Re: [TLS] [Editorial Errata Reported] RFC8996 (7739)

2023-12-21 Thread Rebecca VanRheenen
Greetings, FYI - this report has been deleted as junk (identical text is listed in Original Text, Corrected Text, and Notes, and this text does not even appear in this RFC). Thank you. RFC Editor/rv > On Dec 21, 2023, at 7:02 PM, RFC Errata System > wrote: > > The following errata report

[TLS] [Editorial Errata Reported] RFC8996 (7739)

2023-12-21 Thread RFC Errata System
The following errata report has been submitted for RFC8996, "Deprecating TLS 1.0 and TLS 1.1". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid7739 -- Type: Editorial Reported by: mohamed

Re: [TLS] [EXT] Re: Adoption call for 'TLS 1.2 Feature Freeze'

2023-12-21 Thread Salz, Rich
You can tell the reader whatever you want. The fact remains that if the only way to add QR to the currently deployed TLS-1.2-based “stuff” is modifying TLS-1.2, then that’s what will be done in that particular case. Of course. We’re not the protocol police and nobody from the IETF will come

Re: [TLS] [EXT] Re: Adoption call for 'TLS 1.2 Feature Freeze'

2023-12-21 Thread Blumenthal, Uri - 0553 - MITLL
-1 to Tim. You can tell the reader whatever you want. The fact remains that if the only way to add QR to the currently deployed TLS-1.2-based “stuff” is modifying TLS-1.2, then that’s what will be done in that particular case.   I hope that the majority of the installed base would be

Re: [TLS] Adoption call for 'TLS 1.2 Feature Freeze'

2023-12-21 Thread Ira McDonald
+1 to Tim - tell the reader explicitly that they will only ever get PQC w/ TLS 1.3 or higher. Cheers, - Ira On Thu, Dec 21, 2023, 12:34 PM Tim Hollebeek wrote: > I personally think this point is important enough to be made explicitly > instead of implicitly. > > > > If we want to communicate

Re: [TLS] Adoption call for 'TLS 1.2 Feature Freeze'

2023-12-21 Thread Tim Hollebeek
I personally think this point is important enough to be made explicitly instead of implicitly. If we want to communicate loudly and clearly that post-quantum cryptography is NEVER coming to TLS 1.2, we need to explicitly say that. Otherwise people will say “I know you said TLS 1.2 was