Re: [certid] What DNS-ID if also using a DNS-SRV?
Peter Saint-Andre <stpeter@stpeter.im> Tue, 29 June 2010 21:49 UTC
Return-Path: <stpeter@stpeter.im>
X-Original-To: certid@core3.amsl.com
Delivered-To: certid@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
with ESMTP id 922B23A6C21 for <certid@core3.amsl.com>;
Tue, 29 Jun 2010 14:49:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.42
X-Spam-Level:
X-Spam-Status: No, score=-2.42 tagged_above=-999 required=5 tests=[AWL=0.179,
BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OkZRriMSMU1g for
<certid@core3.amsl.com>; Tue, 29 Jun 2010 14:49:30 -0700 (PDT)
Received: from stpeter.im (stpeter.im [207.210.219.233]) by core3.amsl.com
(Postfix) with ESMTP id 3801028C0D8 for <certid@ietf.org>;
Tue, 29 Jun 2010 14:49:30 -0700 (PDT)
Received: from dhcp-64-101-72-121.cisco.com (dhcp-64-101-72-121.cisco.com
[64.101.72.121]) (Authenticated sender: stpeter) by stpeter.im (Postfix) with
ESMTPSA id 942EF40E4D for <certid@ietf.org>;
Tue, 29 Jun 2010 15:49:40 -0600 (MDT)
Message-ID: <4C2A6A72.5000109@stpeter.im>
Date: Tue, 29 Jun 2010 15:49:38 -0600
From: Peter Saint-Andre <stpeter@stpeter.im>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US;
rv:1.9.1.9) Gecko/20100317 Thunderbird/3.0.4
MIME-Version: 1.0
To: certid@ietf.org
References: <p062408bbc8388055fb6d@[10.20.30.158]>
<4C1CABA1.2050205@isode.com> <p0624082bc8427e79bd60@[10.20.30.158]>
In-Reply-To: <p0624082bc8427e79bd60@[10.20.30.158]>
X-Enigmail-Version: 1.0.1
OpenPGP: url=http://www.saint-andre.com/me/stpeter.asc
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
micalg=sha1; boundary="------------ms010407070703070605090109"
Subject: Re: [certid] What DNS-ID if also using a DNS-SRV?
X-BeenThere: certid@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Representation and verification of identity in certificates
<certid.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/certid>
List-Post: <mailto:certid@ietf.org>
List-Help: <mailto:certid-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jun 2010 21:49:31 -0000
On 6/19/10 8:04 AM, Paul Hoffman wrote: > At 12:36 PM +0100 6/19/10, Alexey Melnikov wrote: >> Hi Paul, >> >> Paul Hoffman wrote: >> >>> 1. The certificate MUST include a "DNS-ID" (i.e., a >>> subjectAltName identifier of type dNSName). >>> >>> 2. If the service using the certificate deploys a technology in >>> which a server is discovered by means of DNS SRV records >>> [DNS-SRV] (e.g., this is true of [XMPP]), then the certificate >>> SHOULD include an "SRV-ID" (i.e., an instance of the SRVName >>> form of otherName from the GeneralName structure in the >>> subjectAltName as specified in [SRVNAME]). >>> >>> If 2 is true, what is the value of the required DNS-ID? >>> >> One or more hostname for machines that would provide the specified >> service. I.e. most likely some/all hostnames from the output of DNS >> SRV lookup, but I can think of some examples where other hostnames >> can be used in addition to or instead of these. E.g. a machine on >> internal network, hostname of a NAT box, etc. > > So a cert says "the hostname of this server is www.example.com, and > you can look up the hostname for the server using SRV"? What does > that mean in a security context? If I get back one name of > yyy.example.com, does that mean that the host has both names, or that > there was a lookup error? My understanding of the SRVName extension is that it is primarily intended to restrict the use of a certificate to a particular application type (e.g., IMAP or XMPP). This is what Shumon meant when he said: If someone intends to deploy a certificate with an application specific name form such as SRV-ID or URI-ID, then they typically would not want to have a dNSName in the certificate, to make sure that the cert can't be (mis)used for unrelated application services at that domain name. However, DNS SRV records have the property of enabling you to redirect the source domain (e.g., example.com) to a target domain (e.g., apps.example.net) that is outside of the trust boundary of the source domain. Thus draft-daboo-srv-email says: A malicious attacker with access to the DNS server data, or able to get spoofed answers cached in a recursive resolver, can potentially cause MUAs to connect to any IMAP, POP3 or submission server chosen by the attacker. In the absence of a secure DNS option, MUAs SHOULD check that the target FQDN returned in the SRV record matches the original service domain that was queried. If the target FQDN is not in the queried domain, MUAs SHOULD verify with the user that the SRV target FQDN is suitable for use before executing any connections to the host. During recent discussions within the XMPP WG, we decided that we didn't need text along those lines because a malicious attacker with access to the DNS server data could simply return an evil IP address in a DNS result, so why bother the user with scary warnings about a DNS SRV mismatch? It's unfortunate that RFC 4985 glosses over the difference between (1) the use of SRVName extensions to restrict deployment to a particular application type and (2) the use of DNS SRV records to redirect a source domain to a target domain that might be outside the trust boundary of the source domain. It might be appropriate for draft-saintandre-tls-server-id-check to have some text about this, and I'll try to write that soon. Peter -- Peter Saint-Andre https://stpeter.im/
- [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? Alexey Melnikov
- Re: [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Alexey Melnikov
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Martin Rex
- Re: [certid] What DNS-ID if also using a DNS-SRV? Love Hörnquist Åstrand
- Re: [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Alexey Melnikov
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV? Martin Rex
- Re: [certid] What DNS-ID if also using a DNS-SRV? Scott Lawrence
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV? SM
- Re: [certid] What DNS-ID if also using a DNS-SRV? Peter Saint-Andre