Skip to main content

IETF Last Call Review of draft-ietf-tls-deprecate-obsolete-kex-05
review-ietf-tls-deprecate-obsolete-kex-05-secdir-lc-harkins-2025-05-12-00

Request Review of draft-ietf-tls-deprecate-obsolete-kex
Requested revision No specific revision (document currently at 08)
Type IETF Last Call Review
Team Security Area Directorate (secdir)
Deadline 2025-04-28
Requested 2025-04-14
Authors Nimrod Aviram
I-D last updated 2026-01-23 (Latest revision 2026-01-12)
Completed reviews Secdir IETF Last Call review of -05 by Dan Harkins (diff)
Genart IETF Last Call review of -05 by Mallory Knodel (diff)
Artart IETF Last Call review of -05 by Valery Smyslov (diff)
Opsdir IETF Last Call review of -05 by Menachem Dodge (diff)
Artart Telechat review of -06 by Valery Smyslov (diff)
Assignment Reviewer Dan Harkins
State Completed
Request IETF Last Call review on draft-ietf-tls-deprecate-obsolete-kex by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/fNSOzbsw4MDySKXnd9gNJpX6rOg/
Reviewed revision 05 (document currently at 08)
Result Ready
Completed 2025-05-12
review-ietf-tls-deprecate-obsolete-kex-05-secdir-lc-harkins-2025-05-12-00
   Hello,

   Apologize for the tardiness of this, the assignment just fell off
my plate.

    I have reviewed this document as part of the security directorate's
  ongoing effort to review all IETF documents being processed by the
  IESG. These comments were written primarily for the benefit of the
  security area directors. Document editors and WG chairs should treat
  these comments just like any other last call comments.

   This draft deprecates some key exchanges-- RSA and finite field
Diffie-Hellman-- from TLS 1.2. I find the arguments to deprecate
things in a protocol because of implementation issues or
interoperability issues or because of what "operators" do somewhat
unpersuasive but there do seem to also be valid technical reasons
to do this and, importantly, it does not seem like any capabilities
will be lost by deprecating this stuff so go for it.

   The summary of the review is Ready.

   regards,

   Dan.

-- 
"The object of life is not to be on the side of the majority, but to
escape finding oneself in the ranks of the insane." -- Marcus Aurelius