[hackathon] ACME STAR

"Fossati, Thomas (Nokia - GB/Cambridge, UK)" <thomas.fossati@nokia.com> Mon, 26 June 2017 08:07 UTC

Return-Path: <thomas.fossati@nokia.com>
X-Original-To: hackathon@ietfa.amsl.com
Delivered-To: hackathon@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6314E12869B for <hackathon@ietfa.amsl.com>; Mon, 26 Jun 2017 01:07:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B5lVV9XziltZ for <hackathon@ietfa.amsl.com>; Mon, 26 Jun 2017 01:07:39 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0139.outbound.protection.outlook.com [104.47.2.139]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 754F7126579 for <hackathon@ietf.org>; Mon, 26 Jun 2017 01:07:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=ox2D5llsW5wqXIdz4K2BIgwc9Lz3D4nieuICcxEy5Mc=; b=pftN3jd2TnW1liBEccEoWx5xnXDeFYzeKnernuhNDlu76ZXQzejQbqd6YuVeJb+t3iduUJuSw9VNCe/lBf6X5oovNogf9NGKvfZY3rwGW76apBSiLOtBZX1Tc4Nw9n3kih1nzy9ZdlGW9/QFw+MlzuMrOc5CCFb2gvV164f+BVw=
Received: from VI1PR07MB1102.eurprd07.prod.outlook.com (10.163.168.26) by VI1PR07MB0816.eurprd07.prod.outlook.com (10.161.107.151) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1220.5; Mon, 26 Jun 2017 08:07:36 +0000
Received: from VI1PR07MB1102.eurprd07.prod.outlook.com ([fe80::f53a:50dc:dcfe:9845]) by VI1PR07MB1102.eurprd07.prod.outlook.com ([fe80::f53a:50dc:dcfe:9845%13]) with mapi id 15.01.1220.011; Mon, 26 Jun 2017 08:07:35 +0000
From: "Fossati, Thomas (Nokia - GB/Cambridge, UK)" <thomas.fossati@nokia.com>
To: "hackathon@ietf.org" <hackathon@ietf.org>
CC: "Fossati, Thomas (Nokia - GB/Cambridge, UK)" <thomas.fossati@nokia.com>
Thread-Topic: ACME STAR
Thread-Index: AQHS7lNElmw+wDey2ESeSaaI8y1cHQ==
Date: Mon, 26 Jun 2017 08:07:35 +0000
Message-ID: <44F1D4FE-5781-4457-B676-288BC4E6ABAD@nokia.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.20.0.170309
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=nokia.com;
x-originating-ip: [81.134.152.4]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; VI1PR07MB0816; 7:ZmTVMpCjLcewUFMHa8Ucww3UVjDzxPhlrmDGI8ghP+KNPFUBWstveu24L9zrDs2/l1Z4ZvRSdZZFZKwRA4gVGxi76iMu07kbaeQRr2oeR6GBQvFBo71oA6pUX/2bPjt3nTY7d/kMr4xbPzdI0xqEfr5p47i60VcF1+cqAktXy0N3yKLfshkRkzN2tHHDGAqGLyYXgW959CPpMkon3J9nduaqCeKeQmk6pjsIL9ckbxK5Uuye4Gz5hI697SN1kn8gSP6m6Ld9eGpuVZiv+08waHSTF9v3n06KFgjcDTWg/UIZ/Zbm1rga0zXIsxjqOv5Ic9EIRaJnawCr4FS84FavzsGImJqN1G5Us+BXUkFaUVg0xShhsU+AB9UonoVZ4xg2K19HAC7C5axClcTbHEiRUay2xOyh1MZC4y+F7acNrNwtzZtEXzevy3aXbG7kXvr0sY+L64RtuGsvcH5ih/i/Eb+XxGrpQ/YOMRybXWTJQ82oxTDbiQpPUts23bIgANpdUvuoBtX3N/W+AwCNgoqEXKzBAtufItVULAZA6JYSQv4XbaQ7sp5BL3jam8ZfYlhLrtKxsKbGH62lAQNUo1FcKwn53ubnmLHQjp2e/wmW6TJPiDJv8TmENfB150ejpbc5ME0oqiFVE5xb2vtP/emES36wo/zJB6Q3Lqz8rWOJHOnH+kd/zpgVuYsqgYsqJupdtJvnA7QMSKbCGcOzZ3A0sLzPgkL1AwfGGbtZTvf/pMlQAVw5TGn5urwUMcmUZZk4Jnd0slFNms+PnhVxdv0S3IYwNQG56Y1M/w/cGCAq0KI=
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10019020)(39450400003)(39860400002)(39840400002)(39850400002)(39410400002)(6306002)(50986999)(14454004)(7906003)(6916009)(25786009)(2351001)(5660300001)(7116003)(6436002)(6506006)(36756003)(33656002)(3660700001)(4326008)(606005)(99286003)(54896002)(2900100001)(8936002)(478600001)(81166006)(1730700003)(3480700004)(3280700002)(966005)(8676002)(2906002)(2501003)(66066001)(7736002)(54356999)(221733001)(6486002)(53936002)(82746002)(86362001)(83506001)(102836003)(189998001)(236005)(3846002)(6116002)(107886003)(83716003)(38730400002)(110136004)(6512007)(4001350100001)(215093002); DIR:OUT; SFP:1102; SCL:1; SRVR:VI1PR07MB0816; H:VI1PR07MB1102.eurprd07.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
x-ms-office365-filtering-correlation-id: 38c0a12d-dbff-4013-5a66-08d4bc6a678e
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(48565401081)(300000503095)(300135400095)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506067)(300135500095); SRVR:VI1PR07MB0816;
x-ms-traffictypediagnostic: VI1PR07MB0816:
x-microsoft-antispam-prvs: <VI1PR07MB081696086A099D0F9BA5AF5980DF0@VI1PR07MB0816.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(151999592597050)(166708455590820)(26388249023172)(236129657087228)(82608151540597)(148574349560750)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(5005006)(8121501046)(3002001)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(6055026)(6041248)(20161123564025)(20161123562025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:VI1PR07MB0816; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:VI1PR07MB0816;
x-forefront-prvs: 0350D7A55D
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_44F1D4FE57814457B676288BC4E6ABADnokiacom_"
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jun 2017 08:07:35.4926 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR07MB0816
Archived-At: <https://mailarchive.ietf.org/arch/msg/hackathon/-obB7GmCSY9s6VZyc7yRljKjWQI>
Subject: [hackathon] ACME STAR
X-BeenThere: hackathon@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussion regarding past, present, and future IETF hackathons." <hackathon.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hackathon>, <mailto:hackathon-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/hackathon/>
List-Post: <mailto:hackathon@ietf.org>
List-Help: <mailto:hackathon-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hackathon>, <mailto:hackathon-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Jun 2017 08:07:41 -0000

Hi again,



ACME STAR

§  Champions

§  Thomas Fossati (thomas.fossati@nokia.com)

§  Integrate ACME-STAR with STAR-request

§  ACME-STAR [https://tools.ietf.org/html/draft-ietf-acme-star-00]<https://tools.ietf.org/html/draft-ietf-acme-star-00%5D> is an ACME extension that allows automatic renewal of short-term certificates

§  STAR-request [https://tools.ietf.org/html/draft-sheffer-acme-star-request-01]<https://tools.ietf.org/html/draft-sheffer-acme-star-request-01%5D> is a protocol for asking a domain name holder a rolling set of short term certificates for a keypair that is held by a third party with a domain holder's name. Typically, the use case is that of a CDN edge cache that needs to answer HTTPS requests for URLs that have the domain name holder's authority.

§  Code repo

§  https://github.com/mami-project/lurk

§  https://github.com/letsencrypt/boulder

§  Project Goals

§  implement the two specs as far as needed to implement an “happy” end-to-end scenario



Cheers, t