[Dance] Last Call: <draft-ietf-dance-client-auth-14.txt> (TLS Client Authentication via DANE TLSA records) to Proposed Standard

The IESG <iesg-secretary@ietf.org> Tue, 15 September 2026 17:59 UTC

Received: by mx.ietf.org (Postfix) id 60C4F30; Tue, 15 Sep 2026 17:59:37 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ietf.org; s=mail; t=1789495177; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc: mime-version:mime-version:mime-version: content-type:content-type:content-type: content-transfer-encoding:content-transfer-encoding:content-transfer-encoding; bh=5yCD5f+CdGXrzk7ohZJVqIANMd1I6JwJ6Zhe6Zwv6oE=; b=gUk+hkqe6yQin37CsfyGkLtW6c2YJhltgNvHJX16VmHS03uhBiZ70AflwOKG/yAfVp5BUU h1WiE2dL+6xvPor1HOBCnpR/oTAaZtXK3oJcgmQwDbTVz4b6JMhr3Pr35dN5gFM+PCSj+G M88MkrGqhxbX6GL3Mobl9GMazIXJzDw=
Authentication-Results: ORIGINATING; auth=pass smtp.auth=mail2@ietf.org smtp.mailfrom=iesg-secretary@ietf.org
Received: from [10.244.8.113] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 1C91013964CEF; Tue, 15 Sep 2026 10:59:37 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 12.75.0
Auto-Submitted: auto-generated
Precedence: bulk
Sender: iesg-secretary@ietf.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <178949517701.908154.12523737857348950173@dt-datatracker-597c8c8754-4t7c8>
Date: Tue, 15 Sep 2026 10:59:37 -0700
Message-ID-Hash: DM5DW5YOJT4Q6LV73YUM6MRFMWYG7FN5
X-Message-ID-Hash: DM5DW5YOJT4Q6LV73YUM6MRFMWYG7FN5
X-MailFrom: iesg-secretary@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dance-chairs@ietf.org, dance@ietf.org, debcooley1@gmail.com, draft-ietf-dance-client-auth@ietf.org, mcr+ietf@sandelman.ca
X-Mailman-Version: 3.3.10
Reply-To: last-call@ietf.org
Subject: [Dance] Last Call: <draft-ietf-dance-client-auth-14.txt> (TLS Client Authentication via DANE TLSA records) to Proposed Standard
List-Id: DANE Authentication for Network Clients Everywhere <dance.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dance/K1_It6bPkE6yuZu4jdh-Yea4-V8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dance>
List-Help: <mailto:dance-request@ietf.org?subject=help>
List-Owner: <mailto:dance-owner@ietf.org>
List-Post: <mailto:dance@ietf.org>
List-Subscribe: <mailto:dance-join@ietf.org>
List-Unsubscribe: <mailto:dance-leave@ietf.org>

The IESG has received a request from the DANE Authentication for Network
Clients Everywhere WG (dance) to consider the following document: - 'TLS
Client Authentication via DANE TLSA records'
  <draft-ietf-dance-client-auth-14.txt> as Proposed Standard

This is a second IETF Last Call; this draft combines the dance-tls-clientid and dance-client-auth draft into one specification. It addresses all of the first IETF Last Call comments.

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
last-call@ietf.org mailing lists by 2026-09-29. Exceptionally, comments may
be sent to iesg@ietf.org instead. In either case, please retain the beginning
of the Subject line to allow automated sorting.

Abstract


   The DANE TLSA protocol describes how to publish Transport Layer
   Security (TLS) server certificates or public keys in the DNS.  This
   document updates RFC 6698 and RFC 7671.  It describes how to use the
   TLSA record to publish client certificates or public keys, and also
   the rules and considerations for using them with TLS.  In addition,
   it defines a new TLS extension, DANE Client Identity, to convey the
   client's domain name identity to the server.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-dance-client-auth/



No IPR declarations have been submitted directly on this I-D.