Re: [Acme] FW: [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt

Mike Ounsworth <Mike.Ounsworth@entrust.com> Fri, 07 July 2023 01:56 UTC

Return-Path: <Mike.Ounsworth@entrust.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 39AA4C1519BB for <acme@ietfa.amsl.com>; Thu, 6 Jul 2023 18:56:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.796
X-Spam-Level:
X-Spam-Status: No, score=-2.796 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5GGarv9Mbq6u for <acme@ietfa.amsl.com>; Thu, 6 Jul 2023 18:56:03 -0700 (PDT)
Received: from mx07-0015a003.pphosted.com (mx07-0015a003.pphosted.com [185.132.183.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE30CC15109F for <acme@ietf.org>; Thu, 6 Jul 2023 18:56:02 -0700 (PDT)
Received: from pps.filterd (m0242864.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.17.1.22/8.17.1.22) with ESMTP id 366Jq4EZ012730; Thu, 6 Jul 2023 20:55:58 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h= from:to:cc:subject:date:message-id:references:in-reply-to :content-type:content-transfer-encoding:mime-version; s=mail1; bh=GGzHrPSL0gN2cVT5mscsoIELS3PcFSfK/utgzKZrwFc=; b=JljxyD4IT/jM Pipwps45IduGTctzkCqgwKPxbVaFIi7ZcqlfEIuhSx3l2fjNjvM6NwQwYvR4WA1w kNXd/8TYXRCXTxr/hJVRkRZGlgLWRFrkzVvBX5rrrHHNPQtsm8U72Liup+rUs7+K 6+6i88WCZ0UdoCD1ALHlmLyaiCg+HYm0MzqgLlPzQjwQ+ueL+5iuSnnmE+1eTurm Qa6yGwogkxdyfGro9WzHE7v6VZDc0am04+Peq+laeiobIH68I1oH5iT0FegYLPqq CzaCFn8SPYmc950RGytDMvysLaVAoeoNdoBcTPZjZPgqij5wNGjOB32jdCeqgICq PeLtq1AtWQ==
Received: from nam12-bn8-obe.outbound.protection.outlook.com (mail-bn8nam12lp2169.outbound.protection.outlook.com [104.47.55.169]) by mx08-0015a003.pphosted.com (PPS) with ESMTPS id 3rp453rqck-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 06 Jul 2023 20:55:58 -0500 (CDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Psih9r2OwXlNkMtGEboCQfmeb0zV9fuCBc7lINmqfS6ChkW8I54kNMM2+JWzxaU5msehVVyLdzWdEtZUPeoeaFijGYPHH7GkNvKrMfp+55QjA4l8hfOgdQ9T8f3qFag2bmLPd1E/ELDGhymYTSTeMBS51f4rrfRTPTPt9u/5pJPaC/PUYNfKcfDYR58w4vId5E8Jr2VNxvzlhEKuldtWujbwsJHFX8H/uHHYk/IKLlfqHgtsl3TxTq/Os/0xX5PQu8jxboYdqlPd+Z2hMQ2vyC/Bk9JJnrPtqYfmQgNQKL+eAwnT+m6UTG17qI5JQByOfRWJSMvAqTuaZXhxWC7vRg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=GGzHrPSL0gN2cVT5mscsoIELS3PcFSfK/utgzKZrwFc=; b=i3E3tonV0xnuZxi68cgN6ToIvvurxuUEPSOTH1P+dOyR12TG12H/d9FZC0UneJixxq6bp9M87/BvHXGVRROmZqAPdP8O9gr4NwkZVOfsDsb7CuDZQgDE9diKlbcCq/1WcOCmhfYxGxt0MC9LfuxSCErxepZEytjP1ae6xB41smNcF23+FLxCaAk4ApQjd5ABemJAnHNjVdwPGf1R04zAGbJowcNsK6cdiIyhvPnA/TBm+ZELQX9hU97zYePXtxPU+taiufAGIQrn9IFn5lQwAGQOWCJAiBmTYkaKXDLccVyv8nHk+1nv9+MCud/WL4bpSChNRhs644W0QfBXZzbIeQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from CH0PR11MB5739.namprd11.prod.outlook.com (2603:10b6:610:100::20) by PH7PR11MB7516.namprd11.prod.outlook.com (2603:10b6:510:275::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6565.17; Fri, 7 Jul 2023 01:55:53 +0000
Received: from CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::3c4:2520:16b0:6271]) by CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::3c4:2520:16b0:6271%6]) with mapi id 15.20.6565.025; Fri, 7 Jul 2023 01:55:52 +0000
From: Mike Ounsworth <Mike.Ounsworth@entrust.com>
To: Fraser Tweedale <frase@frase.id.au>, Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com>
CC: Richard Barnes <rlb@ipv.sx>, "acme@ietf.org" <acme@ietf.org>
Thread-Topic: [Acme] FW: [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt
Thread-Index: AQHZsBeqgO/Qy8UW2EKh0oZ3cvLhkK+s0GpwgAAuOwCAABHCgIAAXRqAgAAJcQCAAA1V0A==
Date: Fri, 07 Jul 2023 01:55:52 +0000
Message-ID: <CH0PR11MB57398336D760C6FEA94E21169F2DA@CH0PR11MB5739.namprd11.prod.outlook.com>
References: <168865435873.61106.2850041921157081937@ietfa.amsl.com> <CH0PR11MB5739FDB26BF675925C449AA69F2CA@CH0PR11MB5739.namprd11.prod.outlook.com> <CAL02cgSH1XM0krpYuCVP1VNpZ8EpprHog1+-oeQkN0a5bX8vHA@mail.gmail.com> <LV2PR11MB5975C3F165D41FBA2BEED912F82CA@LV2PR11MB5975.namprd11.prod.outlook.com> <ZKdW965KnS_C1P6n@bacardi.hollandpark.frase.id.au> <ZKde4llTB-dpA3Kj@bacardi.hollandpark.frase.id.au>
In-Reply-To: <ZKde4llTB-dpA3Kj@bacardi.hollandpark.frase.id.au>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH0PR11MB5739:EE_|PH7PR11MB7516:EE_
x-ms-office365-filtering-correlation-id: 06580563-4f65-45f2-8a4e-08db7e8d4b7f
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: k6GZA84XlBC23yqC6MLXIQMkdUpI4Immmog9ouoSDg3Yk/c7wevPdLpSIglsaHq1XtWQ6dMzqhwqKxsjhdObMXf0v7YXPq+m8K21RtbS2CrWiSklDL3/sVugkztVwVXqNuaUOCzO4sfTPXVOSsBvAKymkhm5ltyHiHE7GS3KoYzP9zvyhDZWf/sdZRxNHoGeVZj1e1paIN+HS+49nJGImimeBqZ5KsgZKP0WgfHpDTfTedkf16+jAGA/7VemBoauba1xSZC+2d+4FhnsWeiwvd4DVT6KYfB79+/hgZgjIgZB81SvptlMAclu1Q1cMapsVVD7wHxG8vSTxY7jkcasNwp+jXzk2tjYvpLbP3auvH8KnnAXKfSRJZFR9O71laFnY9cnmEqXDvfJfTWD9/8hbbRd45uQGFgT3xiV5ZM8aY8/+rNyXjdrEe7tMvK5Z7XiNRrHvBPLoNrId0crfrSpJmd/RGOpIAGL2f++3uYI8l4fDKDZMBoGTbqnHthjxoCYYDTF/VmOVpnqZpQiLxCKejZPg1S4CwxZzMgPIS4dbFFzij5JhzSRbwvzDlsVl2wdQax1JfxlLs9inE7nJgj1V1A+rjmYuX61RGNCa3loPW1Z5nVIQD8aVExsjTN9n5Ef
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5739.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(39860400002)(396003)(346002)(376002)(136003)(366004)(451199021)(66574015)(83380400001)(122000001)(33656002)(86362001)(38100700002)(55016003)(38070700005)(54906003)(110136005)(71200400001)(7696005)(8676002)(41300700001)(5660300002)(8936002)(478600001)(9686003)(52536014)(66446008)(316002)(64756008)(6636002)(2906002)(4326008)(66556008)(76116006)(66946007)(15650500001)(66476007)(186003)(53546011)(6506007)(26005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 14p2iXXUzDNf0BvmAP2VmisrOySR8Pf7wCcN1KRVqNJ8Lru5HEaQp4ZR3GC0jXm6mSJc359WbZtIgARAbLZ81fkrHYMZodliaY1E9YjY0RZd2iACRrWYpkLIBjP0lFPho2CmSmdP874BVya4lsL+z4k4g4emeXnXnU+Yql+YNc3g/KEy1wH79C/LgR+HCMQc/aIexgTsZgseMzWQEcW7BiNIU0anNr8DroDUr6+ofSKAuRAzKwfsenReH+65kKS9BYoG8BavX56hida9C/xKdBu5U+DTJl5Rt8rRfPKlk+Lcp+NsNrVCAzsOQ1kklXGUOxBbv3SealpO/fica2gDPT0x03+YLxFOuJv+69ZG9eLwYlirdjg/0EAgE8b3fjfbG7RRFpyuCrJ1NNQ/QLb9W9WRVbcgnY+u4pmxSG//R4tVRdQ6hpMXzSaT+gCt3qr7uS7A9Y4tiOXEuBGrS2b3CMhahIP2qgSTgATb/m8cCiD/416M/uPtEZV2TB7s9evZOQaEBZSHm6bsyI8HbyoZYiWWjpoVDp06cGPDigEZFKAWh99H+BQWyusf0yCD36KJjES0dCT6cuNClUNUTPXL41gMRaTljr92DXbQc++TuGRGcgnc3up7sh+1utytoeq+k7J/T+imsG0r1dTEWZfyq2rH9JSRH7oeekHaiJxdf30jBvKk0Za+V79eF4PTFTEMYaMP35LMTicHip8nwLOMKifeqSyOghvi6V5VDtSZBIw0JrD+hmPD4sMeHrqAlIkdKNKN6gKBv1QT4QrqeGX0JlBSSrDZfkzPoS1kdCBzH0Zf6F6Gv+xScxULd7UWGokWdn9v2hv9l8uEZkJahX4cc9ML1IeTKBuiuUzV/BWU7pyqIWYQgzYrgsqO5/3BR3blM22IWp4tnx17ooNsb6vmDCC6pvfG5Ifgn5B+vEqMqbTo7M12nfzMFUyaxzaFsjKkgWH2S3NaWfgXJ4bcD26qAktDjcxEID/NkSz1dFkjAOvF5BxzYOCCvnvHLVaEhy0PPNWjxJURRepCXjXhfiAOLsrqswJWhG5t5N6EYDkPBwVSTomR9NYhTb2KDNTD0CrkvLUiEYFvM0gh1I6WsXLs/4glz6SCelPUd7M8NBEu3TblHkF0mBnNLrlKxVQGm28RbUK28JRJlU5M5iNvphZFQYo2KucrH4UndTGgDg6B4IEqtmvp5Ly87hiiXZTyKA72PkmxDHdjeQdBtA+JkNSrmXI2CdTAE8hOZjEEcrjHiKbtiBLLBWI221IVuJdtu6uTrUP9uiDVpX1sOEodwhN8VG183M83gowwg5Wh3H2eLd6qD9DB+B2PmJXYTYwqzUQ8QZPbbqUo3IliF6p0+RFf9CHEd/fG/RF1eCQszqtDTI23f8I5t7zVfYNGUY6zJ3v/4gfbySdcvXL7a/PfApVzGYirB/H2lXGApvEwU9i3fjxSHgdAgd9Ymni/6S2TALLYNqD6O2twUatAZ5FzyUYfyFa/WoDrRIpAiE6RyKjmkVc5dwbeARKe+v6SRqbFpb6xEhVglx34ypPiDGFWhgUgDzy07GgjI+WJIhH0p9Tk+5nIEUfj80Rv99o+apHG1DUh
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5739.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 06580563-4f65-45f2-8a4e-08db7e8d4b7f
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jul 2023 01:55:52.5144 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 8/zVeYEGiAy0cdpaaG9I6buJ55E8wBRWnJAoX+8KFs2FD+6QNRX4X6rlCMVXEq+trtHU5r85gBZuswK2bn0OW42YWeL/wZ72Vpc7dWwcmKw=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR11MB7516
X-Proofpoint-ORIG-GUID: coLPwtI-pKCQ7jcWIEtWTZkj1TugfX0Y
X-Proofpoint-GUID: coLPwtI-pKCQ7jcWIEtWTZkj1TugfX0Y
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.254,Aquarius:18.0.957,Hydra:6.0.591,FMLib:17.11.176.26 definitions=2023-07-06_17,2023-07-06_02,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 malwarescore=0 lowpriorityscore=0 priorityscore=1501 suspectscore=0 impostorscore=0 spamscore=0 adultscore=0 mlxscore=0 mlxlogscore=999 phishscore=0 clxscore=1011 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2305260000 definitions=main-2307070015
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/qFDDqb2M80MUq40SV_9A2o__a_g>
Subject: Re: [Acme] FW: [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Jul 2023 01:56:07 -0000

Thanks for the comments Fraser.

Guilty as charged -- we were not thinking about private enterprise environments when we wrote it; we were thinking about publicly-reachable servers on public clouds getting certs from public CAs. In that context, the quote from the abstract "at the mercy of their hosting provider as to which Certification Authorities (CAs) can be used" is less about the ACME server being reachable in a network sense, and more about public hosting providers -- quite reasonably -- not wanting to maintain a dropdown menu of every ACME server on the internet. Typically if you want to use a CA other than the single one that your hosting provider knows how to ACME to, then your only option is to manually upload a PEM file. Yuck. The other assumption here is that this draft is really for domain owners who care enough about where their certs come from to have a "favourite CA" because people who don't care will be happy to use whatever default ACME server.

That said, it's interesting to think about how this could apply to your enterprise problem of "find me /some/ ACME server that I can reach/use in this network zone". Assuming a private network with multiple DNS zones, you could configure your private DNS to slap on a constant CAA record across a DNS zone, and that gives you your "give me an ACME server, any one will do", right?

Out of curiosity, what happened to draft-tweedale-acme-discovery? Did it just not have enough momentum to proceed? Searching on the ACME list archive did not turn up very much discussion.

---
Mike Ounsworth

-----Original Message-----
From: Fraser Tweedale <frase@frase.id.au>
Sent: Thursday, July 6, 2023 7:40 PM
To: Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com>
Cc: Richard Barnes <rlb@ipv.sx>; Mike Ounsworth <Mike.Ounsworth@entrust.com>; acme@ietf.org
Subject: Re: [Acme] FW: [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt

On Fri, Jul 07, 2023 at 10:06:15AM +1000, Fraser Tweedale wrote:
> - The main problem solved in my draft was: "in this /network
>   environment/, what ACME servers can/should I use?"  The CAA-based
>   proposal answers a different question: "for this /domain/, what
>   ACME server should I use?"  But (a) why would a domain owner need
>   to control this, and (b) it doesn't actually solve the problem
>   stated in the abstract:
>
>   > This often leaves domain owners at the mercy of their hosting
>   > provider as to which Certification Authorities (CAs) can be used.
>
>   The hosting provider can still control which ACME servers can be
>   reached, regardless of the preferences expressed via CAA records.
>

With respect to (a) - never mind.  I thought about it some more and the answer is obvious.  Where a CA authorization (i.e. restriction) exists in the form of a CAA record, it is useful to be able to direct a client to the authorized issuer(s) for the affected domain(s).

I see that your draft solves a real problem.  But it does not help much in enterprise environments, where the question is often "find me /some/ ACME server that I can reach/use, or which the administrators prefer".  Two different problems, two complementary approaches.

Thanks,
Fraser
Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.