Re: [saag] [Trans] draft-iab-crypto-alg-agility-00

Ben Laurie <benl@google.com> Tue, 08 April 2014 14:15 UTC

Return-Path: <benl@google.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 397B71A0425 for <saag@ietfa.amsl.com>; Tue, 8 Apr 2014 07:15:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.651
X-Spam-Level:
X-Spam-Status: No, score=-1.651 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, RP_MATCHES_RCVD=-0.272, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y_cQcpu4CFRw for <saag@ietfa.amsl.com>; Tue, 8 Apr 2014 07:15:46 -0700 (PDT)
Received: from mail-ve0-x232.google.com (mail-ve0-x232.google.com [IPv6:2607:f8b0:400c:c01::232]) by ietfa.amsl.com (Postfix) with ESMTP id A3EB51A041E for <saag@ietf.org>; Tue, 8 Apr 2014 07:14:24 -0700 (PDT)
Received: by mail-ve0-f178.google.com with SMTP id jw12so789210veb.23 for <saag@ietf.org>; Tue, 08 Apr 2014 07:14:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=VpNSm6Z6nzrBiWVXdU/FpiwgH4+VCRqNuL4L3ihoRoQ=; b=cCQSIoy7VyJLiPU9/TFhT+ODC3U3a+PVGHon6qAxwifX53L9faOApSN8p61CGsXUsc zQlWt3xSPszCphDh8ArfRhcphhrYeq4s6vhvjiAB8DxtW6SaWwU+r/VmxMfvVdDubn9e odd+p19kxIeQixhyUc+C338UXPRPz0H5FlEa7WnMgk3sh63PBERDcWbWhg7DaJN3d367 R+sezRkKiz0tThVe6MNBTJ6FUB2Mv9y9Ibref12sp6jerO+05pfzOB/5yDuXxpbqSkoU JcJ+hHUZycFa90bgHV+/8tWDV/uKbT7IZKqFKrDxJ2HE69bhuRjKFdi7lsmr/U89LnNl n7gg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=VpNSm6Z6nzrBiWVXdU/FpiwgH4+VCRqNuL4L3ihoRoQ=; b=khh64XEGJCZDayDSn2ihta8/GYCxN/1FyzI6pZYCOwpNqUt0aOKqPx4DhYwNWmeQ7r Txexx6sBnQuLSZKUFDH+TqjEySbIpoBiMNvMOGQmHoTNVdfwABsIamKsxl2StsI9h8Y1 FDwPq6rNfI5qv5wCz6pGTv3HB0kWRoNgaXQQqvNcuhNymh2QaNspmjynGzbPYPmOszxK w9QQvDdiYU/Q7+3ZLUrK8WYnP9+x8g6S2CH2em2JFIWzYyrjtN5MQUTxV7xKpEs37x68 IzZ1R/23/+bk2O6uZFLojUEEMouw475t0Wd4Z4j1ygyo7oWQujdAe9Uj1hDI2IlHLmrx wngw==
X-Gm-Message-State: ALoCoQmcPhdglD6RwVKZ1rgYWmtDjUoyvtZe9Wcw/kGmn3kJQ9IHA/feYX0FHNcxq3pdPJOyZIV1+Njk3M8TCFQ7zXSPSjfyAxl1D3I/wAfv5enyP0Yo68UNZh4I/xszbmKDH+Lf8aeYi3f/EZeQU+NaMNqMRItMfz6PTuDvBRw7BZnL9rQDtbl/7tEhSSQQhTXXFy3or14K
MIME-Version: 1.0
X-Received: by 10.58.49.10 with SMTP id q10mr3347372ven.5.1396966464417; Tue, 08 Apr 2014 07:14:24 -0700 (PDT)
Received: by 10.52.119.179 with HTTP; Tue, 8 Apr 2014 07:14:24 -0700 (PDT)
In-Reply-To: <2A0EFB9C05D0164E98F19BB0AF3708C7120AC188A7@USMBX1.msg.corp.akamai.com>
References: <5999195E-9073-4649-A224-BF71BA61CBAF@vigilsec.com> <CAG5KPzzqSQ++YpQcnYesecL0GQ0+J0ieMXBrNk6txMAC58xEQQ@mail.gmail.com> <2A0EFB9C05D0164E98F19BB0AF3708C7120A04EBD0@USMBX1.msg.corp.akamai.com> <6.2.5.6.2.20140406121529.0bd2d730@resistor.net> <2A0EFB9C05D0164E98F19BB0AF3708C7120A04EBD7@USMBX1.msg.corp.akamai.com> <CAG5KPzxihe+k0x0njC+BANacmrrQyfU5RAY_EYcMYW2rx8DZfw@mail.gmail.com> <2A0EFB9C05D0164E98F19BB0AF3708C7120A04ED14@USMBX1.msg.corp.akamai.com> <CAG5KPzzzmJhcPfs0cJuS3f8Lu_Rua9dj0XWaOZ0RQ0Mwyd+egw@mail.gmail.com> <2A0EFB9C05D0164E98F19BB0AF3708C7120AC18663@USMBX1.msg.corp.akamai.com> <CABrd9SQaGTFzRaaxs7HNJ7uD_Bb=qPtCtTTsu-ZFYh+QAduzsg@mail.gmail.com> <2A0EFB9C05D0164E98F19BB0AF3708C7120AC188A7@USMBX1.msg.corp.akamai.com>
Date: Tue, 8 Apr 2014 15:14:24 +0100
Message-ID: <CABrd9SQpaDn=FWCtpRxOprt1nus_Fbg6a9dpbDrdjoWi=H8NBg@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: http://mailarchive.ietf.org/arch/msg/saag/SPOnzZzW-ixFEEtUvnmilstMgHk
Cc: "trans@ietf.org" <trans@ietf.org>, "saag@ietf.org" <saag@ietf.org>
Subject: Re: [saag] [Trans] draft-iab-crypto-alg-agility-00
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Apr 2014 14:15:47 -0000

On 8 April 2014 15:10, Salz, Rich <rsalz@akamai.com> wrote:
>> As I responded to Steve, I agree that there should be an identifier, but it belongs in the metadata about the logs.
>
> I do not understand why metadata is more secure then the data itself.

It is created by a different authority.

> I strongly disagree that CT should be a special case from the general agility doc.

I am not saying it is a special case, I am disputing where the agility
should happen. :-)

-- 
Certificate Transparency is hiring! Let me know if you're interested.