Terminology related to TLS and DTLS; RE: TLS 1.3: Enhanced definitions of terms "TLS session" and "TLS connection"
"Schwarz, Albrecht (Albrecht)" <[email protected]> Fri, 10 Oct 2014 19:32:40 +0000
| Newsgroups | gmane.ietf.megaco,gmane.ietf.tls |
|---|---|
| Message-ID | <786615F3A85DF44AA2A76164A71FE1AC33F0C0@FR711WXCHMBA03.zeu.alcatel-lucent.com> |
fyi, we've developed an hierarchical terminology framework for TLS and DTLS (in = context of H.248 gateways, serving the termination or interworking of (D)TL= S protocol). However, the terminology isn't gateway specific, defined in a general manne= r, thus applicable (and fully consistent) to IETF TLS RFCs in our understan= ding. Download: AVD-4600 H.Sup.13 (Rel. 2): Terminology related to TLS and DTLS http://wftp3.itu.int/av-arch/avc-site/2013-2016/1411_Seo/AVD-4600.zip = Regards, Albrecht, Jens & Juergen PS The formal proceeding behind AVD-4600 may be found in: AVD-4614 Backup-material to AVD-4600: Formal description of "TLS terminolog= y framework" http://wftp3.itu.int/av-arch/avc-site/2013-2016/1411_Seo/AVD-4614.zip = -----Original Message----- From: TLS [mailto:[email protected]] On Behalf Of Schwarz, Albrecht (Alb= recht) Sent: Mittwoch, 19. M=E4rz 2014 17:10 To: [email protected] Subject: [TLS] TLS 1.3: Enhanced definitions of terms "TLS session" and "TL= S connection" Dear All, like to raise a question related to the RFC 5246, Appendix B "Glossary": Status: = - connection: = A connection is a transport (in the OSI layering model definition) t= hat provides a suitable type of service. For TLS, such connections are pee= r-to-peer relationships. The connections are transient. Every connection = is associated with one session. - session: = A TLS session is an association between a client and a server. Sessi= ons are created by the handshake protocol. Sessions define a set of crypto= graphic security parameters that can be shared among multiple connections. = Sessions are used to avoid the expensive negotiation of new security param= eters for each connection. Both terms are rather high-level and silent concerning a number of key char= acteristics. E.g., What constitutes exactly a "TLS session"? Just the 1-tuple of a "session id= " or the 6-tuple of {session identifier, peer certificate, compression meth= od, cipher spec, master secret, is resumable}" (based on clause 7/RFC 5246)? Similar, what constitues exactly a "TLS connection"? An n-tuple based on th= e ConnectionState on clause 6.1/RFC 5246, just a sub-set ..., the 5-tuple o= f IP transport connection endpoint addresses? What exactly is the relation between a "TLS session" and its associated "TL= S connection(s)"? Resumption of a "TLS session"? What kind of "data object (configuration)" i= s exactly used as starting point for the "resumption procedure"? Such kind of questions are all leading to the baseline of good terminology.= The existing Glossary could and should be improved in my understanding. Any opinions, comments from TLS expert side? Anyone aware of similar terminology enhancements requests in the past? Thanks, Albrecht _______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls