Re: [Secdispatch] Please help dispatch "Dangerous Labels"

Michael Richardson <mcr+ietf@sandelman.ca> Tue, 26 July 2022 19:22 UTC

Return-Path: <mcr@sandelman.ca>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D6A2C1C6CEA for <secdispatch@ietfa.amsl.com>; Tue, 26 Jul 2022 12:22:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.909
X-Spam-Level:
X-Spam-Status: No, score=-6.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sYH7G9bbMgls for <secdispatch@ietfa.amsl.com>; Tue, 26 Jul 2022 12:22:26 -0700 (PDT)
Received: from relay.sandelman.ca (relay.cooperix.net [IPv6:2a01:7e00:e000:2bb::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C606C1BED17 for <secdispatch@ietf.org>; Tue, 26 Jul 2022 12:22:25 -0700 (PDT)
Received: from dooku.sandelman.ca (dhcp-886b.meeting.ietf.org [31.133.136.107]) by relay.sandelman.ca (Postfix) with ESMTPS id DFE171F448; Tue, 26 Jul 2022 19:22:22 +0000 (UTC)
Received: by dooku.sandelman.ca (Postfix, from userid 179) id 3AE761A04AC; Tue, 26 Jul 2022 15:22:19 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Dan Collins <dcollinsn@gmail.com>, secdispatch@ietf.org
In-reply-to: <CA+tt54KkvCtmJzy_-hQAMmP8DEiLebEQkGBSDmN7y1m25xyRHQ@mail.gmail.com>
References: <87tu73q5c6.fsf@fifthhorseman.net> <258490.1658858623@dooku> <CA+tt54KkvCtmJzy_-hQAMmP8DEiLebEQkGBSDmN7y1m25xyRHQ@mail.gmail.com>
Comments: In-reply-to Dan Collins <dcollinsn@gmail.com> message dated "Tue, 26 Jul 2022 14:15:25 -0400."
X-Mailer: MH-E 8.6+git; nmh 1.7.1; GNU Emacs 26.3
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Tue, 26 Jul 2022 15:22:19 -0400
Message-ID: <273768.1658863339@dooku>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/HZZ4sCRnKMteBiAS_Zi0ROAW4fI>
Subject: Re: [Secdispatch] Please help dispatch "Dangerous Labels"
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Jul 2022 19:22:27 -0000

Dan Collins <dcollinsn@gmail.com> wrote:
    >> Swapped some digits?  RFC8461!
    >> But that RFC uses _mts-sts... underscore.
    >>

    > RFC8461 uses both. `_mta-sts.example.com` is used to store TXT records
    > (which state that a policy exists and give an ID used for caching), but `
    > mta-sts.example.com` is used in section 3.2/3.3 to point to an HTTPS site
    > where the policy may actually be found.

Ah, I didn't read that far :-(
It seems wrong that this RFC did this, and not /.well-known :-( :-(

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-