Re: [Uta] SNI text from 7672

2018-04-18 Thread Viktor Dukhovni
> On Apr 18, 2018, at 11:54 AM, Daniel Margolis wrote: > > How is it counter-intuitive? TLS 1.3 requires SNI, no? No, TLS 1.3, *does not* require SNI. SNI is mandatory to implement, but NOT mandatory to use: https://tools.ietf.org/html/draft-ietf-tls-tls13-28#section-4.4.2.2 - The "se

Re: [Uta] SNI text from 7672

2018-04-18 Thread Ilari Liusvaara
On Wed, Apr 18, 2018 at 03:54:14PM +, Daniel Margolis wrote: > > How is it counter-intuitive? TLS 1.3 requires SNI, no? No, it does not. - The server MAY require SNI. - The client SHOULD send SNI. - If the server requires SNI and client does not send one, the server SHOULD send missing_ex

Re: [Uta] SNI text from 7672

2018-04-18 Thread Viktor Dukhovni
> On Apr 18, 2018, at 11:18 AM, Daniel Margolis wrote: > > Thanks. I think this is consistent with what was added here: > https://github.com/mrisher/smtp-sts/blob/master/mta-sts.txt#L633. If not, let > me know. Looks largely fine to me. I am not fond of the HTTP-specific dictum: HTTP se

Re: [Uta] SNI text from 7672

2018-04-18 Thread Daniel Margolis
Thanks. I think this is consistent with what was added here: https://github.com/mrisher/smtp-sts/blob/master/mta-sts.txt#L633. If not, let me know. Thanks again. On Fri, Mar 23, 2018 at 12:38 AM Viktor Dukhovni wrote: > > > > On Mar 22, 2018, at 4:17 PM, Daniel Kahn Gillmor > wrote: > > > >> >

Re: [Uta] SNI text from 7672

2018-03-22 Thread Viktor Dukhovni
> On Mar 22, 2018, at 4:17 PM, Daniel Kahn Gillmor > wrote: > >> >> [...] The >> server MAY rely on SNI to determine which certificate chain to >> present to the client. Clients that don't send SNI information may >> not see the expected certificate chain. >> >> If the server's TL

Re: [Uta] SNI text from 7672

2018-03-22 Thread Daniel Kahn Gillmor
On Thu 2018-03-22 14:49:18 -0400, Viktor Dukhovni wrote: > https://tools.ietf.org/html/rfc7672#section-8.1 > > >[...] The >server MAY rely on SNI to determine which certificate chain to >present to the client. Clients that don't send SNI information may >not see the expected certif

[Uta] SNI text from 7672

2018-03-22 Thread Viktor Dukhovni
https://tools.ietf.org/html/rfc7672#section-8.1 [...] The server MAY rely on SNI to determine which certificate chain to present to the client. Clients that don't send SNI information may not see the expected certificate chain. If the server's TLSA records match the server's def