Re: [dane] SMIMEA test vectors

"Garfinkel, Simson L." <simson.garfinkel@nist.gov> Mon, 04 January 2016 21:58 UTC

Return-Path: <simson.garfinkel@nist.gov>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 213B11A033B for <dane@ietfa.amsl.com>; Mon, 4 Jan 2016 13:58:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s9NoHAd6n3Xz for <dane@ietfa.amsl.com>; Mon, 4 Jan 2016 13:58:34 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1bon0789.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::1:789]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C3791A0338 for <dane@ietf.org>; Mon, 4 Jan 2016 13:58:34 -0800 (PST)
Received: from CY1PR09MB0647.namprd09.prod.outlook.com (10.161.172.17) by CY1PR09MB0648.namprd09.prod.outlook.com (10.161.172.18) with Microsoft SMTP Server (TLS) id 15.1.361.13; Mon, 4 Jan 2016 21:58:14 +0000
Received: from CY1PR09MB0647.namprd09.prod.outlook.com ([10.161.172.17]) by CY1PR09MB0647.namprd09.prod.outlook.com ([10.161.172.17]) with mapi id 15.01.0361.006; Mon, 4 Jan 2016 21:58:14 +0000
From: "Garfinkel, Simson L." <simson.garfinkel@nist.gov>
To: "Osterweil, Eric" <eosterweil@verisign.com>
Thread-Topic: [dane] SMIMEA test vectors
Thread-Index: AQHRRwOzxjngS5PjBE2ixBMRGV8Xfp7r23EAgAAMhoA=
Date: Mon, 04 Jan 2016 21:58:14 +0000
Message-ID: <1DD8EAF2-9BF6-4B0C-B511-53B4523C8AD1@nist.gov>
References: <6AF3B656-EF46-4E73-8B47-66AF837242F8@nist.gov> <68B4DB21-D91A-4CB5-87A0-ED47B5528BEF@verisign.com>
In-Reply-To: <68B4DB21-D91A-4CB5-87A0-ED47B5528BEF@verisign.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.2104)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=simson.garfinkel@nist.gov;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [129.6.84.113]
x-microsoft-exchange-diagnostics: 1; CY1PR09MB0648; 5:HuL2zxs5iW/OAw036I3ZbaedCPw+4FkjynAMYX3H2EQzwFGjkJtr7Ro4/Tu+IT2e3jlbb9Y2RlFKnXrY4WQxj+AQRZdBPT8yvKfJkyJvtDd2SA3LLNN680DyRDiCGSOi5t1uq/vYE5fugMIC6VrAXA==; 24:ABatow0vHjLTo93QQPNOs52YqQmX4dTBvy4XYvdkVhL/+bg2Oc3DH3DbxoFJLVyefLoVi3VzQ6G7powyCzA36Hfma41payYzqVXVhxL7xx0=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:CY1PR09MB0648;
x-microsoft-antispam-prvs: <CY1PR09MB0648D085EBFAAE7AED8A9EE5F6F20@CY1PR09MB0648.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(65766998875637);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(520078)(5005006)(8121501046)(3002001)(10201501046); SRVR:CY1PR09MB0648; BCL:0; PCL:0; RULEID:; SRVR:CY1PR09MB0648;
x-forefront-prvs: 08118EFC2B
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(24454002)(377454003)(189002)(199003)(52604005)(101416001)(66066001)(11100500001)(50986999)(102836003)(105586002)(33656002)(15975445007)(106356001)(99286002)(2900100001)(50226001)(92566002)(5002640100001)(40100003)(5004730100002)(77096005)(2950100001)(122556002)(3846002)(36756003)(57306001)(97736004)(76176999)(110136002)(586003)(19580405001)(10400500002)(1220700001)(81156007)(5001960100002)(1096002)(82746002)(19580395003)(4326007)(106116001)(87936001)(6116002)(83716003)(189998001)(86362001)(5008740100001)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR09MB0648; H:CY1PR09MB0647.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: nist.gov does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <FAB7CE48E69D1C47A6333B1F943CC138@namprd09.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Jan 2016 21:58:14.0036 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1PR09MB0648
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/nQnCOq9irJ274IvR7ioOSKPvC1w>
Cc: "dane@ietf.org" <dane@ietf.org>
Subject: Re: [dane] SMIMEA test vectors
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Jan 2016 21:58:37 -0000

Hi Eric,

Thanks for pointing me at this. I’m actually writing a second SMIMEA implementation that is specifically created to be a test harness, so I’m looking actually looking for test vectors in the public DNS, rather than a reference implementation.  Are there SMIMEA announcements for any VeriSign email addresses?

While I have your attention — which are the SMIMEA key usages that make sense?  Several of them seem nonsensical.  For example, how would a matching type of 1 be used?  Do you anticipate that anyone will use a selector of 1?

Simson

> On Jan 4, 2016, at 4:13 PM, Osterweil, Eric <eosterweil@verisign.com> wrote:
> 
> 
>> On Jan 4, 2016, at 10:22 AM, Garfinkel, Simson L. <simson.garfinkel@nist.gov> wrote:
>> 
>> Greetings,
>> 
>> Are there any public SMIMEA test vectors?  I’m looking for DANE SMIMEA records that I can use to get an S/MIME certificate, send and email message that’s (optionally) encrypted, and get a response that’s digitally signed.
> 
> Hey Simson,
> 
> There are libsmaug and its associated Thunderbird Plugin:
> 	https://github.com/verisign/smaug
> 	https://github.com/verisign/smaug-tbird-plugin
> 
> The library should easily be useable to implement a test harness.
> 
> Eric