Re: Last Call: <draft-ietf-dane-openpgpkey-07.txt>

Harald Alvestrand <harald@alvestrand.no> Tue, 16 February 2016 10:07 UTC

Return-Path: <harald@alvestrand.no>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6FF871B2E2F for <ietf@ietfa.amsl.com>; Tue, 16 Feb 2016 02:07:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.906
X-Spam-Level:
X-Spam-Status: No, score=-1.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.006] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T4B_nyq-rxDv for <ietf@ietfa.amsl.com>; Tue, 16 Feb 2016 02:07:33 -0800 (PST)
Received: from mork.alvestrand.no (mork.alvestrand.no [IPv6:2001:700:1:2::117]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 176D01B2E2C for <ietf@ietf.org>; Tue, 16 Feb 2016 02:07:32 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mork.alvestrand.no (Postfix) with ESMTP id 4FE197C767B; Tue, 16 Feb 2016 11:07:30 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at alvestrand.no
Received: from mork.alvestrand.no ([127.0.0.1]) by localhost (mork.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o7NN-7xxa6UY; Tue, 16 Feb 2016 11:07:29 +0100 (CET)
Received: from hta-hippo.lul.corp.google.com (unknown [74.125.57.93]) by mork.alvestrand.no (Postfix) with ESMTPSA id 7F2177C7626; Tue, 16 Feb 2016 11:07:29 +0100 (CET)
Subject: Re: Last Call: <draft-ietf-dane-openpgpkey-07.txt>
To: Paul Wouters <paul@nohats.ca>
References: <56C09764.1020700@hagfish.name> <3E8BDD1E0C94F17DFD06C92C@JcK-HP5.jck.com> <56C18E14.8060608@hagfish.name> <56C1EFE3.4020405@alvestrand.no> <28459DA6030B0DF750F2CD57@JcK-HP5.jck.com> <56C20EE5.4060009@alvestrand.no> <alpine.LFD.2.20.1602151813120.5626@bofh.nohats.ca>
From: Harald Alvestrand <harald@alvestrand.no>
Message-ID: <56C2F4E1.2000207@alvestrand.no>
Date: Tue, 16 Feb 2016 11:07:29 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1
MIME-Version: 1.0
In-Reply-To: <alpine.LFD.2.20.1602151813120.5626@bofh.nohats.ca>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/zqtimdR9CDHDgMYJ1YcO1qBDyXg>
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Feb 2016 10:07:35 -0000

On 02/16/2016 12:14 AM, Paul Wouters wrote:
> On Mon, 15 Feb 2016, Harald Alvestrand wrote:
>
>> BTW, this text from the draft is obviously not saying what it intended
>> to say:
>>
>>   o  The user name (the "left-hand side" of the email address, called
>>      the "local-part" in the mail message format definition [RFC5322]
>>      and the local-part in the specification for internationalized
>>      email [RFC6530]) should already be encoded in UTF-8 (or its subset
>>      ASCII).  If it is written in another encoding it should be
>>      converted to UTF-8 and then hashed using the SHA2-256 [RFC5754]
>>      algorithm, with the hash truncated to 28 octets and represented in
>>      its hexadecimal representation, to become the left-most label in
>>      the prepared domain name.  Truncation comes from the right-most
>>      octets.  This does not include the at symbol ("@") that separates
>>      the left and right sides of the email address.
>>
>> As written, it states that hashing is only applied to strings that are
>> not originally in UTF-8 - but the "for example" text below makes it
>> clear that this is not intended.
>
> That text is not quoted from the 07 draft, because 07 states:
>
>    o  The user name (the "left-hand side" of the email address, called
>       the "local-part" in the mail message format definition [RFC5322]
>       and the local-part in the specification for internationalized
>       email [RFC6530]) is encoded in UTF-8 (or its subset ASCII).  If
>       the local-part is written in another encoding it MUST be converted
>       to UTF-8.
>
>    o  The local-part is hashed using the SHA2-256 [RFC5754] algorithm,
>       with the hash truncated to 28 octets and represented in its
>       hexadecimal representation, to become the left-most label in the
>       prepared domain name.
>
> Paul
>
Oops - yes, I was reading -06. Good fix!