Re: [TLS] #445: Enhanced New Session Ticket

2016-04-29 Thread Eric Rescorla
On Fri, Apr 29, 2016 at 10:46 AM, Ilari Liusvaara wrote: > On Fri, Apr 29, 2016 at 09:16:07AM -0700, Eric Rescorla wrote: > > On Fri, Apr 29, 2016 at 8:38 AM, Ilari Liusvaara < > ilariliusva...@welho.com> > > wrote: > > > > > On Fri, Apr 29, 2016 at 04:52:08PM +1000, Martin Thomson wrote: > > > >

Re: [TLS] #445: Enhanced New Session Ticket

2016-04-29 Thread Ilari Liusvaara
On Fri, Apr 29, 2016 at 11:30:02AM -0700, Eric Rescorla wrote: > On Fri, Apr 29, 2016 at 10:46 AM, Ilari Liusvaara > wrote: > > > > > > This doesn't seem awesome from the client's perspective. I'm trying to > > make > > > the ordinary PSK-resumption design less of a special case. > > > > Well, the

Re: [TLS] #445: Enhanced New Session Ticket

2016-04-29 Thread Ilari Liusvaara
On Fri, Apr 29, 2016 at 09:16:07AM -0700, Eric Rescorla wrote: > On Fri, Apr 29, 2016 at 8:38 AM, Ilari Liusvaara > wrote: > > > On Fri, Apr 29, 2016 at 04:52:08PM +1000, Martin Thomson wrote: > > > On 29 April 2016 at 15:58, Ilari Liusvaara > > wrote: > > > > EDI looks like rather sizable struc

Re: [TLS] Review of draft-guballa-tls-terminology-03

2016-04-29 Thread Eric Rescorla
On Fri, Apr 29, 2016 at 8:35 AM, Guballa, Jens (Nokia - DE) < jens.guba...@nokia.com> wrote: > Hi Eric, > > > > See below. > > > > *From:* TLS [mailto:tls-boun...@ietf.org] *On Behalf Of *EXT Eric Rescorla > *Sent:* Dienstag, 26. April 2016 19:46 > *To:* tls@ietf.org > *Subject:* [TLS] Review of d

Re: [TLS] #445: Enhanced New Session Ticket

2016-04-29 Thread Eric Rescorla
On Fri, Apr 29, 2016 at 8:38 AM, Ilari Liusvaara wrote: > On Fri, Apr 29, 2016 at 04:52:08PM +1000, Martin Thomson wrote: > > On 29 April 2016 at 15:58, Ilari Liusvaara > wrote: > > >> [HRR state] > > > > > > That enlarges the state that needs to be kept. If one keeps extensions, > > > one only

Re: [TLS] Data Volume Limits Analysis

2016-04-29 Thread Atul Luykx
Hey Martin, You're right, this analysis works for any block cipher with 128 bit output that is "good enough" (a pseudorandom permutation), and so for all versions of AES regardless of the key size. Determining the appropriate key size for the block cipher relies on accounting for possible att

Re: [TLS] #445: Enhanced New Session Ticket

2016-04-29 Thread Ilari Liusvaara
On Fri, Apr 29, 2016 at 04:52:08PM +1000, Martin Thomson wrote: > On 29 April 2016 at 15:58, Ilari Liusvaara wrote: > >> [HRR state] > > > > That enlarges the state that needs to be kept. If one keeps extensions, > > one only needs ~40 bytes. Whereas saving full hash state needs IIRC 114 > > bytes

Re: [TLS] Review of draft-guballa-tls-terminology-03

2016-04-29 Thread Guballa, Jens (Nokia - DE)
Hi Eric, See below. From: TLS [mailto:tls-boun...@ietf.org] On Behalf Of EXT Eric Rescorla Sent: Dienstag, 26. April 2016 19:46 To: tls@ietf.org Subject: [TLS] Review of draft-guballa-tls-terminology-03 I recently reviewed draft-guballa-tls-terminology-03. Comments below. OVERALL I