[keyassure] [dane] #23: Asserting DANE exclusivity for an entire domain

"dane issue tracker" <trac+dane@trac.tools.ietf.org> Mon, 21 March 2011 19:31 UTC

Return-Path: <trac+dane@trac.tools.ietf.org>
X-Original-To: keyassure@core3.amsl.com
Delivered-To: keyassure@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3AFBF3A6847 for <keyassure@core3.amsl.com>; Mon, 21 Mar 2011 12:31:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level:
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QeUURJD5T4c1 for <keyassure@core3.amsl.com>; Mon, 21 Mar 2011 12:31:01 -0700 (PDT)
Received: from zinfandel.tools.ietf.org (unknown [IPv6:2001:1890:1112:1::2a]) by core3.amsl.com (Postfix) with ESMTP id 421363A6834 for <keyassure@ietf.org>; Mon, 21 Mar 2011 12:31:01 -0700 (PDT)
Received: from localhost ([::1] helo=zinfandel.tools.ietf.org) by zinfandel.tools.ietf.org with esmtp (Exim 4.74) (envelope-from <trac+dane@trac.tools.ietf.org>) id 1Q1kq9-0002EH-Ng; Mon, 21 Mar 2011 12:32:33 -0700
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: dane issue tracker <trac+dane@trac.tools.ietf.org>
X-Trac-Version: 0.11.7
Precedence: bulk
Auto-Submitted: auto-generated
X-Mailer: Trac 0.11.7, by Edgewall Software
To: matt@mattmccutchen.net
X-Trac-Project: dane
Date: Mon, 21 Mar 2011 19:32:33 -0000
X-URL: http://tools.ietf.org/dane/
X-Trac-Ticket-URL: http://trac.tools.ietf.org/wg/dane/trac/ticket/23
Message-ID: <061.05db8c262c83655cb47a8699cab6c2ac@trac.tools.ietf.org>
X-Trac-Ticket-ID: 23
X-SA-Exim-Connect-IP: ::1
X-SA-Exim-Rcpt-To: matt@mattmccutchen.net, keyassure@ietf.org
X-SA-Exim-Mail-From: trac+dane@trac.tools.ietf.org
X-SA-Exim-Scanned: No (on zinfandel.tools.ietf.org); SAEximRunCond expanded to false
Cc: keyassure@ietf.org
Subject: [keyassure] [dane] #23: Asserting DANE exclusivity for an entire domain
X-BeenThere: keyassure@ietf.org
X-Mailman-Version: 2.1.9
List-Id: Key Assurance With DNSSEC <keyassure.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/keyassure>, <mailto:keyassure-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyassure>
List-Post: <mailto:keyassure@ietf.org>
List-Help: <mailto:keyassure-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyassure>, <mailto:keyassure-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Mar 2011 19:31:02 -0000

#23: Asserting DANE exclusivity for an entire domain

 I would like to be able to assert DANE exclusivity for an entire domain so
 that, with respect to clients that check DANE first and fall back to a
 mainstream public CA list, a public CA cannot fabricate a TLS service I do
 not offer.

 Previously discussed in [http://www.ietf.org/mail-
 archive/web/keyassure/current/msg01641.html this thread], but no final
 decision was reached.

 One approach to achieve this is to compose (1) a means of asserting the
 nonexistence of a TLS service at a (hostname, transport, port) triple and
 (2) a means of applying such an assertion to an entire domain except where
 otherwise specified.  Zack Weinberg made a reasonable proposal for (1):
 use a single RR with "certificate type" 0 and no "certificate for
 association".  (2) can be done with DNSSEC wildcards, but that is a little
 messy and will seriously bloat the zone if several different RRtypes each
 require this treatment.

-- 
------------------------------------+---------------------------------------
 Reporter:  matt@…                  |       Owner:     
     Type:  enhancement             |      Status:  new
 Priority:  major                   |   Milestone:     
Component:  protocol                |     Version:     
 Severity:  -                       |    Keywords:     
------------------------------------+---------------------------------------

Ticket URL: <http://trac.tools.ietf.org/wg/dane/trac/ticket/23>
dane <http://tools.ietf.org/dane/>