Re: [lamps] Next steps on CAA

Jacob Hoffman-Andrews <jsha@eff.org> Fri, 06 October 2017 21:42 UTC

Return-Path: <jsha@eff.org>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C58113319E for <spasm@ietfa.amsl.com>; Fri, 6 Oct 2017 14:42:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.102
X-Spam-Level:
X-Spam-Status: No, score=-5.102 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=eff.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b2pTWvc_Ejdl for <spasm@ietfa.amsl.com>; Fri, 6 Oct 2017 14:42:38 -0700 (PDT)
Received: from mail2.eff.org (mail2.eff.org [173.239.79.204]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73ABE13307F for <spasm@ietf.org>; Fri, 6 Oct 2017 14:42:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=eff.org; s=mail2; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:From:References:Cc:To:Subject; bh=1O1nJu7x5Y3QYBSilFYORFeAvdJEHvqYaaHymTs3yjs=; b=fwWRlr4Yog2v5K/LO+W7eNYnjWmkLaojkxJwGubuVCEiXUh2nhdGNrMmOJpmjzQ8CjIkGiT5vLI+eDod9J3nPZUNPs6g1RUmjHS9zxPyvgzIw6xXWdlmVV7MJic05y8vgsIJUyxLRJ51/pkCs1cDiXtOeccwkjew9mSqGAQ7A5k=;
Received: ; Fri, 06 Oct 2017 14:42:35 -0700
To: John R Levine <johnl@taugh.com>, Patrick Donahue <pat@cloudflare.com>
Cc: SPASM <spasm@ietf.org>
References: <CACh0qC+jRjPMsf7YmDqoKZ0X1zWE2p=fUAo5uN3bZwwzBRG9Kg@mail.gmail.com> <alpine.OSX.2.21.1710061656080.33175@ary.qy>
From: Jacob Hoffman-Andrews <jsha@eff.org>
Message-ID: <7b98f765-4fea-5b71-e860-e46c11d6617e@eff.org>
Date: Fri, 06 Oct 2017 14:42:37 -0700
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
In-Reply-To: <alpine.OSX.2.21.1710061656080.33175@ary.qy>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Received-SPF: skipped for local relay
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/R1oLKuI3i-AF0JbiytgZwvvNVSM>
Subject: Re: [lamps] Next steps on CAA
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Oct 2017 21:42:39 -0000

On 10/06/2017 02:04 PM, John R Levine wrote:
> This doesn't deal with DNAMEs but I don't see any reasonable solution
> to DNAMEs since I don't see any reasonble way to construct a
> non-DNAME'd name from a DNAME'd one.
Note that there is no need to deal explicitly with DNAMEs (or CNAMEs).
They are handled for us by the DNS spec, and are resolved transparently
by any recursive resolver. This is the main issue fixed in the
caa-simplification draft.