Re: [dane] I-D Action: draft-ietf-dane-srv-04.txt (Martin Rex) Mon, 17 February 2014 13:31 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id AD2971A0006 for <>; Mon, 17 Feb 2014 05:31:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -6.552
X-Spam-Status: No, score=-6.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id qcOa4N41hnEt for <>; Mon, 17 Feb 2014 05:31:01 -0800 (PST)
Received: from ( []) by (Postfix) with ESMTP id 7F7C81A01E0 for <>; Mon, 17 Feb 2014 05:31:00 -0800 (PST)
Received: from by (26) with ESMTP id s1HDUvh4019855 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for <>; Mon, 17 Feb 2014 14:30:57 +0100 (MET)
In-Reply-To: <>
Date: Mon, 17 Feb 2014 14:30:57 +0100 (CET)
X-Mailer: ELM [version 2.4ME+ PL125 (25)]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="US-ASCII"
Message-Id: <>
From: (Martin Rex)
X-SAP: out
Subject: Re: [dane] I-D Action: draft-ietf-dane-srv-04.txt
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 17 Feb 2014 13:31:04 -0000

Viktor Dukhovni wrote:
>> Defective implementations excepted, the TLS protocol engine will
>> look at the KeyUsage attribute of the Server certificate and check
>> the cipher suite selection for compatibility -- and the application
>> call will NOT have a say in this.
> You seem to be wedded to the idea that DANE support will be in
> application code and not in "TLS engine code".

That isn't my idea, that is a fundamental part of the architecture
of TLS, described in every existing TLS specification at the end
of section 1, Introduction.

                        The TLS standard, however, does not specify how
   protocols add security with TLS; the decisions on how to initiate TLS
   handshaking and how to interpret the authentication certificates
   exchanged are left up to the judgment of the designers and
   implementors of protocols which run on top of TLS. 

> Having actually implemented a complete DANE verifier, I can assure
> you that there will be very few applications indeed that attempt
> to do this.

We know painfully well just how poor apps are in doing certificate
 "The most dangerous Code in the World"

A number of TLS protocol implementations come with utility functions
to make the task easier for applications to consume TLS.

The model how server endpoint identites are checked in HTTP-over-TLS,
as described in rfc2818, is a matter of the application from the
TLS protocol perspective.  Leaving the checking of certificates
entirely to applications is what leads to the problem described in
above paper.

The situation with DANE is very much alike.  DANE does not change
anything about how TLS works, it only changes how applications make
use (including certificate (parh) validation) of the certificates
exchanged within the TLS protocol.

It is likely that TLS implementation will add support for DANE to
the the set of utility functions that are supposed to facilitate
consumption of TLS for applications.  DANE is *NOT* part of TLS,
and it will be the task of application to actually have the checks