[Acme] FW: New Version Notification for draft-ietf-acme-star-delegation-03.txt

Yaron Sheffer <yaronf.ietf@gmail.com> Sun, 08 March 2020 21:03 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 985F83A0AC1 for <acme@ietfa.amsl.com>; Sun, 8 Mar 2020 14:03:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.373
X-Spam-Level:
X-Spam-Status: No, score=-0.373 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, MALFORMED_FREEMAIL=1.713, MIME_QP_LONG_LINE=0.001, SPF_HELO_NONE=0.001, T_SPF_TEMPERROR=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZOK7oOOwzDVC for <acme@ietfa.amsl.com>; Sun, 8 Mar 2020 14:03:47 -0700 (PDT)
Received: from mail-wr1-x42e.google.com (mail-wr1-x42e.google.com [IPv6:2a00:1450:4864:20::42e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC5253A0AC6 for <acme@ietf.org>; Sun, 8 Mar 2020 14:03:46 -0700 (PDT)
Received: by mail-wr1-x42e.google.com with SMTP id p2so7793815wrw.7 for <acme@ietf.org>; Sun, 08 Mar 2020 14:03:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=user-agent:date:subject:from:to:message-id:thread-topic:references :in-reply-to:mime-version:content-transfer-encoding; bh=VVLx4N9UlrsCkhycUjdfbh86TPUjwDMu5ZJ384mBZpw=; b=uAsgIwbcENqPRqXVvI/rWOwRIrauvNCwheLXDFAxF6jsVf6loAcoCE55uPwXWegDEX 8egB0qPJ5GXIhMpsEq0x/E3eShiE5S+oer7BPdla1rQIchSRzKwRzTYK5kxc/32ST0mE SYxcVmCq0zi29XpMt3/kCMqhmhL0PszTZBcI0dtgPuVeAHsvKxKzAtDPVp7LqHB+jZ6p GRB3mXRI+MWSqewDmwhYNIKwV0WkWXnPF6q8jC0KCUbyEGyLsHxZBUt4jkLB1xSrRIQw ZVZZvu9wJ9kXoSJHMjH4feaidNXOSWUQFWB0Q3vbDdQZrYz8Ny+xk6LcBC/M0tQD8GxP rTUw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:user-agent:date:subject:from:to:message-id :thread-topic:references:in-reply-to:mime-version :content-transfer-encoding; bh=VVLx4N9UlrsCkhycUjdfbh86TPUjwDMu5ZJ384mBZpw=; b=uUHHpP9rt6l+qgp2uzMa/Aguv0AM/K6507zs/d8ccBPunM68CB88R9Xkf0ILKrk7Og qFjAsxpnTRzzsX7aGZSSYkPHFjjdTAR93VR4DgLCeNeKEV4HPtJQDf/B6FZRJLTZUAEd nhmx2cb8Xca0iN1nONXWm+GciAZEwOV2nsxcj3mIzgKtf9vkdHlqozJErrsL3YPOUM0l WWHOdU0nRpy41lM3EM7oab2Fsf1s5BrYQqgW/5Ih+qfS172vWc82N/7wEW0OjY0+Jfu7 EANAGfMeDR1mYffEYX9qvsKNBFx5tcEraCGLHV2CTl8AwuzepuZaVOuIeE7HQaWMiZhb IgJg==
X-Gm-Message-State: ANhLgQ3HTjvgS88agpCUOL8hTpfUEFrqXexWiEVdmmJELkfNvskOJtB6 je7X1QxPxyoVz7HVAOqsL3FkPFFH
X-Google-Smtp-Source: =?utf-8?q?ADFU+vs2zaVdrw+D9r/UU7lQC28x7neVc9BYQdzih+JW?= =?utf-8?q?KKo32iRAu/o2YyONlzMg4V83ENbb5XOztA=3D=3D?=
X-Received: by 2002:a5d:45d1:: with SMTP id b17mr16734966wrs.59.1583701424443; Sun, 08 Mar 2020 14:03:44 -0700 (PDT)
Received: from [10.0.0.144] (bzq-79-178-61-110.red.bezeqint.net. [79.178.61.110]) by smtp.gmail.com with ESMTPSA id i1sm39690536wrs.18.2020.03.08.14.03.43 for <acme@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 08 Mar 2020 14:03:43 -0700 (PDT)
User-Agent: Microsoft-MacOutlook/10.22.0.200209
Date: Sun, 08 Mar 2020 23:03:42 +0200
From: Yaron Sheffer <yaronf.ietf@gmail.com>
To: "acme@ietf.org" <acme@ietf.org>
Message-ID: <4D67909D-296F-4CA7-89A4-4A60AB33E5D2@gmail.com>
Thread-Topic: New Version Notification for draft-ietf-acme-star-delegation-03.txt
References: <158370007496.6893.10289910737007298372@ietfa.amsl.com>
In-Reply-To: <158370007496.6893.10289910737007298372@ietfa.amsl.com>
Mime-version: 1.0
Content-type: text/plain; charset="UTF-8"
Content-transfer-encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/vb8Hy4j6oAN7gZOpfzH_Uf1Czfo>
Subject: [Acme] FW: New Version Notification for draft-ietf-acme-star-delegation-03.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Mar 2020 21:03:55 -0000

As promised, we submitted another version of this draft before Vancouver. In addition to the recent work on the CSR template, this version includes a lot more detail on the STIR and CDNI use cases, including recursive delegation.

We would greatly appreciate your comments!

Thanks,
	Yaron

On 3/8/20, 22:41, "internet-drafts@ietf.org" <internet-drafts@ietf.org> wrote:

    
    A new version of I-D, draft-ietf-acme-star-delegation-03.txt
    has been successfully submitted by Yaron Sheffer and posted to the
    IETF repository.
    
    Name:		draft-ietf-acme-star-delegation
    Revision:	03
    Title:		An ACME Profile for Generating Delegated STAR Certificates
    Document date:	2020-03-08
    Group:		acme
    Pages:		26
    URL:            https://www.ietf.org/internet-drafts/draft-ietf-acme-star-delegation-03.txt
    Status:         https://datatracker.ietf.org/doc/draft-ietf-acme-star-delegation/
    Htmlized:       https://tools.ietf.org/html/draft-ietf-acme-star-delegation-03
    Htmlized:       https://datatracker.ietf.org/doc/html/draft-ietf-acme-star-delegation
    Diff:           https://www.ietf.org/rfcdiff?url2=draft-ietf-acme-star-delegation-03
    
    Abstract:
       This memo proposes a profile of the ACME protocol that allows the
       owner of an identifier (e.g., a domain name) to delegate to a third
       party access to a certificate associated with said identifier.  A
       primary use case is that of a CDN (the third party) terminating TLS
       sessions on behalf of a content provider (the owner of a domain
       name).  The presented mechanism allows the owner of the identifier to
       retain control over the delegation and revoke it at any time by
       cancelling the associated STAR certificate renewal with the ACME CA.
       Another key property of this mechanism is it does not require any
       modification to the deployed TLS ecosystem.
    
                                                                                      
    
    
    Please note that it may take a couple of minutes from the time of submission
    until the htmlized version and diff are available at tools.ietf.org.
    
    The IETF Secretariat