Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

2019-03-08 Thread John Mattsson
Hi, Thanks for driving this. Great work. I would like to see deprecation of done more often in IETF and elsewhere. 3GPP has deprecated TLS 1.0 and DTLS 1.0 some years ago (but could at that time not deprecate TLS 1.1 due to interop with older releases). I would estimate that 3GPP will

Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

2019-03-08 Thread Julien ÉLIE
Hi Stephen, And RFC 7525 (belonging to BCP 195) states in Section 3.1.1:    o  Implementations SHOULD NOT negotiate TLS version 1.1 [...]    o  Implementations MUST support TLS 1.2 [RFC5246] and MUST prefer to   negotiate TLS version 1.2 over earlier versions of TLS. That's why I

Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

2019-03-08 Thread Stephen Farrell
Hiya, On 08/03/2019 19:31, Julien ÉLIE wrote: > Hi Stephen, >>> That's why I suggest draft-ietf-tls-oldversions-deprecate does not >>> update RFC 4642.  It is no longer useful. >>> Are you OK with this analysis? >> >> Sorta:-) I think these are overlapping but not quite >> identical updates.

Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

2019-03-08 Thread Julien ÉLIE
Hi Stephen, That's why I suggest draft-ietf-tls-oldversions-deprecate does not update RFC 4642.  It is no longer useful. Are you OK with this analysis? Sorta:-) I think these are overlapping but not quite identical updates. E.g. IIUC 8143 doesn't say to not use TLSv1.1. I added the sentence

Re: [TLS] I-D Action: draft-ietf-tls-oldversions-deprecate-01.txt

2019-03-08 Thread Stephen Farrell
Hi Julien, Thanks for taking the time to check this! On 07/03/2019 20:42, Julien ÉLIE wrote: > Hi Stephen, >> This version attempts to make the few changes discussed >> at the meeting on Monday. I wrote a script that gave me >> a list of 76(!) RFCs this might need to update, and may >> of