Cc: IETF discussion list <ietf@xxxxxxxx>, Bill Frantz <frantz@xxxxxxxxxxxxxx>, Peter Gutmann <pgut001@xxxxxxxxxxxxxxxxx>, General Area Review Team <gen-art@xxxxxxxx>, Steve Fenter <steven.fenter58@xxxxxxxxx>, draft-ietf-tls-tls13.all@xxxxxxxx, "Dale R. Worley" <worley@xxxxxxxxxxx>, "<tls@xxxxxxxx>" <tls@xxxxxxxx>
As you mention, debugging TLS is unnecessarily painful if there's a problem,
you typically just get a handshake-failed alert which is essentially no
information at all. Having a debug-mode capability to send back a long-form
error message would be extremely useful, maybe an extension to say "send back
a long-form alert with more than just 'BOOLEAN succeeded = FALSE' in it"