[Bimi] Re: No cryptographic connection between VMC and DKIM key
Wei Chuang <weihaw@google.com> Tue, 14 May 2024 16:47 UTC
Return-Path: <weihaw@google.com>
X-Original-To: bimi@ietfa.amsl.com
Delivered-To: bimi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A2F9C1840E2 for <bimi@ietfa.amsl.com>; Tue, 14 May 2024 09:47:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.596
X-Spam-Level:
X-Spam-Status: No, score=-17.596 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LE-P72Gxb4I1 for <bimi@ietfa.amsl.com>; Tue, 14 May 2024 09:47:45 -0700 (PDT)
Received: from mail-il1-x12e.google.com (mail-il1-x12e.google.com [IPv6:2607:f8b0:4864:20::12e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8E546C14F61C for <bimi@ietf.org>; Tue, 14 May 2024 09:47:45 -0700 (PDT)
Received: by mail-il1-x12e.google.com with SMTP id e9e14a558f8ab-36c66cc8bd2so25ab.0 for <bimi@ietf.org>; Tue, 14 May 2024 09:47:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1715705264; x=1716310064; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=t/hCoAsxhs7RwlIqjff101tzieSUuIn/N6CmcHxHokc=; b=vWhFYyaFCiYQndxFKflbqfwzAWeDC5TQLrvHsp2KU2Dpqt5eK00kfPpvqz0hiIo+Ib +KXYq5gac1S11GxPVAOsmcJMPhLyE/M6/SgyZBrMbzFR47V79Xx4FPhVZappc3T0zsuH WuLErVLKRqOlIWudFNQV/NMht7SVQh7gCKDnzAPZsvCVR/3pJ3AkVNcuKTcfL0URdau1 kdeUjxjefdt5jerZwnBWXm4Fx/FrfJDkmyGUk5aP0ExlPGUBNqQarQ5ZVVsjYJUz7YaT 97gUHTP8l3nJVcR1tgjzWxrP5DwJbtPxq9qDOW7QWx41d4TapvBI1YKwBV9FP81GtWmc ql7Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715705264; x=1716310064; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=t/hCoAsxhs7RwlIqjff101tzieSUuIn/N6CmcHxHokc=; b=bX3lKQ4+8r/eYAkwKinvJIiOMR4Lc5ihFkiLGAj7jEWI7qJE7LQusCk/vj8k64QmYy tboY7g/AcbQ0Ul2K0wxgUaEISSExHBCSoDSurHyqkPkawwAhVlyQLpj9czNr0gPpi3re zPxhaNFev19Vaj8HnWMhW7i18gLUf1ArOz/E0yYUA8F+LBL3Nz0dR4qqmUHKsDtAbKtl SHL5AVrU+6Qi2X6bO5kYvNEUkeZ7JTn2vigt/SMgZ+k9gh7tJqE+chk6bJay6RMtL6Ea bXAYKND47mCQcEFSgoH8qtf8oa6QzbesAzbzQFzIdmsfVb/CfqkGGu7aiCGdw46WBDXK bUkQ==
X-Forwarded-Encrypted: i=1; AJvYcCXQ7fA8UMVTj85jIWem2XFPhLTix7t2MoSAYDK0Vh6Sf2n6Cil8dytR+a+DS8g0WT+5JosPI2u9r7xUuAcg
X-Gm-Message-State: AOJu0YyXwDe0IAJWifLXciPLHQerF6+WyN4nlCoXK1SX55X4TDYMpIDx yq/lSZX3skIiP7trnMRWg9heMdXxAVUF5aNCp+Ij9KExQIqGkN+pfunhYZmSdSgRDB6AQAVos6n WRgAtbhJJ+udefG6oIirbVmoYP9I+Ns/sNHNd
X-Google-Smtp-Source: AGHT+IHweglaM6rLUaAT1azkDK5l15MkCJIoIe2Au62q+cz/suA2oR4ivlehtFDIw/7O8TK/K3gOdiuO/j6uQTmxxlU=
X-Received: by 2002:a92:c9c5:0:b0:36c:1af8:ef62 with SMTP id e9e14a558f8ab-36dad656e33mr97775ab.2.1715705263765; Tue, 14 May 2024 09:47:43 -0700 (PDT)
MIME-Version: 1.0
References: <20240512102123.5279f4ef@computer> <CAAFsWK3ZB96c63aZcwvaaXK7qEu+asQk+e0TAtebB1ogNeJfWQ@mail.gmail.com> <74e81040-9559-4a9f-8cea-09e17a172ee3@dcrocker.net>
In-Reply-To: <74e81040-9559-4a9f-8cea-09e17a172ee3@dcrocker.net>
From: Wei Chuang <weihaw@google.com>
Date: Tue, 14 May 2024 09:47:27 -0700
Message-ID: <CAAFsWK36jx=hA3UOtYW0ubiN+R9jwsahtJ5C94-LqMMywvBXUQ@mail.gmail.com>
To: dcrocker@bbiw.net
Content-Type: multipart/alternative; boundary="000000000000c9b10906186cc2ad"
Message-ID-Hash: R5NTYFVDWEEZLL3E4XKVPFHUKDOZQLRQ
X-Message-ID-Hash: R5NTYFVDWEEZLL3E4XKVPFHUKDOZQLRQ
X-MailFrom: weihaw@google.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Hanno Böck <hanno@hboeck.de>, bimi@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Bimi] Re: No cryptographic connection between VMC and DKIM key
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/Bfc62IPZExCGliA7XYgbJQKGucs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Owner: <mailto:bimi-owner@ietf.org>
List-Post: <mailto:bimi@ietf.org>
List-Subscribe: <mailto:bimi-join@ietf.org>
List-Unsubscribe: <mailto:bimi-leave@ietf.org>
I think the researcher was calling out the weak keys found in the survey that was done of deployed DKIM keys. In some cases it was due to a Openssl vulnerability from 2008, and others due to short key length < 2048. The researcher suggests that X.509/PKIX keys have a mandate to meet a certain security bar and the certificates have a TTL that forces key rotation. By tying the DKIM public key to the BIMI VMC, the DKIM public key must meet the same requirements as the VMC and those keys are governed by the VMC Requirements in order to be properly issued. -Wei On Tue, May 14, 2024 at 9:17 AM Dave Crocker <dhc@dcrocker.net> wrote: > On 5/12/2024 9:54 AM, Wei Chuang wrote: > > I would agree the lack of connection between the VMC and the DKIM > > public keys is a missed opportunity to strengthen the protocol. > > I'm not understanding how it stregthens the protocol. What threats does > it counter that are not already covered? And how? And how likely and > serious are those threats? > > Also, what will the effort be, to support this on an ongoing basis, for > all users of the protocol? > > > d/ > > -- > Dave Crocker > Brandenburg InternetWorking > bbiw.net > mast:@dcrocker@mastodon.social > >
- [Bimi] No cryptographic connection between VMC an… Hanno Böck
- [Bimi] Re: No cryptographic connection between VM… Richard Clayton
- [Bimi] Re: No cryptographic connection between VM… Dave Crocker
- [Bimi] Re: No cryptographic connection between VM… Dave Crocker
- [Bimi] Re: No cryptographic connection between VM… Wei Chuang
- [Bimi] Re: No cryptographic connection between VM… Wei Chuang