[Acme] Re: Two pull requests from me waiting.

Henry Birge-Lee <henry@crosslayerlabs.com> Wed, 03 June 2026 03:19 UTC

Return-Path: <henry@crosslayerlabs.com>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 09148F9C643D for <acme@mail2.ietf.org>; Tue, 2 Jun 2026 20:19:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780456758; bh=nY8J9ygHt7zRhLgnjAPLCVWDZNyYPv3du0TMkrkj8bg=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=CPin4pTmtiM4I4Nfsc37Gq+mDNdpFbDLRflJpjilb3BCbTx7RJvqwxycO94tfFxsf w/fPXATfJOEKJ0pqJvxOen3Rt/k1G+44SP7GtHeqk/VlAWg3NL1kTTigh9Ndn8sa/C wJIXbtqbsIBuAvEq8X7zCP8w2CN5ZdVAgI/BA1oQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, TVD_PH_BODY_ACCOUNTS_PRE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=crosslayerlabs.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AnCUGgp46sJj for <acme@mail2.ietf.org>; Tue, 2 Jun 2026 20:19:17 -0700 (PDT)
Received: from mail-pg1-x52b.google.com (mail-pg1-x52b.google.com [IPv6:2607:f8b0:4864:20::52b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5FEFEF9C6432 for <acme@ietf.org>; Tue, 2 Jun 2026 20:19:17 -0700 (PDT)
Received: by mail-pg1-x52b.google.com with SMTP id 41be03b00d2f7-c8584e80bd3so1619526a12.3 for <acme@ietf.org>; Tue, 02 Jun 2026 20:19:17 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1780456756; cv=none; d=google.com; s=arc-20240605; b=Yem9xWkyoAdvlEn+9Xn6YFh2Q7gnqGv99qP8tLcjMBzG3y4/SoX2lrYfRLUIOOyWCN wf6TN6dFxsOke/rf6sqSU0vA4MwwkZAZMVCjIM0fmU9w/BR9BDi/It3lhoy/rgKc59Fc 5i8CqLVO+5uzfhLgE14RR7knPpZGXLn1VtktU8rWcj3UjxgHiXeVXF3+QVU941Mqf7ag IRPaVignkffFkqmGcRyWhfopP5gfn9kC8Czj/PzH+FPrsye8MVj7tOnvz7j+DYTDv/G0 RkBOOnWyyarwXQN0s2pizgRoeFbpruIqh5BPLre03LKQhufr1v90Shqy+U8to18Ayd+c MrZQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=nY8J9ygHt7zRhLgnjAPLCVWDZNyYPv3du0TMkrkj8bg=; fh=Wi5RfA25LFKENSECoyD4THOqh7eCE+KpNn78fNT7tms=; b=PG4NhIcqlqqzxE2iXtT4XXGDgCyffAPacMDOlkM74FGktCiRDm7dwPIVXzy/H52T0C KOnDm8i+gJOUuI/0n2vrcr2yukSyiNG5rUFR84moFTKTuhafYa4ZFae1DTjHiIH8UW+O gTGIMJ9nsoAoJMA7ilFaM8Hv/LK/veg0CNk+/fae96w7jWHWGCt2ftJU8nFzkwOXhw1N GIX3hZywTCFIiZcOdZmshpU4SSoCO/t5LTU/5HHeHE4T8xuis3GDM2YOkTeeC0rLvG6w y2MlY77Juhn4V63ZsK6/k4mqQypJPna/8/7huaiBVeWATML8r+ZKGex7T49DBjQUDoec gKDQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=crosslayerlabs.com; s=google; t=1780456756; x=1781061556; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=nY8J9ygHt7zRhLgnjAPLCVWDZNyYPv3du0TMkrkj8bg=; b=fBn9JFP9O2HHIFqiqUcPQmhjr6XkieRAShX9dcKFibgDbNt/QErsEGZyt+QNbhH3Q2 O9x2M/dcIk3Xx1Mfc9sCPT61QegRkhaC7jLfLVHyIAedmRYWsRS2+A/BzVSiCh/rK+6l 2JQDXeRHu8zYjGLzYG20AH6jZulSo8ecPBNCdBaPqLrOIYzW3xBH8vkGTmGw6KEjJ1sF HylcO1FgvzfyVGz/g8awJzD70yTZQ56CnXME4Px4m/yTdj0g4GDQbIt0W5qD3ZGIlCGW g3H4zK200Wu6tSNyCXQCDFZAeU+GnLSVkuQLrMiJVls9VmbAhChxssgY3fjwSEupH6JE ZX8A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780456756; x=1781061556; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=nY8J9ygHt7zRhLgnjAPLCVWDZNyYPv3du0TMkrkj8bg=; b=HVchIzyKdOqIx2PDJfYi+KNjOuystg6CA8Tr5CHj+k4fC74oVC9Dv1o/Rr5muRJd+D /+TkomsvIvjVHLnyvAzyp58UmCnTUt1DBzsQoeDX6aG/NMw6ZBzZJsgW+dSdGQ7gOtvy KtZYvsgCL0DS7Z2zGYKx3RH+r9NeYWMxolWGts2ahpzVaMzVE78TpF/Zy402gfR17LzR 6edKRAE8GD2NMag0S3bHPoa9+8pRdDE+JFGliyzQRbvbvOlfwZ/f/k9CLPGT7WCc/U7Q 2SyYTi61kQ+l2YXDru934sclxfKLBc+xY3MeCP0+PRHtnYamdE8+1CWMXLTGlTDN5LTV NZoQ==
X-Gm-Message-State: AOJu0YzWIzftDlSjbDd3XYPzfssI+Q6sDXDFwrxCnJNZed8q0fEDC5rz 3OFhhBhQHja0WGKIBSNGWhW4lgHgN1k0o5q1cWYXvQPER4RaY0nwn+Nt93yAUFpIkRHnbgxYeLF E5Nny21ghoP9gfSp2F61LjRTnWwfYg/NeUnms0JG0Lck=
X-Gm-Gg: Acq92OExX/spLhaLEpxkxJQi4/hIIxMBh6TrKo++ERhyvGdt9Vcs0F9E/frFC3GkOeH tMbIn97bQTkeKX4gtIBG8avTX8ecXXVEeSW3JG3YB0/sMZ5gbe2RU0zMXrU6zHrINrL5hMDkuCv K67A5ysNUmDlxKIPJ1jiiPCRNOdVaWwolOaFFDNfsR/iZORnvXs/+Ik/0qGv/lD7ghyULwvhDOV 9eTQ79m+lZKD4RoE9eiHMslVzfdfHbU1ZXS1DALfwGGqvq6S3V74ozgvRynMrUzQRQ9BzhPum+a w7O8DbDARaWTdlJPpBoYQlFP9SOhpRu8MtdzNjtUlCPp7e0SvXkLWodmaDT+Hw6JRl/NvqjvqJt QlfJVVqaxgFkzkLlqC6hyGPate0noneYo/nWvU6QZ+6ZDxnR59Bya1UfzGYAq9WF2FF8=
X-Received: by 2002:a05:6a21:a95:b0:3b4:65ac:e2e6 with SMTP id adf61e73a8af0-3b497894b6emr1749166637.36.1780456756393; Tue, 02 Jun 2026 20:19:16 -0700 (PDT)
MIME-Version: 1.0
References: <003901dcf2e6$40b11820$c2134860$@sebbe.eu>
In-Reply-To: <003901dcf2e6$40b11820$c2134860$@sebbe.eu>
From: Henry Birge-Lee <henry@crosslayerlabs.com>
Date: Tue, 02 Jun 2026 20:19:05 -0700
X-Gm-Features: AVHnY4KkDx-P7UIpoUbLDBBFAFOnh_Z6ZPcy6G_PVh4CxJKF30UtT8zaPCdscDA
Message-ID: <CAG0-MR_BH6Y60_gvcfrCjxOcEpvq00b67QEG=pQ3t8hZapohZw@mail.gmail.com>
To: Sebastian Robin Nielsen <sebastian=40sebbe.eu@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="00000000000080ca20065350e42d"
Message-ID-Hash: KGBFWWIBYVQQZMOEAPXLTTS55WME2OK7
X-Message-ID-Hash: KGBFWWIBYVQQZMOEAPXLTTS55WME2OK7
X-MailFrom: henry@crosslayerlabs.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Mailing List <acme@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: Two pull requests from me waiting.
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/Zz06fEjGDNJF0JU5QhSYsmhyhiA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>

Hi Sebastian,

Thanks for opening these up. These are topics we have under discussion and
I plan to discuss these PR with the other authors. I think the points they
address on both topics are valid and worth putting in changes around.

Best,
Henry

On Tue, Jun 2, 2026 at 4:20 PM Sebastian Robin Nielsen <sebastian=
40sebbe.eu@dmarc.ietf.org> wrote:

> https://github.com/ietf-wg-acme/draft-ietf-acme-dns-persist/pulls
>
> First one:
>
> This is to change the language in the document. issuer-domain-name is a
> opaque value from client’s point of view.
>
> That means, the client does not make a request, verify or otherwise make
> any connection to the value in the field ”issuer-domain-name”.
>
>
>
> it could be a random hash like ”adf6a97f6a95f85fda5f9d59a98fda59fa6”. It
> would work perfectly still.
>
>
>
> That means, protecting the ”issuer-domain-name” does not give any security
> advantage from the clients point of view.
>
> A compromise of ”issuer-domain-name” would also not give any security
> degradation.
>
> The ”issuer-domain-name” may even be a domain the CA no longer owns (for
> example a legacy domain they no longer renew, but still keep in their CPS
> to keep old dns-persist-01 records working indefinitely).
>
>
>
> Tthe above pull request changes it to ”ACME Directory URL” – which is the
> sensitive resource the CA owns in the ACME world.
>
>
>
> Max Hearnden suggested that a ACME Directory may emit cross-domain URLs in
> its directory – for example a newAccount URL that does not reside at the
> same domain as the Directory.
>
> This newAccount URL could then be independently compromised.
>
>
>
> However, in my opinion, its the CAs responsibility – if they host parts of
> their ACME infrastructure on different domains - to at least perform some
> basic health checking of their sub-resources and shut down the Directory
> URL if any sub-resource is found to be comrpomised. Thus, the important
> thing to keep secure (with DNSSEC and other things) is the ACME Directory
> URL. Thats a URL that is the ”root of trust” for the ACME client, and
> failing to secure that would mean complete takeover of the ACME client.
>
>
>
>
>
> Second one:
>
> Its a variation of my ”pubkey:” idea, but instead of a SPKI hash of the
> pubkey, I chose a JWK thumbprint. In this way, functionality to verify it
> already exist server-side and functionality to generate it, exist
> client-side (in the same functions which generate a JWK thumbprint for use
> in HTTP-01 challenges).
>
> To avoid a CA going foul of the CAB forum rules, I chose to make a rule
> that a CA must invalidate any authorizations that have been validated using
> a pubkey: record, IF a keyChange is made on the account, so if said key
> would be moved to a second account, a pubkey: record doesn’t accidentially
> validate 2 account to issue certificates simultaniously for the same record
> (which is prohibited by the CAB forum since each dns-persist-01 record may
> only link to ONE account).
>
> Client functionality that a client must reject a pubkey: URL emitted from
> a ACME server (as discussed) – I choose to omit, since a pubkey: record is
> SUPPOSED to be generated completely offline.
>
> Clients implementing support for pubkey: records will thus already do the
> calculations offline.
>
>
>
>
>
>
>
> Hope you like the pull requests, and it would be nice if someone in the
> ACME group could take a look on them and see if there is any problems.
>
> the first one should not really be a problem to merge.
>
>
>
>
>
> Best regards, Sebastian Nielsen
> _______________________________________________
> Acme mailing list -- acme@ietf.org
> To unsubscribe send an email to acme-leave@ietf.org
>