Re: [lamps] Call for adoption for draft-ito-documentsigning-eku

Ryan Sleevi <ryan-ietf@sleevi.com> Thu, 29 July 2021 21:04 UTC

Return-Path: <ryan.sleevi@gmail.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BC143A005C for <spasm@ietfa.amsl.com>; Thu, 29 Jul 2021 14:04:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.648
X-Spam-Level:
X-Spam-Status: No, score=-1.648 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.249, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aPuRc40-6YvY for <spasm@ietfa.amsl.com>; Thu, 29 Jul 2021 14:04:21 -0700 (PDT)
Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A99863A005B for <spasm@ietf.org>; Thu, 29 Jul 2021 14:04:21 -0700 (PDT)
Received: by mail-pl1-f172.google.com with SMTP id e21so8457149pla.5 for <spasm@ietf.org>; Thu, 29 Jul 2021 14:04:21 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=G359NkMZ7H+KrhnwWDzda7xHVhpBCD9vXdhqOUTHQ0A=; b=VLXij5h4FaBDtzOAwGOHPiKOJNbJmspbvW08zHq1lENkst+rTRrAlzG3x/Sv7v+Lqi rVGRB26t/6lE8Lzl0/VQ4No/99btK/lfX8CYEIpyWFlxLhQ63mnARaZDkqDqKII611Jz YrQurZLXixIp5mlWcDgmZXLPhqDgvw9KwXeH8BOcN0Kvsr/OPjM380havI2nlg4U8BV0 bUSLROVRQZ8bwxjk3ez+V2egtQBZ7fqA8kZjA/q6CHeOcNi36DMGR8ljJj5fDdJSmXaz KJY78UobYD0MxnHf/V5wbEbcdsW1pc1GtCdRmr6SsvqtK2YPTSplJ01SI8pJ2iv2qKNp cQdQ==
X-Gm-Message-State: AOAM530IhJ+6lAMNqLeNVHitXo6gsQztKL7Xy3Um2+2ntVeXCdLoJQz3 hBM8UotoqnpgalMG7qk/ISvwQRg3S9A=
X-Google-Smtp-Source: ABdhPJwq60BEQVfz75584tzcKO1Se4Oe5D+24p13V77xAc3NcXVxdamWVtDntquwb5uk19zyFtzw3Q==
X-Received: by 2002:a17:902:eb54:b029:12c:3612:b6e0 with SMTP id i20-20020a170902eb54b029012c3612b6e0mr6272787pli.33.1627592660486; Thu, 29 Jul 2021 14:04:20 -0700 (PDT)
Received: from mail-pl1-f170.google.com (mail-pl1-f170.google.com. [209.85.214.170]) by smtp.gmail.com with ESMTPSA id b13sm4585926pfl.49.2021.07.29.14.04.19 for <spasm@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 29 Jul 2021 14:04:19 -0700 (PDT)
Received: by mail-pl1-f170.google.com with SMTP id k1so8419065plt.12 for <spasm@ietf.org>; Thu, 29 Jul 2021 14:04:19 -0700 (PDT)
X-Received: by 2002:a17:902:b707:b029:12a:d3d7:a82c with SMTP id d7-20020a170902b707b029012ad3d7a82cmr6317476pls.24.1627592659558; Thu, 29 Jul 2021 14:04:19 -0700 (PDT)
MIME-Version: 1.0
References: <CD589623-52EE-4958-80AB-73F0CFB3A36E@vigilsec.com> <CAErg=HF_hcXO=9=KJh5EBEov4ybS_8g4xF=cANL9+83UvP0zvQ@mail.gmail.com> <adf86f46-093f-756f-8292-9b5e088f4344@lear.ch> <CAErg=HEUFV2F8R8g8e6yCDKz_e6RebNyB5Zb2Lvgn4oc3BtE-w@mail.gmail.com> <CO6PR14MB4468A7A5EB138542CEBA5D9CEAE99@CO6PR14MB4468.namprd14.prod.outlook.com> <CAErg=HH4aDgju=8C7Neq_4H19EX8S2inNd9fMAMYH3h95S48Rg@mail.gmail.com> <CO6PR14MB44688BC4188063BCA54E80C4EAE99@CO6PR14MB4468.namprd14.prod.outlook.com> <CAErg=HGDA+16N4xhgMvuQz25DqD+_nkiFC+OuAJMkFzYYqFV0w@mail.gmail.com> <2550c1c3-1400-b380-c9ad-dad59286feee@lear.ch> <CAErg=HGnKMNNyaf-=w+DmqfXg7XYbKD2Ah-WUxf96xNN5Ecikg@mail.gmail.com> <CAErg=HFVx5JTog5_aWOrx3vAm5o=LxHfwxEqkVM8FifYCm2P+A@mail.gmail.com> <CAGgd1OdcLujCJQOaTGvS_Hkqg1=pUP-5Mu=06kqkrgFU3fVG5g@mail.gmail.com> <CAErg=HGL-s2v9=5J64GnaaFxWN4QYWMUnDRPcpC0DN5XgM1-yw@mail.gmail.com> <CAGgd1OemU0qX1Wsmx7YPMTiexKz9hmhKj3c89iT3BcrahiUP8A@mail.gmail.com> <7F1B7734-6CC2-4BDB-B4E9-67E846197387@ll.mit.edu> <CAErg=HF4aXAf8R5hqxwmrHQo=Rs2szWiueRwx+g+DK-tRwQ=iw@mail.gmail.com> <32A91405-D391-49A4-8BE2-BE103F8369B8@redhoundsoftware.com> <CAErg=HG9zxevu4X7CaBhHL1Yuf=Uiwhi0-_k+H9-SfE+ZD=zZA@mail.gmail.com> <D1591BA0-6B43-4C80-A693-86140BA24897@redhoundsoftware.com>
In-Reply-To: <D1591BA0-6B43-4C80-A693-86140BA24897@redhoundsoftware.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Thu, 29 Jul 2021 17:04:08 -0400
X-Gmail-Original-Message-ID: <CAErg=HFqfek5titw0R_yp2aZBZJQiWXVhRWc1g9O+bst_2tkyA@mail.gmail.com>
Message-ID: <CAErg=HFqfek5titw0R_yp2aZBZJQiWXVhRWc1g9O+bst_2tkyA@mail.gmail.com>
To: Carl Wallace <carl@redhoundsoftware.com>
Cc: Ryan Sleevi <ryan-ietf@sleevi.com>, "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>, LAMPS WG <spasm@ietf.org>, "Cooley, Dorothy E" <decoole@nsa.gov>, Deb Cooley <debcooley1@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000004feb0c05c84972ad"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/H0bHZ3RO3xnG0nTnv4hrI9QqbeI>
Subject: Re: [lamps] Call for adoption for draft-ito-documentsigning-eku
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jul 2021 21:04:26 -0000

On Thu, Jul 29, 2021 at 4:27 PM Carl Wallace <carl@redhoundsoftware.com>
wrote:

> [CW] Then write **that** spec so that we cut out the folklore stuff and
> all work from the same sheet of music. It’s not abstract spec “purism”,
> it’s what the spec says. Make it say something different.
>

Check the footnotes in
https://mailarchive.ietf.org/arch/msg/spasm/bV34V37xxxuHhbR85qR1NG47gq0/ to
see how well that's been received in LAMPS/PKIX previously.

The resistance to updating the spec to match widely-deployed reality is
real, unfortunately, but that doesn't change what implementations have been
doing for the past 25 years and will continue to do.