Re: [dane] FYI: New Version Notification for draft-hoffman-dane-smime-04.txt
"Jim Schaad" <ietf@augustcellars.com> Tue, 11 September 2012 15:32 UTC
Return-Path: <ietf@augustcellars.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 489B121F880D for <dane@ietfa.amsl.com>; Tue, 11 Sep 2012 08:32:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.524
X-Spam-Level:
X-Spam-Status: No, score=-3.524 tagged_above=-999 required=5 tests=[AWL=0.075, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y+K2wkFbpDjG for <dane@ietfa.amsl.com>; Tue, 11 Sep 2012 08:32:00 -0700 (PDT)
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171]) by ietfa.amsl.com (Postfix) with ESMTP id 5A70121F87FF for <dane@ietf.org>; Tue, 11 Sep 2012 08:31:59 -0700 (PDT)
Received: from Tobias (mail.augustcellars.com [50.34.17.238]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: schaad@nwlink.com) by smtp1.pacifier.net (Postfix) with ESMTPSA id F31D82CA11; Tue, 11 Sep 2012 08:31:58 -0700 (PDT)
From: Jim Schaad <ietf@augustcellars.com>
To: 'Jakob Schlyter' <jakob@kirei.se>
References: <20120908161345.32470.87669.idtracker@ietfa.amsl.com> <577789DE-4A22-48D3-ACBE-8297B6C1DBCE@kirei.se> <046d01cd8fda$c5670d00$50352700$@augustcellars.com> <7C162211-2928-46E5-83C3-CAEF246CD194@kirei.se>
In-Reply-To: <7C162211-2928-46E5-83C3-CAEF246CD194@kirei.se>
Date: Tue, 11 Sep 2012 08:30:35 -0700
Message-ID: <04a401cd9032$6408df40$2c1a9dc0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQG8NZDUnukvMfDekkDNtxUX+Lj1cwEyVOAsAhUy6bcBkhcgs5eBLIyw
Content-Language: en-us
Cc: 'IETF DANE WG list' <dane@ietf.org>
Subject: Re: [dane] FYI: New Version Notification for draft-hoffman-dane-smime-04.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Sep 2012 15:32:01 -0000
> -----Original Message----- > From: Jakob Schlyter [mailto:jakob@kirei.se] > Sent: Tuesday, September 11, 2012 6:26 AM > To: Jim Schaad > Cc: 'IETF DANE WG list' > Subject: Re: [dane] FYI: New Version Notification for draft-hoffman-dane- > smime-04.txt > > On 11 sep 2012, at 07:03, Jim Schaad <ietf@augustcellars.com> wrote: > > > Problem #3 is almost impossible. It would require that only > > end-entity certificate be listed, and this would mean that either it > > would be directly trusted or one would need to have both an EE > > certificate and a trust anchor listed in the DNS entry. The > > capitalization issue would need to be addressed as in the previous > > paragraph, but is harder given that the sender may have never seen the > > mailbox name for the recipient and may be guessing at what the string > should be if the DNS namespace is not over-populated. > > I believe you somewhat exaggerating this problem. IMHO, the requirements > you list are true but in no way a showstopper and I believe that publishing > down-cased EE cert would be a very pragmatic and deployable way of doing > this. This may or may not be true, however it does not address the question I asked in the mail. Which of the problems is this trying to solve? Jim > > jakob
- [dane] FYI: New Version Notification for draft-ho… Jakob Schlyter
- Re: [dane] FYI: New Version Notification for draf… James Cloos
- Re: [dane] FYI: New Version Notification for draf… Paul Hoffman
- Re: [dane] FYI: New Version Notification for draf… Jim Schaad
- Re: [dane] FYI: New Version Notification for draf… Tony Finch
- Re: [dane] FYI: New Version Notification for draf… Jakob Schlyter
- Re: [dane] FYI: New Version Notification for draf… Nicholas Weaver
- Re: [dane] FYI: New Version Notification for draf… Jim Schaad
- Re: [dane] FYI: New Version Notification for draf… Martin Pels
- Re: [dane] FYI: New Version Notification for draf… Jakob Schlyter
- Re: [dane] FYI: New Version Notification for draf… Paul Hoffman
- Re: [dane] FYI: New Version Notification for draf… Jim Schaad