TLS 1.1/1.2 impact on applications protocols: msg#00040
ietf.apps-discuss
|
Subject: |
TLS 1.1/1.2 impact on applications protocols |
The changes that are happening in the TLS WG with the publication of TLS 1.1
and the upcoming TLS 1.2 do have a significant impact on application
deployment. Many of our application protocols make TLS 1.0
mandatory-to-implement. I'd like to see a discussion of the importance of
transition to 1.2 (when it comes out) and the real-world problems that might
occur. Do we need to update our application protocol specifications to mandate
the newer version? Or perhaps we need an app-area RFC which does that to a set
of application protocols?
Can we just have a blanket exception to the standards status
(proposed/draft/full) reference rules for the TLS base spec (and trust the TLS
WG to do the right thing)? It seems more important to keep up-to-date on
security technology than to have normative reference purity.
Perhaps this would be a good topic for the Prague apparea meeting?
- Chris
|