Re: [Dance] CRLs/OCSP and DANE at RIPE84

Wes Hardaker <wjhns1@hardakers.net> Wed, 25 May 2022 21:23 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dance@ietfa.amsl.com
Delivered-To: dance@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3D17DC07B7D4 for <dance@ietfa.amsl.com>; Wed, 25 May 2022 14:23:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level:
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IoCLfUqK5XgV for <dance@ietfa.amsl.com>; Wed, 25 May 2022 14:23:19 -0700 (PDT)
Received: from mail.hardakers.net (mail.hardakers.net [168.150.192.181]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 284F8C07B7BC for <dance@ietf.org>; Wed, 25 May 2022 14:23:19 -0700 (PDT)
Received: from localhost (unknown [10.0.0.9]) by mail.hardakers.net (Postfix) with ESMTPA id 5DDCD21020; Wed, 25 May 2022 14:23:18 -0700 (PDT)
From: Wes Hardaker <wjhns1@hardakers.net>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Cc: Jim Fenton <fenton@bluepopcorn.net>, Shumon Huque <shuque@gmail.com>, dance <dance@ietf.org>
References: <887547.1653131902@dooku> <CAHPuVdXED50HMmBzkPCRa6pTqUnD8FA_upyWSMZy9OBt=q1GfA@mail.gmail.com> <19724.1653397933@localhost> <CAHPuVdWNe-SFZmRDB5nORs+3fFWgGLVyZKxFSOGx95j4wBpjUA@mail.gmail.com> <924BEB7A-1155-4C79-9F62-BA84BB09BEB6@bluepopcorn.net> <23517.1653511237@localhost>
Date: Wed, 25 May 2022 14:23:18 -0700
In-Reply-To: <23517.1653511237@localhost> (Michael Richardson's message of "Wed, 25 May 2022 16:40:37 -0400")
Message-ID: <ybl4k1dwbll.fsf@wd.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/dance/ECxPvMEAgi9f7xePj6lSyCaxJxQ>
Subject: Re: [Dance] CRLs/OCSP and DANE at RIPE84
X-BeenThere: dance@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: DANE Authentication for Network Clients Everywhere <dance.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dance>, <mailto:dance-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dance/>
List-Post: <mailto:dance@ietf.org>
List-Help: <mailto:dance-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dance>, <mailto:dance-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 May 2022 21:23:21 -0000

Michael Richardson <mcr+ietf@sandelman.ca> writes:

> We probably need to talk about this for client authentication.

Let me turn that question around (or at least sideways): is the guidance
for a TTL and/or signature life *different* from a DANE record for a
server vs a client?
-- 
Wes Hardaker
USC/ISI