Re: [lamps] Call for adoption for draft-ito-documentsigning-eku

"Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu> Fri, 30 July 2021 16:40 UTC

Return-Path: <prvs=7845065c46=uri@ll.mit.edu>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 656023A30B7; Fri, 30 Jul 2021 09:40:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mxo_Sv4ro0Nb; Fri, 30 Jul 2021 09:40:55 -0700 (PDT)
Received: from llmx3.ll.mit.edu (LLMX3.LL.MIT.EDU [129.55.12.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C908C3A0D57; Fri, 30 Jul 2021 09:40:54 -0700 (PDT)
Received: from LLE2K16-HYBRD01.mitll.ad.local (LLE2K16-HYBRD01.mitll.ad.local) by llmx3.ll.mit.edu (unknown) with ESMTPS id 16UGeoVF045639; Fri, 30 Jul 2021 12:40:50 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=lKCPiGDOtqYBu4Ik3flz504Cfq2NT5872Y+1klPyU9l8txwRJ8eBGGduA6Bt1vHuQlJ4k8yZMjc/pHhI4G07UKnmUbGVU2WooShamUl9Vxp5K+f0ynw67uDFsErS7+ENhxkPCU/4HMuNk9ewvDRpBvkTT5Pc+Cg5iDZAXtYxIMdk/xzi7b+FIbv2HnE+5EsLHrFbC1kmH5GCrJzrdvSWLqLdZ9nfCmxwtcSI5B99K3Vq8Allw/vXBsANf2WniKwXQ5av3U2CcQ4yA0pne5QmSeUIjDA8HXYcQLKQnuZ5R+WkOf5Kp24FJIl3r2c8NW2M7JNMC4UMYdvDJKb8/4k4Sg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=u9dNRg398JfPP9VUXi10ZdTT3Qs9HezeutJLVxQJ3oI=; b=VMdFmIRTKIxjZSjuBpaG/La2I4my0bKsIaiOXK+tszXxOx7zCAMqkhbRl29V7Nq/LLVXS9/4szhuG0drGR+PCzH+vFZTGANnxwFJIjcoz9nQyIlDd10y/Z8sUn66W7d+V/z+F15GwSLWHWqwOFs4AyPfKTuxPcdfzdL3uOnMEOHwmifZ5M4Jc5idpFtaHP2iCwmvAVgUrOtwzkd/w/wDL1qNa6TA9nHs/C5YLBX2r2Z/ng13jKY8KGnuyes6IBA6Yj210IefkAqXjXC1lI5K3BYmzOGX5fmbkRW9Kno/k3/MOLXIOglsyVJKx/BnvJ/6NxFxWyVMgal0OGP94U1q/g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ll.mit.edu; dmarc=pass action=none header.from=ll.mit.edu; dkim=pass header.d=ll.mit.edu; arc=none
From: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
To: "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>, LAMPS WG <spasm@ietf.org>
Thread-Topic: [lamps] Call for adoption for draft-ito-documentsigning-eku
Thread-Index: AQHXgmuKk2sKcjNKq0GeFl8+0k2LC6tY5gWAgAK2AYD//99ggA==
Date: Fri, 30 Jul 2021 16:40:47 +0000
Message-ID: <2F429632-ABDF-4A93-9EE2-3764519C272B@ll.mit.edu>
References: <CD589623-52EE-4958-80AB-73F0CFB3A36E@vigilsec.com> <19561F5C-1EED-4D7E-81EB-210A2B47556C@vigilsec.com> <E1B3DCF1-DE9C-4FD9-AD2C-F86D5B0C374A@akamai.com>
In-Reply-To: <E1B3DCF1-DE9C-4FD9-AD2C-F86D5B0C374A@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.50.21061301
authentication-results: dmarc.ietf.org; dkim=none (message not signed) header.d=none;dmarc.ietf.org; dmarc=none action=none header.from=ll.mit.edu;
x-originating-ip: [129.55.200.20]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 3dd824c2-0401-467b-0dd0-08d95378c8c6
x-ms-traffictypediagnostic: SN5P110MB0701:
x-microsoft-antispam-prvs: <SN5P110MB070134170E11AB17AB6319F590EC9@SN5P110MB0701.NAMP110.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:3631;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: SulxG6By9WSCWcGChnAj9tqo8elggq49VC2j9DJQSz1l3RkX3MOjLbzntF5MeHlskRVEZAiu+BWealTZOlNrTL3LIzjLpwRexaeT7NIvviTnUVwvE4BflpJjWkdgVYLMe8SA1qM4cwxCijs4GzW+Nd+C0reBgFdPNzfQzyvLvILxdPNcqTdtfkI1Ln8l0MbSnkvunxso2viJghaPuCKHt9BMpvH6kl8DSj/G3T3g9fjc3bGtVkied2VLASqqiKK8PbLTksJgKzCmap0Gjc+3ycmzQGCAagybwEruC+gnEai/hG03gpmGCX/jDl78g5BRx+j9FSlZsNwcWsNHNi245woCvOMgrrNLxlnrsH4izqZeVwt/WIbS9ClBe1VEBsyJm9uZYoKRYOIimu1Fy6oNnKDz1w7Ia9V+mxebHdY1S0UV3K/75FX9yJvpHmj+NnbtwnBpnfU80xR7j3l+vSMK+sKdC4IKMipwv68GIswQHTWpucZYBpaV+pvA8zBhx1ssuJyi41rgFkZUALkOkTu2KI1dWSQ5dsXiS3BrrIf6O2nHoLVUOBo3uqyBwXjtm9A72h4YqA7kubbrx38Y8wEo98gt6bw6JkgzftiQ0Pr0cIT00eRraYCVzXh2KI6+J6Ox5aumWx6k6VLcFFB/FMfQx20/EC95+KQivgUtziBE/Fc=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SN5P110MB0560.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(4636009)(366004)(376002)(39850400004)(396003)(346002)(136003)(2906002)(6512007)(71200400001)(86362001)(5660300002)(186003)(8936002)(316002)(26005)(2616005)(8676002)(110136005)(38100700002)(122000001)(38070700005)(66946007)(66616009)(66556008)(6486002)(478600001)(99936003)(76116006)(66476007)(75432002)(33656002)(66446008)(6506007)(64756008)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: +TOb2/o1ubvWv5iK5m5SB5KR/+e1I82UaOm1HcCd06r8BDFAtoDuMdnFcZLcnBumWya31Jj6l58JIlhyLazES2EzMfZXI3nfDeUMMxb5JerVlG1EK773YRzi/9FONQaJ6jRRIT//NLtvDhXdGqS2rlYylEnPiUdmG/dMigedoYBkqmGVANnNjZt2zrdE1GeFJibu50TRx0SsjiGNQv+bBJBkbuxMHIXfFfgjSUDurk3vZtaEy9iahfTTNW2to8Wp9HyTp2xk81rVrm4TyjUaKeebj4Nj5ljk3sCM6I348RWlyiZva7ZQjgITb9wIYtTgNKm0P3aeDckjZwfEaq5UW1Q5VBly9xwuYJ+FUqSSy4S3a8BgEo9RK8xTDvVj7RpsNy+eF0QuakmEVs+sTVt2RofKDJNVXnk7UMxNRcDLOlDEgW1OaSAYpg+G9SmJR0TNNJE9/ARzek1HPKanIJrZALQHFLYd7fd7ADnD63dyf0ziQhH6l2i+iDet0Ml3EfabQAG0JdYI3AO/E/fEAVAtar6vLsFqb3YEm4I/LI0FyvTUz+1iRjVywwUOom3Zu1iEMB12PL6uOAz20oJaxp5Y9UO0HdDo5C1XATdhpiRo8x35XzMVIxiHpHx2+ixGyjiNVyA2/jkL1lFh8Iq9w1+TX4jq2pfzASEE1sOQ9n7CGm7XKd3RDXptDkc7h6NvppGPm/mx5rYiAQ/nOTbVe+HWwg==
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha256"; boundary="B_3710493647_468974833"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN5P110MB0560.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 3dd824c2-0401-467b-0dd0-08d95378c8c6
X-MS-Exchange-CrossTenant-originalarrivaltime: 30 Jul 2021 16:40:47.8270 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 83d1efe3-698e-4819-911b-0a8fbe79d01c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN5P110MB0701
X-OriginatorOrg: ll.mit.edu
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.391, 18.0.790 definitions=2021-07-30_11:2021-07-30, 2021-07-30 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-2103310000 definitions=main-2107300111
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/A5crp7p3IzVvvR6v8mrOwFVY-Kk>
Subject: Re: [lamps] Call for adoption for draft-ito-documentsigning-eku
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Jul 2021 16:40:58 -0000

> This is tougher than I thought.

It does seem tough enough.

> Ryan has more in-the-trenches experience with these things than most,
> and perhaps more than most of us combined. 

I wouldn't bet on it. ;-)

> On the other hand, defining an EKU is pretty small potatoes, and there's likely not to be much cost
> to the s/w stacks because they already have to make the cert, ku, eku available to the application anyway. 

This is where one disconnect is. 

Merely *defining* an EKU is cheap. The cost to the s/w stacks is negligible, as far as I'm concerned.

The real cost is in the certificate management. 

And [in]ability of principals to carry multiple certs. E.g., think of how many Signature certs PIV or CAC token can have.

> On the third hand, the idea of CABforum starting to address email worries me -- will membership
> open up to allow email app providers? I guess that's really not our concern.

It may well become one.

> So I support changing the charter and adopting this.

I do not know. I don't support it, but I'm not violently opposing it.