Re: [Danish] Charter Text and the Problem Statement

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Mon, 21 June 2021 17:01 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: danish@ietfa.amsl.com
Delivered-To: danish@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16B863A1164 for <danish@ietfa.amsl.com>; Mon, 21 Jun 2021 10:01:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.001
X-Spam-Level:
X-Spam-Status: No, score=0.001 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=lwLW1aYH; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=lwLW1aYH
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U7T4EyRGLZqz for <danish@ietfa.amsl.com>; Mon, 21 Jun 2021 10:01:09 -0700 (PDT)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04on060e.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0d::60e]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DB2593A1166 for <danish@ietf.org>; Mon, 21 Jun 2021 10:01:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=73rF1igt0hCx6EETYLlYvGarh8ccdUurygn5iyQwAI4=; b=lwLW1aYH7dD84vFHtFVXeBfIXug0eTa6QU4lFCmF/uzOsiJdkiBzOY2QYHkz+ij+9p4L6Rg2atFwjMcO75UwdklJINcueAkGuyCUxmZ5GHi+yI+8GR3roBbeowj8Bs8kzZH6Vf07Z5wB1O17RvPtLntATHj+1MdX9tTgmkvRQnU=
Received: from AM5PR0202CA0022.eurprd02.prod.outlook.com (2603:10a6:203:69::32) by DBBPR08MB6282.eurprd08.prod.outlook.com (2603:10a6:10:20c::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.18; Mon, 21 Jun 2021 17:01:04 +0000
Received: from VE1EUR03FT041.eop-EUR03.prod.protection.outlook.com (2603:10a6:203:69:cafe::c4) by AM5PR0202CA0022.outlook.office365.com (2603:10a6:203:69::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.21 via Frontend Transport; Mon, 21 Jun 2021 17:01:04 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT041.mail.protection.outlook.com (10.152.19.163) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.16 via Frontend Transport; Mon, 21 Jun 2021 17:01:03 +0000
Received: ("Tessian outbound 7f55dcc5b33a:v96"); Mon, 21 Jun 2021 17:01:03 +0000
X-CR-MTA-TID: 64aa7808
Received: from 05992012c0b1.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id FC7FDD26-C05C-45CF-9FE5-42C0FE34172C.1; Mon, 21 Jun 2021 17:00:58 +0000
Received: from EUR02-AM5-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 05992012c0b1.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 21 Jun 2021 17:00:58 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Rxy0IX6DYdvRt8IVm3x9SElRUX3UC/ScOi1xtgso/uixsmJvg5pPnvDVFNoVYl9QQVLCwSc7xFAJCjhutRQmIEUmHy8ULl1yUSOZV392PM0xyqGkCI28tg4L0SWUmJtKoTH8+UzRMbJo20E3x7s25lgbtpfYqPnrv7OKtsWLjpLBTuVYqJaPHtyxI792NkdgatTNcvnUugc+Ep28R8eVOiaWF7UymbLLSLT+r23UpdGauePz0fxczRToR6W9h2gMR2xYrtXkDuBsyDQqu4QrpnbQI/xYI5pK2vBh46iLd/ErxKNkcQ+s+QR20amvwxQtmR81f8g7rEVwA7PCCIwkGw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=73rF1igt0hCx6EETYLlYvGarh8ccdUurygn5iyQwAI4=; b=oJ8coT48g8pABXIAnrj4rc19VHxMwUr9+PaOv3+c/9LXqBchVpmFq/U2ylWeBoH3lGClHSqtw05GTzf8nTa0iTTy1gp122JK1NICA/2Ger5UwDhb7CRDMsvN0fVdydZXIdFG2PP46VWRWzCj5hcL9m2Iwog8gL0uTMVe/e+MjSIikK7K3ac3ZeoC/q8hVpkXB/JFdYflUU4Cik2VC78VtHnluct61G129m4IiKnN6sSHbTOh5LgXdsgl9UQorDWCxx6B3sGsWhy6gJgdGVaIa+3c0JO8RQKwTjc0bXs/PnTbuWrid+Sjjy0z2+tmpM6M8pKpQJW22J9NYtARt9zqtA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=73rF1igt0hCx6EETYLlYvGarh8ccdUurygn5iyQwAI4=; b=lwLW1aYH7dD84vFHtFVXeBfIXug0eTa6QU4lFCmF/uzOsiJdkiBzOY2QYHkz+ij+9p4L6Rg2atFwjMcO75UwdklJINcueAkGuyCUxmZ5GHi+yI+8GR3roBbeowj8Bs8kzZH6Vf07Z5wB1O17RvPtLntATHj+1MdX9tTgmkvRQnU=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DB8PR08MB4108.eurprd08.prod.outlook.com (2603:10a6:10:b1::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.21; Mon, 21 Jun 2021 17:00:56 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::69cf:4429:a804:7f41]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::69cf:4429:a804:7f41%3]) with mapi id 15.20.4242.023; Mon, 21 Jun 2021 17:00:56 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "danish@ietf.org" <danish@ietf.org>
Thread-Topic: [Danish] Charter Text and the Problem Statement
Thread-Index: Addin8Z32g6ibl9RQiW6iIvXVU0WhwAVq2gAABL3x4AAGNNDAAAroAeQAD1ePYAAGAHboAAc2eSAAA9o/EAAGGtIgAAAdFUg
Date: Mon, 21 Jun 2021 17:00:56 +0000
Message-ID: <DBBPR08MB5915B9871F8FA2D051277BF9FA0A9@DBBPR08MB5915.eurprd08.prod.outlook.com>
References: <DBBPR08MB5915066E1CE5BDB2D695A8DAFA0F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <CAEfM=vQehhvSNeBNitJJjisEbimn_gizoo8VTtHWUJ1zSU+rQg@mail.gmail.com> <DBBPR08MB5915D8FC201DFEB31F7D8EA8FA0E9@DBBPR08MB5915.eurprd08.prod.outlook.com> <CAEfM=vTHPmDcOimf9xOvkYgeObbHvpfG1uZUVjBJFhykrZNafg@mail.gmail.com> <DBBPR08MB5915C107E3620968DFE34D97FA0C9@DBBPR08MB5915.eurprd08.prod.outlook.com> <23295.1624134481@localhost> <DBBPR08MB591546610B09B3606721EF2CFA0B9@DBBPR08MB5915.eurprd08.prod.outlook.com> <5631.1624225291@localhost> <DBBPR08MB5915DB801CD6D3FFD8D69E96FA0A9@DBBPR08MB5915.eurprd08.prod.outlook.com> <84B82C84-0C88-4EF3-B21C-C4713CE968C1@dukhovni.org>
In-Reply-To: <84B82C84-0C88-4EF3-B21C-C4713CE968C1@dukhovni.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 6AEC3FDA463FD148B2835BC1AEA08163.0
x-checkrecipientchecked: true
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.123.248]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 624e5caa-8173-4f15-876d-08d934d62790
x-ms-traffictypediagnostic: DB8PR08MB4108:|DBBPR08MB6282:
X-Microsoft-Antispam-PRVS: <DBBPR08MB62825D293D381161F1A36904FA0A9@DBBPR08MB6282.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:10000;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: rCU/aS5LTiZeJsVxD0kj0aencuskdZq9bPVGj55P26dCXtzGXezzZALmlexpBHUUZN849X4ZSgR+XYxJ/9ErR9aJEoN9WFVdJwGQJtwQC5USO/PTXf31NHKMcLI/jTNmhZW1/0oAEy6eejsMIbjymHrtZc3Am0N+xAMdujsODYGL/BJFftlq8YoIqhQqK84BVC4jiFkSOZGSLtC5shKRJYRVZdsS3HrV2KwHDN/yTTWOIXJbYvUpugWs5Fh3ohmOBVI+Q6cRqBpcz8LIIt6k0JqFQnIjw5JGVwLlh8z2wqX8L2uItQyX+L87XwyqISODzJ9fp4R2Dy8+wnsY7Pb/7i28Ai9bMoup3ciwYpCzdOTLKXzwIEYaIgCcBueVg81PDPywu57Nfzhq6kevGL9gSiFYHeaBUw5J9uAcr5euOkD0DgqPz7RWYpurjeM2e0r7YZ7s5iQOKrox6IfS2QUVlyVRcm2DktMr9uHDBASpoXakM/RtiZL+AkQV5kKXAJmqb/ymJzY3nzqOA/8clUefuRx1Tu1GFBzhVSM7l0v/PEnma0jDGAPkYmr8Xu+cn7QHPGfui3MDDmkRO4jhZk6MgMLv9VX2ma871P+KEBoMRphdwmaiXUo520ldE6J6oWfamXrjpe6YONU26jnqihFRrrPLAiCF/YBrUkfXPo2TBBEctifjZ0Hko7l0JspJ52XOPBkrQQuzGlayIEUaA/MAMw0yhKyWlXCfWs7CsOCXtWo=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(346002)(39850400004)(136003)(396003)(376002)(38100700002)(76116006)(52536014)(55016002)(83380400001)(64756008)(66446008)(71200400001)(66946007)(122000001)(5660300002)(9686003)(66556008)(66476007)(478600001)(6506007)(53546011)(86362001)(2906002)(26005)(33656002)(186003)(6916009)(7696005)(8936002)(316002)(8676002)(966005); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Qwk+hWTOyA5+qP5Cu7Sp4p3ubPh/BoPCCj6l5s8EOdnAasiOhPnae9sCQ3AKqSebWIpe/FeJunMPu1CKsmH0SWs4vnYmCdGHGeMlgrNEKNZtUbL4z62MnJBMXYEYQfBN7XSQSZTBccQ3bpp62+B2fr445q2y2C+Boi7HFxlE91absu3nwCFDsZek6i9QG/nYHWFeDKzN0kFyEpuxo9P2St5UY5kldykBvH/SDvh3E7qzrEsV7UsW8gFHa6E6UFn+IDjQgAhc8Z8LZmH4+X7p95c+Co46JCk/PaAbJhSkiGQ3lEpYnnl2Fc/H+Qtwxt53MFDLVyUjNvJ/hjjIGFR+9cKBqBSyQ8LeIhDY5jUxWKbtxRrjpQUXclp8Jh1EX79NSNmpwaF/EdEBV/XxMrSRTIhdpMkUm/IC71WCMeMEe/ytWJr2sivTMtfyYN5YvL5nS3hyN7WOTG2jUKvQu1TihE3kQ/BgJBYsexVo0zX4ENDGqtCb0KvGCpT3LqydM7IdxUnd6WDHsiKGrwRFfXNhB5zAs42DXUK89E1BhR3gJgcnmB5t7qES+Qhb4E7eFKs/RHFdjnkbNof57aKdoN3DrQXNcKEq+YpkgD7tD54weDRk16W1bv+uBF1gDNETq6XZU2q6i5wCqBnhszUVGheSYTavgbpKkN+vjmSgyYYoFAGe6ruMjholuF4tRO/FizpxST2qLbawkuTiev0dh4/O6x0uTfBH9/7KxjcYJV3SqZF5L5cq2uNJmTNX3uqRLQI/wDs2PeOc/KTxOuVad9b1e2wbgxnuxS4//R3AXK8rTJYbutaSBFmzziyZSioWEzYM+W8zfbvPKPlRnP9PDYMeI9eJr+cstQtjDriz1UqG4xuiWdZVSsh8L/54EIGZ7P+rsI9LeRlTbd7DAtzQhnljLTNVsScZ6vb81mOaJfsTonCb57La6LdHCF6bqVMgAgY/KX+Rko7ObKu5UpEvJqjLOBU1WDfp2Q+uSwNeHw1ruSH4Pe7ddIzUbtUQC/7slFzK+W8WXhMEYWf2JQcC77CJSEUKGcROybeFWdMfCRVQPoSlUs6j4hIRH6nmMgI7jG2NPv7rmGmrzssRCep7huryr+9jhcCxd547nDOOxoW607ZIy8tEC/qaxLz07QJEcqmCOqwII91M0pSp86q+f4sNNuzI+P+9fpcW7rC4JwbhGYHtongKatH05TvW6wWF3kGpfxGn7hMwNaPpmuSq5Z1ztCd6KLgrnFh3wJ13Vswnb0jBbsByHgOpj1ssNIApi04Wrqb0SOxy1GGtzF0IXpQ9JkvmZoucskX02naVzediZoo6lLP0V+Q7HgP46ntasuy9
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB8PR08MB4108
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT041.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: c59e1720-ff37-49fe-38ea-08d934d62321
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 5g94eVOB//NMdz5tKFlnzHrj3E0/ANermE3D0mcFc6738CeS3qhR03iGxqICqClA667847wQjFHSG9RgRDuzMwdhSmNRtiFAuC2qd4Eivz+WSsaN0WcjNHYgb9B7E0MObneeDxXzbRXFBkgVXOiOSGFE76DN+GvPtGSyctaBDOlIuRzdD4KKYPSOG2grwTm7k1ON2UZm7gHUx6GphwRIZCSCtuGfmn0iooXmNZ0E/g+d7/5R60vMP/kT2PmP/599YazsEi8Do0a7mpoQ27QZrlX9jJrq1DWfV0y8cDLOEp/GdbwCbeUAgj8NgIxQRg/o07b5W+yQkKc94VM32KC7CKLEHMk3PXWSi2yYm9Mcg3kCkZgs1iG650/UewF5aqQWlWtFTJ6Q8RZkczFMbYwcqRkkjBq7Ff+TYTEVMfddZxo+KzREre3ttlXUK7pHnwc44tOoqzpVudQf5qZFpEt0UINrJox0BzLS0itF2bsvsEafOATlTwD0qnosR4ee9+pmKHxVkb/0IozP9crfvFnkxsPDZjLXzxmdAnVFg37eyM2XLcfWxykzLqALLroJKJSc/ydCpfAXDf4KR/pKgW+Sn15k9aSfyHHPw2gsZYj8wO9/weF4pz2iD10I/vNaxBWFYZm8JqLiYjTlW5NOLQXUONTpUhNaWTga8TcJtiQm70QUtiQNqlJGVIU3v4c6eDprBc7MzOabAESyigXoVP2cWWE07YEXHK/g/QFsGqNUna6aYcmti/Q/tDPU/Skl0RbFUeTzjAGYQvU7E73JrljLFg==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(39840400004)(396003)(376002)(346002)(136003)(46966006)(36840700001)(33656002)(8936002)(966005)(52536014)(86362001)(5660300002)(356005)(478600001)(82310400003)(9686003)(55016002)(2906002)(83380400001)(6916009)(7696005)(336012)(70206006)(316002)(26005)(81166007)(6506007)(36860700001)(53546011)(8676002)(70586007)(47076005)(186003); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Jun 2021 17:01:03.9515 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 624e5caa-8173-4f15-876d-08d934d62790
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT041.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB6282
Archived-At: <https://mailarchive.ietf.org/arch/msg/danish/STK1kZ6np-p9vwPvkYIHAH3K2og>
Subject: Re: [Danish] Charter Text and the Problem Statement
X-BeenThere: danish@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: DANE AutheNtication for Iot Service Hardening <danish.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/danish>, <mailto:danish-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/danish/>
List-Post: <mailto:danish@ietf.org>
List-Help: <mailto:danish-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/danish>, <mailto:danish-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jun 2021 17:01:14 -0000

Hi Viktor,

Thanks for the clarification.

What other information do you envision storing in the DNS besides the public keys?

Ciao
Hannes

PS: Btw, I don't think the comparison to WebPKI is necessary because (a) the WebPKI is not used in the IoT context and (b) the WebPKI focuses on server certificates.

-----Original Message-----
From: Danish <danish-bounces@ietf.org> On Behalf Of Viktor Dukhovni
Sent: Monday, June 21, 2021 6:42 PM
To: danish@ietf.org
Subject: Re: [Danish] Charter Text and the Problem Statement

> On 21 Jun 2021, at 1:10 am, Hannes Tschofenig <Hannes.Tschofenig@arm.com> wrote:
>
> In the past we used different keys for different purposes. A manufacturer provided key was used for a relatively small number of tasks (typically for obtaining operational keys). For use with application services we used a different key. We used yet another key for firmware updates and again another for attestation.
>
> What has changed?

FWIW, nothing about DANE suggests using a single key for multiple purposes.  On the contrary for server identity, DANE has a much better story than WebPKI, because the server is authenticated by port and name, not just name, which makes it easier (with DANE-EE(3)) to field a separate key for each service endpoint.

If we're extending DANE to client identities, we can again create application-specific names, with a separate key for each application:


    _app1.device12345.example.com. IN TLSA 3 1 1 ...
    _app2.device12345.example.com. IN TLSA 3 1 1 ...
    ...

Just register appropriate special-use labels for each distinct application-specific key, perhaps even multiple keys for a single application where it makes sense to have key separation.

If the protocol in question is unrelated to TLS, one should consider using a new record type, other than TLSA.  There may be additional data beyond the key value or digest that would be beneficial to return.

--
--
        Viktor.

--
Danish mailing list
Danish@ietf.org
https://www.ietf.org/mailman/listinfo/danish
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.