Re: [certid] Review of draft-saintandre-tls-server-id-check

Dave Cridland <dave@cridland.net> Mon, 13 September 2010 19:12 UTC

Return-Path: <dave@cridland.net>
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 87D6A3A6A97; Mon, 13 Sep 2010 12:12:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.467
X-Spam-Level:
X-Spam-Status: No, score=-2.467 tagged_above=-999 required=5 tests=[AWL=0.132, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2HXpL8Gl+-pZ; Mon, 13 Sep 2010 12:12:25 -0700 (PDT)
Received: from peirce.dave.cridland.net (peirce.dave.cridland.net [217.155.137.61]) by core3.amsl.com (Postfix) with ESMTP id A61EF3A69A1; Mon, 13 Sep 2010 12:12:24 -0700 (PDT)
Received: from localhost (localhost.localdomain [127.0.0.1]) by peirce.dave.cridland.net (Postfix) with ESMTP id 46B5711680C3; Mon, 13 Sep 2010 20:12:50 +0100 (BST)
X-Virus-Scanned: Debian amavisd-new at peirce.dave.cridland.net
Received: from peirce.dave.cridland.net ([127.0.0.1]) by localhost (peirce.dave.cridland.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EjKgYVxG0MgK; Mon, 13 Sep 2010 20:12:47 +0100 (BST)
Received: from puncture (unknown [217.155.137.60]) by peirce.dave.cridland.net (Postfix) with ESMTPA id 5318011680AA; Mon, 13 Sep 2010 20:12:47 +0100 (BST)
Subject: Re: [certid] Review of draft-saintandre-tls-server-id-check
References: <C8B43307.EE07%stefan@aaa-sec.com>
In-Reply-To: <C8B43307.EE07%stefan@aaa-sec.com>
MIME-Version: 1.0
Message-Id: <8252.1284405167.326805@puncture>
Date: Mon, 13 Sep 2010 20:12:47 +0100
From: Dave Cridland <dave@cridland.net>
To: Stefan Santesson <stefan@aaa-sec.com>, Bernard Aboba <bernard_aboba@hotmail.com>, IETF cert-based identity <certid@ietf.org>, IETF-Discussion <ietf@ietf.org>, Shumon Huque <shuque@isc.upenn.edu>, Peter Saint-Andre <stpeter@stpeter.im>
Content-Type: text/plain; delsp="yes"; charset="us-ascii"; format="flowed"
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Sep 2010 19:12:27 -0000

On Mon Sep 13 18:59:03 2010, Stefan Santesson wrote:
> I agree here. Both to this and to former speakers stating that the  
> assertion
> is made by the CA and no the subject.
> 
> 
Well, I'd say the assertion is the presence of the SAN in the cert. I  
mean, an assertion is a positive statement made *without* evidence.  
The evidence is then the signature of the issuer, who certifies the  
assertion - it doesn't matter who makes that assertion. But anyway,  
that's somewhat moot, and as Shumon points out, we needn't care about  
who authorized what unto whom.


> I'm struggling with the most easy to understand text, but I think  
> this says
> at least the correct thing:
> 
>       "A DNS domain name, representing a domain for which the  
> certificate
>        issuer has asserted that the certified subject is a  
> legitimate
>        provider of the identified service."

"The requested DNS domain name for the specified service. That is,  
the domain name which would be found in the URI for the service, and  
other protocol identifiers of a similar nature. Where the service is  
directly requested by hostname, this domain name would be the  
requested hostname."

I think that covers all the cases I'd expect by example, without  
worrying about who's asserting and certifying. No doubt someone will  
reword with a sprinkling of 2119.

Dave.
-- 
Dave Cridland - mailto:dave@cridland.net - xmpp:dwd@dave.cridland.net
  - acap://acap.dave.cridland.net/byowner/user/dwd/bookmarks/
  - http://dave.cridland.net/
Infotrope Polymer - ACAP, IMAP, ESMTP, and Lemonade