[Acme] Re: Éric Vyncke's Discuss on draft-ietf-acme-onion-05: (with DISCUSS and COMMENT)
Q Misell <q@as207960.net> Wed, 15 January 2025 08:07 UTC
Return-Path: <q@as207960.net>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2B23C1D6203 for <acme@ietfa.amsl.com>; Wed, 15 Jan 2025 00:07:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=as207960.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9MbZYETTTVWU for <acme@ietfa.amsl.com>; Wed, 15 Jan 2025 00:07:45 -0800 (PST)
Received: from mail-vk1-xa36.google.com (mail-vk1-xa36.google.com [IPv6:2607:f8b0:4864:20::a36]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 943A5C1D5C59 for <acme@ietf.org>; Wed, 15 Jan 2025 00:07:45 -0800 (PST)
Received: by mail-vk1-xa36.google.com with SMTP id 71dfb90a1353d-5160f1870f3so2095645e0c.0 for <acme@ietf.org>; Wed, 15 Jan 2025 00:07:45 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=as207960.net; s=google; t=1736928464; x=1737533264; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=EH/g+3GXzaBjgTgVrhGBbSY21w+BjltgxG+D9zt0f/0=; b=JiKBYYl/4HpFncj+r3QngJqiIUwGn+MXJfrd9kUA/19/AMC1QRXzokRamr1rprVWCj zUvrUAUOPQxmMKqwyzpsY42N1F6gVBxHtJIzi2ehsbv4hcOH0S4CnH6wwRKcYViIvWRM pn0nDck8kSpvsukGgWZ3GH8ssjkHuvJ4s3jBRdm5CEajy9UM5BInsFfcmbLhZ2rCJIDA BNyoelgfjph4zCD9qGL1BXBfQsCiNIjTt/6ZeZn3iYZ+nPsu5tOieL6vNXrGmifH424X HD4/F43cnsLYlT85N+foozrKqzK9V5njgkuV9JX0CX4er6116aVWqDWN0RxEizSBr6N1 J6lA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736928464; x=1737533264; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=EH/g+3GXzaBjgTgVrhGBbSY21w+BjltgxG+D9zt0f/0=; b=iikbCKe0e66PYxbUyF+FyLi+9Rsms6wmzPehs0N/OKWNgWFFheUI/XHH10Ndfcq+el 331Kot29IkUqJy7S56FhHC9zKhvpzZQRGUY93CVwCUO9I+PJOtrznR0E/D2jYD0xbLlI b198yvQWkSPgyEDWo/lXetiy89cVqRq9t3O70fqFI4tYNhmXBm3rv0GrR20n3jXSNC/s O5gSohp/ymjCdnpvrG/iXNM6zVdDgMBp9v7jUR1L3oDDBtkWIWNCTXaEdgVhmpoixKIE 3j3f6ajNc1zVHryibzqC4TASQtkci5L4QxokdYbgNU76OgA/2XVa3DG8nzrDgXVh/OID JvdA==
X-Forwarded-Encrypted: i=1; AJvYcCXguArq1LGlqZPEUeUjba8QvPcPand/DEhzEKn7zQnlh8RLAsJNu7gZSDPAgDSlC9ObHpay@ietf.org
X-Gm-Message-State: AOJu0YzFirGOJ1RcQ5yunD0g7JMPdH5vyxD2DnbIjd726vFyCQFc0YbV ZYkPghJ5UjdxjyGlg1fZF9sXPt2cN55QH9UE4VIG+KWhVfUKGcyO5cuBTv3DU1RCUhIXnZUCUSD ukqakPOrZtC88TGc9af+P8RcmMph0cM3FOn3emyg/JQdV28TGikc=
X-Gm-Gg: ASbGnctKmUhRr8JOb9A782jtD3qJcLKqauxcmtgtoiLfGmdkd4BDe5jITI1b4h4z66B 482cenomJcPkkVr3weQg+HR1xqKenPulRdkLogJGEoKK0PNOAfI6jCfm3MKG6PzHvC0/j2g==
X-Google-Smtp-Source: AGHT+IEnEIcmtQUVn6QTO6K1sA7l8DiyGixzVHOjzO4r48ANOqYumuNU6eOpGw3CUwow/ptTRnVoPEAzVYZ65e7IePI=
X-Received: by 2002:a05:6122:50b:b0:50c:9834:57b3 with SMTP id 71dfb90a1353d-51c6c46b338mr24437863e0c.4.1736928463997; Wed, 15 Jan 2025 00:07:43 -0800 (PST)
MIME-Version: 1.0
References: <173582117952.1341220.11145754440923005582@dt-datatracker-65f549669d-2xld9> <CAJwNE+9thLJX6TyC10Gpoc54QXpMD2T65Mh6ST5Ffmsg0Z4JfQ@mail.gmail.com> <SA2PR11MB49727195737541B583F5725DA9132@SA2PR11MB4972.namprd11.prod.outlook.com> <CAMEWqGukbtUFNNTWNLSWwfD3AbU__Vt4bsUSHbmjA5o7iiQ_Vw@mail.gmail.com> <PH0PR11MB49669B9A1BC7666F4B4ADD47A9182@PH0PR11MB4966.namprd11.prod.outlook.com> <CAMEWqGuqaWoJC4LsRwkYRhkmCQMsYqoQ3UYLf6_86fmFyFswNQ@mail.gmail.com> <PH0PR11MB4966FE1AFA3273030509B208A9182@PH0PR11MB4966.namprd11.prod.outlook.com>
In-Reply-To: <PH0PR11MB4966FE1AFA3273030509B208A9182@PH0PR11MB4966.namprd11.prod.outlook.com>
From: Q Misell <q@as207960.net>
Date: Wed, 15 Jan 2025 09:07:08 +0100
X-Gm-Features: AbW1kvbAiZQ1a9PrFXyG2u0i1s-04PShLFohBNli1uqLrlLnEUww2oTCXR_LWnw
Message-ID: <CAMEWqGtaaOtr24nBdbzb9PE4JRmp81uAZQFLCn+eN-ZuT9_izw@mail.gmail.com>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
Content-Type: multipart/alternative; boundary="00000000000018e7b9062bba2c46"
Message-ID-Hash: 5UTMZ3WRL5KVM34GWB5LYYANUYLSMSEZ
X-Message-ID-Hash: 5UTMZ3WRL5KVM34GWB5LYYANUYLSMSEZ
X-MailFrom: q@as207960.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Q Misell <q=40as207960.net@dmarc.ietf.org>, Tomofumi Okubo <tomofumi.okubo@gmail.com>, The IESG <iesg@ietf.org>, "draft-ietf-acme-onion@ietf.org" <draft-ietf-acme-onion@ietf.org>, "acme-chairs@ietf.org" <acme-chairs@ietf.org>, "acme@ietf.org" <acme@ietf.org>, "tomofumi.okubo+ietf@gmail.com" <tomofumi.okubo+ietf@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: Éric Vyncke's Discuss on draft-ietf-acme-onion-05: (with DISCUSS and COMMENT)
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/1dEVbYHN8i2rdK_4yufkXQ-ctV8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>
Your wish is my command, I have just pushed -07 with that change. ------------------------------ Any statements contained in this email are personal to the author and are not necessarily the statements of the company unless specifically stated. AS207960 Cyfyngedig, having a registered office at 13 Pen-y-lan Terrace, Caerdydd, Cymru, CF23 9EU, trading as Glauca Digital, is a company registered in Wales under № 12417574 <https://find-and-update.company-information.service.gov.uk/company/12417574>, LEI 875500FXNCJPAPF3PD10. ICO register №: ZA782876 <https://ico.org.uk/ESDWebPages/Entry/ZA782876>. UK VAT №: GB378323867. EU VAT №: EU372013983. Turkish VAT №: 0861333524. South Korean VAT №: 522-80-03080. AS207960 Ewrop OÜ, having a registered office at Lääne-Viru maakond, Tapa vald, Porkuni küla, Lossi tn 1, 46001, trading as Glauca Digital, is a company registered in Estonia under № 16755226. Estonian VAT №: EE102625532. Glauca Digital and the Glauca logo are registered trademarks in the UK, under № UK00003718474 and № UK00003718468, respectively. Ar Maw, 14 Ion 2025 am 18:37 Eric Vyncke (evyncke) <evyncke@cisco.com> ysgrifennodd: > Q, this would be perfect. > > > > As soon as the revised -07 is submitted with such a text, I am clearing my > DISCUSS. > > > > Please note that I will be away from my keyboard for 2 weeks in 2 days 😲 > > > > Regards > > > > -éric > > > > *From: *Q Misell <q@as207960.net> > *Date: *Tuesday, 14 January 2025 at 17:25 > *To: *Eric Vyncke (evyncke) <evyncke@cisco.com> > *Cc: *Q Misell <q=40as207960.net@dmarc.ietf.org>, Tomofumi Okubo < > tomofumi.okubo@gmail.com>, The IESG <iesg@ietf.org>, > draft-ietf-acme-onion@ietf.org <draft-ietf-acme-onion@ietf.org>, > acme-chairs@ietf.org <acme-chairs@ietf.org>, acme@ietf.org <acme@ietf.org>, > tomofumi.okubo+ietf@gmail.com <tomofumi.okubo+ietf@gmail.com> > *Subject: *Re: Éric Vyncke's Discuss on draft-ietf-acme-onion-05: (with > DISCUSS and COMMENT) > > Indeed, I did not understand - thanks for clarifying. I will make an > appropriate amendment to make it clear that "onion-csr-01" is only for use > in the context of .onion domains. > ------------------------------ > > Any statements contained in this email are personal to the author and are > not necessarily the statements of the company unless specifically stated. > AS207960 Cyfyngedig, having a registered office at 13 Pen-y-lan Terrace, > Caerdydd, Cymru, CF23 9EU, trading as Glauca Digital, is a company > registered in Wales under № 12417574 > <https://find-and-update.company-information.service.gov.uk/company/12417574>, > LEI 875500FXNCJPAPF3PD10. ICO register №: ZA782876 > <https://ico.org.uk/ESDWebPages/Entry/ZA782876>. UK VAT №: GB378323867. > EU VAT №: EU372013983. Turkish VAT №: 0861333524. South Korean VAT №: > 522-80-03080. AS207960 Ewrop OÜ, having a registered office at Lääne-Viru > maakond, Tapa vald, Porkuni küla, Lossi tn 1, 46001, trading as Glauca > Digital, is a company registered in Estonia under № 16755226. Estonian VAT > №: EE102625532. Glauca Digital and the Glauca logo are registered > trademarks in the UK, under № UK00003718474 and № UK00003718468, > respectively. > > > > > > Ar Maw, 14 Ion 2025 am 15:47 Eric Vyncke (evyncke) <evyncke@cisco.com> > ysgrifennodd: > > Hello Q, > > > > Thanks for your reply and the updated version, which addresses all my > non-blocking COMMENT. > > > > It seems that I was not clear in my DISCUSS point though, sorry about that. > > > > The DISCUSS is based on the text below that I find ambiguous whether > “onion-csr-01” challenge can be used also for non “.onion” FQDN, and by > ‘can be used’ I do not only mean technically but also whether the ACME WG > has agreed on this extended non .onion use and whether it fits the ACME > charter. All in all, adding a sentence like “This “onion-csr-01” challenge > MAY (or MUST NOT) be used for non “.onion” Special-Use Domain Names.” Will > clear the ambiguity and I will clear my DISCUSS ballot. > > > > ``` > > Two methods already defined in ACME and allowed by the CA/BF ("http-01" > and "tls-alpn-01") do not allow issuance of wildcard certificates. A > ".onion" Special-Use Domain Name can have subdomains (just like any other > domain in the DNS), and a site operator may find it useful to have one > certificate for all virtual hosts on their site. > > ``` > > > > Regards > > > > -éric > > > > *From: *Q Misell <q=40as207960.net@dmarc.ietf.org> > *Date: *Monday, 13 January 2025 at 10:57 > *To: *Eric Vyncke (evyncke) <evyncke@cisco.com> > *Cc: *Tomofumi Okubo <tomofumi.okubo@gmail.com>, The IESG <iesg@ietf.org>, > draft-ietf-acme-onion@ietf.org <draft-ietf-acme-onion@ietf.org>, > acme-chairs@ietf.org <acme-chairs@ietf.org>, acme@ietf.org <acme@ietf.org>, > tomofumi.okubo+ietf@gmail.com <tomofumi.okubo+ietf@gmail.com> > *Subject: *Re: Éric Vyncke's Discuss on draft-ietf-acme-onion-05: (with > DISCUSS and COMMENT) > > > > Hi Eric, > > > > > May the onion-csr-01 challenge be used over the plain global Internet? > As it allows for wildcard certificates and plain ACME does not, it would > seem necessary to specify whether it is supported or forbidden. > > > > I do not quite follow what you mean here. This document defines extensions > to ACME, and ACME may be carried over the plain Internet or over Tor. > "onion-csr-01" only makes sense in the context of requesting certificates > for .onion domains, however the medium over which these are requests are > made is of no concern to ACME. > > > > > s/These use the ".onion"/These services use the ".onion"/ (I had to > re-read the whole sentence 3 times to understand it) > > > > Will incorporate. > > > > > As 3.1.1 uses 'MUST NOT', suggest to s/can be used/MAY be used/ > > > > Agreed, will incorporate. > > > > > What is the basis for selecting 30 days? I would assume that the ACME > challenge/response is done within minutes if not seconds. Or is this > challenge/response assumed to be executed multiple times? > > > > This is copied from the CA/BF BRs, I will add a reference to them. It may > be that some manual work is involved in accessing an offline identity key > on a HSM or some air-gapped machine, hence the long time. > > > > > Only supporting Ed25519 seems to lack agility or am I missing something? > > > > Tor only supports Ed25519. > > > > > It is also unclear to me whether authKey is the client public key > (probably) or the server public key. Please add clarifying text. > > > > Will do. > > > > > Is authKey the same field as in section 3.2? > > > > I will add a cross reference between section 3.2 and section 4. > > > > > To avoid any ambiguity, please add a reference to the registry by its URI > > > > Will do. > > > > Q > ------------------------------ > > Any statements contained in this email are personal to the author and are > not necessarily the statements of the company unless specifically stated. > AS207960 Cyfyngedig, having a registered office at 13 Pen-y-lan Terrace, > Caerdydd, Cymru, CF23 9EU, trading as Glauca Digital, is a company > registered in Wales under № 12417574 > <https://find-and-update.company-information.service.gov.uk/company/12417574>, > LEI 875500FXNCJPAPF3PD10. ICO register №: ZA782876 > <https://ico.org.uk/ESDWebPages/Entry/ZA782876>. UK VAT №: GB378323867. > EU VAT №: EU372013983. Turkish VAT №: 0861333524. South Korean VAT №: > 522-80-03080. AS207960 Ewrop OÜ, having a registered office at Lääne-Viru > maakond, Tapa vald, Porkuni küla, Lossi tn 1, 46001, trading as Glauca > Digital, is a company registered in Estonia under № 16755226. Estonian VAT > №: EE102625532. Glauca Digital and the Glauca logo are registered > trademarks in the UK, under № UK00003718474 and № UK00003718468, > respectively. > > > > > > Ar Iau, 9 Ion 2025 am 12:58 Eric Vyncke (evyncke) <evyncke@cisco.com> > ysgrifennodd: > > Hello Tomofumi, > > > > Thanks for your reply and for the shepherd’s write-up update: it makes > sense indeed to set the intended status to PS. > > > > Regards > > > > -éric > > > > *From: *Tomofumi Okubo <tomofumi.okubo@gmail.com> > *Date: *Wednesday, 8 January 2025 at 20:01 > *To: *Eric Vyncke (evyncke) <evyncke@cisco.com> > *Cc: *The IESG <iesg@ietf.org>, draft-ietf-acme-onion@ietf.org < > draft-ietf-acme-onion@ietf.org>, acme-chairs@ietf.org < > acme-chairs@ietf.org>, acme@ietf.org <acme@ietf.org>, > tomofumi.okubo+ietf@gmail.com <tomofumi.okubo+ietf@gmail.com> > *Subject: *Re: Éric Vyncke's Discuss on draft-ietf-acme-onion-05: (with > DISCUSS and COMMENT) > > Hello Éric, > > > > My apologies for the delayed response. > > Thank you very much for the review and comments. > > > > Onion is an extension to RFC8555 which is standards track and already has > some implementations as well. Therefore, I do believe that the proposed > standard would be the suitable status for this draft. I have also updated > the shepherd's write-up accordingly. > > > Thanks again! > > Tomofumi > > > > On Thu, Jan 2, 2025 at 8:33 PM Éric Vyncke via Datatracker < > noreply@ietf.org> wrote: > > Éric Vyncke has entered the following ballot position for > draft-ietf-acme-onion-05: Discuss > > When responding, please keep the subject line intact and reply to all > email addresses included in the To and CC lines. (Feel free to cut this > introductory paragraph, however.) > > > Please refer to > https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ > for more information about how to handle DISCUSS and COMMENT positions. > > > The document, along with other ballot positions, can be found here: > https://datatracker.ietf.org/doc/draft-ietf-acme-onion/ > > > > ---------------------------------------------------------------------- > DISCUSS: > ---------------------------------------------------------------------- > > > # Éric Vyncke, INT AD, comments for draft-ietf-acme-onion-05 > CC @evyncke > > Thank you for the work put into this document. > > Please find below one blocking DISCUSS points (easy to address, i.e., I > simply > want to check this point), some non-blocking COMMENT points (but replies > would > be appreciated even if only for my own education), and some nits. > > Special thanks to Tomofumi Okubo for the shepherd's detailed write-up > including > the WG consensus *but it lacks* the justification of the intended status. > > You may also expect a DNS directorate review as it has been requested. > > I hope that this review helps to improve the document, > > Regards, > > -éric > > ## DISCUSS (blocking) > > As noted in https://www.ietf.org/blog/handling-iesg-ballot-positions/, a > DISCUSS ballot is just a request to have a discussion on the following > topics: > > ### onion-csr-01 and global Internet ACME > > It is easy to clear this DISCUSS by replying to the next paragraph. > > May the onion-csr-01 challenge be used over the plain global Internet ? As > it > allows for wildcard certificates and plain ACME does not, it would seem > necessary to specify whether it is supported or forbidden. > > > ---------------------------------------------------------------------- > COMMENT: > ---------------------------------------------------------------------- > > > ## COMMENTS (non-blocking) > > ### Section 1 > > s/These use the ".onion"/These services use the ".onion"/ (I had to > re-read the > whole sentence 3 times to understand it) > > ### Sections 3.1.2 and 3.1.3 > > As 3.1.1 uses 'MUST NOT', suggest to s/can be used/MAY be used/ > > ### Section 3.2 > > What is the basis for selecting 30 days? I would assume that the ACME > challenge/response is done within minutes if not seconds. Or is this > challenge/response assumed to be executed multiple times ? > > Only supporting Ed25519 seems to lack agility or am I missing something ? > > It is also unclear to me whether authKey is the client public key > (probably) or > the server public key. Please add clarifying text. Some explanations could > be > given on when to use this field. > > ### Section 4 > > Is authKey the same field as in section 3.2 ? This would explain this field > role but is confusing to the reader. Suggest adding something like "this > field > is specified in section 4' when introducing this field in section 3.2. > > ### Section 7.1 > > To avoid any ambiguity, please add a reference to the registry by its URI > https://www.iana.org/assignments/acme/acme.xhtml#acme-validation-methods > > The legend of table 1 should probably use singular and not plural. > >
- [Acme] Éric Vyncke's Discuss on draft-ietf-acme-o… Éric Vyncke via Datatracker
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Eric Vyncke (evyncke)
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Tomofumi Okubo
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Q Misell
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Eric Vyncke (evyncke)
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Q Misell
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Eric Vyncke (evyncke)
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Q Misell
- [Acme] Re: Éric Vyncke's Discuss on draft-ietf-ac… Eric Vyncke (evyncke)