Re: [regext] rfc7484bis: https only?

Patrick Mevzek <pm@dotandco.com> Fri, 21 August 2020 16:59 UTC

Return-Path: <pm@dotandco.com>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 510F43A0DC3 for <regext@ietfa.amsl.com>; Fri, 21 Aug 2020 09:59:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=dotandco.com header.b=YcJGdHMN; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=aWIu0aat
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NjSWppmF1PYu for <regext@ietfa.amsl.com>; Fri, 21 Aug 2020 09:59:56 -0700 (PDT)
Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B2613A0DBD for <regext@ietf.org>; Fri, 21 Aug 2020 09:59:55 -0700 (PDT)
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.west.internal (Postfix) with ESMTP id DFD1FB32 for <regext@ietf.org>; Fri, 21 Aug 2020 12:59:54 -0400 (EDT)
Received: from imap22 ([10.202.2.72]) by compute3.internal (MEProxy); Fri, 21 Aug 2020 12:59:55 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dotandco.com; h= mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm3; bh=xdWkl 23Tt12l+b9yHk3jiTE+qlYlCZOcogO7SGWrizg=; b=YcJGdHMNiNBtiXSn1b1LD VD1mxB1p0lEat0LlPChf2pShGwUA7Ol7/5NDq2i5COYecCfEMcBl64wC785yKP9h 1c274gXrmI/RQNFjVZQ31MJlsTbntBYiFmNzZqnc62x/HynwgNWuKE1IrWgDhz1w NqDPGGgXDMw4n1Rnqt5zQbF25BeGXvDnCeASFWgPEd7O3ruqDkJsjUHAmruFkP+r WRqkNqhR8Zw75yPOy6fL6MfBARxeZZeQFaZ3MWsb6UDUxbhsIwNZNQW5ZdNS8Htm rVdEjAaTWNEgdltRTEP+t28mSsfQ42YCSNNRab8hISSVLJ6r3yhkFezW5DTifRG+ Q==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm3; bh=xdWkl23Tt12l+b9yHk3jiTE+qlYlCZOcogO7SGWri zg=; b=aWIu0aatv3ctX/wWB384zUdhmO4+6lfaViRsBxsTJYWN7ahV/w56nJLv1 I8Vrvpm67RFsMnNen0j5ZGj7yROhY2K8U6Z38AW4q0XrCREUIHYeyYIVAJLAPDMb +9V+xwaSE2cE5n0LIuzxLh0lglPgsH1NayN1k/33R5Po65CguT5j3E2nuHOGsAfe oGWQxBDJnSuu4X0+3CukEJJ+bBbMa51hndHqIzrlYhbbPNiXANBD1lV44pK/0XA5 hKmINoQlyRyBZI6XWdd6jRmdOWVNRgY1bOVA+H46tmP688mZyj9p6xrDvl3Cev01 OLRPOfx0G/9SiaiRIJs97lbQwD6fg==
X-ME-Sender: <xms:iv0_X664UzQ3zDBoO3ddF-0M36dM1f3uuEIps50d3ph4IUUI3RxnUlzrPaQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduiedrudduvddgleelucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtgfesth hqredtreerjeenucfhrhhomhepfdfrrghtrhhitghkucfovghviigvkhdfuceophhmsegu ohhtrghnuggtohdrtghomheqnecuggftrfgrthhtvghrnheptdevgedvveduieeihedtje dvgeeuueeiieffhedtffdvjefgfeeifeetheduvddtnecuffhomhgrihhnpehhthhtphhs uhhrlhhsrdhimhdpihgtrghnnhdrohhrghdphhhtthhpshhonhhlhidrshhonecuvehluh hsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepphhmseguohhtrghn uggtohdrtghomh
X-ME-Proxy: <xmx:iv0_Xz4S8OtXrJHczjCUyuHbdNaRJZngkIzc6B7Y5IEnextssgkk2Q> <xmx:iv0_X5fQI7JxmPxdWCErnifdMvYiHpHNAiSI7-vQ98RuFxvfenuBRQ> <xmx:iv0_X3LmvohxUz28Efv80688HXamiZiS8wIlfi8IjlfC9gGBXGI09A> <xmx:iv0_X1ZG9pBBfXK84DKCqQ_xu-dNwQhJvUPiKIiQ4ec8b3eTHGYapA>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 062D06680073; Fri, 21 Aug 2020 12:59:53 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.3.0-214-g5a29d88-fm-20200818.002-g5a29d882
Mime-Version: 1.0
Message-Id: <df8735bb-197f-4ea0-897b-1eed7953c363@www.fastmail.com>
In-Reply-To: <DEB7C82B-A217-47A1-B4D4-FF7421017970@viagenie.ca>
References: <DEB7C82B-A217-47A1-B4D4-FF7421017970@viagenie.ca>
Date: Fri, 21 Aug 2020 11:59:33 -0500
From: "Patrick Mevzek" <pm@dotandco.com>
To: regext@ietf.org
Content-Type: text/plain;charset=utf-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/RR6MQR7-2CCgHMSdXHVwgXgwghU>
Subject: Re: [regext] rfc7484bis: https only?
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Aug 2020 16:59:58 -0000


On Fri, Aug 21, 2020, at 11:26, Marc Blanchet wrote:
> Hello,
>   for the rdap bootstrap registries, there has been (well since the very 
> beginning of the work) discussions about only supporting https URLs. 
> I’m happy to make it mandatory. Is there a working group agreement on 
> this? Please speak up if you don’t agree (i.e. you still want no TLS 
> http).

I would agree with saying TLS is mandatory... only if followed by either recommendations
or link to proper RFC/Internet-Draft giving guidance and minimum requirements,
because TLS enabled with TLS 1.0 only for example, or using deprecated algorithms,
or with a self-signed server certificate (it would be ok if coupled with DANE) is not really useful TLS.

So probably a reference at least to BCP195.

Also,
https://www.icann.org/en/system/files/files/rdap-technical-implementation-guide-15feb19-en.pdf
§1.2 already has "The RDAP service MUST be provided over HTTPS only."
so that will already cover a not small amount of entries in the bootstrap registry.

-- 
  Patrick Mevzek
  pm@dotandco.com