Re: [Anima] [Acme] Long-lived certificates, but frequently renewed certificates

Jacob Hoffman-Andrews <jsha@letsencrypt.org> Fri, 19 March 2021 00:25 UTC

Return-Path: <jsha@letsencrypt.org>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D403A3A102E for <anima@ietfa.amsl.com>; Thu, 18 Mar 2021 17:25:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.346
X-Spam-Level:
X-Spam-Status: No, score=-2.346 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.248, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=letsencrypt.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9UvR-jWkIW21 for <anima@ietfa.amsl.com>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
Received: from mail-qv1-xf29.google.com (mail-qv1-xf29.google.com [IPv6:2607:f8b0:4864:20::f29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 816C63A1034 for <anima@ietf.org>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
Received: by mail-qv1-xf29.google.com with SMTP id dc12so3295641qvb.4 for <anima@ietf.org>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=letsencrypt.org; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=FLXUwsl5yl2K/+rXTnev2mDJz3s5LnNnm2/kTPFUY2o=; b=DT9qb2dBByHAjamzd1gw0J2mH4460usrCsibyqWASD1jEUj7fOyqAqhJny3K5+4SBZ 3HFLYwl9OKQl4l3HQ9+CtbhUE5unuj7HIh8G4SkbK0wWkzg5rn4iHOBB14zaynUH+FCz bGddLjHM8ne4cKpp3Z/vQgS9pS0LxlMzqcDhg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=FLXUwsl5yl2K/+rXTnev2mDJz3s5LnNnm2/kTPFUY2o=; b=Oesjq4PKEi0t960k1J3AMlqrGypFKGTVYg3ICjp2cimnjPMgl7dye71wyioMwbRnge ccvvI4zQxINh4vpilmxoZi6u8Sa7LRvSCV30TpYxNLk6fYY7hj2ntQvzbkKMNPNbTJIr M305Klj/S/NQcvK9gnxvLMw/uiUEpI/8oODwPV2ih1EE/MUpG3l95/hvUZ5D9HpnNzIU BS8UUSgL9HE9D0T+Rutigexl45GZxsW1xRGyO6Ic9O18PWtmNfTufUpGsqo6JVETk0re aWSZgmzJmH8wn4/o671/7qpnIfmlBvbh8WyV6sle9yoFA1G0ApbEQm+V4g2HE9DedlEW KR4w==
X-Gm-Message-State: AOAM530djFEtcMAmJXw+bqUGJcIsW0c+wsvQCoLej9DdR5ARC4Nyp8WA BwJfF0DzcvNTBo9ycWcooeeosp0aoCcS6SXuKuCNPQ==
X-Google-Smtp-Source: ABdhPJyVjdeBKOU/VlpA4cqTugNwoPrHuB/vcB27fbJdEp6w96YJPfFuympenPUbnYdOjtZ4tCZMG1Qt5WKvYWO6KAI=
X-Received: by 2002:a05:6214:c8a:: with SMTP id r10mr7169886qvr.13.1616113544755; Thu, 18 Mar 2021 17:25:44 -0700 (PDT)
MIME-Version: 1.0
References: <20210318130241.A6B44389A8@tuna.sandelman.ca> <22886.1616091336@localhost>
In-Reply-To: <22886.1616091336@localhost>
From: Jacob Hoffman-Andrews <jsha@letsencrypt.org>
Date: Thu, 18 Mar 2021 17:25:18 -0700
Message-ID: <CAN3x4QmmAiA+L9fqj8_or8z0o1Uu9VHb8RFua6x_BAF41Z2A2Q@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Cc: spasm@ietf.org, acme@ietf.org, anima@ietf.org
Content-Type: multipart/alternative; boundary="000000000000c0958105bdd8c1dd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/KbORZu2BVAnigY35igziLqrhK6Q>
Subject: Re: [Anima] [Acme] Long-lived certificates, but frequently renewed certificates
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Mar 2021 00:25:48 -0000

Roland Shoemaker sent a proposal a while back for ACME Renewal Info (ARI)
with the goal of solving both "impending revocation" and "expressing
suggested renewal times."
https://mailarchive.ietf.org/arch/msg/acme/b-RddSX8TdGYvO3f9c7Lzg6I2I4/. We
at Let's Encrypt hope to develop this idea further and implement it soon.