Re: [dane] Compressed Call for Adoption: draft-gilmore-dane-rawkeys-00

Viktor Dukhovni <viktor1dane@dukhovni.org> Mon, 23 June 2014 15:02 UTC

Return-Path: <viktor1dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46DDB1B2965 for <dane@ietfa.amsl.com>; Mon, 23 Jun 2014 08:02:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.2
X-Spam-Level:
X-Spam-Status: No, score=-99.2 tagged_above=-999 required=5 tests=[BAYES_50=0.8, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kIpbthE3vnOt for <dane@ietfa.amsl.com>; Mon, 23 Jun 2014 08:02:12 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [38.117.134.19]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 287E21B2AFF for <dane@ietf.org>; Mon, 23 Jun 2014 08:02:00 -0700 (PDT)
Received: by mournblade.imrryr.org (Postfix, from userid 1034) id EF8AC2AB0B4; Mon, 23 Jun 2014 15:01:58 +0000 (UTC)
Date: Mon, 23 Jun 2014 15:01:58 +0000
From: Viktor Dukhovni <viktor1dane@dukhovni.org>
To: dane@ietf.org
Message-ID: <20140623150158.GE17723@mournblade.imrryr.org>
References: <CAHw9_i+EtVskqkT1V9V_bvPOCpGdZpz4-Vr4ME_DiC7EvxVQwg@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAHw9_i+EtVskqkT1V9V_bvPOCpGdZpz4-Vr4ME_DiC7EvxVQwg@mail.gmail.com>
User-Agent: Mutt/1.5.23 (2014-03-12)
Archived-At: http://mailarchive.ietf.org/arch/msg/dane/AdCECTWxe8DY5SVx1prxSOqqmIQ
Subject: Re: [dane] Compressed Call for Adoption: draft-gilmore-dane-rawkeys-00
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: dane@ietf.org
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 15:02:16 -0000

On Mon, Jun 23, 2014 at 06:16:01AM -0400, Warren Kumari wrote:

> This starts a Call for Adoption for draft-gilmore-dane-rawkeys-00.
> The draft is available here:
> https://datatracker.ietf.org/doc/draft-gilmore-dane-rawkeys-00/

I am a day or two away from essentially compatible language in the
next (04) revision of draft-ietf-dane-ops.

I have no major objections to the substance of the new draft, we'll
mostly just need to decide how it relates to the revised ops draft,
which is now a 6698 update.   We should be able to merge the best
parts of the two parallel treatments, and either expand the coverage
of raw public keys in the ops draft, or shrink it, moving all
coverage of this issue to the new draft.

My technical issue with the new draft was that it seemed to suggest
that any DANE-EE(3) TLSA RR can be used to match raw public keys,
while in fact only DANE-EE(3) SPKI(1) matches raw public keys.

The new draft operates at two layers, on the one hand concretely
extending 6698 to support raw public keys, and on the other hand
generalizing the approach to arbitrary "key material" (conceptually
beyond even raw public keys).  My best guess is that were some
other kind of "key material" to be used with TLS, that is not in
SPKI format, the draft is trying to suggest that we'd use DANE-EE(3)
anyway (but likely with a new selector value, though this is not
stated).  I would for now not try to generalize beyond SPKI.  It
is not clear what those generalizations will really entail or
whether any are likely to happen in the near future.

Since I think "adoption" is not final approval of the content, but
rather agreement that there is useful and relevant material to
build on, while the draft is not done, I support adoption.

-- 
	Viktor.