Re: [pkix] [saag] Fwd: New Version Notification for draft-belyavskiy-certificate-limitation-policy-04.txt

Dmitry Belyavsky <beldmit@gmail.com> Wed, 20 September 2017 13:22 UTC

Return-Path: <beldmit@gmail.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8BC76133205; Wed, 20 Sep 2017 06:22:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iCtZtxPKn-RN; Wed, 20 Sep 2017 06:21:58 -0700 (PDT)
Received: from mail-wm0-x235.google.com (mail-wm0-x235.google.com [IPv6:2a00:1450:400c:c09::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 685EC134212; Wed, 20 Sep 2017 06:21:58 -0700 (PDT)
Received: by mail-wm0-x235.google.com with SMTP id r68so7151958wmg.3; Wed, 20 Sep 2017 06:21:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=/ntSqCCIbi5IkG8kBgc+o6EXHSWRyN429laHemOqxSM=; b=ogf2l0hNQ6+ZSAgnET/FT8vO/ho9jE4+WC58zPIeyD3qmEuNPs6loLXAXeTq+bMzzT 3MWs5kwuzdSrILEyhXCqq1nnlZUiZW61ZHPHEQSWUGlWoUvxva0K0mRnZ5S6cdb1d16V abZs4i1oreUR0g429UvDjsXbOK58oj8SWymSMhRmJ5zIO4jjURz78fPBGYbHaoB7e2l/ cYxpjH6NZZE6f/pl9CwS1+BZ6AIV1do3x5ntPxvTlkEdflowCbc8Gv/UNlVVXm2X31rA QA7xLQ6n+lBuk6BksfdkAx0oEz/Ef2nPQKpA83BgQabdpIOOSl86glZD64Tg46qlImRH 1KIw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=/ntSqCCIbi5IkG8kBgc+o6EXHSWRyN429laHemOqxSM=; b=Jbex6MMKE9i32dl5am6KAulA/iCUx2RvzeqL0FtuS7d2u4eabRpHvt3ngq2UG1FlCC ZPPvEjBoJSRmdrQgwc0jgHGzxOJm1FFQdlnNQn8MR3gtQSDgjP1vrtG16xeUQxXIocgQ dMbFbepF2P/93Au9aCwX0jimG71hurajBwalHPRUe9D2rdljb+qL3Ik0lbz3BdGcL2Xd vtO+jyBc70CEUZCxPWD7pVzFTf66wMvv8GhaGRhmqINj5aeVpzIJeetLpUHTiTLfwp8Q Ma817piy7ojkdLPp4vhOSV/lWsS6icw/4U7vtX4evSHUnMO+S5SSEC55qGItlYzwDx2i 7Mcw==
X-Gm-Message-State: AHPjjUiWGXJ/Sx0WIMHUk+XphIopqfL2kQZKNLftjz9CEiXOkB6JF+H3 eVMSkVVxcFUScLQNOlZbL8FUclGMNyE4FqC5uY8=
X-Google-Smtp-Source: AOwi7QBotSqgFsU8jOJorTakDVqL7xoy0IBn3No/0KfsXfe8XFIHZI99co7uKUZbX7onAmAoSSuzx7GFAyF7oLQ2ZOo=
X-Received: by 10.80.165.82 with SMTP id z18mr4463837edb.172.1505913716867; Wed, 20 Sep 2017 06:21:56 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.80.220.202 with HTTP; Wed, 20 Sep 2017 06:21:56 -0700 (PDT)
In-Reply-To: <CAJU7zaLsza65gvERm__njLYM82jGWx9ht_QwHi+e6WQAtFKsZA@mail.gmail.com>
References: <150522092693.4724.2532571098567577114.idtracker@ietfa.amsl.com> <CADqLbz+OB86s4E-Ntr6eaEow+sBtxscJ703nGN+PAS7zQmJ==Q@mail.gmail.com> <CAJU7zaLsza65gvERm__njLYM82jGWx9ht_QwHi+e6WQAtFKsZA@mail.gmail.com>
From: Dmitry Belyavsky <beldmit@gmail.com>
Date: Wed, 20 Sep 2017 16:21:56 +0300
Message-ID: <CADqLbz+-86OoH6wJQj4cu4daCUmh6mDPCkmVhbBYnLgv9AmOHw@mail.gmail.com>
To: Nikos Mavrogiannopoulos <nmav@gnutls.org>
Cc: "saag@ietf.org" <saag@ietf.org>, LAMPS <spasm@ietf.org>, dev-security-policy@lists.mozilla.org, pkix@ietf.org
Content-Type: multipart/alternative; boundary="94eb2c0de67c28062305599edcf9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/pkix/4rP1L63bd0mVRwSImUArTVlrW5I>
Subject: Re: [pkix] [saag] Fwd: New Version Notification for draft-belyavskiy-certificate-limitation-policy-04.txt
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Sep 2017 13:22:02 -0000

Dear Nikos

On Wed, Sep 13, 2017 at 9:39 AM, Nikos Mavrogiannopoulos <nmav@gnutls.org>
wrote:

>
> 4. How do you handle extensions to this format?
>
> Overall, why not use X.509 extensions to store such additional
> constraints? We already (in the p11-kit trust store in Fedora/RHEL
> systems) use the notion of stapled extensions to limit certificates
> [0, 1] and seems quite a flexible approach. Have you considered that
> path?
>
> regards,
> Nikos
>
> [0]. https://p11-glue.freedesktop.org/doc/storing-trust-policy/
> storing-trust-model.html
> [1]. http://nmav.gnutls.org/2016/06/restricting-scope-of-ca-
> certificates.html
>

I've looked through the specification. It's OK for me, but I do not get
whether the attached extensions are crypto-protected.
I'm ready to cooperate with you if there is any interest.

-- 
SY, Dmitry Belyavsky