[saag] Re: [EXTERNAL] Re: NIST Requests Comments on SP 800-52 Rev. 2 | Selection, Configuration, and Use of TLS Implementations
Eric Rescorla <[email protected]> Tue, 2 Jun 2026 12:42:06 -0700
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBOvrAD0LHB3kKa4feAm9_VmoXiGkNeZT94ARJcWC4X_tQ@mail.gmail.com> |
--===============3070690208113237642== Content-Type: multipart/alternative; boundary="000000000000d676df06534a83d5" --000000000000d676df06534a83d5 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Tue, Jun 2, 2026 at 12:35=E2=80=AFPM Loganaden Velvindron <loganaden@gma= il.com> wrote: > I think that enterprises that operate with tight licenses want full > visibility into their endpoints. They aren't big fans of tls 1.3, ech and > quic. They want proxies for outgoing tls connections. > This seems like it conflates two questions: 1. Visibility for incoming connections, which is more difficult with 1.3 (and 1.2 with (EC)DH) 2. Visibility for outgoing connections which works fine with TLS 1.3 with proxies. I think that those enterprises will likely support tls 1.2 for a very > very long time ? > Well, TLS 1.2 will not support post-quantum, so I think our recommendation needs to be that you ought to be moving to TLS 1.3 (I'm deliberately using "ought to" to avoid the MUST/SHOULD/MAY discussion). -Ekr > > > > On Tue, 02 Jun 2026, 23:28 Salz, Rich, <[email protected]= rg> > wrote: > >> The RFC-to-be 9846, a product of the UTA working group, says TLS 1.3 is = a >> MUST and you MAY do TLS 1.2 if you have installed base or other deployme= nt >> concerns. The pre-pub draft is at [1]. >> >> Disclaimer: I=E2=80=99m a co-author. >> >> [1] https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/ >> _______________________________________________ >> saag mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> > --000000000000d676df06534a83d5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Jun 2, = 2026 at 12:35=E2=80=AFPM Loganaden Velvindron <<a href=3D"mailto:loganad= [email protected]">[email protected]</a>> wrote:<br></div><blockquote class= =3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg= b(204,204,204);padding-left:1ex"><div dir=3D"auto">I think that enterprises= that operate with tight licenses want full visibility into their endpoints= . They aren't big fans of tls 1.3, ech and quic. They want proxies for = outgoing tls connections.=C2=A0</div></blockquote><div><br></div><div>This = seems like it conflates two questions:</div><div><br></div><div>1. Visibili= ty for incoming connections, which is more difficult with 1.3 (and 1.2 with= (EC)DH)</div><div>2. Visibility for outgoing connections which works fine = with TLS 1.3 with proxies.</div><div><br></div><div><br></div><blockquote c= lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli= d rgb(204,204,204);padding-left:1ex"><div dir=3D"auto"><div dir=3D"auto">I = think that those enterprises will likely support tls 1.2 for a very very=C2= =A0long time ?</div></div></blockquote><div><br></div><div>Well, TLS 1.2 wi= ll not support post-quantum, so I think our recommendation needs</div><div>= to be that you ought to be moving=C2=A0to TLS 1.3 (I'm deliberately usi= ng "ought to" to</div><div>avoid the MUST/SHOULD/MAY discussion).= </div><div><br></div><div>-Ekr=C2=A0</div><blockquote class=3D"gmail_quote"= style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);p= adding-left:1ex"><div dir=3D"auto"><div dir=3D"auto"><br></div><div dir=3D"= auto"><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class= =3D"gmail_attr">On Tue, 02 Jun 2026, 23:28 Salz, Rich, <rsalz=3D<a href= =3D"mailto:[email protected]" target=3D"_blank">40akamai.com@dmar= c.ietf.org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style= =3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding= -left:1ex"> <div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> The RFC-to-be=C2=A09846, a product of the UTA working group, says TLS 1.3 i= s a MUST and you MAY do TLS 1.2 if you have installed base or other deploym= ent concerns.=C2=A0 The pre-pub draft is at [1].</div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> <br> </div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> Disclaimer: I=E2=80=99m a co-author.</div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> <br> </div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> [1] <a href=3D"https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls1= 3/" rel=3D"noreferrer" target=3D"_blank"> https://datatracker.ietf.org/doc/draft-ietf-uta-require-tls13/</a></div> </div> _______________________________________________<br> saag mailing list -- <a href=3D"mailto:[email protected]" rel=3D"noreferrer" ta= rget=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" rel= =3D"noreferrer" target=3D"_blank">[email protected]</a><br> </blockquote></div> </blockquote></div></div> --000000000000d676df06534a83d5-- --===============3070690208113237642== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2FhZyBtYWls aW5nIGxpc3QgLS0gc2FhZ0BpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHNhYWctbGVhdmVAaWV0Zi5vcmcK --===============3070690208113237642==--