Re: [Acme] [Errata Held for Document Update] RFC8555 (6843)

Amir Omidi <amir@aaomidi.com> Fri, 12 January 2024 03:15 UTC

Return-Path: <amir@aaomidi.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8348FC14F6A0 for <acme@ietfa.amsl.com>; Thu, 11 Jan 2024 19:15:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.106
X-Spam-Level:
X-Spam-Status: No, score=-7.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=aaomidi.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PqnFnl9bsZYX for <acme@ietfa.amsl.com>; Thu, 11 Jan 2024 19:15:13 -0800 (PST)
Received: from mail-lf1-x130.google.com (mail-lf1-x130.google.com [IPv6:2a00:1450:4864:20::130]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2AE7DC14F69D for <acme@ietf.org>; Thu, 11 Jan 2024 19:15:13 -0800 (PST)
Received: by mail-lf1-x130.google.com with SMTP id 2adb3069b0e04-50eabbc3dccso6740538e87.2 for <acme@ietf.org>; Thu, 11 Jan 2024 19:15:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aaomidi.com; s=google; t=1705029311; x=1705634111; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=kNvkcSritbujME37m6GzfyWmvCwh2tE8Sy541bvCgWM=; b=XA4JT7QDmH7nVZHshkAX75EAZTSMVFfRddTMF683R7X+0tm4BZwP3luKJqhuc7wdaM O+t72ZCGC2jyjB4lUWqbB9pYkmrtbUDlmCBSDELx1RbfApXAIZYrC/lfpWc752KuGL/R 7fEujQV28OAzDDKzpd0zQZLSWM11KBn1i3mlCQQRC/gE8twHKWX+ImgTElTxWBixyTjl fsPgk6qzV8wINJXcgqdgLzgAEn7Y28eXKpzMMKe7YnKsynaBwzhTY1Um2xAps0Fl7Dmf guYphsFuJJj7saS/kMdcS76tJ49pJlRvVZIA9ZzjwRlnhxX87iCMVW4R4PEwwdeBbkRt oyUA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1705029311; x=1705634111; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=kNvkcSritbujME37m6GzfyWmvCwh2tE8Sy541bvCgWM=; b=I+mxFHEpBjEXukTMNO1xKuQ1eBiWYozOVvohy6+cRUCET2OSnNzn08axPmt1RctJ4j d416ZgWDtEhq9u7ScnIzB3xbb29/gQRk6D3w3spZJXor5USV8y6j2hgXn9MIUS9aws4c WUKPWr9aAq7QqKJx+UVH7eb9yhzosSHmG6kNw6rRmMg4ZdwuvosfCgmJsgdiwh32k9P/ hzJkijscfjPsJm7CD2t/C5/h1PzjTl8LbjK4UlL+OMRDE1ItOAoYIUeg8v6rpr2cDH+0 t1ejAFqO5whAQdQT0++r9aBasErKP33CgJ10paamdm6N+HUURrSkarnNfKSiqq5cN4oX 1Mzw==
X-Gm-Message-State: AOJu0YxQ7jNsgiIaNc8g9hUTSYkEW+OYlhdeB8b2trer//3cEFj5hecI IqHJLkxFIoFnDP25ytYh/ST/qfcm1GrtbETSXkUBuXF1Y8hsFf2DOB6YB/rJiJlogw==
X-Google-Smtp-Source: AGHT+IGO5n3AhEQnZsymbkC+gbPmOla1ETEoTEkD2UTXKV22lplBOsKT7DQsYBwbMibHPN+ZhTY+ZfZkZaiNXiQ88EM=
X-Received: by 2002:a05:6512:ad5:b0:50e:7476:e027 with SMTP id n21-20020a0565120ad500b0050e7476e027mr154613lfu.275.1705029310932; Thu, 11 Jan 2024 19:15:10 -0800 (PST)
MIME-Version: 1.0
References: <CAChr6SypX6PN_00OQUzRbtyXeQYsuVeZeRjg9Xosk8uRTkzr2Q@mail.gmail.com> <CAEmnErfE=-HMKkf4MHUfYCLam0baWA+QnAA7tg_tREtPFvRhdQ@mail.gmail.com> <CAChr6SzGo-4RZ0TwfqcJhy4FzL53LmsWHpe9EmN5eN_GDhdLzw@mail.gmail.com>
In-Reply-To: <CAChr6SzGo-4RZ0TwfqcJhy4FzL53LmsWHpe9EmN5eN_GDhdLzw@mail.gmail.com>
From: Amir Omidi <amir@aaomidi.com>
Date: Thu, 11 Jan 2024 22:14:59 -0500
Message-ID: <CAOG=JU+YFE826M7aW_KJRXNw639QjvVgH4WryPJ++Xq+BGS+Uw@mail.gmail.com>
To: Rob Sayre <sayrer@gmail.com>
Cc: Aaron Gable <aaron@letsencrypt.org>, acme@ietf.org
Content-Type: multipart/alternative; boundary="00000000000068ff27060eb71250"
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/hOKZA6oKvgDKA1188HwoC0UOkVw>
Subject: Re: [Acme] [Errata Held for Document Update] RFC8555 (6843)
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Jan 2024 03:15:17 -0000

There is nothing blocking .dev domains responding over http. To be
specific, a TLD can not block a protocol like that.

Amir Omidi (he/them)


On Thu, Jan 11, 2024 at 22:13 Rob Sayre <sayrer@gmail.com> wrote:

> It sounds like that's a bug or at least a discrepancy.
>
> .dev domains should never respond over HTTP. The whole point is to avoid
> that initial request.
>
> thanks,
> Rob
>
>
> On Thu, Jan 11, 2024 at 7:10 PM Aaron Gable <aaron@letsencrypt.org> wrote:
>
>> This erratum changed "completed" to "initiated", so the document now
>> correctly allows redirects from HTTP to HTTPS. If you believe that
>> challenges should be able to be initiated over HTTPS as well, this erratum
>> is not the right place for that discussion.
>>
>> But perhaps more importantly, ACME Servers do not have an HSTS Preload
>> list. The idea of the preload list is an extension of HSTS implemented by
>> certain browsers, but other user-agents are under no obligation to respect
>> a preload list.
>>
>> Aaron
>>
>> On Thu, Jan 11, 2024 at 7:03 PM Rob Sayre <sayrer@gmail.com> wrote:
>>
>>> Hi,
>>>
>>> Is this one valid?
>>>
>>> https://www.rfc-editor.org/errata/eid6843
>>>
>>> > the challenge must be initiated over HTTP, not HTTPS.
>>>
>>> What if the host is on a .dev domain? That should be in the HSTS preload
>>> list.
>>>
>>> thanks,
>>> Rob
>>>
>>> _______________________________________________
>>> Acme mailing list
>>> Acme@ietf.org
>>> https://www.ietf.org/mailman/listinfo/acme
>>>
>> _______________________________________________
> Acme mailing list
> Acme@ietf.org
> https://www.ietf.org/mailman/listinfo/acme
>