RE: question on cipher suites
"Alberti Antoine" <[email protected]> Wed, 22 Jun 2005 10:41:52 +0200
| Newsgroups | gmane.ietf.ediint |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. ------_=_NextPart_001_01C57706.3CB267DF Content-Type: text/plain; charset="windows-1250" Content-Transfer-Encoding: quoted-printable This is TLS matter. This issue, if you consider this negociation as an = issue, appears on every protocol based on TLS (HTTPS, FTPS, ASx, SMTPS, = and so on...), and none of them adds any precision over TLS. But you may consider that TLS ciphersuite recommandations are too old, = and add mandatory supported ciphersuites. However, I don't think = overriding other specs' recommandations is a good idea, since you never = know how this spec may evolve. AS3 may become incompatible with TLS's = future versions by doing this. =20 Antoine Alberti XPP project manager +33 (0) 1 47 17 24 37 [email protected] Axway. software a Sopra Group company www.axway.com =20 -----Message d'origine----- De : [email protected] = [mailto:[email protected]]De la part de Kyle Meadors Envoy=E9 : mardi 21 juin 2005 20:59 A : [email protected] Objet : question on cipher suites An issue was recently brought up in regards to using TLS in AS3. Within = the TLS handshaking, the connecting AS3 application only uses one = cipher, 3DES, in the handshaking. In this case, the FTP server receiving = the connection does not support 3DES but does support others. Since the = AS3 app does not support anything but 3DES, it can not work through the = handshaking to find a cipher both agree on. =20 Would it be necessary to state something within the AS3 draft about = supporting a specific set of ciphers. Or, is this outside the scope of = AS3 since it may lie only with the FTP server be beyond the control of = the AS3 application. =20 Kyle Meadors Principal, Test Process Drummond Group Inc. 615.384.5006 =20 -- No virus found in this outgoing message. Checked by AVG Anti-Virus. Version: 7.0.323 / Virus Database: 267.7.8/22 - Release Date: 6/17/2005 ------_=_NextPart_001_01C57706.3CB267DF Content-Type: text/html; charset="windows-1250" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML xmlns=3D"http://www.w3.org/TR/REC-html40" xmlns:o =3D=20 "urn:schemas-microsoft-com:office:office" xmlns:w =3D=20 "urn:schemas-microsoft-com:office:word"><HEAD> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Dwindows-1250"> <META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR> <STYLE>@page Section1 {size: 8.5in 11.0in; margin: 1.0in 1.25in 1.0in = 1.25in; } P.MsoNormal { FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman" } LI.MsoNormal { FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman" } DIV.MsoNormal { FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman" } A:link { COLOR: blue; TEXT-DECORATION: underline } SPAN.MsoHyperlink { COLOR: blue; TEXT-DECORATION: underline } A:visited { COLOR: purple; TEXT-DECORATION: underline } SPAN.MsoHyperlinkFollowed { COLOR: purple; TEXT-DECORATION: underline } SPAN.EmailStyle17 { COLOR: windowtext; FONT-FAMILY: Arial; mso-style-type: personal-compose } DIV.Section1 { page: Section1 } </STYLE> </HEAD> <BODY lang=3DEN-US vLink=3Dpurple link=3Dblue> <DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D765153408-22062005>This = is TLS matter.=20 This issue, if you consider this negociation as an issue, appears on = every=20 protocol based on TLS (HTTPS, FTPS, ASx, SMTPS, and so on...), and none = of them=20 adds any precision over TLS.</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2><SPAN class=3D765153408-22062005>But = you may consider=20 that TLS ciphersuite recommandations are too old, and add mandatory = supported=20 ciphersuites. However, I don't think overriding other specs' = recommandations is=20 a good idea, since you never know how this spec may evolve. AS3 may = become=20 incompatible with TLS's future versions by doing = this.</SPAN></FONT></DIV> <DIV><FONT face=3DArial size=3D2></FONT> </DIV> <DIV><FONT face=3DArial size=3D2>Antoine Alberti</FONT></DIV> <DIV><FONT face=3DArial size=3D2>XPP project manager</FONT></DIV> <DIV><FONT face=3DArial size=3D2>+33 (0) 1 47 17 24 37</FONT></DIV> <DIV><FONT face=3DArial size=3D2><A=20 href=3D"mailto:[email protected]">[email protected]</A></FONT></DIV> <DIV><FONT face=3DArial size=3D2><FONT color=3D#808080 = size=3D4><STRONG><FONT=20 face=3D"Arial Black">Axwa<FONT color=3D#ff0000>y.</FONT> <FONT=20 size=3D2>software</FONT></FONT></STRONG></FONT> <FONT size=3D1><EM>a = Sopra Group=20 company</EM></FONT></FONT></DIV> <DIV><FONT face=3DArial size=3D2><A=20 href=3D"http://www.axway.com">www.axway.com</A></FONT></DIV> <DIV><FONT face=3DArial color=3D#0000ff = size=3D2></FONT> </DIV></DIV> <BLOCKQUOTE dir=3Dltr=20 style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px = solid; MARGIN-RIGHT: 0px"> <DIV class=3DOutlookMessageHeader dir=3Dltr align=3Dleft><FONT = face=3DTahoma=20 size=3D2>-----Message d'origine-----<BR><B>De :</B>=20 [email protected] = [mailto:[email protected]]<B>De la=20 part de</B> Kyle Meadors<BR><B>Envoy=E9 :</B> mardi 21 juin 2005=20 20:59<BR><B>À :</B> = [email protected]<BR><B>Objet :</B> question=20 on cipher suites<BR><BR></FONT></DIV> <DIV class=3DSection1> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">An issue was recently = brought up=20 in regards to using TLS in AS3. Within the TLS handshaking, the = connecting AS3=20 application only uses one cipher, 3DES, in the handshaking. In this = case, the=20 FTP server receiving the connection does not support 3DES but does = support=20 others. Since the AS3 app does not support anything but 3DES, it can = not work=20 through the handshaking to find a cipher both agree=20 on.<o:p></o:p></SPAN></FONT></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: = Arial"><o:p> </o:p></SPAN></FONT></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Would it be necessary to = state=20 something within the AS3 draft about supporting a specific set of = ciphers. Or,=20 is this outside the scope of AS3 since it may lie only with the FTP = server be=20 beyond the control of the AS3 = application.<o:p></o:p></SPAN></FONT></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: = Arial"><o:p> </o:p></SPAN></FONT></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Kyle=20 Meadors</SPAN></FONT><o:p></o:p></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Principal, Test=20 Process</SPAN></FONT><o:p></o:p></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Drummond Group=20 Inc.</SPAN></FONT><o:p></o:p></P> <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN=20 style=3D"FONT-SIZE: 10pt; FONT-FAMILY: = Arial">615.384.5006</SPAN></FONT><o:p></o:p></P> <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20 style=3D"FONT-SIZE: = 12pt"><o:p> </o:p></SPAN></FONT></P></DIV><BR> <P><FONT size=3D2>--<BR>No virus found in this outgoing = message.<BR>Checked by=20 AVG Anti-Virus.<BR>Version: 7.0.323 / Virus Database: 267.7.8/22 - = Release=20 Date: 6/17/2005<BR></FONT></P></BLOCKQUOTE></BODY></HTML> ------_=_NextPart_001_01C57706.3CB267DF--