Skip to main content

PEM file format for ECH
draft-farrell-tls-pemesni-13

Yes

(Erik Kline)
(Paul Wouters)

No Objection

Andy Newton
Gunter Van de Velde
Jim Guichard
Ketan Talaulikar
Mahesh Jethanandani
Mike Bishop

Note: This ballot was opened for revision 12 and is now closed.

Deb Cooley
Yes
Comment (2026-01-18 for -12) Not sent
In my opinion, this is a clear, concise, and easy to understand data format.
Andy Newton
No Objection
Éric Vyncke
No Objection
Comment (2026-01-09 for -12) Sent
Simple and straight to the topic draft, thanks for writing it.

Now, I have some comments:

1) why isn't this a TLS WG document ? I have read Sean Turner's explanation (thanks the shepherd's write-up), but this does not sound doing the 'right thing'. Anyway, this is IETF stream PS so all it good

2) the abstract is more like an introduction to the problem, it should really state the obvious (for completeness) "This document specifies the format used to store the keys"

3) explanation about the need for `BEGIN ECHCONFIG` rather than "BEGIN PUBLICKEY" would be welcome, I guess it allows for also having to store the public key in the same file for potentially other uses.

-éric
Gorry Fairhurst
No Objection
Comment (2026-01-12 for -12) Sent
Thank you for a clearly written document.

I have one comment which I think would be a useful addition: The current abstract doesn't say that this document specifies the format to be used to store the ECH keys. It would be good to a sentence saying this.
Gunter Van de Velde
No Objection
Jim Guichard
No Objection
Ketan Talaulikar
No Objection
Mahesh Jethanandani
No Objection
Mike Bishop
No Objection
Mohamed Boucadair
(was Discuss) No Objection
Comment (2026-01-23) Sent
Hi Stephen,

Thank you for the discussion and taking care of the feedback.

Cheers,
Med
Roman Danyliw
No Objection
Comment (2026-01-21 for -12) Sent
I support Med Boucadair’s DISCUSS feedback.
** Abstract.  Editorial.
   Encrypted ClientHello (ECH) key pairs need to be configured into TLS
   servers, which can be built using different TLS libraries, so there
   is a benefit and little cost in documenting a file format to use for
   these key pairs, similar to how RFC 7468 defines other PEM file
   formats.
Consider if defining this file format needs to be rationalized.  Maybe just a straight declaration of what it is:

NEW
Encrypted ClientHello (ECH) key pairs need to be configured into TLS 1.3 servers when the ECH feature is used.  This document specifies a file format to use for these key pairs.
Erik Kline Former IESG member
Yes
Yes (for -12) Not sent

                            
Paul Wouters Former IESG member
Yes
Yes (for -12) Unknown