mailman/listinfo/tls
_______________________________________________
TLS mailing list
TLS@xxxxxxxxxxxxxx
https://www1.ietf.org/mailman/listinfo/tls