Re: [Anima] Russ: Re: rfc822Name use in Autonomic Control Plane document

Toerless Eckert <tte@cs.fau.de> Sun, 28 June 2020 01:11 UTC

Return-Path: <eckert@i4.informatik.uni-erlangen.de>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9213E3A08D8 for <anima@ietfa.amsl.com>; Sat, 27 Jun 2020 18:11:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.87
X-Spam-Level:
X-Spam-Status: No, score=-0.87 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, SPF_HELO_NONE=0.001, SPF_NEUTRAL=0.779, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ngr3uG5U8KCE for <anima@ietfa.amsl.com>; Sat, 27 Jun 2020 18:11:19 -0700 (PDT)
Received: from faui40.informatik.uni-erlangen.de (faui40.informatik.uni-erlangen.de [IPv6:2001:638:a000:4134::ffff:40]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3364E3A08D7 for <anima@ietf.org>; Sat, 27 Jun 2020 18:11:19 -0700 (PDT)
Received: from faui48f.informatik.uni-erlangen.de (faui48f.informatik.uni-erlangen.de [131.188.34.52]) by faui40.informatik.uni-erlangen.de (Postfix) with ESMTP id 8B8EA548068; Sun, 28 Jun 2020 03:11:14 +0200 (CEST)
Received: by faui48f.informatik.uni-erlangen.de (Postfix, from userid 10463) id 7E70F440043; Sun, 28 Jun 2020 03:11:14 +0200 (CEST)
Date: Sun, 28 Jun 2020 03:11:14 +0200
From: Toerless Eckert <tte@cs.fau.de>
To: Eric Rescorla <ekr@rtfm.com>
Cc: Russ Housley <housley@vigilsec.com>, Michael Richardson <mcr+ietf@sandelman.ca>, Ben Kaduk <kaduk@mit.edu>, Anima WG <anima@ietf.org>
Message-ID: <20200628011114.GH41058@faui48f.informatik.uni-erlangen.de>
References: <9406.1592756905@localhost> <3A92516D-B980-4231-9059-EF7234BA8610@vigilsec.com> <20200627054056.GA35664@faui48f.informatik.uni-erlangen.de> <FF181E1F-2B93-47BB-AB45-7F66D880108B@vigilsec.com> <20200627224640.GA41058@faui48f.informatik.uni-erlangen.de> <CABcZeBN_tQgH8ZZmVg82h8-cthm0uQ6b846N71G9NYFSxdUMRQ@mail.gmail.com> <20200628000922.GE41058@faui48f.informatik.uni-erlangen.de> <CABcZeBNJ_yA3K95a-21aVDq+_Tp270TsCvVx4an_7ackr=n5eg@mail.gmail.com> <20200628005433.GG41058@faui48f.informatik.uni-erlangen.de> <CABcZeBOTNNXj2wNNVgh2qHi=0dEPYMQ2PwcZVDQhRyXeGDVEvA@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CABcZeBOTNNXj2wNNVgh2qHi=0dEPYMQ2PwcZVDQhRyXeGDVEvA@mail.gmail.com>
User-Agent: Mutt/1.10.1 (2018-07-13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/EcCWV6Fuz5ruJ2fCibM6nxyaJDw>
Subject: Re: [Anima] Russ: Re: rfc822Name use in Autonomic Control Plane document
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 Jun 2020 01:11:22 -0000

On Sat, Jun 27, 2020 at 05:57:45PM -0700, Eric Rescorla wrote:
> On Sat, Jun 27, 2020 at 5:54 PM Toerless Eckert <tte@cs.fau.de> wrote:
> 
> > On Sat, Jun 27, 2020 at 05:18:46PM -0700, Eric Rescorla wrote:
> > > Well, I understand you think you explained it, but unfortunately I don't
> > > find that argument persuasive, nor, I suspect, do others.
> > >
> > > The ACP operator can perfectly well set up mailxobxes if he desires to.
> > > >
> > >
> > > And if ACP required the operators to do so, I think that would also
> > resolve
> > > this issue from an IETF perspective (although you still would likely not
> > be
> > > able to get publicly verifiable certificates for this purpose, at least
> > > from any CA in the Mozilla root program, for the reasons I indicated
> > > previously).
> >
> > FInd the email in the thread where i eplained to Russ how a public CA
> > is useless if not dangerous for what the ACP does right now, but it
> > could be quite useful in future extensons, such as for interdomain
> > auhentication via ACMPE S/MIME.
> >
> > Please understand the use case first before thinking that apply
> > Internet public PKI requirements is always the right think to do.
> >
> 
> I didn't say any such thing. I merely observed that it would not be
> compatible with the requirements those CAs operate under. That's why I put it in
> parentheses.

Thanks.

Cheers
    Toerless

> -Ekr

-- 
---
tte@cs.fau.de