Hi Wei,Thank you for addressing my comments. I had a very quick look. Some very quick follow-up comments below:
On 09.04.26 08:10, Wei Wang wrote:
Hi Usama,Sorry for the late response. We have uploaded the -v01 of draft-wang-tls-service-affinity. In the latest version, the following modifications have been made according to your comments:1. The introduction has been re-write, the CATS part has been moved to Use case section.
Thank you!
1.
A new section is added to describe the Motivation and design
rationale.
Thank you!
1.
The protocol design in section 4 has been revised based on TLS 1.3.
I am not sure if this one has been /fully/ addressed. As an example,
please note that you still have 4xChangeCipherSpec messages in Figure 1
while this message seems to have been removed in TLS 1.3, "except when
needed for middlebox compatibility" [0]. There seems to be no
explanation in your draft why you need this message. Please explain this
in the text.
RFC8446bis [1] also seems to be vague about it and does not seem to explain how to use this message correctly for "middlebox compatibility". I haven't worked with middleboxes. Maybe others can help here. I think we should clarify it in RFC8446bis too. I am particularly curious about:
1. the placement of this message in the handshake and 2. how this message will be handled in the TranscriptHash. I have created an issue [2] for this.
1.
Since we are not very familiar with security-related technologies,
would you like to help us improve the content of security
considerations?
Yes, with great pleasure. I am currently stuck in another high-stake
issue. When I get some time, I will update my draft [3] to explain this
and then come back to you.
Best regards, -Usama[0] https://www.ietf.org/archive/id/draft-ietf-tls-rfc8446bis-14.html#section-1.3-2.6.1
[1] https://www.ietf.org/archive/id/draft-ietf-tls-rfc8446bis-14.html [2] https://github.com/tlswg/tls13-spec/issues/1413[3] https://www.ietf.org/archive/id/draft-usama-tls-fatt-extension-02.html#section-4.3
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
