Re: [Acme] Reference implementation of draft-misell-acme-onion

Q Misell <q@as207960.net> Mon, 24 April 2023 18:46 UTC

Return-Path: <q@as207960.net>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CBE94C159A1D for <acme@ietfa.amsl.com>; Mon, 24 Apr 2023 11:46:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.595
X-Spam-Level:
X-Spam-Status: No, score=-1.595 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, URI_NOVOWEL=0.5] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=as207960.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wg2Z_8O6lTSt for <acme@ietfa.amsl.com>; Mon, 24 Apr 2023 11:46:42 -0700 (PDT)
Received: from mail-ej1-x631.google.com (mail-ej1-x631.google.com [IPv6:2a00:1450:4864:20::631]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0424CC13AE4E for <acme@ietf.org>; Mon, 24 Apr 2023 11:46:41 -0700 (PDT)
Received: by mail-ej1-x631.google.com with SMTP id a640c23a62f3a-94f7a7a3351so883805166b.2 for <acme@ietf.org>; Mon, 24 Apr 2023 11:46:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=as207960.net; s=google; t=1682361999; x=1684953999; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=G47wqoTbd8IrbF2arjSy8xvypnaOu6Tah6Gn/Mhy/ZQ=; b=eEhIa3h+Ho68TLXPK1fj9x8EUcCFeo82X3ZEOb9Rt/qYeCHcHoC6CHrhmKOMtp3uhU UrsYo2o1TQd9wvdNy1H3uccCepFJQs2cFnDsR8NrE2OqZdLAoSl3XY/d6tDGm6N1g4ov R1wKmYotfq6LEGuOHR7CzcCiF39jroCIgUv7ArxsSKKw5zPXtN9exv2BqCP9qvsNZBP2 F1wVKPS8/hJstfQ9x07pB8UhgAzCHFz/iII5VJ0ezcxXD48XXg1hrF0bD1QPZtsYDXB7 sojdlYQmTG0RzkMjG2Hm5XIKc/iVkel9s5rOLZVKZujsYuYhVu44NaDiN/T++TnotsJ+ nOFQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1682361999; x=1684953999; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=G47wqoTbd8IrbF2arjSy8xvypnaOu6Tah6Gn/Mhy/ZQ=; b=SXZC993Huziq+NioRqUmtvl3LhZvh1rwUfz3e1xbSa0kZAVU7yNczcyMsjXRy5H3L1 jQSatY7IUXNbsF3hRZGJkPYbK7v1KhIZTuzK8+mknQjtew/K1siD7dNWLvZJMFgab1oV KEJexM/xiQtlp9aUbIxCplslOn3SdEvcIAx9ESKRy8wbHeUtN+ySLBwRUJcYN6G/ColP /SgohRh9qTGgy8d8YWYe80adNr/7ReCBGprM0wRt+iKQTnZSt+ycyRswQK/LrCkMk0n3 GPLkGM4cF9N3A8QzZCPzJbc2FpFikYUrBY84wKBzNqV43bV+s4z/hl6hXe02BFqbuZtf +L+A==
X-Gm-Message-State: AAQBX9csRoAYYjqPPLaK+DyA6AVODzgtLag3KcF2iLBieK3KPAK51hNx mm+948nDXULkayYrIqKxND5k5BcnBa5DmyaWHBoXXequhU9w0pYYn1RxzA==
X-Google-Smtp-Source: AKy350ZtAYq0JMmss9MuSaDdahEx+AJ0wlNmZ3GznEFIKnVrRLdVZ1Bdz8qxuDpxAexIH6jb4/dBPEqfPfOuBkn7bXY=
X-Received: by 2002:a17:906:2095:b0:953:9024:1b50 with SMTP id 21-20020a170906209500b0095390241b50mr9306440ejq.74.1682361999528; Mon, 24 Apr 2023 11:46:39 -0700 (PDT)
MIME-Version: 1.0
References: <CAMEWqGvDnUAttLh=0VPnWXdWxiH96hzm+XGX-q9vG_vmO9U85g@mail.gmail.com> <c14c31fc-8985-0d5a-2034-9dbc9d20ab77@gmail.com> <CAMEWqGu4+LCVjKf_cszfY0nUE8trate9b1-Q4uGopqJrFqKdeA@mail.gmail.com>
In-Reply-To: <CAMEWqGu4+LCVjKf_cszfY0nUE8trate9b1-Q4uGopqJrFqKdeA@mail.gmail.com>
From: Q Misell <q@as207960.net>
Date: Mon, 24 Apr 2023 19:46:03 +0100
Message-ID: <CAMEWqGsDm5xdF74KUT1KQn0uRELO-k+Qc=aYUj2uA3ano9KNGA@mail.gmail.com>
To: Seo Suchan <tjtncks@gmail.com>
Cc: Q Misell <q=40as207960.net@dmarc.ietf.org>, acme@ietf.org
Content-Type: multipart/alternative; boundary="0000000000005dadd105fa196d5c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/rTU_8aBckeUGdH_vKPazYOi3VaU>
Subject: Re: [Acme] Reference implementation of draft-misell-acme-onion
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Apr 2023 18:46:46 -0000

Hi again Seo,

I've published my fork of Tor with support for publishing CAA records:
https://github.com/as207960/tor.
There's also now a hidden service at
znkiu4wogurrktkqqid2efdg4nvztm7d2jydqenrzeclfgv3byevnbid.onion with CAA
records in its hidden service descriptor.

Thanks,
Q
------------------------------

Any statements contained in this email are personal to the author and are
not necessarily the statements of the company unless specifically stated.
AS207960 Cyfyngedig, having a registered office at 13 Pen-y-lan Terrace,
Caerdydd, Cymru, CF23 9EU, trading as Glauca Digital, is a company
registered in Wales under № 12417574
<https://find-and-update.company-information.service.gov.uk/company/12417574>.
ICO register №: ZA782876 <https://ico.org.uk/ESDWebPages/Entry/ZA782876>.
UK VAT №: GB378323867. EU VAT №: EU372013983. Turkish VAT №: 0861333524.
South Korean VAT №: 522-80-03080. Glauca Digital and the Glauca logo are
registered trademarks in the UK, under № UK00003718474 and № UK00003718468,
respectively.


On Sun, 23 Apr 2023 at 22:12, Q Misell <q@as207960.net> wrote:

> Hi Seo,
>
> Thanks for the feedback.
>
> I copy pasted the list of logs into my code from
> https://github.com/google/certificate-transparency-community-site/blob/master/docs/google/known-logs.md,
> it would probably be a good idea to delete the old logs.
>
> The SERVFAIL response is non very clear, agreed. I'll improve my error
> handling there.
>
> In my testing, adding new records to the first layer descriptor doesn't
> bother the current Tor project tor implementation (seemingly the only one
> anyone ever uses).
> I'm still working on patching the tor router to add support for defining
> CAA but I'll definitely put up a few test services with different
> configurations once that's done.
>
> Thanks,
> Q
> ------------------------------
>
> Any statements contained in this email are personal to the author and are
> not necessarily the statements of the company unless specifically stated.
> AS207960 Cyfyngedig, having a registered office at 13 Pen-y-lan Terrace,
> Caerdydd, Cymru, CF23 9EU, trading as Glauca Digital, is a company
> registered in Wales under № 12417574
> <https://find-and-update.company-information.service.gov.uk/company/12417574>.
> ICO register №: ZA782876 <https://ico.org.uk/ESDWebPages/Entry/ZA782876>.
> UK VAT №: GB378323867. EU VAT №: EU372013983. Turkish VAT №: 0861333524.
> South Korean VAT №: 522-80-03080. Glauca Digital and the Glauca logo are
> registered trademarks in the UK, under № UK00003718474 and № UK00003718468,
> respectively.
>
>
> On Sun, 23 Apr 2023 at 14:27, Seo Suchan <tjtncks@gmail.com> wrote:
>
>> google's solera 2018~2022 are no longer accept new record. solera ct log
>> is sharded by notafter day of incoming certificates, so only log able to
>> use currently be 2023 (assume 90 day certificate)
>>
>> when I ran you client for onion-csr without having hosted onion hidden
>> service, server returned caa servfail, not sure this is right response
>> for such (not yet hosted) domain: NXdomain or dedicated error code looks
>> better.
>>
>> not sure how one can add a format in first layer like in 5.3 without
>> breaking old tor client implementations. could make a hidden service
>> with caa-critical online?
>>
>> P.S didn't notice you already posted v 02 of this draft.
>>
>> 2023-04-21 오전 7:04에 Q Misell 이(가) 쓴 글:
>> > Hi all,
>> >
>> > Thanks for all your feedback over my draft. I've incorporated your
>> > comments into a new draft, and published this.
>> >
>> > I've also finished my reference implementation of the draft, more
>> > details available at https://acmeforonions.org. I'd be delighted if
>> > you'd try it out and let me know what you think.
>> >
>> > Thanks,
>> > Q
>> >
>> > _______________________________________________
>> > Acme mailing list
>> > Acme@ietf.org
>> > https://www.ietf.org/mailman/listinfo/acme
>>
>> _______________________________________________
>> Acme mailing list
>> Acme@ietf.org
>> https://www.ietf.org/mailman/listinfo/acme
>>
>