Re: [dane] direction of effort (was: Re: Second WGLC draft-ietf-dane-smime)

Viktor Dukhovni <ietf-dane@dukhovni.org> Tue, 29 November 2016 23:35 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA5C2129442 for <dane@ietfa.amsl.com>; Tue, 29 Nov 2016 15:35:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gm8Jkz7imMKX for <dane@ietfa.amsl.com>; Tue, 29 Nov 2016 15:35:04 -0800 (PST)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [38.117.134.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 57169129527 for <dane@ietf.org>; Tue, 29 Nov 2016 15:35:03 -0800 (PST)
Received: by mournblade.imrryr.org (Postfix, from userid 1034) id F149C284EAD; Tue, 29 Nov 2016 23:35:01 +0000 (UTC)
Date: Tue, 29 Nov 2016 23:35:01 +0000
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
To: dane@ietf.org
Message-ID: <20161129233501.GO26244@mournblade.imrryr.org>
References: <1479102464.995918272@apps.rackspace.com> <alpine.LRH.2.20.1611170410140.28374@bofh.nohats.ca> <D96EB1EE-A7C6-4C21-B1AC-1D0A5F8547E8@rfc1035.com> <CADyWQ+EC4v5U1tcw3OTd7j2D0KNWveNhsUSGc6c=NvX9VhtRLg@mail.gmail.com> <42510095-2182-422E-8A47-1EF3181B16F3@nist.gov> <1d348f05-ab84-ada8-a8fd-9fba59f2c2b1@cs.tcd.ie> <9548FA7F-B229-458B-B739-B1083FBC4028@nist.gov>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <9548FA7F-B229-458B-B739-B1083FBC4028@nist.gov>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/5rQb5GdlNi7UQ-iLnN0HFKOF_7c>
Subject: Re: [dane] direction of effort (was: Re: Second WGLC draft-ietf-dane-smime)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: dane@ietf.org
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Nov 2016 23:35:06 -0000

On Tue, Nov 29, 2016 at 02:14:43PM +0000, Garfinkel, Simson L. (Fed) wrote:

> Thanks for your email.  Much of the DANE-related work that I�ve been doing
> at NIST is focused on the enterprise of the US Government. However you
> are correct, the DANE protocols could also be used for enable interoperable
> e2e email security for consumers. Thanks for the reminder.

It would be nice to see a few "real" .gov domains with TLSA records
for SMTP.  At present only dnsops.gov seems to have TLSA records,
and ironically with a WoSign/StartCom certificate...

-- 
	Viktor.

    dnsops.gov. IN MX 10 monitor.dnsops.gov.
    dnsops.gov. IN MX 10 snip1v6.dnsops.gov.
    _25._tcp.monitor.dnsops.gov. IN TLSA 3 0 1 1d97435ab70152d4de428f9a24f36e80dc1d455dee183505a61be02553ff4f1c ; passed
    _25._tcp.snip1v6.dnsops.gov. IN TLSA 3 0 1 1d97435ab70152d4de428f9a24f36e80dc1d455dee183505a61be02553ff4f1c ; ?
    snip1v6.dnsops.gov. IN AAAA 2610:20:6005:100:0:0:0:203 ; Connection refused

    Subject = CN=monitor.dnsops.gov,C=US
    Issuer = CN=StartCom Class 1 DV Server CA,OU=StartCom Certification Authority,O=StartCom Ltd.,C=IL
    Inception = 2016-10-12T17:02:00Z
    Expiration = 2019-10-12T17:02:00Z
    DNS = monitor.dnsops.gov
    
    _25._tcp.monitor.dnsops.gov. IN TLSA 3 1 1 d46a41adc0402b80e5706f32bc4ad4cbe30f25a73b54c54b427378a6375e5ad5