Return-Path: <shuque@gmail.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 1B0341ACFE3
 for <dane@ietfa.amsl.com>; Mon, 10 Nov 2014 15:18:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.399
X-Spam-Level: 
X-Spam-Status: No, score=-1.399 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001,
 J_CHICKENPOX_65=0.6, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 3gzM8qtzLKgT for <dane@ietfa.amsl.com>;
 Mon, 10 Nov 2014 15:18:40 -0800 (PST)
Received: from mail-ie0-x22d.google.com (mail-ie0-x22d.google.com
 [IPv6:2607:f8b0:4001:c03::22d])
 (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 802871ACFE1
 for <dane@ietf.org>; Mon, 10 Nov 2014 15:18:40 -0800 (PST)
Received: by mail-ie0-f173.google.com with SMTP id tr6so10248662ieb.4
 for <dane@ietf.org>; Mon, 10 Nov 2014 15:18:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; 
 h=mime-version:reply-to:in-reply-to:references:date:message-id
 :subject:from:to:content-type;
 bh=2K7gAreG/4rjFv6ymwJ0xGm3g5cQxSiRFn1F0acfcIE=;
 b=w5/txxVWFAxcoje/P1qGZZgNe1ch0bKDYl+ho8ujT3jg8LylOn+RmD0xVpaHm/TLWK
 ItspvoXAYfOgJj3lUkBAlIrAxK94092v5xY0A9NaoFwiQPrsgh4X2gOZ5TuYRxaYFmOH
 y9kQ72qxlCB1zw+qb9yqo8c2AaK1gbbmsWpYTYZsRiM9/Bo69J3BA2KVgTNuigBl8l8H
 SUeAZMJd4buCCfif7yMDwPifSXaUwFKwzxXvbyrxJIkQGV9z4aDQBkK1NmdJ3AYyomIr
 CLs9/x48oa89lH1NEbZ2nLIXTgyLFKAAKmssBDrWHVCUPLJkCEB9yd/hnHvwV1KCdEkK
 9rvQ==
MIME-Version: 1.0
X-Received: by 10.50.93.98 with SMTP id ct2mr28089314igb.47.1415661519500;
 Mon, 10 Nov 2014 15:18:39 -0800 (PST)
Received: by 10.64.225.197 with HTTP; Mon, 10 Nov 2014 15:18:39 -0800 (PST)
In-Reply-To: <20141110213931.GJ161@mournblade.imrryr.org>
References: <20141027225310.29285.24437.idtracker@ietfa.amsl.com>
 <F0C0FC32-FAA7-4D07-A230-59A538754BCD@isoc.org>
 <20141027233223.GL19158@mournblade.imrryr.org>
 <20141110164617.GZ161@mournblade.imrryr.org>
 <20141110213931.GJ161@mournblade.imrryr.org>
Date: Mon, 10 Nov 2014 13:18:39 -1000
Message-ID: <CAHPuVdU-Oqc3qqDFDF6EwfKdpec5VqF5iZ7WRphF=bVDuYqwKA@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
To: dane@ietf.org
Content-Type: multipart/alternative; boundary=047d7b41432cfdfcaf05078961b5
Archived-At: http://mailarchive.ietf.org/arch/msg/dane/9fgDMbQRTBWAGh1r6RUxVe9dHNM
Subject: Re: [dane] Fwd: New Version Notification for
 draft-york-dane-deployment-observations-00.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: shuque@gmail.com
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>,
 <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>,
 <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Nov 2014 23:18:42 -0000

--047d7b41432cfdfcaf05078961b5
Content-Type: text/plain; charset=UTF-8

On Mon, Nov 10, 2014 at 11:39 AM, Viktor Dukhovni <ietf-dane@dukhovni.org>
wrote:

> On Mon, Nov 10, 2014 at 04:46:17PM +0000, Viktor Dukhovni wrote:
>
> > Speaking of testing, the Deploy360 site's list of test servers is
> > in need of ongoing maintenance.  A noticeable fraction behave
> > differently than advertised.
>
> > ;; Passed(depth 1, hostname fedoraproject.org): fedoraproject.org. IN
> TLSA 0 0 1 19400BE5B7A31FB733917700789D2F0A2471C0C9D506C0E504C06C16D7CB17C0
> > ;; Passed(depth 0): www.freebsd.org. IN TLSA 3 0 1
> 3F86A1FA85F6E5169CB27BF25C863805EBFD3225A16AADB75587804680992096
> > ;; Passed(depth 0): torproject.org. IN TLSA 3 1 1
> 578582E6B4569A4627AEF5DFE876EEC0539388E605DB170217838B10D2A58DA5
> > ;; Passed(depth 0): good.dane.verisignlabs.com. IN TLSA 3 0 1
> 0332AA2D58B3E0544B65656438937068BA44CE2F14469C4F50C9CC6933C808D3
> > ;; Passed(depth 0): nohats.ca. IN TLSA 3 1 1
> 462573195C86E861ABAB8ECCFBC7F0486958EFDFF9449AC10729B3A0F906F388
> > ;; Passed(depth 0): www.nlnetlabs.nl. IN TLSA 3 1 1
> F7DB964ED80ED0773F82A21997B2DCBAE434AE821AB1E3E337AD0CCFBFE2359F
> > ;; Passed(depth 0): www.huque.com. IN TLSA 3 0 1
> 0013BEF11B875A58F3B0B1D7A0D439A608277F58433BBB12245B2A28B398C281
>
> As advertised.  Mind you there should perhaps be a distinction in
> the classification of test sites between sites whose TLSA RRs
> actually leverage the CA they're signed by "usage 0, 1 or 2" vs.
> sites with a valid CA cert, but DANE-EE TLSA records.  This would
> separate fedora and freebsd into separate categories.
>

My site (www.huque.com.) also falls into that latter category. The
annotation on Dan York's page should be updated - it currently says I don't
have a secure delegation, which was true at one time in the past (blame a
DNSSEC oblivious registrar), but no longer.

--Shumon.

--047d7b41432cfdfcaf05078961b5
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">On Mon, Nov 10, 2014 at 11:39 AM, Viktor Dukhovni <span di=
r=3D"ltr">&lt;<a href=3D"mailto:ietf-dane@dukhovni.org" target=3D"_blank">i=
etf-dane@dukhovni.org</a>&gt;</span> wrote:<br><div class=3D"gmail_extra"><=
div class=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin=
:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=3D"">O=
n Mon, Nov 10, 2014 at 04:46:17PM +0000, Viktor Dukhovni wrote:<br>
<br>
&gt; Speaking of testing, the Deploy360 site&#39;s list of test servers is<=
br>
&gt; in need of ongoing maintenance.=C2=A0 A noticeable fraction behave<br>
&gt; differently than advertised.<br>
<br>
</span><span class=3D"">&gt; ;; Passed(depth 1, hostname <a href=3D"http://=
fedoraproject.org" target=3D"_blank">fedoraproject.org</a>): <a href=3D"htt=
p://fedoraproject.org" target=3D"_blank">fedoraproject.org</a>. IN TLSA 0 0=
 1 19400BE5B7A31FB733917700789D2F0A2471C0C9D506C0E504C06C16D7CB17C0<br>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://www.free=
bsd.org" target=3D"_blank">www.freebsd.org</a>. IN TLSA 3 0 1 3F86A1FA85F6E=
5169CB27BF25C863805EBFD3225A16AADB75587804680992096<br>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://torproje=
ct.org" target=3D"_blank">torproject.org</a>. IN TLSA 3 1 1 578582E6B4569A4=
627AEF5DFE876EEC0539388E605DB170217838B10D2A58DA5<br>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://good.dan=
e.verisignlabs.com" target=3D"_blank">good.dane.verisignlabs.com</a>. IN TL=
SA 3 0 1 0332AA2D58B3E0544B65656438937068BA44CE2F14469C4F50C9CC6933C808D3<b=
r>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://nohats.c=
a" target=3D"_blank">nohats.ca</a>. IN TLSA 3 1 1 462573195C86E861ABAB8ECCF=
BC7F0486958EFDFF9449AC10729B3A0F906F388<br>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://www.nlne=
tlabs.nl" target=3D"_blank">www.nlnetlabs.nl</a>. IN TLSA 3 1 1 F7DB964ED80=
ED0773F82A21997B2DCBAE434AE821AB1E3E337AD0CCFBFE2359F<br>
</span><span class=3D"">&gt; ;; Passed(depth 0): <a href=3D"http://www.huqu=
e.com" target=3D"_blank">www.huque.com</a>. IN TLSA 3 0 1 0013BEF11B875A58F=
3B0B1D7A0D439A608277F58433BBB12245B2A28B398C281<br>
<br>
</span>As advertised.=C2=A0 Mind you there should perhaps be a distinction =
in<br>
the classification of test sites between sites whose TLSA RRs<br>
actually leverage the CA they&#39;re signed by &quot;usage 0, 1 or 2&quot; =
vs.<br>
sites with a valid CA cert, but DANE-EE TLSA records.=C2=A0 This would<br>
separate fedora and freebsd into separate categories.<br></blockquote><div>=
<br></div><div>My site (<a href=3D"http://www.huque.com">www.huque.com</a>.=
) also falls into that latter category. The annotation on Dan York&#39;s pa=
ge should be updated - it currently says I don&#39;t have a secure delegati=
on, which was true at one time in the past (blame a DNSSEC oblivious regist=
rar), but no longer.<br><br></div><div>--Shumon.<br></div><div><br></div></=
div></div></div>

--047d7b41432cfdfcaf05078961b5--

