Re: [TLS] Uplifting 5289

2017-03-17 Thread Stephen Farrell
FWIW, the IETF LC for this has ended now and I plan to send the approval message for the uplift to the secretariat later today. Thanks, S. On 16/03/17 20:33, Yoav Nir wrote: > Oh, sorry. I missed that it was Informational. > > In that case there’s just the issue that it has ECDH ciphersuites at

Re: [TLS] Uplifting 5289

2017-03-16 Thread Yoav Nir
Oh, sorry. I missed that it was Informational. In that case there’s just the issue that it has ECDH ciphersuites at a time where 4492bis is deprecating all the other ones. But some of the ciphersuites in there are in wide enough use that it shouldn’t remain Informational. Yes, it should be upl

Re: [TLS] Uplifting 5289

2017-03-16 Thread Eric Rescorla
This is actually uplift to PS. On Thu, Mar 16, 2017 at 12:16 PM, Yoav Nir wrote: > > On 16 Mar 2017, at 21:01, kathleen.moriarty.i...@gmail.com wrote: > > > > Please excuse typos, sent from handheld device > > On Mar 16, 2017, at 11:37 AM, Yoav Nir wrote: > > > On 16 Mar 2017, at 17:17, Eric Re

Re: [TLS] Uplifting 5289

2017-03-16 Thread Yoav Nir
> On 16 Mar 2017, at 21:01, kathleen.moriarty.i...@gmail.com wrote: > > > > Please excuse typos, sent from handheld device > >> On Mar 16, 2017, at 11:37 AM, Yoav Nir wrote: >> >> >>> On 16 Mar 2017, at 17:17, Eric Rescorla wrote: >>> >>> Hi folks >>> >>> I note that we are proposing to

Re: [TLS] Uplifting 5289

2017-03-16 Thread kathleen . moriarty . ietf
Please excuse typos, sent from handheld device > On Mar 16, 2017, at 11:37 AM, Yoav Nir wrote: > > >> On 16 Mar 2017, at 17:17, Eric Rescorla wrote: >> >> Hi folks >> >> I note that we are proposing to uplift RFC 5289 to PS, despite the fact that >> it >> standardizes some CBC cipher sui

Re: [TLS] Uplifting 5289

2017-03-16 Thread Yoav Nir
> On 16 Mar 2017, at 17:17, Eric Rescorla wrote: > > Hi folks > > I note that we are proposing to uplift RFC 5289 to PS, despite the fact that > it > standardizes some CBC cipher suites, which the WG is looking to move away > from. I recognize that these are the only cipher suites you can use

Re: [TLS] Uplifting 5289

2017-03-16 Thread Sean Turner
ekr, While we’re moving the entire document to PS, we’re also following it with https://datatracker.ietf.org/doc/draft-ietf-tls-iana-registry-updates/ that adds a “Recommended" column that is not (see s6) going to include marking “Y” for any of the CBC algorithms. So, I think we’re okay. spt

[TLS] Uplifting 5289

2017-03-16 Thread Eric Rescorla
Hi folks I note that we are proposing to uplift RFC 5289 to PS, despite the fact that it standardizes some CBC cipher suites, which the WG is looking to move away from. I recognize that these are the only cipher suites you can use in TLS 1.0 and 1.1, but we also want people to move away from them.