Re: [dane] Fwd: New Version Notification for draft-york-dane-deployment-observations-00.txt

Shumon Huque <shuque@gmail.com> Mon, 10 November 2014 23:18 UTC

Return-Path: <shuque@gmail.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B0341ACFE3 for <dane@ietfa.amsl.com>; Mon, 10 Nov 2014 15:18:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.399
X-Spam-Level:
X-Spam-Status: No, score=-1.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, J_CHICKENPOX_65=0.6, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3gzM8qtzLKgT for <dane@ietfa.amsl.com>; Mon, 10 Nov 2014 15:18:40 -0800 (PST)
Received: from mail-ie0-x22d.google.com (mail-ie0-x22d.google.com [IPv6:2607:f8b0:4001:c03::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 802871ACFE1 for <dane@ietf.org>; Mon, 10 Nov 2014 15:18:40 -0800 (PST)
Received: by mail-ie0-f173.google.com with SMTP id tr6so10248662ieb.4 for <dane@ietf.org>; Mon, 10 Nov 2014 15:18:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:content-type; bh=2K7gAreG/4rjFv6ymwJ0xGm3g5cQxSiRFn1F0acfcIE=; b=w5/txxVWFAxcoje/P1qGZZgNe1ch0bKDYl+ho8ujT3jg8LylOn+RmD0xVpaHm/TLWK ItspvoXAYfOgJj3lUkBAlIrAxK94092v5xY0A9NaoFwiQPrsgh4X2gOZ5TuYRxaYFmOH y9kQ72qxlCB1zw+qb9yqo8c2AaK1gbbmsWpYTYZsRiM9/Bo69J3BA2KVgTNuigBl8l8H SUeAZMJd4buCCfif7yMDwPifSXaUwFKwzxXvbyrxJIkQGV9z4aDQBkK1NmdJ3AYyomIr CLs9/x48oa89lH1NEbZ2nLIXTgyLFKAAKmssBDrWHVCUPLJkCEB9yd/hnHvwV1KCdEkK 9rvQ==
MIME-Version: 1.0
X-Received: by 10.50.93.98 with SMTP id ct2mr28089314igb.47.1415661519500; Mon, 10 Nov 2014 15:18:39 -0800 (PST)
Received: by 10.64.225.197 with HTTP; Mon, 10 Nov 2014 15:18:39 -0800 (PST)
In-Reply-To: <20141110213931.GJ161@mournblade.imrryr.org>
References: <20141027225310.29285.24437.idtracker@ietfa.amsl.com> <F0C0FC32-FAA7-4D07-A230-59A538754BCD@isoc.org> <20141027233223.GL19158@mournblade.imrryr.org> <20141110164617.GZ161@mournblade.imrryr.org> <20141110213931.GJ161@mournblade.imrryr.org>
Date: Mon, 10 Nov 2014 13:18:39 -1000
Message-ID: <CAHPuVdU-Oqc3qqDFDF6EwfKdpec5VqF5iZ7WRphF=bVDuYqwKA@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
To: dane@ietf.org
Content-Type: multipart/alternative; boundary="047d7b41432cfdfcaf05078961b5"
Archived-At: http://mailarchive.ietf.org/arch/msg/dane/9fgDMbQRTBWAGh1r6RUxVe9dHNM
Subject: Re: [dane] Fwd: New Version Notification for draft-york-dane-deployment-observations-00.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: shuque@gmail.com
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Nov 2014 23:18:42 -0000

On Mon, Nov 10, 2014 at 11:39 AM, Viktor Dukhovni <ietf-dane@dukhovni.org>
wrote:

> On Mon, Nov 10, 2014 at 04:46:17PM +0000, Viktor Dukhovni wrote:
>
> > Speaking of testing, the Deploy360 site's list of test servers is
> > in need of ongoing maintenance.  A noticeable fraction behave
> > differently than advertised.
>
> > ;; Passed(depth 1, hostname fedoraproject.org) fedoraproject.org. IN
> TLSA 0 0 1 19400BE5B7A31FB733917700789D2F0A2471C0C9D506C0E504C06C16D7CB17C0
> > ;; Passed(depth 0): www.freebsd.org. IN TLSA 3 0 1
> 3F86A1FA85F6E5169CB27BF25C863805EBFD3225A16AADB75587804680992096
> > ;; Passed(depth 0): torproject.org. IN TLSA 3 1 1
> 578582E6B4569A4627AEF5DFE876EEC0539388E605DB170217838B10D2A58DA5
> > ;; Passed(depth 0): good.dane.verisignlabs.com. IN TLSA 3 0 1
> 0332AA2D58B3E0544B65656438937068BA44CE2F14469C4F50C9CC6933C808D3
> > ;; Passed(depth 0): nohats.ca. IN TLSA 3 1 1
> 462573195C86E861ABAB8ECCFBC7F0486958EFDFF9449AC10729B3A0F906F388
> > ;; Passed(depth 0): www.nlnetlabs.nl. IN TLSA 3 1 1
> F7DB964ED80ED0773F82A21997B2DCBAE434AE821AB1E3E337AD0CCFBFE2359F
> > ;; Passed(depth 0): www.huque.com. IN TLSA 3 0 1
> 0013BEF11B875A58F3B0B1D7A0D439A608277F58433BBB12245B2A28B398C281
>
> As advertised.  Mind you there should perhaps be a distinction in
> the classification of test sites between sites whose TLSA RRs
> actually leverage the CA they're signed by "usage 0, 1 or 2" vs.
> sites with a valid CA cert, but DANE-EE TLSA records.  This would
> separate fedora and freebsd into separate categories.
>

My site (www.huque.com.) also falls into that latter category. The
annotation on Dan York's page should be updated - it currently says I don't
have a secure delegation, which was true at one time in the past (blame a
DNSSEC oblivious registrar), but no longer.

--Shumon.