Return-Path: <danwing@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 94993C1DA1F8
	for <add@ietfa.amsl.com>; Wed, 24 Jul 2024 13:22:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.104
X-Spam-Level: 
X-Spam-Status: No, score=-7.104 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
	HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5,
	RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001,
	SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
	URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id iwdTOSvlEDDc for <add@ietfa.amsl.com>;
	Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
Received: from mail-pf1-x42a.google.com (mail-pf1-x42a.google.com
 [IPv6:2607:f8b0:4864:20::42a])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest
 SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id BC62DC1E0D9A
	for <add@ietf.org>; Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
Received: by mail-pf1-x42a.google.com with SMTP id
 d2e1a72fcca58-70d2b921cd1so179395b3a.1
        for <add@ietf.org>; Wed, 24 Jul 2024 13:22:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20230601; t=1721852545; x=1722457345; darn=ietf.org;
        h=to:date:message-id:subject:mime-version:from:from:to:cc:subject
         :date:message-id:reply-to;
        bh=Q7VeJ7hCPSHzH0onTdXSwWyHeyZFA+190VTOXsZzicQ=;
        b=ndoJNLW8udV+OYMIsYJxq/Lv4exECTyXlQtdq7nGkmZ1OtSzSgIkwR/pmDMrKnYpqy
         KKjCWcUP6S0nbE3/K5cegpR2pnn3dJJlePNlBPRI4pC9lIRzY7gp37/LZeCfZiHtuzJa
         aVi6CuP/kYVcTRv4n13Emz4dLWfyYrpWXgJni/+voOYqXRWEvj+zuGouJYt/3xwaGA4J
         HCH5mnS0sB13D20Zcath7hDE9/CB7Wv8226wHGH9ovEJQtGKqEkGjQgOXwBTOawj3w1q
         v9gHQrwEk89imgUZ4rpYNKimD0bKZgkytfbRFjBup0m21ulIDNg5+wVeCTf1tk35cz9p
         Ix0Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1721852545; x=1722457345;
        h=to:date:message-id:subject:mime-version:from:x-gm-message-state
         :from:to:cc:subject:date:message-id:reply-to;
        bh=Q7VeJ7hCPSHzH0onTdXSwWyHeyZFA+190VTOXsZzicQ=;
        b=v7PJd7ON+kJsYknL1NuqhTrRLDdqIKvz6ijnUeb3l3AcUwxAUie09BmVwsjmCjdrEX
         2kT/CgaGUKA2a1FLOk7MCbGshEdSQtX+xkj7OMG9vdPNUlyWW5/wC3SfarA1Ywl89JWV
         tPKRpIkMJQoqczqvGJrXsoZRt5ig4JgrX+gXuS38SAqWtAUB3RU0Jg02Nf660BiaUWUx
         V7xU1b4DjQsquvmiQTK+SedFWdVGtLU5UKGGfzOFjS1iLVoqmlyfLNN0o6qscVgqlLqU
         GFBH3WB7jVba+KML+z5cJcTuYthAbSkXSOvvgnNhTzuhVk8aRgJUnWgBMTChWAiQaoIz
         0gAg==
X-Gm-Message-State: AOJu0Ywwcj48arot0QfsQkxrOqa17XWJYAQeq5VQLRX31bZPAMD3TLC8
	vsNgIUS2xRhddNt+Zdd2qwh+WydjW8s7CTSouiKfMf8s4Begcy70REe3Iw==
X-Google-Smtp-Source: 
 AGHT+IFsGScbwc/ipoD/dy63GqU+CWwD8WXKZq1A58o+csmgrDAiIu68b/8VhhTznoLIqg7f32sN4g==
X-Received: by 2002:a05:6a00:1a87:b0:70d:2892:402b with SMTP id
 d2e1a72fcca58-70eaa8b1371mr933041b3a.7.1721852543907;
        Wed, 24 Jul 2024 13:22:23 -0700 (PDT)
Received: from smtpclient.apple ([47.208.219.53])
        by smtp.gmail.com with ESMTPSA id
 d2e1a72fcca58-70cff4b2f6esm8919585b3a.67.2024.07.24.13.22.22
        for <add@ietf.org>
        (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
        Wed, 24 Jul 2024 13:22:23 -0700 (PDT)
From: Dan Wing <danwing@gmail.com>
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_2F8E2A4B-AEE3-4149-85EB-6E079760D493"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.600.62\))
Message-Id: <6FCA933A-F329-4B45-9C72-32FFCAD289BE@gmail.com>
Date: Wed, 24 Jul 2024 13:22:22 -0700
To: add@ietf.org
X-Mailer: Apple Mail (2.3774.600.62)
Message-ID-Hash: 672Q6C4POIFE7MWRIPL67OZASQTSU4MI
X-Message-ID-Hash: 672Q6C4POIFE7MWRIPL67OZASQTSU4MI
X-MailFrom: danwing@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; nonmember-moderation; administrivia;
 implicit-dest; max-recipients; max-size; news-moderation; no-subject;
 digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: =?utf-8?q?=5BAdd=5D_Hosting_Encrypted_Servers_on_CPEs_/_HTTPS_for_Local_Doma?=
	=?utf-8?q?ins?=
List-Id: Applications Doing DNS <add.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/add/-aK8R2X1QAHiwq6A4-Jy80c6Bdc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Owner: <mailto:add-owner@ietf.org>
List-Post: <mailto:add@ietf.org>
List-Subscribe: <mailto:add-join@ietf.org>
List-Unsubscribe: <mailto:add-leave@ietf.org>


--Apple-Mail=_2F8E2A4B-AEE3-4149-85EB-6E079760D493
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

ADD WG,

While working to provide TLS for encrypted DNS on CPE, Tiru Reddy's =
IETF119 ADD presentation made it clear ADD had bumped into a larger =
problem: IETF and the industry has not documented how to best get =
certificates onto CPE.  A few companies (McAfee, Mozilla, Cujo) have =
deployed a system where a unique FQDN is assigned to each CPE (e.g., to =
the DNS server) and the CPE requests a vendor-operated cloud service to =
get that certificate signed by a CA and returned to the CPE and CPE uses =
that CA-signed certificate for incoming TLS connections.  Such a system =
works but the disadvantages are needing to get millions of certificates =
continually signed by the CA (short-lived certificates) and continued =
reliance on the vendor to operate the certificate-signing service.  =
Experience is that an exception is necessary to overcome the CA's normal =
rate limit.

There are two documents that discuss such a system, its drawbacks, and =
also explore some other system designs:
  - Martin Thomson's "HTTPS for Local Domains" (*, below), and
  - draft-rbw-add-encrypted-dns-forwarders (**, below).

Please read them prior to Thursday's ADD meeting, as I will only spend =
3-4 minutes presenting and the rest of the time will be microphone =
discussion.


I am hoping there are authors interested in writing a problem statement =
document (if consensus is existing practice is too difficult) or writing =
a BCP/Informational document on such a vendor-operated service (if =
consensus is continue existing practice).

-d


(*) Martin Thomson's "HTTPS for Local Domains", =
https://docs.google.com/document/d/170rFC91jqvpFrKIqG4K8Vox8AL4LeQXzfikBQX=
YPmzU/edit, https://tinyurl.com/https-for-local-domains

(**) "Hosting Encrypted Servers on CPEs" slide deck for IETF120 ADD =
meeting, https://datatracker.ietf.org/meeting/120/session/add
      "Hosting Encrypted DNS Forwarders on CPEs", =
https://datatracker.ietf.org/doc/draft-rbw-add-encrypted-dns-forwarders/


--Apple-Mail=_2F8E2A4B-AEE3-4149-85EB-6E079760D493
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;"><div>ADD =
WG,</div><div><br></div><div>While working to provide TLS for encrypted =
DNS on CPE, Tiru Reddy's IETF119 ADD presentation made it clear ADD had =
bumped into a larger problem: IETF and the industry has not documented =
how to best get certificates onto CPE. &nbsp;A few companies (McAfee, =
Mozilla, Cujo) have deployed a system where a unique FQDN is assigned to =
each CPE (e.g., to the DNS server) and the CPE requests a =
vendor-operated cloud service to get that certificate signed by a CA and =
returned to the CPE and CPE uses that CA-signed certificate for incoming =
TLS connections. &nbsp;Such a system works but the disadvantages are =
needing to get millions of certificates continually signed by the CA =
(short-lived certificates) and continued reliance on the vendor to =
operate the certificate-signing service. &nbsp;Experience is that an =
exception is necessary to overcome the CA's normal rate =
limit.</div><div><br></div><div>There are two documents that discuss =
such a system, its drawbacks, and also explore some other system =
designs:</div><div>&nbsp; - Martin Thomson's "HTTPS for Local Domains" =
(*, below), and</div><div>&nbsp; - =
draft-rbw-add-encrypted-dns-forwarders (**, =
below).</div><div><br></div><div>Please read them prior to Thursday's =
ADD meeting, as I will only spend 3-4 minutes presenting and the rest of =
the time will be microphone =
discussion.</div><div><br></div><div><br></div><div>I am hoping there =
are authors interested in writing a problem statement document (if =
consensus is existing practice is too difficult) or writing a =
BCP/Informational document on such a vendor-operated service (if =
consensus is continue existing =
practice).</div><div><br></div><div>-d</div><div><br></div><div><br></div>=
<div>(*) Martin Thomson's "HTTPS for Local Domains",&nbsp;<a =
href=3D"https://docs.google.com/document/d/170rFC91jqvpFrKIqG4K8Vox8AL4LeQ=
XzfikBQXYPmzU/edit">https://docs.google.com/document/d/170rFC91jqvpFrKIqG4=
K8Vox8AL4LeQXzfikBQXYPmzU/edit</a>,&nbsp;<a =
href=3D"https://tinyurl.com/https-for-local-domains" style=3D"font-family:=
 =
Arial;">https://tinyurl.com/https-for-local-domains</a></div><div><br></di=
v>(**) "Hosting Encrypted Servers on CPEs" slide deck for IETF120 ADD =
meeting,&nbsp;<a =
href=3D"https://datatracker.ietf.org/meeting/120/session/add">https://data=
tracker.ietf.org/meeting/120/session/add</a><div>&nbsp; &nbsp; &nbsp; =
"Hosting Encrypted DNS Forwarders on CPEs",&nbsp;<a =
href=3D"https://datatracker.ietf.org/doc/draft-rbw-add-encrypted-dns-forwa=
rders/">https://datatracker.ietf.org/doc/draft-rbw-add-encrypted-dns-forwa=
rders/</a></div><div><br></div></body></html>=

--Apple-Mail=_2F8E2A4B-AEE3-4149-85EB-6E079760D493--

