Re: [dane] deployment of DANE

Dan York <dan-ietf@danyork.org> Tue, 25 September 2012 17:44 UTC

Return-Path: <dan-ietf@danyork.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D96D221F87F3 for <dane@ietfa.amsl.com>; Tue, 25 Sep 2012 10:44:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.998
X-Spam-Level:
X-Spam-Status: No, score=-2.998 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, J_CHICKENPOX_57=0.6, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U1n43qiYQZwB for <dane@ietfa.amsl.com>; Tue, 25 Sep 2012 10:44:33 -0700 (PDT)
Received: from mail-qa0-f51.google.com (mail-qa0-f51.google.com [209.85.216.51]) by ietfa.amsl.com (Postfix) with ESMTP id CEC0821F87E7 for <dane@ietf.org>; Tue, 25 Sep 2012 10:44:32 -0700 (PDT)
Received: by qabj40 with SMTP id j40so318908qab.10 for <dane@ietf.org>; Tue, 25 Sep 2012 10:44:32 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to:x-mailer:x-gm-message-state; bh=51EjLMpvuaRe94IhPSFaNVoA+2nA0PlFStwC82+z45w=; b=AiQcCwr/uS+1D0ucwytYIhtQsF0sacvry6LzLAfge4659+Rob/9YGwIMKXz+n35bRA YJhppH4dcG47o8f5IG4FxKreGom1WbV6V1yAmrHhNwI+DIFoDso4xGCc4fQAAjLTTeX6 BZ8K3nGrAuJu9AjUzPnAbWHR885f0hKNnA6acKEpJxA/bp3IccsKhYg911e6GYMBPr0j 7YyO+z0qd/xkV7tmtzy8/+IHC53EhyrKFRYSQ6Vw7UzVAOxtDcCuepBH0Li9BXW8f0Az YhvrtD58cpSe9mctTwMHqTVJ8zM8M0ppH/PvyTyASdGJZbHfAilXZKxzkIHV0mS1oZwS x9Ww==
Received: by 10.229.136.208 with SMTP id s16mr11636396qct.112.1348595072035; Tue, 25 Sep 2012 10:44:32 -0700 (PDT)
Received: from ?IPv6:2001:470:1f07:309:c985:582a:dc5b:4c9c? ([2001:470:1f07:309:c985:582a:dc5b:4c9c]) by mx.google.com with ESMTPS id d11sm1490005qaj.18.2012.09.25.10.44.30 (version=TLSv1/SSLv3 cipher=OTHER); Tue, 25 Sep 2012 10:44:31 -0700 (PDT)
Mime-Version: 1.0 (Apple Message framework v1257)
Content-Type: multipart/alternative; boundary="Apple-Mail=_9F6F955B-BEFC-4332-93B1-E89C5CAFAB8C"
From: Dan York <dan-ietf@danyork.org>
In-Reply-To: <6E1939C1-E3EB-4A00-B553-7A0EF640C01A@bblfish.net>
Date: Tue, 25 Sep 2012 13:44:28 -0400
Message-Id: <D70512B7-6F48-4BCA-9AD3-3783715ACA12@danyork.org>
References: <6E1939C1-E3EB-4A00-B553-7A0EF640C01A@bblfish.net>
To: Henry Story <henry.story@bblfish.net>
X-Mailer: Apple Mail (2.1257)
X-Gm-Message-State: ALoCoQlMaU/Ts8heewBaQugGPRixpMtZPlibaWGdZxwkQlS5oljPjRNnUJe/9jIM1ZIb9XFocXDt
Cc: IETF DANE WG list <dane@ietf.org>
Subject: Re: [dane] deployment of DANE
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Sep 2012 17:44:34 -0000

So in a funny bit of synchronicity, I just turned to my mail client to write basically this exact message that Henry sent this morning:

On Sep 25, 2012, at 4:13 AM, Henry Story wrote:

> Any feedback on advances on deployment of DANE in browsers?
> 
> Are there any browsers that support this already, are working on it? 

I also am very interested in this info.  My work is with the Internet Society's Deploy360 Programme ( http://www.internetsociety.org/deploy360/ ) where our focus is on promoting materials and information to accelerate the deployment of DNSSEC and IPv6.  I have lately been promoting the work of this (DANE) working group in recent presentations at conferences and there has been quite a good bit of interest in DANE.  I see DANE as providing an excellent reason for companies and organizations to deploy DNSSEC (in fact perhaps *THE* reason for some companies) and it finally gives us a way to talk about how DNSSEC and TLS/SSL can complement each other to provide a more secure solution.

But... if there's no timeframe for seeing DANE actually deployed in browsers... then... I'm winding up setting expectations for something that may not happen. :-(

Any info about there on getting it in Chrome? Firefox? Opera? IE? Safari?

Any and all info would be greatly appreciated.

Thanks,
Dan

-- 
Dan York  dyork@lodestar2.com
http://www.danyork.me/   skype:danyork
Phone: +1-802-735-1624
Twitter - http://twitter.com/danyork