Re: [TLS] ECH-HRR Design Team output

2023-08-29 Thread Stephen Farrell
Hiya, Wasn't sure which email to reply to, but this one'll do... Until very recently I was of the opinion that ECH split-mode when one hits HRR with our current design was significantly problematic. The main reason was that supporting that scenario with haproxy seemed like it'd require

Re: [TLS] [Technical Errata Reported] RFC8446 (7620)

2023-08-29 Thread Viktor Dukhovni
On Tue, Aug 29, 2023 at 10:55:56AM +0200, Ben Smyth wrote: > TLS 1.2 dictates: Either party may initiate a close by sending a > close_notify alert...The other party MUST respond with a close_notify > alert of its own and close down the connection immediately, discarding > any pending writes. > >

Re: [TLS] [Technical Errata Reported] RFC8446 (7620)

2023-08-29 Thread Eric Rescorla
On Tue, Aug 29, 2023 at 1:56 AM Ben Smyth wrote: > On Mon, 28 Aug 2023, Eric Rescorla, wrote: > >> ...there are quite a few situations in which endpoints close the connection before receiving a close_notify, for instance, when they receive an end of data message in the application

Re: [TLS] [Technical Errata Reported] RFC8446 (7620)

2023-08-29 Thread Ben Smyth
On Mon, 28 Aug 2023, Eric Rescorla, wrote: > ...there are quite a few situations in which endpoints close the >>> connection before receiving a close_notify, for instance, when they receive >>> an end of data message in the application protocol or when they time out. >>> The former case is