[Acme] Re: Call for adoption: draft-geng-acme-public-key-06 (Ends 2026-05-12)
Michael Richardson <mcr+ietf@sandelman.ca> Tue, 05 May 2026 15:16 UTC
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 74647E95203B for <acme@mail2.ietf.org>; Tue, 5 May 2026 08:16:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777994179; bh=R+6hlYnDIkcOduI19xKlX3sq9rRj7OunyBW4bgEO5Jk=; h=From:cc:Subject:In-Reply-To:References:Date; b=flTLQnUqNw1XlLO2a2Gw2qf9c580TKR3HcXxQ5SRAIAmUSg8jad5C2XGEL+cfFvQE YydNnDBQ2ZXsT1+vxYITCYk9P8KPUMSjtaaKEZmQnKMFUNcgvd8GvkGqCMhWJjHYdn /bMGsKyVsijKErQ1m7BWDsKAIg+Wp5+bJch4wHVg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.077
X-Spam-Level:
X-Spam-Status: No, score=-1.077 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, MISSING_HEADERS=1.021, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UWWSVUVbOLkl for <acme@mail2.ietf.org>; Tue, 5 May 2026 08:16:15 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7D95DE951FE0 for <acme@ietf.org>; Tue, 5 May 2026 08:16:15 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id 04E1C1800E; Tue, 05 May 2026 11:16:15 -0400 (EDT)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavis, port 10024) with LMTP id zs1UrvItfE5o; Tue, 5 May 2026 11:16:14 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sandelman.ca; s=mail; t=1777994174; bh=VsrrObJpb5a0PlEOw4XidNyQLjewJ9qSwjSxuNscZrE=; h=From:cc:Subject:In-Reply-To:References:Date:From; b=pop8hcJuMtXX9LOnj14SDg7FbVOa3thnKpF5ECEwXDcmwnI3WGEOPuZ6kr/x+qy4z u5ic0NeGc9E4o+ApRlpX+LhfL+lhLCVVys3pQ9dtBZBjVhnM0tJbmlVMVGNYgXnHFm ZIz1sy2kVsP+hFIF8t4/3W55pF4OPs2DJ7dsc/8rExCD0PdogCD7v9mJVufST8pd6u Bf+LmuJ9+dAPunYdj/4qbrUvBPP4oyRK+6PR5wyqaLedIzOf/uWi+n2gJCOqrILeYs x+nr+KAX5J119f32gdeJVav6m7xQ4+A9BmAf0CbLs/fkgz1TYxh0sy5xLNqx+xFU0f ViTc2w1kYZi1g==
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 181D01800C; Tue, 05 May 2026 11:16:14 -0400 (EDT)
Received: from obiwan.sandelman.ca (obiwan.sandelman.ca [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 149B41B6; Tue, 05 May 2026 11:16:14 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
In-Reply-To: <3BE2723E-6FD5-45F3-B5AF-BE5C2D05B91F@trustasia.com>
References: <177741722137.243357.10440835172964235548@dt-datatracker-b45949c58-t72jx> <15374.1777570611@obiwan.sandelman.ca> <3BE2723E-6FD5-45F3-B5AF-BE5C2D05B91F@trustasia.com>
X-Mailer: MH-E 8.6+git; nmh 1.8+dev; Emacs 30.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0;<'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Tue, 05 May 2026 11:16:14 -0400
Message-ID: <23423.1777994174@obiwan.sandelman.ca>
Message-ID-Hash: C2IOMEB662K53DQQTZR6FKGQFRN53WV2
X-Message-ID-Hash: C2IOMEB662K53DQQTZR6FKGQFRN53WV2
X-MailFrom: mcr+ietf@sandelman.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "acme@ietf.org" <acme@ietf.org>, "507069@qq.com" <507069@qq.com>, "wupanyuuu@gmail.com" <wupanyuuu@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: Call for adoption: draft-geng-acme-public-key-06 (Ends 2026-05-12)
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/xqqwxJyB71mQ0EZKejPEI0IW-7E>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>
palos.chen <palos.chen@trustasia.com> wrote:
>> It seems that this almost suffers from the same mis-understanding of
>> challenges as acme-rats originally did. At least though, the intention
>> is that it is pk-01 OR dns-01 OR http-01 OR ... (not AND as rats
>> needed)
> In -07, pk-01 is no longer entangled with identifier validation. We
> introduced a new "pk" identifier type (Section 3); pk-01 is bound to
> "pk" identifiers and proves possession of the certificate private key
> only. Existing challenges (dns-01, http-01, ...) remain bound to their
> own identifier types per [RFC8555] without modification.
But, it's the wrong approach.
You have to change pk-01 each time someone comes along with a new challenge
type. What you are doing is orthogonal to the challenge.
> The async/sync modes of -06 are entirely removed in -07. pk-01 no
> longer carries any identifier control role. Existing extensions
> (onion-csr-01, subdomain, dns-persist, etc.) continue to operate
> unchanged alongside pk-01.
okay, but I still think this is the wrong direction.
I think that what you are proposing is useful, but it's a fundamental change
to ACME, and should be treated that way.
>> Replacing the CSR with something better, something that can deal with
>> keys that can't make signatures (either do to math or policy) is
>> important. I had proposed work like this if/when we start RFC7030bis.
> We share this motivation. KEM-key support is in fact one of the
> primary reasons for a dedicated PoP mechanism rather than relying on
> the CSR self-signature, which is impossible for KEM-only keys. -07
> supports ML-KEM-512/768/1024 via a Decapsulate + HKDF + HMAC PoP — see
> Section 5.2 (KEM PoP construction) and Section 5.4 (KEM algorithm
> registry).
Then, let's fix/replace CSR.
>> The ACME server should simply announce the set of POP methods that it
>> can support, with CSR being the default. I don't think a new challenge
>> method is the correct way to negotiate this.
> This is the one architectural point where we've taken a different
> direction, following the chair's earlier guidance and the model that
> ACME has consistently used: challenges bound to identifier types
> (dns-01 for dns, http-01 for dns-via-http, onion-csr-01 for onion,
> etc.). -07 introduces a "pk" identifier type and a pk-01 challenge
> bound to it, which keeps the architecture modular and aligned with how
> the working group has handled similar extensions.
I think the chairs are wrong here :-)
I don't think this is a good direction to go, because I don't think your
needs are not the same as, for instance, .onion.
--
Michael Richardson <mcr+IETF@sandelman.ca> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
** My working hours and your working hours may be different. **
** Please do not feel obligated to reply outside your normal working hours **
- [Acme] Call for adoption: draft-geng-acme-public-… Mike Ounsworth via Datatracker
- [Acme] 回复:Call for adoption: draft-geng-acme-publ… 皮皮猪
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Liuchunchi(Peter)
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Michael Richardson
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Ilari Liusvaara
- [Acme] Re: Call for adoption: draft-geng-acme-pub… palos.chen
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Michael Richardson
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Lijun Liao
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Ilari Liusvaara
- [Acme] Re: Call for adoption: draft-geng-acme-pub… 皮皮猪
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Mike Ounsworth
- [Acme] 回复:Re: Call for adoption: draft-geng-acme-… 皮皮猪
- [Acme] Re: Call for adoption: draft-geng-acme-pub… Mike Ounsworth
- [Acme] 回复:Re: Call for adoption: draft-geng-acme-… 皮皮猪