[Acme] FW: New Version Notification for draft-ietf-acme-star-delegation-09.txt

Yaron Sheffer <yaronf.ietf@gmail.com> Fri, 11 June 2021 08:29 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0ADCF3A2EB8 for <acme@ietfa.amsl.com>; Fri, 11 Jun 2021 01:29:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, MALFORMED_FREEMAIL=0.001, MIME_QP_LONG_LINE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5x4pFyA12cb8 for <acme@ietfa.amsl.com>; Fri, 11 Jun 2021 01:29:07 -0700 (PDT)
Received: from mail-io1-xd30.google.com (mail-io1-xd30.google.com [IPv6:2607:f8b0:4864:20::d30]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BFE303A2EBD for <acme@ietf.org>; Fri, 11 Jun 2021 01:29:07 -0700 (PDT)
Received: by mail-io1-xd30.google.com with SMTP id k5so20264604iow.12 for <acme@ietf.org>; Fri, 11 Jun 2021 01:29:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=user-agent:date:subject:from:to:message-id:thread-topic:references :in-reply-to:mime-version:content-transfer-encoding; bh=b8SCCM4OI+E+i71PgpA6yzKQeEWPMzOr9ypAhaqOcD8=; b=JG7Z1M/Pg0F9/KnoHi7L7l0peG73T+xyTmnMBFtKSqtpl+ABuIKIOAGBCGvZK0MkLd nUAMqZkFV+6rLHtNlpF/lHYPif/3LU3IEDlOQb9dPvzUYxNJs1XXdT3KbnJjygRWagVB /sC5/c20ZHxPPxiFAqIi+ooNicJtB4b7Do4ew36FpSN2iYzFGpwhoVNqdeIfd4J12eUS lcORtSHRBDPw01TWZkf8PkdrVZwbxAFitRsW3Oc+vIFPu8+n9VeTljSwTcaPM49ZRcU8 EGgLzd20cUFkLdMVIxUw2H/7ctnpsbdjwgFwY2+c0pqK6ATEy1nypDCy81PWr2M7Bndz pdWA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:user-agent:date:subject:from:to:message-id :thread-topic:references:in-reply-to:mime-version :content-transfer-encoding; bh=b8SCCM4OI+E+i71PgpA6yzKQeEWPMzOr9ypAhaqOcD8=; b=RTJKgIJYYaoUy0fDMLkrtrRbm+AbGnCaxtSrdLdSQWZFkxgbHmPsYCmV6AZ98T47Oe zJ6r3C9un6jlbpt5Nf2+jrp+jTqGg9Th/sRA0/9FKkW4ZCg6g+i6rX3tr9xVQ6rCppA0 7HJSmNT1mJnDaP+w62ZBv6FwIgxPiBtjG5aSXqXuCrhekjXQfrY0vg0On1hArswggUG7 KkX6Qx6vEyF2buWMyyqgrxp1y5/L5HjIc55Vf+7VYR2Kj76HgveH7Idw114vIRVT7ttb 99oqM6ch7ecvqd9Db0xSsLCImi/7hkzyhl/CSslr4t72w5tMNulYJz/Dcc+iWxD7y3+K WqvQ==
X-Gm-Message-State: AOAM533N3aLIe3Azln75e2vTcmT90ZIPDvDq/3xdgT6Etp50ErMCxcA0 l9hsyjAjlCUkKwFTXtnqcwMeMa5oWVk=
X-Google-Smtp-Source: ABdhPJwi9B/K6nrofYdU6g34GPLp2/RU5gtl+esMRjsVfbZss8serTp5c1niC/7stYiM6iqeBrO5Vg==
X-Received: by 2002:a02:9692:: with SMTP id w18mr2755882jai.65.1623400145716; Fri, 11 Jun 2021 01:29:05 -0700 (PDT)
Received: from [192.168.68.107] (bzq-79-182-62-6.red.bezeqint.net. [79.182.62.6]) by smtp.gmail.com with ESMTPSA id h200sm2987912iof.6.2021.06.11.01.29.04 for <acme@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 11 Jun 2021 01:29:05 -0700 (PDT)
User-Agent: Microsoft-MacOutlook/16.49.21050901
Date: Fri, 11 Jun 2021 11:29:01 +0300
From: Yaron Sheffer <yaronf.ietf@gmail.com>
To: IETF ACME <acme@ietf.org>
Message-ID: <995E7F68-159C-4516-9F01-3F908E1086A4@gmail.com>
Thread-Topic: New Version Notification for draft-ietf-acme-star-delegation-09.txt
References: <162340005752.16655.7825059659225429093@ietfa.amsl.com>
In-Reply-To: <162340005752.16655.7825059659225429093@ietfa.amsl.com>
Mime-version: 1.0
Content-type: text/plain; charset="UTF-8"
Content-transfer-encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/ullDbyWOiPCM-aTqP0Orzl6Xi5g>
Subject: [Acme] FW: New Version Notification for draft-ietf-acme-star-delegation-09.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jun 2021 08:29:12 -0000

This is a minor update to address a few remaining comments by Ben.

Thanks,
	Yaron

On 6/11/21, 11:27, "internet-drafts@ietf.org" <internet-drafts@ietf.org> wrote:


    A new version of I-D, draft-ietf-acme-star-delegation-09.txt
    has been successfully submitted by Yaron Sheffer and posted to the
    IETF repository.

    Name:		draft-ietf-acme-star-delegation
    Revision:	09
    Title:		An ACME Profile for Generating Delegated Certificates
    Document date:	2021-06-11
    Group:		acme
    Pages:		48
    URL:            https://www.ietf.org/archive/id/draft-ietf-acme-star-delegation-09.txt
    Status:         https://datatracker.ietf.org/doc/draft-ietf-acme-star-delegation/
    Html:           https://www.ietf.org/archive/id/draft-ietf-acme-star-delegation-09.html
    Htmlized:       https://datatracker.ietf.org/doc/html/draft-ietf-acme-star-delegation
    Diff:           https://www.ietf.org/rfcdiff?url2=draft-ietf-acme-star-delegation-09

    Abstract:
       This document defines a profile of the Automatic Certificate
       Management Environment (ACME) protocol by which the holder of an
       identifier (e.g., a domain name) can allow a third party to obtain an
       X.509 certificate such that the certificate subject is the delegated
       identifier while the certified public key corresponds to a private
       key controlled by the third party.  A primary use case is that of a
       Content Delivery Network (CDN, the third party) terminating TLS
       sessions on behalf of a content provider (the holder of a domain
       name).  The presented mechanism allows the holder of the identifier
       to retain control over the delegation and revoke it at any time.
       Importantly, this mechanism does not require any modification to the
       deployed TLS clients and servers.




    The IETF Secretariat