[TLS] Jonathan's "pause" extension

"Salz, Rich" <[email protected]> Thu, 23 Jul 2026 09:52:13 +0000
Newsgroups gmane.ietf.tls
Message-ID <MN2PR17MB40310666BBE1097CC321967BCDC02@MN2PR17MB4031.namprd17.prod.outlook.com>
--===============1483676631025138053==
Content-Language: en-US
Content-Type: multipart/alternative;
 boundary="_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_"

--_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

I wanted to bring to the list a suggestion Jonathan Hoyland might at the mi=
c line today.

During the Supplemental Authentication discussion, several people brought u=
p the idea of using exporters and channel bindings (9261, 9266). Yaroslav p=
ointed out that it requires application changes to use them.

Jonathan suggested a =93pause=94 extension. Rather than changing the handsh=
ake, this new extension would tell the peer that more data is coming and do=
 not accept/send application data until the pause is lifted. He and I chatt=
ed after the session, and we realized this could probably handle multi-exch=
ange PAKE traffic as well. Anything that would modify the handshake, or is =
normally post-handshake (cough, authentication, cough) would also work. Pro=
bably need to nail down the semantics such as when to lift the pause (E.g.,=
 when you don=92t get records with the pause extension or wait until the =
=93done=94 message is sent, etc), but this seems to me like an elegant solu=
tion.


 during the presentation on Suppl
During the Supplemental

--_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
I wanted to bring to the list a suggestion Jonathan Hoyland might at the mi=
c line today.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
During the Supplemental Authentication discussion, several people brought u=
p the idea of using exporters and channel bindings (9261, 9266). Yaroslav p=
ointed out that it requires application changes to use them.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
Jonathan suggested a =93pause=94 extension. Rather than changing the handsh=
ake, this new extension would tell the peer that more data is coming and do=
 not accept/send application data until the pause is lifted. He and I chatt=
ed after the session, and we realized
 this could probably handle multi-exchange PAKE traffic as well. Anything t=
hat would modify the handshake, or is normally post-handshake (cough, authe=
ntication, cough) would also work. Probably need to nail down the semantics=
 such as when to lift the pause
 (E.g., when you don=92t get records with the pause extension or wait until=
 the =93done=94 message is sent, etc), but this seems to me like an elegant=
 solution.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
&nbsp;during the presentation on Suppl</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
During the Supplemental</div>
</body>
</html>

--_000_MN2PR17MB40310666BBE1097CC321967BCDC02MN2PR17MB4031namp_--


--===============1483676631025138053==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============1483676631025138053==--