RE: TLS cipersuites for Rserpool

[email protected]
Newsgroups gmane.ietf.rserpool
Message-ID <57A26D272F67A743952F6B4371B8F811021CFEFC@daebe007.americas.nokia.com>
It is my understanding that AES is free from IPR.  I saw a letter from the AES co-author Dr. Joan Daemen waiving all rights posted on a NIST website.  I didn't save the URL.

-- maureen

-----Original Message-----
From: ext Qiaobing Xie [mailto:[email protected]]
Sent: Tuesday, September 16, 2003 3:32 PM
To: Stillman Maureen (NVO-NIC/Ithaca)
Cc: [email protected]
Subject: Re: [Rserpool] TLS cipersuites for Rserpool


I guess this must have been talked about by others but I am just not
well informed about the answer - will there be any IPR ramifications
when we say RSERPOOL MUST use certain ciphersuite? My impression is that
a lot of ciphers contain IPR. If that is the case, does the "MUST" imply
that RSERPOOL can not be implemented without tripping over some cipher
IPR?

regards,
-Qiaobing

[email protected] wrote:
> 
> Although we have reached consensus on TLS for securing the Rserpool
> infrastructure, we have not discussed TLS cipher suites.  TLS has a very
> long and growing list of ciphersuites.  They vary in strength.  Security
> experts want strong security.  Application developers worry about
> interoperability.  The answer to this is for applications to mandate a
> ciphersuite along with one or more shoulds for backward compatibility.
> 
> I am including the SIP RFC 3261 security section as an example.
> In the SIP specification there is the following text:
> 
> The TLS_RSA_WITH_AES_128_CBC_SHA ciphersuite [6] MUST be supported at
>    a minimum by implementers when TLS is used in a SIP application.  For
>    purposes of backwards compatibility, proxy servers, redirect servers,
>    and registrars SHOULD support TLS_RSA_WITH_3DES_EDE_CBC_SHA.
>    Implementers MAY also support any other ciphersuite.
> 
> For Rserpool we need to secure the following:
> 
> PU <----> ENRP Server
> PE <----> ENRP Server
> ENRP server <-----> ENRP Server
> 
> I recommend Rserpool security text as follows (for ENRP and ASAP security
> sections):
> 
> The TLS_RSA_WITH_AES_128_CBC_SHA ciphersuite MUST be supported at a minimum
> by implementers of TLS for Rserpool.   For purposes of backwards
> compatibility, ENRP SHOULD support TLS_RSA_WITH_3DES_EDE_CBC_SHA.
> Implementers MAY also support any other ciphersuite.
> 
> I'll get Eric Rescorla's advice about this TLS cipher suite being the right one
> to make mandatory to support and also his take on backward compatibility.  We might not need
> this in ENRP assuming that everyone will write new code for Rserpool
> infrastructure.
> 
> Any comments?
> 
> -- maureen
> 
> _______________________________________________
> rserpool mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/rserpool

_______________________________________________
rserpool mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/rserpool
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.