Skip to main content

Credential Protection Ciphersuites for Transport Layer Security (TLS)
draft-hajjeh-tls-identity-protection-09

Revision differences

Document history

Date Rev. By Action
2015-10-14
09 (System) Notify list changed from badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@ietf.org, rfc-ise@rfc-editor.org to rfc-ise@rfc-editor.org
2013-06-06
09 (System) Document has expired
2013-06-05
09 Cindy Morgan Changed field(s): group,ad,abstract,iesg_state
2013-06-04
09 Nevil Brownlee ISE state changed to No Longer In Independent Submission Stream from None
2010-03-02
09 Cindy Morgan State Change Notice email list have been change to badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org, rfc-ise@rfc-editor.org from badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org, rfc-editor@rfc-editor.org
2010-02-11
09 Cindy Morgan State Changes to RFC Ed Queue from Approved-announcement sent by Cindy Morgan
2009-12-22
09 (System) IANA Action state changed to No IC from In Progress
2009-12-22
09 (System) IANA Action state changed to In Progress
2009-12-21
09 Amy Vezza IESG state changed to Approved-announcement sent
2009-12-21
09 Amy Vezza IESG has approved the document
2009-12-21
09 Amy Vezza Closed "Approve" ballot
2009-12-18
09 (System) Removed from agenda for telechat - 2009-12-17
2009-12-17
09 Amy Vezza State Changes to Approved-announcement to be sent from IESG Evaluation by Amy Vezza
2009-12-17
09 Lisa Dusseault [Ballot Position Update] New position, No Objection, has been recorded by Lisa Dusseault
2009-12-17
09 Cullen Jennings [Ballot Position Update] Position for Cullen Jennings has been changed to Yes from Undefined by Cullen Jennings
2009-12-17
09 Cullen Jennings [Ballot Position Update] Position for Cullen Jennings has been changed to Undefined from Yes by Cullen Jennings
2009-12-17
09 Adrian Farrel [Ballot Position Update] New position, No Objection, has been recorded by Adrian Farrel
2009-12-17
09 Adrian Farrel
[Ballot comment]
At the end of Section 1...

  The reader is expected to become familiar with the TLS standards
  ([RFC5246] and, …
[Ballot comment]
At the end of Section 1...

  The reader is expected to become familiar with the TLS standards
  ([RFC5246] and, if needed, [RFC4346] and [RFC2246] for its
  predecessors) prior to studying this document.

Well, is it needed to become familiar with RFC 4346 and RFC 2246?

---

As with all Experimental RCs, I would have liked to see some description of the experimental parameters; how the experiment is to be set up, kept isolated, and evaluated.
2009-12-17
09 Magnus Westerlund [Ballot Position Update] Position for Magnus Westerlund has been changed to No Objection from Yes by Magnus Westerlund
2009-12-15
09 Tim Polk [Ballot Position Update] Position for Tim Polk has been changed to Yes from Undefined by Tim Polk
2009-12-15
09 Tim Polk [Ballot Position Update] Position for Tim Polk has been changed to Undefined from Yes by Tim Polk
2009-12-09
09 Robert Sparks [Ballot Position Update] New position, No Objection, has been recorded by Robert Sparks
2009-12-09
09 Russ Housley [Ballot Position Update] Position for Russ Housley has been changed to Yes from No Objection by Russ Housley
2009-12-08
09 Pasi Eronen Placed on agenda for telechat - 2009-12-17 by Pasi Eronen
2009-12-08
09 Pasi Eronen State Changes to IESG Evaluation from AD Evaluation by Pasi Eronen
2009-12-08
09 Pasi Eronen [Note]: 'This is a second 3932(bis) check - remember to re-enter your ballot position.' added by Pasi Eronen
2009-12-08
09 Pasi Eronen Ballot has been issued by Pasi Eronen
2009-12-08
09 Pasi Eronen Created "Approve" ballot
2009-12-02
09 Cindy Morgan State Changes to AD Evaluation from Dead by Cindy Morgan
2009-11-13
09 (System) New version available: draft-hajjeh-tls-identity-protection-09.txt
2009-06-01
09 (System) Document has expired
2009-04-24
09 Amy Vezza State Change Notice email list have been change to badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org, rfc-editor@rfc-editor.org from badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org
2008-12-17
(System) Posted related IPR disclosure: GROUPE DES ECOLES DES TELECOMMUNICATIONS - ECOLE NATIONALE SUPERIEURE DES TELECOMMUNICATIONS 's Statement about IPR related to draft-hajjeh-tls-identity-protection-08
2008-12-01
09 Cindy Morgan State Change Notice email list have been change to badra@isima.fr, ibrahim.hajjeh@ineovation.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org from badra@isima.fr, Ibrahim.Hajjeh@enst.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org
2008-12-01
09 Cindy Morgan State Change Notice email list have been change to badra@isima.fr, Ibrahim.Hajjeh@enst.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org from Mohamad.Badra@enst.fr, Ibrahim.Hajjeh@enst.fr, draft-hajjeh-tls-identity-protection@tools.ietf.org
2008-11-28
08 (System) New version available: draft-hajjeh-tls-identity-protection-08.txt
2008-11-26
(System) Posted related IPR disclosure: Eric Rescorla's Statement about IPR related to draft-hajjeh-tls-identity-protection-07 belonging to GROUPE DES ECOLES DES TELECOMMUNICATIONS - ECOLE NATIONALE SUPERIEURE DES TELECOMMUNICATIONS
2008-10-06
07 (System) New version available: draft-hajjeh-tls-identity-protection-07.txt
2008-09-15
09 Amy Vezza IESG state changed to Dead
2008-09-15
09 Amy Vezza Do Not Publish note has been sent to the RFC Editor
2008-09-15
09 Amy Vezza Closed "Approve" ballot
2008-09-15
09 Amy Vezza State Changes to DNP-announcement to be sent from DNP-waiting for AD note by Amy Vezza
2008-09-11
09 Amy Vezza State Changes to DNP-waiting for AD note from IESG Evaluation by Amy Vezza
2008-09-11
09 Russ Housley [Ballot Position Update] New position, No Objection, has been recorded by Russ Housley
2008-09-11
09 David Ward [Ballot Position Update] New position, No Objection, has been recorded by David Ward
2008-09-11
09 Mark Townsley [Ballot Position Update] New position, No Objection, has been recorded by Mark Townsley
2008-09-11
09 Dan Romascanu [Ballot Position Update] New position, No Objection, has been recorded by Dan Romascanu
2008-09-11
09 Magnus Westerlund [Ballot Position Update] New position, Yes, has been recorded by Magnus Westerlund
2008-09-10
09 Tim Polk [Ballot Position Update] New position, Yes, has been recorded by Tim Polk
2008-09-10
09 Ron Bonica [Ballot Position Update] New position, No Objection, has been recorded by Ron Bonica
2008-09-10
09 Jari Arkko [Ballot Position Update] New position, Yes, has been recorded by Jari Arkko
2008-09-08
09 Chris Newman [Ballot comment]
I concur that note #5 from RFC 3932 applies.
2008-09-08
09 Chris Newman [Ballot Position Update] New position, Yes, has been recorded by Chris Newman
2008-09-08
09 Cullen Jennings [Ballot Position Update] New position, Yes, has been recorded by Cullen Jennings
2008-09-07
09 Pasi Eronen [Ballot Position Update] New position, Yes, has been recorded for Pasi Eronen
2008-09-07
09 Pasi Eronen Ballot has been issued by Pasi Eronen
2008-09-07
09 Pasi Eronen Created "Approve" ballot
2008-09-07
09 (System) Ballot writeup text was added
2008-09-07
09 (System) Last call text was added
2008-09-07
09 (System) Ballot approval text was added
2008-08-28
09 Pasi Eronen State Changes to IESG Evaluation from Publication Requested by Pasi Eronen
2008-08-28
09 Pasi Eronen Responsible AD has been changed to Pasi Eronen from Russ Housley
2008-08-28
09 Pasi Eronen Area acronymn has been changed to sec from gen
2008-08-28
09 Pasi Eronen Intended Status has been changed to Experimental from None
2008-08-26
09 Cindy Morgan Placed on agenda for telechat - 2008-09-11 by Cindy Morgan
2008-08-26
09 Cindy Morgan
This RFC-to-be was submitted to the RFC Editor to be published as
Experimental: draft-hajjeh-tls-identity-protection-05.txt

Please let us know if this document conflicts with the IETF …
This RFC-to-be was submitted to the RFC Editor to be published as
Experimental: draft-hajjeh-tls-identity-protection-05.txt

Please let us know if this document conflicts with the IETF standards
process or other work being done in the IETF community.

Four week timeout expires on 23 September 2008.


Credential Protection Ciphersuites for Transport Layer Security (TLS)

The Transport Layer Security (TLS) supports three authentication
modes: authentication of both parties, server authentication with
an unauthenticated client, and total anonymity. For each mode, TLS
specifies a set of cipher suites. Whenever the server is
authenticated, the channel is secure against man-in-the-middle
attacks, but completely anonymous sessions are inherently
vulnerable to such attacks.

The authentication is usually based on either preshared keys or
public key certificates. If a public key certificate is used to
authenticate the TLS client during the TLS Handshake, the TLS
client credentials are sent in clear text over the wire. Thus, any
observer can determine the credentials used by the client, learn
who is reaching the network, when, and from where, and hence
correlate the client credentials to the connection location.

This document defines a set of cipher suites to add client
credential protection to the TLS protocol. This is useful
especially if TLS is used in wireless environments or to secure
remote access. By negotiating one of the ciphersuites described in
this document, the TLS clients will be able to determine for
themselves when, how, to what extent and for what purpose
information about them is communicated to others.
2008-08-26
09 Cindy Morgan Responsible AD has been changed to Russ Housley from Tim Polk
2008-08-26
09 Cindy Morgan State Changes to Publication Requested from Dead by Cindy Morgan
2008-08-04
06 (System) New version available: draft-hajjeh-tls-identity-protection-06.txt
2008-04-02
05 (System) New version available: draft-hajjeh-tls-identity-protection-05.txt
2008-03-27
04 (System) New version available: draft-hajjeh-tls-identity-protection-04.txt
2008-01-28
03 (System) New version available: draft-hajjeh-tls-identity-protection-03.txt
2007-12-12
02 (System) New version available: draft-hajjeh-tls-identity-protection-02.txt
2007-12-10
09 (System) Document has expired
2007-10-26
09 Tim Polk State Changes to Dead from Publication Requested by Tim Polk
2007-09-11
09 Tim Polk Draft Added by Tim Polk in state Publication Requested
2007-06-08
01 (System) New version available: draft-hajjeh-tls-identity-protection-01.txt
2006-11-13
00 (System) New version available: draft-hajjeh-tls-identity-protection-00.txt