Re: [dane] Start of WGLC for draft-ietf-dane-registry-acronym

James Cloos <cloos@jhcloos.com> Thu, 19 September 2013 22:04 UTC

Return-Path: <cloos@jhcloos.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE7D521F8790 for <dane@ietfa.amsl.com>; Thu, 19 Sep 2013 15:04:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.352
X-Spam-Level:
X-Spam-Status: No, score=-2.352 tagged_above=-999 required=5 tests=[AWL=0.248, BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JbdvNal6jpHP for <dane@ietfa.amsl.com>; Thu, 19 Sep 2013 15:04:37 -0700 (PDT)
Received: from ore.jhcloos.com (ore.jhcloos.com [IPv6:2604:2880::b24d:a297]) by ietfa.amsl.com (Postfix) with ESMTP id 01D3A21F8613 for <dane@ietf.org>; Thu, 19 Sep 2013 15:04:36 -0700 (PDT)
Received: by ore.jhcloos.com (Postfix, from userid 10) id 92E7A1DFC5; Thu, 19 Sep 2013 22:04:31 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jhcloos.com; s=ore13; t=1379628271; bh=E6zy15k5oldnYq5Hjd+P6Vfy9hcwTK40NpcSZ1nhams=; h=From:To:Subject:In-Reply-To:References:Date:From; b=A1rQRp89SvPiykngJEDmDIAQlcFClhSpOGOaiuVbcm5cs6bo+jxkpDSBZ3dmNtmQ2 aLBBNyxJxI7rox9+0NnicLpm90LFm8gGk6xuhWec0wSBFel3GIEKUMjAUj0Xc4qpIw d0X0BKvwINchng5rRrwVPGXeg540eOxpuAUlDw4SxHw==
Received: by carbon.jhcloos.org (Postfix, from userid 500) id CE2346001E; Thu, 19 Sep 2013 22:00:49 +0000 (UTC)
From: James Cloos <cloos@jhcloos.com>
To: "dane@ietf.org list" <dane@ietf.org>
In-Reply-To: <EACEEB05-2023-4F76-A6FE-A9B2FDC0AA59@kumari.net> (Warren Kumari's message of "Thu, 19 Sep 2013 16:18:39 -0400")
References: <20130919201216.14866.61161.idtracker@ietfa.amsl.com> <EACEEB05-2023-4F76-A6FE-A9B2FDC0AA59@kumari.net>
User-Agent: Gnus/5.130008 (Ma Gnus v0.8) Emacs/24.3.50 (gnu/linux)
Face: iVBORw0KGgoAAAANSUhEUgAAABAAAAAQAgMAAABinRfyAAAACVBMVEX///8ZGXBQKKnCrDQ3 AAAAJElEQVQImWNgQAAXzwQg4SKASgAlXIEEiwsSIYBEcLaAtMEAADJnB+kKcKioAAAAAElFTkSu QmCC
Copyright: Copyright 2013 James Cloos
OpenPGP: ED7DAEA6; url=http://jhcloos.com/public_key/0xED7DAEA6.asc
OpenPGP-Fingerprint: E9E9 F828 61A4 6EA9 0F2B 63E7 997A 9F17 ED7D AEA6
Date: Thu, 19 Sep 2013 18:00:49 -0400
Message-ID: <m361twqxn9.fsf@carbon.jhcloos.org>
Lines: 31
MIME-Version: 1.0
Content-Type: text/plain
X-Hashcash: 1:28:130919:"dane\@ietf.org::47xvjElLUEv0F2t4:05uBQp
X-Hashcash: 1:28:130919:dane@ietf.org::cL7WMpii+tyOiC1/:000g64WX
Subject: Re: [dane] Start of WGLC for draft-ietf-dane-registry-acronym
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Sep 2013 22:04:37 -0000

PKIX-TA looks better than PKIX-CA; CA makes it look like it has to be an
association to a root cert.

It would be nice to have a better short description for type 3 than
Domain-issued certificate, notwithstanding the existance of that string
in rfc 6698.  DANE isn't about issuing certs, but rather about
establishing trust paths to them.  But I cannot come up with an
alternative.... 

Nits:

The paragraph: "It is expected that DANE parser's in applications and
DNS software MAY adopt parsing the acronyms for each field, installed
base MAY NOT get updated." could use better grammar.  Perhaps:

  s/each field, installed base/each field, but the installed base/

And perhaps /MAY NOT/may not/.  Unlike the first MAY, the may not isn't
really a 2119.  (The Nits link agrees.)

In the xml, I'd do:

   s(<c>CA     constraint</c>)(<c>CA constraint</c>)

it should look better in the output.

-JimC
-- 
James Cloos <cloos@jhcloos.com>         OpenPGP: 1024D/ED7DAEA6