[saag] Re: NIST Requests Comments on SP 800-52 Rev. 2 | Selection, Configuration, and Use of TLS Implementations
Deb Cooley <[email protected]> Thu, 7 May 2026 19:22:23 -0400
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
--===============4257687776635430816== Content-Type: multipart/alternative; boundary=Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3 Content-Transfer-Encoding: 7bit --Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Usama,=20 Please note that Quynh did not say post comments here as well as to the NIST= address in the link. If you have relevant comments, I=E2=80=99m sure NIST will be happy to have t= hem. =20 Deb Sec AD > On May 7, 2026, at 6:54=E2=80=AFPM, Muhammad Usama Sardar <muhammad_usama.= [email protected]> wrote: > =EF=BB=BF > Hi Quynh, >=20 > Thank you for sharing NIST document for comments. I have the following com= ments: >=20 > On 07.05.26 23:11, Eric Rescorla wrote: >> The latest version of this document is from 2019 and it really is in fair= ly bad need of revision beyond the questions asked on the NIST page. > I agree with Ekr. It would be helpful to update the document before reques= ting comments. >=20 > In addition, in my reading, the three questions being asked seem to be som= ewhat settled at the IETF, no? See for example [0] and [1]. >=20 > Finally, modern extension of TLS, known as attested TLS, supports remote a= ttestation to provide additional trust anchor for protection. At the very le= ast, I think NIST should add remote attestation as "future capabilities" in A= ppendix E. Please see the proposed design [2] for details. Please encourage t= he relevant team at NIST to join SEAT WG [3] to contribute to the work. We w= ould welcome any feedback from NIST on the design [2]. >=20 > Thank you for considering my comments. >=20 > Best regards, >=20 > -Usama >=20 > [0] https://datatracker.ietf.org/doc/draft-ietf-tls-tls12-frozen/ >=20 > [1] https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/ >=20 > [2] https://datatracker.ietf.org/doc/draft-fossati-seat-expat/ >=20 > [3] https://datatracker.ietf.org/wg/seat/about/ >=20 > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] --Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto"><div dir=3D"ltr"><meta http-equiv=3D"content-type" content=3D"text/ht= ml; charset=3Dutf-8">Usama, <br id=3D"lineBreakAtBeginningOfSignature">= <div dir=3D"ltr"><br></div><div dir=3D"ltr">Please note that Quynh did not s= ay post comments here as well as to the NIST address in the link.</div><div d= ir=3D"ltr"><br></div><div dir=3D"ltr">If you have relevant comments, I=E2=80= =99m sure NIST will be happy to have them. </div><div dir=3D"ltr"><br>= </div><div dir=3D"ltr">Deb</div><div dir=3D"ltr">Sec AD</div><div dir=3D"ltr= "><br><blockquote type=3D"cite">On May 7, 2026, at 6:54=E2=80=AFPM, Muhammad= Usama Sardar <[email protected]> wrote:<br><br></bl= ockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF =20 <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-8"= > =20 =20 <p>Hi Quynh,</p> <p>Thank you for sharing NIST document for comments. I have the following comments:<br> </p> <div class=3D"moz-cite-prefix">On 07.05.26 23:11, Eric Rescorla wrote:<b= r> </div> <blockquote type=3D"cite" cite=3D"mid:CABcZeBOQYDPugjSSLuRKaB5DnwJigdZRj= [email protected]"> <div dir=3D"ltr"> <div>The latest version of this document is from 2019 and it really is in fairly bad need of revision beyond the question= s asked on the NIST page.</div> </div> </blockquote> <p>I agree with Ekr. It would be helpful to update the document before requesting comments.<br> </p> <p>In addition, in <i>my</i> reading, the three questions being asked seem to be somewhat settled at the IETF, no? See for example [0] and [1].</p> <p>Finally, modern extension of TLS, known as <i>attested TLS,</i> supports <i>remote attestation</i> to provide additional trust anchor for protection. At the very least, I think NIST should add remote attestation as "future capabilities" in Appendix E. Please see the proposed design [2] for details. Please encourage the relevant team at NIST to join SEAT WG [3] to contribute to the work. We would welcome any feedback from NIST on the design [2].<br> </p> <p>Thank you for considering my comments.</p> <p>Best regards,</p> <p>-Usama<br> </p> <p>[0] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie= tf.org/doc/draft-ietf-tls-tls12-frozen/">https://datatracker.ietf.org/doc/dr= aft-ietf-tls-tls12-frozen/</a></p> <p>[1] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ietf.or= g/doc/draft-ietf-uta-require-tls13/">https://datatracker.ietf.org/doc/draft-= ietf-uta-require-tls13/</a></p> <p>[2] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie= tf.org/doc/draft-fossati-seat-expat/">https://datatracker.ietf.org/doc/draft= -fossati-seat-expat/</a></p> <p>[3] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie= tf.org/wg/seat/about/">https://datatracker.ietf.org/wg/seat/about/</a><br> </p> =20 <span>_______________________________________________</span><br><span>saag m= ailing list -- [email protected]</span><br><span>To unsubscribe send an email to= [email protected]</span><br></div></blockquote></div></body></html>= --Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3-- --===============4257687776635430816== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHNhYWctbGVhdmVAaWV0Zi5vcmcK --===============4257687776635430816==--