[TLS]Re: TLS trust expressions and certificate_authorities

2024-06-17 Thread David Benjamin
On Mon, Jun 17, 2024 at 9:10 AM Dennis Jackson wrote: > David Benjamin wrote: > > Broadly, the fingerprinting story is the same as the > certificate_authorities extension, in that trust expressions targets the > cases where the trust anchor list is common to your desired anonymity set, > whatever

[TLS]Re: Working Group Last Call for Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings

2024-06-17 Thread Salz, Rich
> This email starts the working group last call for "Bootstrapping TLS > Encrypted ClientHello with DNS Service Bindings” I-D The draft says: " It is applicable to all TLS-based protocols (including DTLS [RFC9147] and QUIC version 1 [RFC9001]) unless otherwise specified." But the ECH draft says

[TLS]Re: TLS trust expressions and certificate_authorities

2024-06-17 Thread Dennis Jackson
On 11/06/2024 02:24, Devon O'Brien wrote: Focusing on the actual draft text, the TLS trust expressions extension does not represent any kind of major paradigm shift, primarily due to its strong similarity to the existing certificate_authorities TLS extension. [...] There is no fundamental c