Skip to main content

Using TLS 1.3 with HTTP/2
draft-ietf-httpbis-http2-tls13-03

Revision differences

Document history

Date Rev. By Action
2020-02-20
03 (System) RFC Editor state changed to AUTH48-DONE from AUTH48
2020-02-10
03 (System) RFC Editor state changed to AUTH48 from RFC-EDITOR
2020-01-08
03 (System) RFC Editor state changed to RFC-EDITOR from EDIT
2019-10-22
03 (System) IANA Action state changed to No IANA Actions from In Progress
2019-10-22
03 (System) IANA Action state changed to In Progress
2019-10-21
03 (System) RFC Editor state changed to EDIT
2019-10-21
03 (System) IESG state changed to RFC Ed Queue from Approved-announcement sent
2019-10-21
03 (System) Announcement was received by RFC Editor
2019-10-21
03 Amy Vezza IESG state changed to Approved-announcement sent from Approved-announcement to be sent
2019-10-21
03 Amy Vezza IESG has approved the document
2019-10-21
03 Amy Vezza Closed "Approve" ballot
2019-10-21
03 Amy Vezza Ballot approval text was generated
2019-10-18
03 Gunter Van de Velde Assignment of request for Last Call review by OPSDIR to Tianran Zhou was marked no-response
2019-10-17
03 Barry Leiba IESG state changed to Approved-announcement to be sent from Approved-announcement to be sent::Point Raised - writeup needed
2019-10-17
03 David Benjamin New version available: draft-ietf-httpbis-http2-tls13-03.txt
2019-10-17
03 (System) New version approved
2019-10-17
03 (System) Request for posting confirmation emailed to previous authors: David Benjamin
2019-10-17
03 David Benjamin Uploaded new revision
2019-10-17
03 David Benjamin Uploaded new revision
2019-10-17
02 Cindy Morgan IESG state changed to Approved-announcement to be sent::Point Raised - writeup needed from IESG Evaluation
2019-10-17
02 Martin Vigoureux [Ballot Position Update] New position, No Objection, has been recorded for Martin Vigoureux
2019-10-16
02 Alvaro Retana [Ballot Position Update] New position, No Objection, has been recorded for Alvaro Retana
2019-10-16
02 Matthew Miller Request for Last Call review by ARTART Completed: Ready. Reviewer: Matthew Miller. Sent review to list.
2019-10-16
02 Benjamin Kaduk
[Ballot comment]
Thanks for this; I just have some minor nit-level comments; no response necessary.

Abstract

  This document updates HTTP/2 to prohibit TLS 1.3 …
[Ballot comment]
Thanks for this; I just have some minor nit-level comments; no response necessary.

Abstract

  This document updates HTTP/2 to prohibit TLS 1.3 post-handshake
  authentication, as an analog to existing TLS 1.2 renegotiation
  restriction.

nit: either "restrictions" or "the existing".

Section 1

  TLS 1.3 [RFC8446] updates TLS 1.2 to remove renegotiation in favor of
  separate post-handshake authentication and key update mechanisms.
  The former shares the same problems with multiplexed protocols, but
  the prohibition in HTTP/2 only applies to TLS 1.2 renegotiation.

nit: I'd suggest referring to a specific RFC rather than "HTTP/2" --
this document will in some sense become part of "HTTP/2" upon
publication :)

Section 3

  HTTP/2 servers MUST NOT send post-handshake TLS 1.3
  CertificateRequest messages.  HTTP/2 clients MUST treat TLS 1.3 post-
  handshake authentication as a connection error (see Section 5.4.1 of
  [RFC7540]) of type PROTOCOL_ERROR.

nit: is it the authentication or the request thereof that is the
connection error?

Section 4

  Unless the use of a new type of TLS message depends on an interaction
  with the application layer protocol, that TLS message can be sent
  after the handshake completes.

I don't see anything better to say than this, but ... will
draft-ietf-tls-exported-authenticator be considered to "depend on an
interaction with the application layer protocol"?
(Also, nit: hyphenate "application-layer".)
2019-10-16
02 Benjamin Kaduk [Ballot Position Update] New position, Yes, has been recorded for Benjamin Kaduk
2019-10-16
02 Alissa Cooper [Ballot Position Update] New position, No Objection, has been recorded for Alissa Cooper
2019-10-16
02 Alexey Melnikov [Ballot comment]
Thank you for this document.
2019-10-16
02 Alexey Melnikov [Ballot Position Update] New position, No Objection, has been recorded for Alexey Melnikov
2019-10-15
02 Adam Roach [Ballot Position Update] New position, Yes, has been recorded for Adam Roach
2019-10-15
02 Suresh Krishnan [Ballot Position Update] New position, No Objection, has been recorded for Suresh Krishnan
2019-10-15
02 Deborah Brungard [Ballot Position Update] New position, No Objection, has been recorded for Deborah Brungard
2019-10-15
02 Warren Kumari
[Ballot comment]
Please update the Abstract to say something like:
"This document updates RFC 7540 by  forbidding  TLS 1.3 post-handshake authentication." or similar.

Also, thanks …
[Ballot comment]
Please update the Abstract to say something like:
"This document updates RFC 7540 by  forbidding  TLS 1.3 post-handshake authentication." or similar.

Also, thanks to Tianran for the OpsDir review.
2019-10-15
02 Warren Kumari [Ballot Position Update] New position, No Objection, has been recorded for Warren Kumari
2019-10-15
02 Ignas Bagdonas [Ballot Position Update] New position, No Objection, has been recorded for Ignas Bagdonas
2019-10-15
02 Magnus Westerlund [Ballot Position Update] New position, No Objection, has been recorded for Magnus Westerlund
2019-10-15
02 Roman Danyliw [Ballot comment]
** Abstract.  Recommend adding a sentence to the abstract that this draft updates RFC7540.
2019-10-15
02 Roman Danyliw [Ballot Position Update] New position, No Objection, has been recorded for Roman Danyliw
2019-10-13
02 Tianran Zhou Request for Last Call review by OPSDIR Completed: Ready. Reviewer: Tianran Zhou. Sent review to list.
2019-10-12
02 Erik Kline Request for Last Call review by GENART Completed: Ready. Reviewer: Erik Kline. Sent review to list.
2019-10-12
02 Barry Leiba IESG state changed to IESG Evaluation from Waiting for AD Go-Ahead
2019-10-11
02 Mirja Kühlewind [Ballot Position Update] New position, No Objection, has been recorded for Mirja Kühlewind
2019-10-11
02 (System) IESG state changed to Waiting for AD Go-Ahead from In Last Call
2019-10-10
02 Éric Vyncke [Ballot Position Update] New position, No Objection, has been recorded for Éric Vyncke
2019-10-10
02 Rich Salz Request for Last Call review by SECDIR Completed: Ready. Reviewer: Rich Salz. Sent review to list.
2019-10-09
02 (System) IANA Review state changed to IANA OK - No Actions Needed from IANA - Review Needed
2019-10-09
02 Sabrina Tanamal
(Via drafts-lastcall@iana.org): IESG/Authors/WG Chairs:

The IANA Functions Operator has reviewed draft-ietf-httpbis-http2-tls13-02, which is currently in Last Call, and has the following comments:

We …
(Via drafts-lastcall@iana.org): IESG/Authors/WG Chairs:

The IANA Functions Operator has reviewed draft-ietf-httpbis-http2-tls13-02, which is currently in Last Call, and has the following comments:

We understand that this document doesn't require any registry actions.

While it's often helpful for a document's IANA Considerations section to remain in place upon publication even if there are no actions, if the authors strongly prefer to remove it, we do not object.

If this assessment is not accurate, please respond as soon as possible.

Thank you,

Sabrina Tanamal
Senior IANA Services Specialist
2019-10-09
02 Amy Vezza Placed on agenda for telechat - 2019-10-17
2019-10-09
02 Barry Leiba Ballot has been issued
2019-10-09
02 Barry Leiba [Ballot Position Update] New position, Yes, has been recorded for Barry Leiba
2019-10-09
02 Barry Leiba Created "Approve" ballot
2019-10-09
02 Barry Leiba Ballot writeup was changed
2019-10-04
02 Jean Mahoney Request for Last Call review by GENART is assigned to Erik Kline
2019-10-04
02 Jean Mahoney Request for Last Call review by GENART is assigned to Erik Kline
2019-10-03
02 Suhas Nandakumar Request for Last Call review by ARTART is assigned to Matthew Miller
2019-10-03
02 Suhas Nandakumar Request for Last Call review by ARTART is assigned to Matthew Miller
2019-10-03
02 Tero Kivinen Request for Last Call review by SECDIR is assigned to Rich Salz
2019-10-03
02 Tero Kivinen Request for Last Call review by SECDIR is assigned to Rich Salz
2019-10-01
02 Gunter Van de Velde Request for Last Call review by OPSDIR is assigned to Tianran Zhou
2019-10-01
02 Gunter Van de Velde Request for Last Call review by OPSDIR is assigned to Tianran Zhou
2019-10-01
02 Gunter Van de Velde Request for Last Call review by OPSDIR is assigned to Tianran Zhou
2019-10-01
02 Gunter Van de Velde Request for Last Call review by OPSDIR is assigned to Tianran Zhou
2019-09-27
02 Cindy Morgan IANA Review state changed to IANA - Review Needed
2019-09-27
02 Cindy Morgan
The following Last Call announcement was sent out (ends 2019-10-11):

From: The IESG
To: IETF-Announce
CC: httpbis-chairs@ietf.org, draft-ietf-httpbis-http2-tls13@ietf.org, Mark Nottingham , mnot@mnot.net, …
The following Last Call announcement was sent out (ends 2019-10-11):

From: The IESG
To: IETF-Announce
CC: httpbis-chairs@ietf.org, draft-ietf-httpbis-http2-tls13@ietf.org, Mark Nottingham , mnot@mnot.net, ietf-http-wg@w3.org, barryleiba@gmail.com
Reply-To: ietf@ietf.org
Sender:
Subject: Last Call:  (Using TLS 1.3 with HTTP/2) to Proposed Standard


The IESG has received a request from the Hypertext Transfer Protocol WG
(httpbis) to consider the following document: - 'Using TLS 1.3 with HTTP/2'
  as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2019-10-11. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the beginning of
the Subject line to allow automated sorting.

Abstract


  This document updates HTTP/2 to prohibit TLS 1.3 post-handshake
  authentication, as an analog to existing TLS 1.2 renegotiation
  restriction.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-httpbis-http2-tls13/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-httpbis-http2-tls13/ballot/


No IPR declarations have been submitted directly on this I-D.




2019-09-27
02 Cindy Morgan IESG state changed to In Last Call from Last Call Requested
2019-09-27
02 Barry Leiba Last call was requested
2019-09-27
02 Barry Leiba Last call announcement was generated
2019-09-27
02 Barry Leiba Ballot approval text was generated
2019-09-27
02 Barry Leiba Ballot writeup was generated
2019-09-27
02 Barry Leiba IESG state changed to Last Call Requested from AD Evaluation
2019-09-26
02 Barry Leiba IESG state changed to AD Evaluation from Publication Requested
2019-09-26
02 Mark Nottingham
# Shepherd Writeup for draft-ietf-httpbis-http2-tls13

## 1. Summary

Mark Nottingham is the Document Shepherd; Barry Lieba is the responsible Area Director.0

This document updates HTTP/2 …
# Shepherd Writeup for draft-ietf-httpbis-http2-tls13

## 1. Summary

Mark Nottingham is the Document Shepherd; Barry Lieba is the responsible Area Director.0

This document updates HTTP/2 to prohibit TLS 1.3 post-handshake authentication, as an analog to
existing TLS 1.2 renegotiation restriction.

Its intended status is Proposed Standard.

## 2. Review and Consensus

This document was prepared when Working Group members noticed that the restrictions for post-handshake authentication in HTTP/2, which were designed with the constraints of TLS 1.2 in mind, no longer were necessary for TLS 1.3.

Therefore, this is a very short update to address that. It has wide support amongst the working group, including from implementers.

## 3. Intellectual Property

The author has confirmed that to their direct, personal knowledge, all IPR related to this document has already been disclosed, in conformance with BCPs 78 and 79.

## 4. Other Points

None.
2019-09-26
02 Mark Nottingham Responsible AD changed to Barry Leiba
2019-09-26
02 Mark Nottingham IETF WG state changed to Submitted to IESG for Publication from In WG Last Call
2019-09-26
02 Mark Nottingham IESG state changed to Publication Requested from I-D Exists
2019-09-26
02 Mark Nottingham IESG process started in state Publication Requested
2019-09-26
02 Mark Nottingham Changed consensus to Yes from Unknown
2019-09-26
02 Mark Nottingham Intended Status changed to Proposed Standard from None
2019-09-26
02 Mark Nottingham
# Shepherd Writeup for draft-ietf-httpbis-http2-tls13

## 1. Summary

Mark Nottingham is the Document Shepherd; Barry Lieba is the responsible Area Director.0

This document updates HTTP/2 …
# Shepherd Writeup for draft-ietf-httpbis-http2-tls13

## 1. Summary

Mark Nottingham is the Document Shepherd; Barry Lieba is the responsible Area Director.0

This document updates HTTP/2 to prohibit TLS 1.3 post-handshake authentication, as an analog to
existing TLS 1.2 renegotiation restriction.

Its intended status is Proposed Standard.

## 2. Review and Consensus

This document was prepared when Working Group members noticed that the restrictions for post-handshake authentication in HTTP/2, which were designed with the constraints of TLS 1.2 in mind, no longer were necessary for TLS 1.3.

Therefore, this is a very short update to address that. It has wide support amongst the working group, including from implementers.

## 3. Intellectual Property

The author has confirmed that to their direct, personal knowledge, all IPR related to this document has already been disclosed, in conformance with BCPs 78 and 79.

## 4. Other Points

None.
2019-09-26
02 Mark Nottingham Notification list changed to Mark Nottingham <mnot@mnot.net>
2019-09-26
02 Mark Nottingham Document shepherd changed to Mark Nottingham
2019-09-20
02 David Benjamin New version available: draft-ietf-httpbis-http2-tls13-02.txt
2019-09-20
02 (System) New version approved
2019-09-20
02 (System) Request for posting confirmation emailed to previous authors: David Benjamin
2019-09-20
02 David Benjamin Uploaded new revision
2019-09-20
02 David Benjamin Uploaded new revision
2019-09-13
01 David Benjamin New version available: draft-ietf-httpbis-http2-tls13-01.txt
2019-09-13
01 (System) New version approved
2019-09-13
01 (System) Request for posting confirmation emailed to previous authors: David Benjamin
2019-09-13
01 David Benjamin Uploaded new revision
2019-09-13
01 David Benjamin Uploaded new revision
2019-09-04
00 Mark Nottingham IETF WG state changed to In WG Last Call from WG Document
2019-05-14
00 Patrick McManus adopted individual draft by httpbis wg
2019-05-14
00 Patrick McManus This document now replaces draft-davidben-http2-tls13 instead of None
2019-05-13
00 David Benjamin New version available: draft-ietf-httpbis-http2-tls13-00.txt
2019-05-13
00 (System) WG -00 approved
2019-05-13
00 David Benjamin Set submitter to "David Benjamin ", replaces to (none) and sent approval email to group chairs: httpbis-chairs@ietf.org
2019-05-13
00 David Benjamin Uploaded new revision