[Secdispatch] Requesting agenda time for draft-rsalz-use-san

"Salz, Rich" <rsalz@akamai.com> Thu, 04 February 2021 15:43 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 074D63A15D6 for <secdispatch@ietfa.amsl.com>; Thu, 4 Feb 2021 07:43:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.349
X-Spam-Level:
X-Spam-Status: No, score=-2.349 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.25, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gVZiZRvOs-gI for <secdispatch@ietfa.amsl.com>; Thu, 4 Feb 2021 07:43:54 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B49EE3A15D3 for <secdispatch@ietf.org>; Thu, 4 Feb 2021 07:43:54 -0800 (PST)
Received: from pps.filterd (m0122332.ppops.net [127.0.0.1]) by mx0a-00190b01.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 114FT9IA021607 for <secdispatch@ietf.org>; Thu, 4 Feb 2021 15:43:54 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=R2rjf5+2oaXsMwHANaQZvwB5CJHyn7wksdLBlhxJ3so=; b=W4af/1Yzweeo0Q8IkhShs519Fppgo3dp+4oTwfFd217TEsnLjyxVGwhaYJ/TIkrvFl40 1HNKqMKQWsRg36L83m5RKtiT1cG0OBD1YvMkO7GiUfMThLDlyjUeIP9QA/GfJlJhM4f6 zUDWDHILu4/sbSuYb7RnV0t7Pi24XUW/7rhA6Ox5zC/Fw6xWP71Cn5q8kXeRST7LijZN YJY9NA6e5B05pZkC7+61VRQZDoBUSXyB/QBO1MrZd3qGHdseusghCzqusuJWjHEB0czk nKar/lq9F4t8wVQy7X5oCIQdLFmyK1D1DurfZEsHwDken6ys7XWeyG1Rw4Kdl/sdMNjo 1A==
Received: from prod-mail-ppoint8 (a72-247-45-34.deploy.static.akamaitechnologies.com [72.247.45.34] (may be forged)) by mx0a-00190b01.pphosted.com with ESMTP id 36d0kj24vu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <secdispatch@ietf.org>; Thu, 04 Feb 2021 15:43:54 +0000
Received: from pps.filterd (prod-mail-ppoint8.akamai.com [127.0.0.1]) by prod-mail-ppoint8.akamai.com (8.16.0.43/8.16.0.43) with SMTP id 114FYZdT001493 for <secdispatch@ietf.org>; Thu, 4 Feb 2021 10:43:53 -0500
Received: from email.msg.corp.akamai.com ([172.27.165.113]) by prod-mail-ppoint8.akamai.com with ESMTP id 36d3p3fa4k-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT) for <secdispatch@ietf.org>; Thu, 04 Feb 2021 10:43:53 -0500
Received: from USTX2EX-DAG1MB1.msg.corp.akamai.com (172.27.165.119) by ustx2ex-dag1mb6.msg.corp.akamai.com (172.27.165.124) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 4 Feb 2021 09:43:52 -0600
Received: from USTX2EX-DAG1MB1.msg.corp.akamai.com ([172.27.165.119]) by ustx2ex-dag1mb1.msg.corp.akamai.com ([172.27.165.119]) with mapi id 15.00.1497.010; Thu, 4 Feb 2021 09:43:52 -0600
From: "Salz, Rich" <rsalz@akamai.com>
To: "secdispatch@ietf.org" <secdispatch@ietf.org>
Thread-Topic: Requesting agenda time for draft-rsalz-use-san
Thread-Index: AQHW+wyJezb1AHqFOUaUt+h0/CBr6A==
Date: Thu, 4 Feb 2021 15:43:51 +0000
Message-ID: <619EB16E-48E6-459A-A63A-18A805F75D34@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.45.21011103
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.27.164.43]
Content-Type: text/plain; charset="utf-8"
Content-ID: <B273F8AFC012EC46898ABE60C820DC99@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.369, 18.0.737 definitions=2021-02-04_08:2021-02-04, 2021-02-04 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 suspectscore=0 spamscore=0 mlxscore=0 phishscore=0 malwarescore=0 bulkscore=0 mlxlogscore=479 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2102040100
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.369, 18.0.737 definitions=2021-02-04_08:2021-02-04, 2021-02-04 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 spamscore=0 mlxlogscore=397 impostorscore=0 clxscore=1011 priorityscore=1501 lowpriorityscore=0 bulkscore=0 adultscore=0 mlxscore=0 malwarescore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2102040100
X-Agari-Authentication-Results: mx.akamai.com; spf=${SPFResult} (sender IP is 72.247.45.34) smtp.mailfrom=rsalz@akamai.com smtp.helo=prod-mail-ppoint8
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/TAk5H3u_5C_JehUB7EKAnfegxj0>
Subject: [Secdispatch] Requesting agenda time for draft-rsalz-use-san
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Feb 2021 15:43:56 -0000

I would like to present https://datatracker.ietf.org/doc/draft-rsalz-use-san/

This updates RFC 6125 to remove commonName as a way to identify the server; just use subjectAltName.  It also limits where the "*" can go in wildcard certificates. This is a simplification of widely implemented existing practice. It may even be de facto what's mostly done. Perhaps the wildcard limitation is controversial and I'd be willing to remove it.

6125 was AD-sponsored. I think this could also be, or perhaps it could go to UTA. I would not present any slides, and think 10-15 minutes would be enough time.