[Anima] Re: [Add] Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
Dan Wing <danwing@gmail.com> Mon, 09 September 2024 23:25 UTC
Return-Path: <danwing@gmail.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 308FDC14CF1E; Mon, 9 Sep 2024 16:25:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4leunw0drFho; Mon, 9 Sep 2024 16:25:42 -0700 (PDT)
Received: from mail-pf1-x42f.google.com (mail-pf1-x42f.google.com [IPv6:2607:f8b0:4864:20::42f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BCA2EC14F70B; Mon, 9 Sep 2024 16:25:42 -0700 (PDT)
Received: by mail-pf1-x42f.google.com with SMTP id d2e1a72fcca58-718e56d7469so1525288b3a.0; Mon, 09 Sep 2024 16:25:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1725924342; x=1726529142; darn=ietf.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=fbBbFMLP0bopMZ4XMLjx6+6NFVRcU88UCMSDBPgyUpE=; b=TGAm7e6aSWsNQ1mReUbDQarQPuIDOobf0C/+DK21dgJJvfd4IJ3OoCPhFjWbv33A73 hq5KGYtGHEWEDBo3FFxILCBpkb8Y54gUuwjWMmWTE7RR5zpJ5GcOb1HZQPhPcsm0ZdmZ bIqWMrM3CdUPhSYDTghMDCg0vlgn6/7pg+SNXZh5t+GlXUXJKEb6xwfUQQr8E/eQ36+A JPb6mzr/3+v008zpnWMzwmqlHkPFUjqISP6ukuWlOB4YrDrVNebBeYZOAyTGK/hYu5q7 roo3P6vYCoNLsatXyEEsICbReO3gsPO4IKg8je/7gjFstJ83q81KK1aOx4+gdZzO31YR eI7A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1725924342; x=1726529142; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=fbBbFMLP0bopMZ4XMLjx6+6NFVRcU88UCMSDBPgyUpE=; b=HSV3Z8lk05YYzg61EZZzu1YkdH4ktgPQGKfqLL3HiqmLrMZhcBuikK0zx4ySD+VVu6 jd6/8SW83DfcI/gNT9h+nSR+v8xcI/mGdGD0tXF4lijffxvx9EdECr+7ZrJFQFD1FdHq M17d/7Boxnwr1QxqQpfAE2je7NKG3SaVTc5Wfhfisp8sF9yRCbcjomSi0845PcxEti/o lugJPoKXKqh+bfSX/rBy61M+ERJmpkTZ2cOpnpm8CXl24Tfsn7luWg9XxVCrjuu14/q5 FQRnvAxxw5pKMdlKC/D0HIE990Ziclf3lh4+aRxL2DYNX2RutUb67s6VndbCi5zxBD4N A4cA==
X-Forwarded-Encrypted: i=1; AJvYcCVptN9rru4ENcqTvzHzicgyky910CTXdtQZhv9lavr0srQoN+nLtIGyGWMNohcZmTafnLCWQ6c=@ietf.org, AJvYcCWuRhPHIKhG051L6CpoeKJbm3pEHS8uMwQHjeRnywMEKbGZUmhjEVUmTTMOOCUyB3gY+yo=@ietf.org, AJvYcCXw4YuGq9Ei9CGktJI5QqycjTow3kMmLi148Y8so/JFIs1Y7V/eYZJRDZZXPd2PJQ5XwnGGTXSv@ietf.org
X-Gm-Message-State: AOJu0Yzn9nMaHa4o2CDSOcyL0IEUIHhuKbH68eTvKfxu7RO/oSPL6tov BwEIEApQWA88r8zor1nmgfwSJy0aWZEjEFefMFGNtWh2PTfpKJPP
X-Google-Smtp-Source: AGHT+IGDKTGhlmko9DNmmdPMK8Kw2R1WE1i+9DGUdPPF6ZLAccXCTGf/+R9+vXiDXrkrUrY2r+Pxdw==
X-Received: by 2002:a05:6a00:1ac9:b0:718:ea3c:35c3 with SMTP id d2e1a72fcca58-718ea3c369amr7329871b3a.15.1725924341906; Mon, 09 Sep 2024 16:25:41 -0700 (PDT)
Received: from smtpclient.apple ([47.208.124.206]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-71908fc8d53sm255491b3a.38.2024.09.09.16.25.40 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 09 Sep 2024 16:25:41 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3776.700.51\))
From: Dan Wing <danwing@gmail.com>
In-Reply-To: <21866.1725908702@obiwan.sandelman.ca>
Date: Mon, 09 Sep 2024 16:25:40 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <3B84302E-11BC-4695-9C31-9179AD32FDB3@gmail.com>
References: <6FCA933A-F329-4B45-9C72-32FFCAD289BE@gmail.com> <CACJ6M16MgxzE+8Yiebd9hbYC_tY2tt0Sroc4_izOnP3kO3e5fQ@mail.gmail.com> <MW4PR15MB437956E8735320FFE83037C7B3952@MW4PR15MB4379.namprd15.prod.outlook.com> <ZtpGfh15m58gId0Z@faui48e.informatik.uni-erlangen.de> <21866.1725908702@obiwan.sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.3776.700.51)
Message-ID-Hash: UFKOTYDOCVSAPL63VML5GWFG2RGF4TF4
X-Message-ID-Hash: UFKOTYDOCVSAPL63VML5GWFG2RGF4TF4
X-MailFrom: danwing@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-anima.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Toerless Eckert <tte@cs.fau.de>, "add@ietf.org" <add@ietf.org>, anima@ietf.org, iotops@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Anima] Re: [Add] Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/1m7D_C35hQUNG2PRz6P5ofuxqq0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Owner: <mailto:anima-owner@ietf.org>
List-Post: <mailto:anima@ietf.org>
List-Subscribe: <mailto:anima-join@ietf.org>
List-Unsubscribe: <mailto:anima-leave@ietf.org>
On Sep 9, 2024, at 12:05 PM, Michael Richardson <mcr+ietf@sandelman.ca> wrote: > > > Toerless Eckert <tte@cs.fau.de> wrote: >> If i want to go through all the trouble of A), assigning muggle friendly names first, >> then i really wonder if we're promoting the best solution by first looking into >> .local solutions instead of trying to figure out what's missing so that i can run >> my own ACME certification on e.g.: my home (or private industry/enterprise) network's >> router for my own global domain. And how to get this all auto-configured so that >> muggles can operate it. I for once am not aware of any easily deployable self-hosted >> ACME server solution, and if whatever we come up with for .local would not be a heck >> of a lot easier than ACME, then we're not going to get that deployed either in the >> networks where we would like it. > > ACME is mostly about establishing authorization of the device across the > Internet using DNS. (Either DNS-01, or indirectly DNS for HTTP-01 challenge). > > I'm not sure what it brings in a home network using .local. > Doing EST with an unauthenticated TLS connection, but using IPv6-LL addresses > would seem to be as strong as an HTTP-01 challenge would be. > >> In other words: I'd love to see good solutions for B), and i'd challenge the priority >> of A) (for .local) over solutions that do make global domain names more >> easy to use in non-internet >> use-cases. After all, it could be piece of cake to add my own networks root-CA to >> my browsers web-pki trust-anchor list if we wanted that to be the solution. > > It's a piece of cake for you, and your five devices. Harder when you have > five members of the household with five devices each, and then guests. And > then, device to device communication. Adopting the technique from Matter, we might also consider suggesting vendors allow QR codes (or some similar fanciful way) to establish a shared secret or public key for more secure bootstrapping than TOFU. For guests and even family members, this could be similar to the QR code containing the guest network's SSID and password that is taped onto the refrigerator for parties; this new QR code could also be used to bootstrap that network's Certification Authority for that network's client devices. -d > Would you like to be able to shush your multi-room surround-sound music > so that you can hear: the door bell, the coffee is ready, or the oven has > preheated, waiting for the next tray of ordeuves? > > -- > Michael Richardson <mcr+IETF@sandelman.ca> . o O ( IPv6 IøT consulting ) > Sandelman Software Works Inc, Ottawa and Worldwide > > > > > -- > Add mailing list -- add@ietf.org > To unsubscribe send an email to add-leave@ietf.org
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Erik Nygren
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Dan Wing
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Michael Sweet
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Dan Wing
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Brian E Carpenter
- [Anima] Re: [Iotops] [Add] Hosting Encrypted Serv… Michael Sweet
- [Anima] Re: [Iotops] Re: [Add] Hosting Encrypted … Michael Sweet