[saag] Re: NIST Requests Comments on SP 800-52 Rev. 2 | Selection, Configuration, and Use of TLS Implementations

Deb Cooley <[email protected]> Thu, 7 May 2026 19:22:23 -0400
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
--===============4257687776635430816==
Content-Type: multipart/alternative;
 boundary=Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3
Content-Transfer-Encoding: 7bit


--Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Usama,=20

Please note that Quynh did not say post comments here as well as to the NIST=
 address in the link.

If you have relevant comments, I=E2=80=99m sure NIST will be happy to have t=
hem. =20

Deb
Sec AD

> On May 7, 2026, at 6:54=E2=80=AFPM, Muhammad Usama Sardar <muhammad_usama.=
[email protected]> wrote:
> =EF=BB=BF
> Hi Quynh,
>=20
> Thank you for sharing NIST document for comments. I have the following com=
ments:
>=20
> On 07.05.26 23:11, Eric Rescorla wrote:
>> The latest version of this document is from 2019 and it really is in fair=
ly bad need of  revision beyond the questions asked on the NIST page.
> I agree with Ekr. It would be helpful to update the document before reques=
ting comments.
>=20
> In addition, in my reading, the three questions being asked seem to be som=
ewhat settled at the IETF, no? See for example [0] and [1].
>=20
> Finally, modern extension of TLS, known as attested TLS, supports remote a=
ttestation to provide additional trust anchor for protection. At the very le=
ast, I think NIST should add remote attestation as "future capabilities" in A=
ppendix E. Please see the proposed design [2] for details. Please encourage t=
he relevant team at NIST to join SEAT WG [3] to contribute to the work. We w=
ould welcome any feedback from NIST on the design [2].
>=20
> Thank you for considering my comments.
>=20
> Best regards,
>=20
> -Usama
>=20
> [0] https://datatracker.ietf.org/doc/draft-ietf-tls-tls12-frozen/
>=20
> [1] https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/
>=20
> [2] https://datatracker.ietf.org/doc/draft-fossati-seat-expat/
>=20
> [3] https://datatracker.ietf.org/wg/seat/about/
>=20
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

--Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto"><div dir=3D"ltr"><meta http-equiv=3D"content-type" content=3D"text/ht=
ml; charset=3Dutf-8">Usama,&nbsp;<br id=3D"lineBreakAtBeginningOfSignature">=
<div dir=3D"ltr"><br></div><div dir=3D"ltr">Please note that Quynh did not s=
ay post comments here as well as to the NIST address in the link.</div><div d=
ir=3D"ltr"><br></div><div dir=3D"ltr">If you have relevant comments, I=E2=80=
=99m sure NIST will be happy to have them. &nbsp;</div><div dir=3D"ltr"><br>=
</div><div dir=3D"ltr">Deb</div><div dir=3D"ltr">Sec AD</div><div dir=3D"ltr=
"><br><blockquote type=3D"cite">On May 7, 2026, at 6:54=E2=80=AFPM, Muhammad=
 Usama Sardar &lt;[email protected]&gt; wrote:<br><br></bl=
ockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF

 =20
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-8"=
>
 =20
 =20
    <p>Hi Quynh,</p>
    <p>Thank you for sharing NIST document for comments. I have the
      following comments:<br>
    </p>
    <div class=3D"moz-cite-prefix">On 07.05.26 23:11, Eric Rescorla wrote:<b=
r>
    </div>
    <blockquote type=3D"cite" cite=3D"mid:CABcZeBOQYDPugjSSLuRKaB5DnwJigdZRj=
[email protected]">
      <div dir=3D"ltr">
        <div>The latest version of this document is from 2019 and it
          really is in fairly bad need of&nbsp; revision beyond the question=
s
          asked on the NIST page.</div>
      </div>
    </blockquote>
    <p>I agree with Ekr. It would be helpful to update the document
      before requesting comments.<br>
    </p>
    <p>In addition, in <i>my</i> reading, the three questions being
      asked seem to be somewhat settled at the IETF, no? See for example
      [0] and [1].</p>
    <p>Finally, modern extension of TLS, known as <i>attested TLS,</i>
      supports <i>remote attestation</i> to provide additional trust
      anchor for protection. At the very least, I think NIST should add
      remote attestation as "future capabilities" in Appendix E. Please
      see the proposed design [2] for details. Please encourage the
      relevant team at NIST to join SEAT WG [3] to contribute to the
      work. We would welcome any feedback from NIST on the design [2].<br>
    </p>
    <p>Thank you for considering my comments.</p>
    <p>Best regards,</p>
    <p>-Usama<br>
    </p>
    <p>[0] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie=
tf.org/doc/draft-ietf-tls-tls12-frozen/">https://datatracker.ietf.org/doc/dr=
aft-ietf-tls-tls12-frozen/</a></p>
    <p>[1]
      <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ietf.or=
g/doc/draft-ietf-uta-require-tls13/">https://datatracker.ietf.org/doc/draft-=
ietf-uta-require-tls13/</a></p>
    <p>[2] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie=
tf.org/doc/draft-fossati-seat-expat/">https://datatracker.ietf.org/doc/draft=
-fossati-seat-expat/</a></p>
    <p>[3] <a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ie=
tf.org/wg/seat/about/">https://datatracker.ietf.org/wg/seat/about/</a><br>
    </p>
 =20

<span>_______________________________________________</span><br><span>saag m=
ailing list -- [email protected]</span><br><span>To unsubscribe send an email to=
 [email protected]</span><br></div></blockquote></div></body></html>=

--Apple-Mail-0F0AC951-3613-46D9-98D3-F4505E7065A3--


--===============4257687776635430816==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls
aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHNhYWctbGVhdmVAaWV0Zi5vcmcK

--===============4257687776635430816==--