[Add] Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
Dan Wing <danwing@gmail.com> Wed, 24 July 2024 20:22 UTC
Return-Path: <danwing@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94993C1DA1F8 for <add@ietfa.amsl.com>; Wed, 24 Jul 2024 13:22:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.104
X-Spam-Level:
X-Spam-Status: No, score=-7.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iwdTOSvlEDDc for <add@ietfa.amsl.com>; Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
Received: from mail-pf1-x42a.google.com (mail-pf1-x42a.google.com [IPv6:2607:f8b0:4864:20::42a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC62DC1E0D9A for <add@ietf.org>; Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
Received: by mail-pf1-x42a.google.com with SMTP id d2e1a72fcca58-70d2b921cd1so179395b3a.1 for <add@ietf.org>; Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1721852545; x=1722457345; darn=ietf.org; h=to:date:message-id:subject:mime-version:from:from:to:cc:subject :date:message-id:reply-to; bh=Q7VeJ7hCPSHzH0onTdXSwWyHeyZFA+190VTOXsZzicQ=; b=ndoJNLW8udV+OYMIsYJxq/Lv4exECTyXlQtdq7nGkmZ1OtSzSgIkwR/pmDMrKnYpqy KKjCWcUP6S0nbE3/K5cegpR2pnn3dJJlePNlBPRI4pC9lIRzY7gp37/LZeCfZiHtuzJa aVi6CuP/kYVcTRv4n13Emz4dLWfyYrpWXgJni/+voOYqXRWEvj+zuGouJYt/3xwaGA4J HCH5mnS0sB13D20Zcath7hDE9/CB7Wv8226wHGH9ovEJQtGKqEkGjQgOXwBTOawj3w1q v9gHQrwEk89imgUZ4rpYNKimD0bKZgkytfbRFjBup0m21ulIDNg5+wVeCTf1tk35cz9p Ix0Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1721852545; x=1722457345; h=to:date:message-id:subject:mime-version:from:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=Q7VeJ7hCPSHzH0onTdXSwWyHeyZFA+190VTOXsZzicQ=; b=v7PJd7ON+kJsYknL1NuqhTrRLDdqIKvz6ijnUeb3l3AcUwxAUie09BmVwsjmCjdrEX 2kT/CgaGUKA2a1FLOk7MCbGshEdSQtX+xkj7OMG9vdPNUlyWW5/wC3SfarA1Ywl89JWV tPKRpIkMJQoqczqvGJrXsoZRt5ig4JgrX+gXuS38SAqWtAUB3RU0Jg02Nf660BiaUWUx V7xU1b4DjQsquvmiQTK+SedFWdVGtLU5UKGGfzOFjS1iLVoqmlyfLNN0o6qscVgqlLqU GFBH3WB7jVba+KML+z5cJcTuYthAbSkXSOvvgnNhTzuhVk8aRgJUnWgBMTChWAiQaoIz 0gAg==
X-Gm-Message-State: AOJu0Ywwcj48arot0QfsQkxrOqa17XWJYAQeq5VQLRX31bZPAMD3TLC8 vsNgIUS2xRhddNt+Zdd2qwh+WydjW8s7CTSouiKfMf8s4Begcy70REe3Iw==
X-Google-Smtp-Source: AGHT+IFsGScbwc/ipoD/dy63GqU+CWwD8WXKZq1A58o+csmgrDAiIu68b/8VhhTznoLIqg7f32sN4g==
X-Received: by 2002:a05:6a00:1a87:b0:70d:2892:402b with SMTP id d2e1a72fcca58-70eaa8b1371mr933041b3a.7.1721852543907; Wed, 24 Jul 2024 13:22:23 -0700 (PDT)
Received: from smtpclient.apple ([47.208.219.53]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-70cff4b2f6esm8919585b3a.67.2024.07.24.13.22.22 for <add@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 24 Jul 2024 13:22:23 -0700 (PDT)
From: Dan Wing <danwing@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_2F8E2A4B-AEE3-4149-85EB-6E079760D493"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.600.62\))
Message-Id: <6FCA933A-F329-4B45-9C72-32FFCAD289BE@gmail.com>
Date: Wed, 24 Jul 2024 13:22:22 -0700
To: add@ietf.org
X-Mailer: Apple Mail (2.3774.600.62)
Message-ID-Hash: 672Q6C4POIFE7MWRIPL67OZASQTSU4MI
X-Message-ID-Hash: 672Q6C4POIFE7MWRIPL67OZASQTSU4MI
X-MailFrom: danwing@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Add] Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
List-Id: Applications Doing DNS <add.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/-aK8R2X1QAHiwq6A4-Jy80c6Bdc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Owner: <mailto:add-owner@ietf.org>
List-Post: <mailto:add@ietf.org>
List-Subscribe: <mailto:add-join@ietf.org>
List-Unsubscribe: <mailto:add-leave@ietf.org>
ADD WG, While working to provide TLS for encrypted DNS on CPE, Tiru Reddy's IETF119 ADD presentation made it clear ADD had bumped into a larger problem: IETF and the industry has not documented how to best get certificates onto CPE. A few companies (McAfee, Mozilla, Cujo) have deployed a system where a unique FQDN is assigned to each CPE (e.g., to the DNS server) and the CPE requests a vendor-operated cloud service to get that certificate signed by a CA and returned to the CPE and CPE uses that CA-signed certificate for incoming TLS connections. Such a system works but the disadvantages are needing to get millions of certificates continually signed by the CA (short-lived certificates) and continued reliance on the vendor to operate the certificate-signing service. Experience is that an exception is necessary to overcome the CA's normal rate limit. There are two documents that discuss such a system, its drawbacks, and also explore some other system designs: - Martin Thomson's "HTTPS for Local Domains" (*, below), and - draft-rbw-add-encrypted-dns-forwarders (**, below). Please read them prior to Thursday's ADD meeting, as I will only spend 3-4 minutes presenting and the rest of the time will be microphone discussion. I am hoping there are authors interested in writing a problem statement document (if consensus is existing practice is too difficult) or writing a BCP/Informational document on such a vendor-operated service (if consensus is continue existing practice). -d (*) Martin Thomson's "HTTPS for Local Domains", https://docs.google.com/document/d/170rFC91jqvpFrKIqG4K8Vox8AL4LeQXzfikBQXYPmzU/edit, https://tinyurl.com/https-for-local-domains (**) "Hosting Encrypted Servers on CPEs" slide deck for IETF120 ADD meeting, https://datatracker.ietf.org/meeting/120/session/add "Hosting Encrypted DNS Forwarders on CPEs", https://datatracker.ietf.org/doc/draft-rbw-add-encrypted-dns-forwarders/
- [Add] Hosting Encrypted Servers on CPEs / HTTPS f… Dan Wing
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Chris Box
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Ben Schwartz
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Lanlan Pan
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Toerless Eckert
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Erik Nygren
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Michael Sweet
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Michael Sweet
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Dan Wing
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Dan Wing
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Toerless Eckert
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Alan DeKok
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Toerless Eckert
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Michael Sweet
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Toerless Eckert
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Alan DeKok
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Dan Wing
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Dan Wing
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: [Anima] Re: Hosting Encrypted Servers o… Brian E Carpenter
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: [EXTERNAL] Re: [Iotops] Re: Hosting Enc… Deen, Glenn (Comcast Cable)
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Sweet
- [Add] Re: [Iotops] Re: Hosting Encrypted Servers … Michael Sweet
- [Add] Re: [Iotops] [Anima] Re: Hosting Encrypted … Michael Sweet
- [Add] Re: [Iotops] Hosting Encrypted Servers on C… Michael Sweet
- [Add] Re: [EXTERNAL] Re: [Iotops] Re: Hosting Enc… Michael Sweet
- [Add] Re: [EXTERNAL] Re: [Iotops] Re: Hosting Enc… Deen, Glenn (Comcast Cable)
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… David Farmer
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Ben Schwartz
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Brian E Carpenter
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Erik Nygren
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Michael Richardson
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Dan Wing
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Brian E Carpenter
- [Add] Re: Hosting Encrypted Servers on CPEs / HTT… Eric Rescorla