Re: [dane] Working group Last call: draft-ietf-dane-smime-11.txt

"Paul Hoffman" <paul.hoffman@vpnc.org> Mon, 01 August 2016 01:08 UTC

Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C3A112D0C6 for <dane@ietfa.amsl.com>; Sun, 31 Jul 2016 18:08:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dgomt3IDDd0z for <dane@ietfa.amsl.com>; Sun, 31 Jul 2016 18:08:38 -0700 (PDT)
Received: from mail.proper.com (Opus1.Proper.COM [207.182.41.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D2F512D0C4 for <dane@ietf.org>; Sun, 31 Jul 2016 18:08:38 -0700 (PDT)
Received: from [10.32.60.36] (50-1-98-193.dsl.dynamic.fusionbroadband.com [50.1.98.193]) (authenticated bits=0) by mail.proper.com (8.15.2/8.14.9) with ESMTPSA id u7118BXc065311 (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 31 Jul 2016 18:08:13 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
X-Authentication-Warning: mail.proper.com: Host 50-1-98-193.dsl.dynamic.fusionbroadband.com [50.1.98.193] claimed to be [10.32.60.36]
From: Paul Hoffman <paul.hoffman@vpnc.org>
To: Jim Schaad <ietf@augustcellars.com>
Date: Sun, 31 Jul 2016 18:08:11 -0700
Message-ID: <82DB30B8-FA78-4B35-AE4B-CC6AC984715E@vpnc.org>
In-Reply-To: <032801d1e67d$34d80d90$9e8828b0$@augustcellars.com>
References: <F7B890A0-6A67-41C0-B46A-831EC55452D3@ogud.com> <CAHw9_i+2wGPgKk9oKJLH+ZF-5pztPMeDv+4=SXP5qgM1-PH7fw@mail.gmail.com> <alpine.LRH.2.20.1607250908430.18124@bofh.nohats.ca> <032801d1e67d$34d80d90$9e8828b0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.4r5234)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/r2bmrL1Bmbc0qTG2oIYRZellwx0>
Cc: dane WG list <dane@ietf.org>
Subject: Re: [dane] Working group Last call: draft-ietf-dane-smime-11.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Aug 2016 01:08:39 -0000

On 25 Jul 2016, at 7:02, Jim Schaad wrote:

>>> I also wanted to make sure people (including the authors) had seen:
>>> https://www.ietf.org/mail-archive/web/dane/current/msg08382.html
>>
>> This has come up in the past when discussing SMIME. One suggestion 
>> was to use
>> a different prefix (like _encrypt. and _sign). When this was brought 
>> up, the
>> patent status of this was not entirely clear, and there were privacy 
>> discussions
>> raised on exposing queries to the purpose of the query. Perhaps the 
>> document
>> can state that if the certificate is obtained via SMIMEA, it should 
>> be checked
>> whether it is suitable for the task to perform. And that publishers 
>> are
>> encouraged to publish SMIMEA records for certificates that allow both 
>> signing
>> and encryption.
>> But this latter approach did not have a clear consensus.
>
> This is not the issue that my message was designed to highlight.  In 
> S/MIME it is possible to say which of the message formats and which 
> content encryption algorithms are supported by a client.  This is not 
> the same as designating if a certificate is being used for encryption 
> or signing.

We will add a mention of RFC 4262 to the draft.

--Paul Hoffman