[Acme] Of revocation, time, and certificates

"Salz, Rich" <rsalz@akamai.com> Tue, 26 March 2024 17:24 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4FF4FC14F5E6 for <acme@ietfa.amsl.com>; Tue, 26 Mar 2024 10:24:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ah9iQXQmms_B for <acme@ietfa.amsl.com>; Tue, 26 Mar 2024 10:24:46 -0700 (PDT)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 21D2CC14F5E9 for <acme@ietf.org>; Tue, 26 Mar 2024 10:24:34 -0700 (PDT)
Received: from pps.filterd (m0050093.ppops.net [127.0.0.1]) by m0050093.ppops.net-00190b01. (8.17.1.24/8.17.1.24) with ESMTP id 42QFgltb011871; Tue, 26 Mar 2024 16:25:02 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h= from:to:subject:date:message-id:content-type:mime-version; s= jan2016.eng; bh=1zcAbSAimP5PvqPPpvvz6ISJeoAPHvh3+/2L43B/tK8=; b= MmcFlVAkA6Iq0FhQFruL/YlqGerT3q4qE5/NSXUyVRafzaoaZO8Ah9gnZJ6R5MzX Be+eBQivhKEPS9aWHDq4PSd1O1wl0m4OuthRXtmQGfbgLwMWP3DXw1HBBa9TbInl OOdHWr6f4RhnppxG3AeRbL4rJC567z6xmTQlcEkab8JleuMBWSOBc9OfFuObhZwv xPJabVN+Kjd/U36FeVYc/7bIFzuAhX4o8sm0Qxk/Ns2L+WQlU/BXlNpmMi/hgz0y azKyv60/l9YikR6OKV7pdrHXr7v0nNT9GW9GUorc0Vj7Qr18P/kLPjhjELkwYwP3 rWEz5zJja9g79cbRREylxQ==
Received: from prod-mail-ppoint8 (a72-247-45-34.deploy.static.akamaitechnologies.com [72.247.45.34] (may be forged)) by m0050093.ppops.net-00190b01. (PPS) with ESMTPS id 3x1q7ydcba-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 26 Mar 2024 16:25:01 +0000 (GMT)
Received: from pps.filterd (prod-mail-ppoint8.akamai.com [127.0.0.1]) by prod-mail-ppoint8.akamai.com (8.17.1.19/8.17.1.19) with ESMTP id 42QFwlBi030698; Tue, 26 Mar 2024 12:25:00 -0400
Received: from email.msg.corp.akamai.com ([172.27.50.203]) by prod-mail-ppoint8.akamai.com (PPS) with ESMTPS id 3x1tdyg7vg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 26 Mar 2024 12:25:00 -0400
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) by ustx2ex-dag4mb4.msg.corp.akamai.com (172.27.50.203) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.28; Tue, 26 Mar 2024 09:24:59 -0700
Received: from ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) by ustx2ex-dag4mb4.msg.corp.akamai.com ([172.27.50.203]) with mapi id 15.02.1258.028; Tue, 26 Mar 2024 09:24:59 -0700
From: "Salz, Rich" <rsalz@akamai.com>
To: "lamps@ietf.org" <lamps@ietf.org>, "acme@ietf.org" <acme@ietf.org>
Thread-Topic: Of revocation, time, and certificates
Thread-Index: AQHaf5oly7Kr2fLBD0ONpCrtC4xAOA==
Date: Tue, 26 Mar 2024 16:24:59 +0000
Message-ID: <56CA447A-3B68-4FCB-9CD8-925BADEB069B@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.81.24012814
x-originating-ip: [172.27.118.139]
Content-Type: multipart/alternative; boundary="_000_56CA447A3B684FCB9CD8925BADEB069Bakamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-03-26_06,2024-03-21_02,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 spamscore=0 adultscore=0 suspectscore=0 mlxlogscore=584 phishscore=0 mlxscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2403210000 definitions=main-2403260115
X-Proofpoint-ORIG-GUID: FE2NH9JqLqXDEqyW2iVrpwd2H5HhWEB_
X-Proofpoint-GUID: FE2NH9JqLqXDEqyW2iVrpwd2H5HhWEB_
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-03-26_06,2024-03-21_02,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 priorityscore=1501 mlxlogscore=476 lowpriorityscore=0 clxscore=1011 suspectscore=0 spamscore=0 mlxscore=0 phishscore=0 malwarescore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2403210001 definitions=main-2403260116
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/uE2MxTXDQapAiga3GJir-lMRHoQ>
Subject: [Acme] Of revocation, time, and certificates
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Mar 2024 17:24:57 -0000

An amusing story about NTP failures, affecting PKI issuance, and embedded devices.  Worth a read IMO https://infosec.exchange/@bob_zim/111862834586135218  Cross-posted to two active lists, please reply appropriately.