[TLS] Jonathan's "pause" extension
"Salz, Rich" <[email protected]> Thu, 23 Jul 2026 09:52:13 +0000
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <MN2PR17MB40310666BBE1097CC321967BCDC02@MN2PR17MB4031.namprd17.prod.outlook.com> |
--===============1483676631025138053== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_" --_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable I wanted to bring to the list a suggestion Jonathan Hoyland might at the mi= c line today. During the Supplemental Authentication discussion, several people brought u= p the idea of using exporters and channel bindings (9261, 9266). Yaroslav p= ointed out that it requires application changes to use them. Jonathan suggested a =93pause=94 extension. Rather than changing the handsh= ake, this new extension would tell the peer that more data is coming and do= not accept/send application data until the pause is lifted. He and I chatt= ed after the session, and we realized this could probably handle multi-exch= ange PAKE traffic as well. Anything that would modify the handshake, or is = normally post-handshake (cough, authentication, cough) would also work. Pro= bably need to nail down the semantics such as when to lift the pause (E.g.,= when you don=92t get records with the pause extension or wait until the = =93done=94 message is sent, etc), but this seems to me like an elegant solu= tion. during the presentation on Suppl During the Supplemental --_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1= 252"> </head> <body> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> I wanted to bring to the list a suggestion Jonathan Hoyland might at the mi= c line today.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> During the Supplemental Authentication discussion, several people brought u= p the idea of using exporters and channel bindings (9261, 9266). Yaroslav p= ointed out that it requires application changes to use them.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> Jonathan suggested a =93pause=94 extension. Rather than changing the handsh= ake, this new extension would tell the peer that more data is coming and do= not accept/send application data until the pause is lifted. He and I chatt= ed after the session, and we realized this could probably handle multi-exchange PAKE traffic as well. Anything t= hat would modify the handshake, or is normally post-handshake (cough, authe= ntication, cough) would also work. Probably need to nail down the semantics= such as when to lift the pause (E.g., when you don=92t get records with the pause extension or wait until= the =93done=94 message is sent, etc), but this seems to me like an elegant= solution.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> during the presentation on Suppl</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> During the Supplemental</div> </body> </html> --_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_-- --===============1483676631025138053== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0 bHMtbGVhdmVAaWV0Zi5vcmcK --===============1483676631025138053==--