Re: (short version) Re: Last Call: <draft-faltstrom-uri-10.txt> (The Uniform Resource Identifier (URI) DNS Resource Record) to Proposed Standard

Nico Williams <nico@cryptonector.com> Fri, 27 February 2015 19:50 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 788F21AD358 for <ietf@ietfa.amsl.com>; Fri, 27 Feb 2015 11:50:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.666
X-Spam-Level:
X-Spam-Status: No, score=-1.666 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7SkeBRO0ERiW for <ietf@ietfa.amsl.com>; Fri, 27 Feb 2015 11:50:32 -0800 (PST)
Received: from homiemail-a77.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id 9EF621AD363 for <ietf@ietf.org>; Fri, 27 Feb 2015 11:50:23 -0800 (PST)
Received: from homiemail-a77.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a77.g.dreamhost.com (Postfix) with ESMTP id 5D5A49405E for <ietf@ietf.org>; Fri, 27 Feb 2015 11:50:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h=date :from:to:subject:message-id:references:mime-version:content-type :in-reply-to; s=cryptonector.com; bh=RiJr7TeNpjO05N6nrnf96jYqG8c =; b=MzfrAYJyJNsm7US5F324Ci6WTNqNdUNIHHjihPBBWXthNzxcQY7T0dhy8YE a3LdAyCCfJ7zJzI3Ne1yH7WRhGzTjuqNiC+BGymnfL4xG3Du5ZOYgpynP2SUkgl5 GsZ3lCILVljfqiwQVa4WHEXPq46gmi673j6DN5APVmVMYKHM=
Received: from localhost (108-207-244-174.lightspeed.austtx.sbcglobal.net [108.207.244.174]) (Authenticated sender: nico@cryptonector.com) by homiemail-a77.g.dreamhost.com (Postfix) with ESMTPA id 1E3109405C for <ietf@ietf.org>; Fri, 27 Feb 2015 11:50:23 -0800 (PST)
Date: Fri, 27 Feb 2015 13:50:22 -0600
From: Nico Williams <nico@cryptonector.com>
To: ietf@ietf.org
Subject: Re: (short version) Re: Last Call: <draft-faltstrom-uri-10.txt> (The Uniform Resource Identifier (URI) DNS Resource Record) to Proposed Standard
Message-ID: <20150227195020.GB11145@localhost>
References: <2DF7230C-D1D8-4B21-9003-B336108A38CB@vpnc.org> <20150224172649.GX1260@mournblade.imrryr.org> <tslvbircj0d.fsf@mit.edu> <0325DF3F-17F3-4400-BDEA-EDB5334BF35C@frobbit.se> <20150225180227.GT1260@mournblade.imrryr.org> <7AB921D35A7F9B23A53BD11A@JcK-HP8200.jck.com> <tslvbip8io6.fsf@mit.edu> <54F09A35.9060506@qti.qualcomm.com> <CAK3OfOjTs84ckEXanQrtQZU-ei-o5C0wRLQq4inQ8mb5cKXAow@mail.gmail.com> <20150227182707.GW1260@mournblade.imrryr.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20150227182707.GW1260@mournblade.imrryr.org>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/ShVESvpAPlUTejkF5UTW0Kr8tWY>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Feb 2015 19:50:33 -0000

On Fri, Feb 27, 2015 at 06:27:07PM +0000, Viktor Dukhovni wrote:
> > I would much prefer a Standards-Track document that says to
> > authenticate the origin domainname as follows:
> > 
> >  - use DNSSEC for all DNS queries needed to find the URI RRs and DANE
> > to authenticate the authorities of the resulting URIs
> > 
> > or
> > 
> >  - expect the target authorities to have certificates that
> > authenticate the origin, using SNI if need be.
> > 
> > I would still drop everything related to NAPTR and DDDS.
> 
> That works for me, and is in reasonable alignment with
> 
> 	draft-ietf-dane-srv

Good.

> which ignoring the gory details says essentially the same thing,
> but with the choice made dynamically, based on presence of "secure"
> SRV and TLSA RRsets, rather than as a static prior dichotomy.

I did not mean to imply a static choice.  Dynamic is fine.

> I am also fine with the informational variant.  Either way, perhaps
> an informational reference to the DANE SRV draft would be helpful.

The problem with an FYI that doesn't say these things is that people
will make use of the URI RR type without knowing the trap they're
walking into.  A document with proper text will do.

Alternatively, publish a BCP or Standards-Track RFC about how to use
indirection via DNS securely, then publish this I-D with merely a
reference to the former.  I think just fixing this I-D is the easier way
forward, and it's just one short section of prose.

> As an instigator of the security sub-discussion, I just wanted to
> make sure than the document did not claim that introducing indirection
> into HTTPS has minor security consequences.  Rather it is a significant
> change in the threat analysis for any application that makes the switch.

Yes, but given that the RR type has been registered and used, we should
not now hide our heads in the sand.

> Likely there are existing applications that have glossed over this
> issue (going through the motions) with MX and SRV records, but any
> such poor practices are not IMHO sufficient grounds to say that
> the current text's security considerations match the scope of the
> proposed semantics.

Right, SMTP is one thing.  So it's been not secure for ages, but we've
also all understood this (and you're fixing it).  It's different for
*new* uses.

> And I still support the proposed semantics, just with eyes wide
> open to the security implications.

Right.

Nico
--