Re: [pkix] [smime] Key lookup service via draft-bhjl-x509-srv-00

"Miller, Timothy J." <tmiller@mitre.org> Wed, 23 March 2016 20:00 UTC

Return-Path: <tmiller@mitre.org>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55FF812D7DE; Wed, 23 Mar 2016 13:00:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mitre.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bR0G2pKhr2u4; Wed, 23 Mar 2016 13:00:22 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id D81C612D891; Wed, 23 Mar 2016 13:00:12 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 7F6436C0167; Wed, 23 Mar 2016 16:00:12 -0400 (EDT)
Received: from imshyb02.MITRE.ORG (imshyb02.mitre.org [129.83.29.3]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id 6D2526C0BDE; Wed, 23 Mar 2016 16:00:12 -0400 (EDT)
Received: from imshyb01.MITRE.ORG (129.83.29.2) by imshyb02.MITRE.ORG (129.83.29.3) with Microsoft SMTP Server (TLS) id 15.0.1130.7; Wed, 23 Mar 2016 16:00:12 -0400
Received: from gcc01-CY1-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1130.7 via Frontend Transport; Wed, 23 Mar 2016 16:00:11 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mitre.onmicrosoft.com; s=selector1-mitre-org; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=RF+nkEUgUxWl4mgs43bbcBXqlRKbgprngH3X7VlYv+U=; b=LoW227zfkz6J5siJkavIxMOvOnB9mWNk4aWSbffC1aAogL0Pn1+76X/Bu2uJDzHxzsP25EfSrGael2SzFQyf9y5JZ7au0gR02kTLRcYDtK9v1WgHdgaHrNYhH04W7VjTB4SsgRPbqa5Wvs2nLCutsC30iDw3xOY/Qjf1vgkDso0=
Received: from BY1PR09MB0920.namprd09.prod.outlook.com (10.162.144.157) by BY1PR09MB0920.namprd09.prod.outlook.com (10.162.144.157) with Microsoft SMTP Server (TLS) id 15.1.434.16; Wed, 23 Mar 2016 20:00:10 +0000
Received: from BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) by BY1PR09MB0920.namprd09.prod.outlook.com ([10.162.144.157]) with mapi id 15.01.0434.019; Wed, 23 Mar 2016 20:00:10 +0000
From: "Miller, Timothy J." <tmiller@mitre.org>
To: John R Levine <johnl@taugh.com>, Wei Chuang <weihaw@google.com>
Thread-Topic: [smime] Key lookup service via draft-bhjl-x509-srv-00
Thread-Index: AQHRhTGmh22EPby4TE+kk5RKeaJMBp9nWoUA///EeQA=
Date: Wed, 23 Mar 2016 20:00:09 +0000
Message-ID: <FB501B0B-999D-45E4-A739-4D561A25275B@mitre.org>
References: <CAAFsWK3HEXDgqONxBohBCGMKk2qMa230fxcNEaGhoTwQZVYQoQ@mail.gmail.com> <alpine.OSX.2.11.1603221443230.18473@ary.lan> <CAAFsWK2Xbw0eU2oz4edtmPH5PhwJgQkTYWKhFruZnCnD37c_CQ@mail.gmail.com> <alpine.OSX.2.11.1603231431110.4624@ary.lan>
In-Reply-To: <alpine.OSX.2.11.1603231431110.4624@ary.lan>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/0.0.0.160212
authentication-results: taugh.com; dkim=none (message not signed) header.d=none;taugh.com; dmarc=none action=none header.from=mitre.org;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [192.80.55.87]
x-ms-office365-filtering-correlation-id: 349701db-b6cb-4a67-7710-08d35355bd28
x-microsoft-exchange-diagnostics: 1; BY1PR09MB0920; 5:Tx98D8Cf7UnvyOjze0Iyoy0yFVyw9udYmtKJUWz90f9Og/6FwgouxD2Pro4VajokrZLNC3J/2zjnpEICl1BbWs2/NrftRQfWB+HsygpACn/L/tDZJc1N6v/GMlSiR+d5uXFWHpRGwYLu8rbELb3vIw==; 24:BzU1rdqP2Oq8+U8DXcSMq5S4gj6sme00iz/G4mZ81V0mdLFJo61jhok3FJ5r2DZ5x7YvYijlzO5+lDaUL2tgmUjls7InKNhm5WPmNCh4XAA=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY1PR09MB0920;
x-microsoft-antispam-prvs: <BY1PR09MB092087FEDCB054BDE86FF911AE810@BY1PR09MB0920.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001); SRVR:BY1PR09MB0920; BCL:0; PCL:0; RULEID:; SRVR:BY1PR09MB0920;
x-forefront-prvs: 08902E536D
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(24454002)(377454003)(4001350100001)(5008740100001)(92566002)(3660700001)(230783001)(11100500001)(86362001)(189998001)(5002640100001)(2950100001)(5001770100001)(2900100001)(3280700002)(66066001)(33656002)(586003)(1220700001)(4326007)(76176999)(1096002)(36756003)(83716003)(54356999)(93886004)(10400500002)(2906002)(50986999)(19580395003)(19580405001)(87936001)(81166005)(3846002)(5004730100002)(99286002)(102836003)(82746002)(77096005)(83506001)(122556002)(6116002)(106116001); DIR:OUT; SFP:1101; SCL:1; SRVR:BY1PR09MB0920; H:BY1PR09MB0920.namprd09.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <875080D3697B75499D48BEF82AF3E95A@namprd09.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Mar 2016 20:00:09.8524 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR09MB0920
X-OriginatorOrg: mitre.org
Archived-At: <http://mailarchive.ietf.org/arch/msg/pkix/0X3FexIT8voJC2h8ooHKWiug0yA>
Cc: PKIX <pkix@ietf.org>, Brian Haberman <brian@innovationslab.net>, IETF SMIME <smime@ietf.org>
Subject: Re: [pkix] [smime] Key lookup service via draft-bhjl-x509-srv-00
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Mar 2016 20:00:24 -0000

On 3/23/16, 1:33 PM, "smime on behalf of John R Levine" <smime-bounces@ietf.org on behalf of johnl@taugh.com> wrote:



>If the WG thinks the domain's key should be authoritative, that'd be fine
>with me.  We didn't want to make any unilateral changes to the trust model 
>without it being clear that it's a change and that there's consensus 
>behind it.

So an authoritative service makes sense in an Enterprise context, but not in a consumer context.  How do you preserve consumer choice if Yahoo! owns their email service, but they want to certify keys elsewhere?

-- T