Re: [Acme] [Technical Errata Reported] RFC8555 (5771)

Rob Stradling <rob@sectigo.com> Thu, 04 July 2019 16:08 UTC

Return-Path: <rob@sectigo.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8196C12011F for <acme@ietfa.amsl.com>; Thu, 4 Jul 2019 09:08:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=comodoca.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id traGsvKEz-Mv for <acme@ietfa.amsl.com>; Thu, 4 Jul 2019 09:08:45 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-eopbgr750044.outbound.protection.outlook.com [40.107.75.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 693F91200CD for <acme@ietf.org>; Thu, 4 Jul 2019 09:08:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comodoca.onmicrosoft.com; s=selector1-comodoca-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=q4okzbpKxJzVJ89iewg/z2muFDleacwchjO8MVEGE9s=; b=DbCr3Qp2ViLcPnftGcY8Nbl9+MRivf0PabFi7TB+6BZgzMRrzBWbwJ61Y6QBdoxm9W5Mx91SeKfgOQKZr3UAYpoSNSVsyGDOHftwS+puG45/knklnWBLIHoxrCPfhukWQyuFNUGBkut/CQlo8nF3a7Xk2WWTzfLbPXyGkWTUIf0=
Received: from DM5PR17MB1211.namprd17.prod.outlook.com (10.173.132.148) by DM5PR17MB1289.namprd17.prod.outlook.com (10.173.132.149) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2032.20; Thu, 4 Jul 2019 16:08:43 +0000
Received: from DM5PR17MB1211.namprd17.prod.outlook.com ([fe80::b556:345c:94cf:7258]) by DM5PR17MB1211.namprd17.prod.outlook.com ([fe80::b556:345c:94cf:7258%6]) with mapi id 15.20.2052.010; Thu, 4 Jul 2019 16:08:43 +0000
From: Rob Stradling <rob@sectigo.com>
To: "stefan@eissing.org" <stefan@eissing.org>
CC: Salz Rich <rsalz@akamai.com>, RFC Errata System <rfc-editor@rfc-editor.org>, "rlb@ipv.sx" <rlb@ipv.sx>, "jsha@eff.org" <jsha@eff.org>, "cpu@letsencrypt.org" <cpu@letsencrypt.org>, "jdkasten@umich.edu" <jdkasten@umich.edu>, "rdd@cert.org" <rdd@cert.org>, "kaduk@mit.edu" <kaduk@mit.edu>, "ynir.ietf@gmail.com" <ynir.ietf@gmail.com>, "acme@ietf.org" <acme@ietf.org>
Thread-Topic: [Acme] [Technical Errata Reported] RFC8555 (5771)
Thread-Index: AQHVMN8HQnk98bJ0t0yXECJcNI6oBaa3ZbEAgAE5vQCAADCKAIAAGM8AgAE1JoCAAIXNAA==
Date: Thu, 04 Jul 2019 16:08:43 +0000
Message-ID: <17946d15-dc2d-d5e1-43f8-f1b49d7bab67@sectigo.com>
References: <20190702140400.527D3B81CB0@rfc-editor.org> <015B3FA2-45AA-4D06-9C18-99693FB2B785@akamai.com> <368f9853-11e4-1367-9ad0-7dc6f4fa343c@sectigo.com> <F2724322-7533-4D0D-9637-E44E31F3192B@akamai.com> <323a3a4d-93f6-0ab6-496d-83f03ca32759@sectigo.com> <80B62119-819E-4E39-AD71-7F0B3092C6A5@eissing.org>
In-Reply-To: <80B62119-819E-4E39-AD71-7F0B3092C6A5@eissing.org>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-clientproxiedby: LO2P265CA0161.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:9::29) To DM5PR17MB1211.namprd17.prod.outlook.com (2603:10b6:3:8b::20)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=rob@sectigo.com;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [2a0e:ac00:25d:300:f68e:38ff:fe7a:a226]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b2e8a4cf-4074-4300-09e4-08d70099e2cb
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:DM5PR17MB1289;
x-ms-traffictypediagnostic: DM5PR17MB1289:
x-microsoft-antispam-prvs: <DM5PR17MB1289740D1E9A70FE71C47EBEAAFA0@DM5PR17MB1289.namprd17.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:5797;
x-forefront-prvs: 0088C92887
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39850400004)(346002)(366004)(396003)(136003)(376002)(199004)(189003)(8936002)(1730700003)(53546011)(102836004)(68736007)(81156014)(5660300002)(8676002)(6506007)(99286004)(76176011)(386003)(71190400001)(2501003)(305945005)(4744005)(64756008)(476003)(66446008)(14454004)(14444005)(2351001)(7736002)(2616005)(66476007)(486006)(66946007)(66556008)(46003)(6916009)(81166006)(73956011)(52116002)(71200400001)(25786009)(5640700003)(4326008)(36756003)(86362001)(478600001)(316002)(11346002)(6436002)(6486002)(6512007)(7416002)(446003)(54906003)(31696002)(53936002)(256004)(6116002)(6246003)(31686004)(186003)(229853002)(2906002); DIR:OUT; SFP:1101; SCL:1; SRVR:DM5PR17MB1289; H:DM5PR17MB1211.namprd17.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: sectigo.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: EzPOYfDQ4IMJoPzWeZv1hBAqY0MaDQOQQVNLyx4tNUX7hzO3Q0452TAYvzseyYXtO6KZDpPivDfqtUdv2YBKlrHHARurhLxIQsa60RM6dWdj/e+5wU49+3szSX+Rc5t5Pd3QPzZN7VLhkXO7GkLG7emICsuwT1YHwXa6+wiUMUqtnrTUPGSLwnOBpvYmL4g1WJPllLG4hF8kZYjzhv1oeMKJ+EFeA1MLoxu+TnKC47w5tPtfY840o2jRdiRVT+fJyHOh8wvLdfdSM3ZDST/1u+/ohry9PTlaJc1R+rhfnLWbPOfQIs2FbF3qYqwqUrk61NaSWx4KwWjI1Iy2qOeozco23Pk+p7rph3e3b9jeICTmmON4AQbsfVZl7VKWNsdmEOJXmUKTnhWhBm+L1rJn2TD8kI4yGgUuryVEpxEff5M=
Content-Type: text/plain; charset="utf-8"
Content-ID: <07656E822D94ED4BA599F0297A745324@namprd17.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: sectigo.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b2e8a4cf-4074-4300-09e4-08d70099e2cb
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Jul 2019 16:08:43.3930 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0e9c4894-6caa-465d-9660-4b6968b49fb7
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: robs@comodoca.net
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR17MB1289
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/7Iw5-Ucm4UvEayOj29Dzepc1URo>
X-Mailman-Approved-At: Thu, 04 Jul 2019 09:13:19 -0700
Subject: Re: [Acme] [Technical Errata Reported] RFC8555 (5771)
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Jul 2019 16:08:47 -0000

I believe it's a theoretical concern at this point.

On 04/07/2019 09:09, stefan@eissing.org wrote:
> 
>> Am 03.07.2019 um 15:43 schrieb Rob Stradling <rob@sectigo.com>:
>>
>> The idea behind the erratum is to force HTTP caching rules to apply to
>> directory objects, so that servers can update their directory objects
>> and expect clients to take note.
> 
> Is this a theoretical concern or do you have examples where current clients cache directory information that would harm a server update?
> 
> Cheers, Stefan
> 

-- 
Rob Stradling
Senior Research & Development Scientist
Sectigo Limited