Re: [Acme] acme in a firewalled environment

Richard Barnes <rlb@ipv.sx> Tue, 02 December 2014 18:07 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F25141A0392 for <acme@ietfa.amsl.com>; Tue, 2 Dec 2014 10:07:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level:
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wHnONL9amjWv for <acme@ietfa.amsl.com>; Tue, 2 Dec 2014 10:07:50 -0800 (PST)
Received: from mail-vc0-f170.google.com (mail-vc0-f170.google.com [209.85.220.170]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE9FF1A6EE7 for <acme@ietf.org>; Tue, 2 Dec 2014 10:07:49 -0800 (PST)
Received: by mail-vc0-f170.google.com with SMTP id hy4so6116677vcb.15 for <acme@ietf.org>; Tue, 02 Dec 2014 10:07:49 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=l57jRCIrHekeJhxHvCbjtP+H99lc0URZRKUx/OX38gw=; b=ZysCJylmFhvwjnNKODzLgVcHPfcQK31szP0Uyo9JwpaNX0JcV3bYu3S/MRk0vraLQM Kqmf2Gky6ZS3dTZabAfKsWg8KHQT+h3vNFDOCA/6ShiIdq3UDB0EhF36+/N3JuUo8qAs T6nfP8gYJIF8wfC/3SHc05sN0xF2B4TRhDeVhZcXrnZmu5RrVSOfA5Aeae2ZxIk5CR6q S7d99/cclO3CFuHlYKwiA0asvi6Ra9aE4kQIn6RcYz+qBJmMp/NZA6XBzeOBCkbOCNtu +pDm1QQmEX9p1o0/JPjvbtYdhnbTVNJkzcOvgK4ueea3Ccu3K/ol+GegW12Yh4ythQ0u 43hg==
X-Gm-Message-State: ALoCoQmF6kTVI4U43p6juaDhEmF34dYP/BowqBVN7eu1b6QqCocvVv27e1YOycsCEjKHzRLXvpCb
MIME-Version: 1.0
X-Received: by 10.221.66.143 with SMTP id xq15mr430567vcb.35.1417543669091; Tue, 02 Dec 2014 10:07:49 -0800 (PST)
Received: by 10.31.149.1 with HTTP; Tue, 2 Dec 2014 10:07:49 -0800 (PST)
In-Reply-To: <547DFE94.6090307@cisco.com>
References: <547DFC4B.9040408@cisco.com> <547DFE94.6090307@cisco.com>
Date: Tue, 02 Dec 2014 10:07:49 -0800
Message-ID: <CAL02cgSsLk-xjnL1bC_FbeRykMzAU8a9h-JTqUu58_ZpipCuHQ@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
To: Ben Schumacher <bschumac@cisco.com>
Content-Type: multipart/alternative; boundary="001a113608d2d9a31d05093f9aa3"
Archived-At: http://mailarchive.ietf.org/arch/msg/acme/RRP-JK1soAGzMYcbAXssYIcKh4U
Cc: "acme@ietf.org" <acme@ietf.org>
Subject: Re: [Acme] acme in a firewalled environment
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Dec 2014 18:07:52 -0000

Presumably, your web server (or whatever server you're going to use this
cert for) is going to need to accept incoming connections.

On Tue, Dec 2, 2014 at 10:01 AM, Ben Schumacher <bschumac@cisco.com> wrote:

> On 12/2/14 10:52 AM, Eliot Lear wrote:
>
>> Question:
>>
>> Are the myriad of enterprise servers in scope for ACME?  In those
>> environments it's not unreasonable to assume that a firewall exists to
>> prevent incoming connections, and DNS control is not available.  In fact
>> split DNS might introduce all sorts of fun resolution issues even if
>> control is possible from the inside.
>>
>
> Eliot-
>
> I would say it is probably out of scope, with regard to public CAs, but
> there is nothing that would prevent an enterprise-wide CA that could be
> ACME enabled.
>
> For example, ACME could be integrated into the Certificate Management
> functionality of your enterprise directory services / host management
> infrastructure.
>
> Thanks,
> Ben
>
> _______________________________________________
> Acme mailing list
> Acme@ietf.org
> https://www.ietf.org/mailman/listinfo/acme
>