[Anima] Re: [Add] Re: Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
Michael Richardson <mcr+ietf@sandelman.ca> Mon, 09 September 2024 19:05 UTC
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF598C1CAE99; Mon, 9 Sep 2024 12:05:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FjrxfB11O3Wg; Mon, 9 Sep 2024 12:05:07 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A7E4C1CAE96; Mon, 9 Sep 2024 12:05:06 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id 229B438EA4; Mon, 9 Sep 2024 15:05:04 -0400 (EDT)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavis, port 10024) with LMTP id CFyq2gD6yfT8; Mon, 9 Sep 2024 15:05:02 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sandelman.ca; s=mail; t=1725908702; bh=02yF14VOls78lZUDj2JQ0ip/7lj/tXmLo3nMau6MOVA=; h=From:To:Subject:In-Reply-To:References:Date:From; b=NMYBBsrdVOjN2NlxH9N7FCdE8qmawP/xwZB6Tc88COnRnNx7nbnW+e2qQTEJrASh4 Ec+Gf5PEiG0pWwbMOudskAFfBdt4dndvJY49hLU3qTAA8O2Qteb2h+ZDiZ8njQlWuj 56Nf2OuhaiGDqM8kbC3txpqNZXbkfMpSbOHiIDq6CBDs4X+wKbrZ0JeHXIqsMQj82H wJau3L19qPfkaSptiyHjbeyuWqdy6NpN20PMOI5nY34nvJ3Xbcv9pufzHLfoq3qaD6 cr+XQR1yDt+s0I5r0MbeOMDFlGdFWvclywkDiHDGwxLEPkjHs+Kh6IWyQQeO3DVyLa zVUzY/qd8bSDQ==
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 841AD38EA1; Mon, 9 Sep 2024 15:05:02 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 7F89F96D; Mon, 9 Sep 2024 15:05:02 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Toerless Eckert <tte@cs.fau.de>, "add@ietf.org" <add@ietf.org>, anima@ietf.org, iotops@ietf.org
In-Reply-To: <ZtpGfh15m58gId0Z@faui48e.informatik.uni-erlangen.de>
References: <6FCA933A-F329-4B45-9C72-32FFCAD289BE@gmail.com> <CACJ6M16MgxzE+8Yiebd9hbYC_tY2tt0Sroc4_izOnP3kO3e5fQ@mail.gmail.com> <MW4PR15MB437956E8735320FFE83037C7B3952@MW4PR15MB4379.namprd15.prod.outlook.com> <ZtpGfh15m58gId0Z@faui48e.informatik.uni-erlangen.de>
X-Mailer: MH-E 8.6+git; nmh 1.8+dev; GNU Emacs 28.2
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0;<'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Mon, 09 Sep 2024 15:05:02 -0400
Message-ID: <21866.1725908702@obiwan.sandelman.ca>
Message-ID-Hash: 5H32MLEIIWA3BWALP2ZNKTBPZFOWCI4X
X-Message-ID-Hash: 5H32MLEIIWA3BWALP2ZNKTBPZFOWCI4X
X-MailFrom: mcr+ietf@sandelman.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-anima.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Anima] Re: [Add] Re: Hosting Encrypted Servers on CPEs / HTTPS for Local Domains
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/z_ZDP-um6yOFQ5odcWvvoE83cG0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Owner: <mailto:anima-owner@ietf.org>
List-Post: <mailto:anima@ietf.org>
List-Subscribe: <mailto:anima-join@ietf.org>
List-Unsubscribe: <mailto:anima-leave@ietf.org>
Toerless Eckert <tte@cs.fau.de> wrote:
> If i want to go through all the trouble of A), assigning muggle friendly names first,
> then i really wonder if we're promoting the best solution by first looking into
> .local solutions instead of trying to figure out what's missing so that i can run
> my own ACME certification on e.g.: my home (or private industry/enterprise) network's
> router for my own global domain. And how to get this all auto-configured so that
> muggles can operate it. I for once am not aware of any easily deployable self-hosted
> ACME server solution, and if whatever we come up with for .local would not be a heck
> of a lot easier than ACME, then we're not going to get that deployed either in the
> networks where we would like it.
ACME is mostly about establishing authorization of the device across the
Internet using DNS. (Either DNS-01, or indirectly DNS for HTTP-01 challenge).
I'm not sure what it brings in a home network using .local.
Doing EST with an unauthenticated TLS connection, but using IPv6-LL addresses
would seem to be as strong as an HTTP-01 challenge would be.
> In other words: I'd love to see good solutions for B), and i'd challenge the priority
> of A) (for .local) over solutions that do make global domain names more
> easy to use in non-internet
> use-cases. After all, it could be piece of cake to add my own networks root-CA to
> my browsers web-pki trust-anchor list if we wanted that to be the solution.
It's a piece of cake for you, and your five devices. Harder when you have
five members of the household with five devices each, and then guests. And
then, device to device communication.
Would you like to be able to shush your multi-room surround-sound music
so that you can hear: the door bell, the coffee is ready, or the oven has
preheated, waiting for the next tray of ordeuves?
--
Michael Richardson <mcr+IETF@sandelman.ca> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Erik Nygren
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Dan Wing
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Brian E Carpenter
- [Anima] Re: [Iotops] Re: [Add] Hosting Encrypted … Michael Sweet
- [Anima] Re: [Iotops] [Add] Hosting Encrypted Serv… Michael Sweet
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Dan Wing
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Hosting Encrypted Servers on CP… Michael Sweet
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Toerless Eckert
- [Anima] Re: [Add] Re: Hosting Encrypted Servers o… Michael Richardson