Re: [Acme] Issuing certificates based on Simple HTTP challenges

Phillip Hallam-Baker <phill@hallambaker.com> Wed, 16 December 2015 17:14 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D3CC1A1C04 for <acme@ietfa.amsl.com>; Wed, 16 Dec 2015 09:14:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.278
X-Spam-Level:
X-Spam-Status: No, score=-1.278 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CYspAEPguI0j for <acme@ietfa.amsl.com>; Wed, 16 Dec 2015 09:14:39 -0800 (PST)
Received: from mail-lf0-x229.google.com (mail-lf0-x229.google.com [IPv6:2a00:1450:4010:c07::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0477E1A1B6F for <acme@ietf.org>; Wed, 16 Dec 2015 09:04:07 -0800 (PST)
Received: by mail-lf0-x229.google.com with SMTP id z124so28963115lfa.3 for <acme@ietf.org>; Wed, 16 Dec 2015 09:04:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=5pipe+qTpZvd3lHtBcRP0+DjCcBxLscQrsprPQAjVcI=; b=LEcGxOPHZZFUMKlMI0Qs3XAK6+CxGF236TR9OlSbpFsv6YV8tEdbeyzeRKjKPQmOW5 PPDzy0P9b8Uljcf9GlhEPEiOv/6i0YUY07VM3ttXXu1PLTDfrnah6bneYtPHKK73aXSP CkyAaiB8iFuWcU5rhtHWUl1LfrbHC4NG88wfrz32UkgIzCqQHehNzVR9Ckchej9mKNS2 hV39rSn5qSAJ1/KDH4KXYlLhQEU+6Tw0zFkryC14YI60H2ITqiiuqVt5RK3taDfAh4k8 YP6dC1vxwiukxaUNZD8sAM5S3V2I5DYEQnMobJHAY6FEeVa4A827XVnqGEFh3YuYk+Eq 3iCg==
MIME-Version: 1.0
X-Received: by 10.25.208.206 with SMTP id h197mr19314957lfg.153.1450285445096; Wed, 16 Dec 2015 09:04:05 -0800 (PST)
Sender: hallam@gmail.com
Received: by 10.112.1.227 with HTTP; Wed, 16 Dec 2015 09:04:04 -0800 (PST)
In-Reply-To: <894b0ad1f1c34184bbbc9133702ed474@usma1ex-dag1mb1.msg.corp.akamai.com>
References: <CAF+SmEpOLoaREymVhi=qOUg2opz1vKzzNp6tGrDTZAjYSKFDkg@mail.gmail.com> <566F15DC.7090607@wyraz.de> <6B677A87-C6A0-485E-80DF-24960D585F46@coderanger.net> <566F2CB5.90402@wyraz.de> <89774336-0BA6-48FC-821D-1E8F3ED9AC14@coderanger.net> <566F4701.7050308@wyraz.de> <F3DA31B1-B27C-4C63-8ED4-6D27D46FF282@coderanger.net> <C2C239F2-E8A7-499B-BE52-3A48EA92B86D@dropmann.org> <BF7F8411-3E83-4A1F-B3A1-4C37DC8B4618@coderanger.net> <3CDE1749-3143-49EE-BD66-0AE4A8CC4175@dropmann.org> <566FDAB7.2030403@cs.tcd.ie> <56700F68.3040103@wyraz.de> <56701904.2070009@cs.tcd.ie> <56702EFA.1050008@wyraz.de> <13B5E9A8-E9CE-4018-8A9D-7856CBF06B4F@coderanger.net> <CAMm+Lwhvf+nRVV38q1U1DKm1WStV1UJv4+EJ_zvq0G_Tb25S9w@mail.gmail.com> <2761E0B2-8DCC-4150-813F-8CAB756C0392@coderanger.net> <174B082E-2721-41AE-992D-2937DCCB74CB@dropmann.org> <894b0ad1f1c34184bbbc9133702ed474@usma1ex-dag1mb1.msg.corp.akamai.com>
Date: Wed, 16 Dec 2015 12:04:04 -0500
X-Google-Sender-Auth: O_6IGudtbYJISZIJjYckZICBXBg
Message-ID: <CAMm+Lwgc9Q73BP0CTF=tFQ8a-+-3Oax=nhT5_0wqoHG1_0AnLA@mail.gmail.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/acme/TnJPgkxubFLexinuKvGXjm7quC0>
Cc: "acme@ietf.org" <acme@ietf.org>, Julian Dropmann <julian@dropmann.org>
Subject: Re: [Acme] Issuing certificates based on Simple HTTP challenges
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Dec 2015 17:14:40 -0000

On Wed, Dec 16, 2015 at 11:22 AM, Salz, Rich <rsalz@akamai.com> wrote:
>> The target users are server admins right?
>> In order to set up their services, they should be familiar with DNS.
>
> Nope, not a requirement.

Even if you are familiar with the protocol to the point of having
written your own client and server, this does not mean that your
hosting provider gives you the access required to do more than
configure a few records.

I can edit A, AAAA, MX, SPF, TXT and SRV records and that is it.

I can't set up my own DNS server because my local ISP does not offer
static IP addresses unless I pay significantly more for my service.


An 'automated' certificate issue scheme that requires me to change my
ISP configuration isn't going to be a labor saver for me.