Re: [TLS] ClientFinished calculation following EndOfEarlyData in draft-19

2017-03-24 Thread Eric Rescorla
https://github.com/tlswg/tls13-spec/pull/912 On Fri, Mar 24, 2017 at 6:32 AM, Eric Rescorla wrote: > > > On Fri, Mar 24, 2017 at 6:27 AM, Matt Caswell wrote: > >> In draft-19 EndOfEarlyData was changed from an alert to a handshake >> message. Therefore I would have expected to see it included i

Re: [TLS] ClientFinished calculation following EndOfEarlyData in draft-19

2017-03-24 Thread Eric Rescorla
On Fri, Mar 24, 2017 at 6:27 AM, Matt Caswell wrote: > In draft-19 EndOfEarlyData was changed from an alert to a handshake > message. Therefore I would have expected to see it included in the > calculation of the ClientFinished (where early data is accepted). > However section 4.4.4 defines the v

Re: [TLS] ClientFinished calculation following EndOfEarlyData in draft-19

2017-03-24 Thread David Benjamin
I think it's a typo. My understanding is EndOfEarlyData was meant to be in the transcript. David On Fri, Mar 24, 2017 at 9:27 AM Matt Caswell wrote: > In draft-19 EndOfEarlyData was changed from an alert to a handshake > message. Therefore I would have expected to see it included in the > calcu

[TLS] ClientFinished calculation following EndOfEarlyData in draft-19

2017-03-24 Thread Matt Caswell
In draft-19 EndOfEarlyData was changed from an alert to a handshake message. Therefore I would have expected to see it included in the calculation of the ClientFinished (where early data is accepted). However section 4.4.4 defines the verify_data as follows: verify_data = HMAC(fini