[TLS]Re: [EXTERNAL] Re: WG Adoption for TLS Trust Expressions

2024-05-22 Thread Carl Wallace
From: Joseph Salowey Date: Wednesday, May 22, 2024 at 5:04 PM To: "tls@ietf.org" Subject: [TLS]Re: [EXTERNAL] Re: WG Adoption for TLS Trust Expressions Thanks to the working group for all the discussion on this document. We will kick off an official adoption call soon. While

[TLS]Re: [EXTERNAL] Re: WG Adoption for TLS Trust Expressions

2024-05-22 Thread Joseph Salowey
Thanks to the working group for all the discussion on this document. We will kick off an official adoption call soon. While this work is clearly applicable to TLS, the topic of trust stores is broader. The working group should be aware that if the document is adopted as a working group item, It's p

[TLS]Re: [EXTERNAL] Re: WG Adoption for TLS Trust Expressions

2024-05-22 Thread Andrei Popov
* While a TLS extension could be used to identify which approaches/algorithms/protocols the client supports, the server also needs to know which of its certificate chains the client trusts. To me, these are two separate issues: 1. Selecting a certificate chain based on the client’s signat