Re: [lamps] CAA processing for email addresses

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 30 November 2022 23:19 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B888C094EDE for <spasm@ietfa.amsl.com>; Wed, 30 Nov 2022 15:19:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.997
X-Spam-Level:
X-Spam-Status: No, score=-6.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m4GseGy7Q-pC for <spasm@ietfa.amsl.com>; Wed, 30 Nov 2022 15:19:02 -0800 (PST)
Received: from EUR03-DBA-obe.outbound.protection.outlook.com (mail-dbaeur03on20727.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe1a::727]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D40A1C0D7C27 for <spasm@ietf.org>; Wed, 30 Nov 2022 15:18:52 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BCq4hk8kHSY0UsecR6R8j070pF6qssqzyAEh/5AuJTBYWCyb4bZELXNh0o9sSKDJi7Ms+/uAkMXU+pp+ZUdGh+e4X0DoZHcpsxZIK8p//cFPliMCpgfLCneBrRgj4lp/bvx57JJduo9razpvekCoEM/mjKJGqhGqMe2FSMvUF6x5p65DrvnpHBRRckwji1Sck7GhYfsYgh9scl3uV8pm2vZp0SXlirvPhXgnXAl7KS2CpQ0/KiOKFIbfMJlZy2inftx/tFOXzXj13028hju5Mqv3QCNBqAg3lV2/EKJbpgO5cd6JHMGRy85exEhY6PaDKWASGP+A0k170HngzJrh4g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=wKay25vSc5aqvs3A1Uzp8jKbJXZ1NbNCbGcbKc/1Ygc=; b=JPGXDh7OHwFhQO927ka4q2zm5Zlzn3FVZNE0sFsXYFy4OmZMQOETGlolu0B9pexiCcONG1Ce3vL0uC84xLYe7QEKuON7trko/ZErPCGYPCu2yJm8pIRk9Bo3SV/l35/SgpMqh4Z7dk3K2Ry3/EZKcBGlfWKzEXuoVneBTsrylhJz4caiptK9ey7tLdHm0HVPCJDdViD7lTqnjvbO7Ci/sXYNi7bKCwcCx1FzK7hcuRpWW2zZarT5YP2/3IOIDVrLqAY78IhNfNSP03n1gc1r1zGzKzYNSBPI+WXnc6n2T5vZR7x5b65A5tpZ1E/QxCHnJAV/tppMd9QIpgb84tgG7w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wKay25vSc5aqvs3A1Uzp8jKbJXZ1NbNCbGcbKc/1Ygc=; b=rgtEx0rCbhtrhKXqrJmmLC8gIyZSNvwVOrV87Aaa97fjo0HOZkDV6HrxkJBo2tGWNtyX3UqFA50tNGXUJsRIRtBQqsOT3sd3fiRl0ZNOHQD4DnWzHPZwndOEs6Nx6AiudM55sl/weeJFENkXA9nWdpgsfYPWz8kaemzvC+IZTDgcWwoYzzmDOGv0BlVde/iitsYLHAz+0mwIRAibRqQfN5PHD4IiEOdlLtiNJIJ51z6P852p098gyktfA6RozvZThJu6lSBTKIYmCsNZWETAJm/pam8rRTGybIrmG781g0cd2DAtAoYPgvNgd+dS/XJrNkVft9qjD+NavpcKw+6Plw==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by AS8PR02MB9532.eurprd02.prod.outlook.com (2603:10a6:20b:5a8::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5857.20; Wed, 30 Nov 2022 23:18:48 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::ec35:f546:d772:4fc6]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::ec35:f546:d772:4fc6%4]) with mapi id 15.20.5857.023; Wed, 30 Nov 2022 23:18:48 +0000
Message-ID: <daba6e40-227e-6229-173d-c9085902af91@cs.tcd.ie>
Date: Wed, 30 Nov 2022 23:18:46 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.4.2
Content-Language: en-US
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: Corey Bonnell <Corey.Bonnell=40digicert.com@dmarc.ietf.org>, Seo Suchan <tjtncks@gmail.com>, "spasm@ietf.org" <spasm@ietf.org>
References: <DM6PR14MB2186A5E0A82D87085564B90D92159@DM6PR14MB2186.namprd14.prod.outlook.com> <5d2804c9-cd04-14e8-9fad-91254212e04d@gmail.com> <DM6PR14MB2186880BB993689D6CE890F292159@DM6PR14MB2186.namprd14.prod.outlook.com> <3c5ce299-8647-c481-57d8-ca604a655e0c@cs.tcd.ie>
In-Reply-To: <3c5ce299-8647-c481-57d8-ca604a655e0c@cs.tcd.ie>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------aSVz3u4XnM2nlw5KYPAmSCiG"
X-ClientProxiedBy: DB6PR07CA0162.eurprd07.prod.outlook.com (2603:10a6:6:43::16) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB7PR02MB5113:EE_|AS8PR02MB9532:EE_
X-MS-Office365-Filtering-Correlation-Id: 6df92d1b-97f8-4e2c-9a76-08dad3293bee
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: zrfY58Tjmr6noQM7HkTcymEk6R4jaxx0Bo9n56y9jMV9yTpw1xsCr/S7s/83aWVZIfuEl2C5Aovhzmi4STKFu+g8ktg/ykJjQjFlTTqoLrFbJ2xaNzdpgVIrjrcsJSdUSUdKAhtNR4q8xkqpTyvtMuUFk6u+kmppY0Wd8fm3CSEOBLx735M6RdhgsBjORiuz6Cc9J65x8sL89e4zqPEEL0iNOsNs84R7Pu8e1rhKR+SCFkBZhg45bvcTQF+jKpSkJG1y2F25c7jOm2MGuJgUSu7wFh5NhJOxq2b0mMx6/s5Y+/+Zr3juIyg34FD5HQgKvJqHcseD+jcV52cqtnZgfht8jj8m8OJGJfB/yj9xIVChYnApYIc4F66+mA/5gnsRkashzOLX5XehtoPluL2W1b0+wCgvFSc1Z7qv9B5LT5sTAahChg9Z77E1AJmbQ86XeP8MFAHlKon+jTQm6pnM88Ju6YyQEIvBhhJJLrW/gskiUof5z+AzOsSmLKP9yFBH9UPWe2LF7tebK8TWVLYfSGk7Hgyx/QGwB3LkWVaDXZxIYZJKctZQ7y6ETCa0TAtXH4Zu+pJeVFN3ffEhTXeI/BD1OE9O4DrZ74ZA1POSp2cbqxzo0pXCrpNBBO1+UQDlag1Qa/173aUGtg4tZB9Mh9UxrJgOVGF/eH5Lgj1LZhgo1LuheFr7CZGNrnxVGC8awqyT4/scZozsFA53ytUmTNtUJP/XkRCPDboOSdyJr4fTxkh74+AAO1JXVyasn3JK
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(346002)(396003)(376002)(366004)(136003)(39860400002)(451199015)(36756003)(41320700001)(6512007)(6506007)(8936002)(53546011)(66476007)(66556008)(45080400002)(478600001)(33964004)(6486002)(2616005)(8676002)(186003)(86362001)(31696002)(235185007)(2906002)(83380400001)(41300700001)(31686004)(66946007)(110136005)(786003)(21480400003)(44832011)(316002)(38100700002)(5660300002)(199583001)(43740500002)(45980500001); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 2qLEu4yyHqBzHCrNmQ89Py7/RbpN8MTeM3c5a7a0F4cG71Jj4VsM4n1s7LYNBBA/CX4Cs/01zcdswlrwJ6YMtDe26w+k7dlg3/vNh+zgGfDz5tKYa+1tY23w0OXRWP7cgLR8U62tH29l9TKNUFqP0sLbGw2L95/WyCKhvBtJdrSLl/TzO2fVrZVTt3U64/A0heWOI7U/uM4dJ6JHLnm6pLY/VNJ232RPkZ72n9TTJHSsMR6/dipIx5CV1PkCtYpR1072/W9/sJWA1ey49SntNSX7qcJD2XiWpmuW9ddpF9c0iJaBZ1rSMk84DpbimeSFdnyF7NePKKcx68w7VsX+l8ukUqOVjgS5zSn//oZ2fXGcqOPsCoSO8vDwFFkuZjNF6d//F3ekZiWxYcjaTZdkSsd3yZtSdcpiqdeqX+jRLOfEgwvewdGUNxXJuatciGS2obD9pDzg+3nXQKK12taFfBgTonB3pRXY0QYQsASTRkzfL1Bi4dSNwxUQGFPRhup4EHNj3Oij+IiM7vihpFTDie6+YRVqJpmLi6pKL4M1pL3mG9SVg+8E3kxRJy7ltCVlPvBB/Rky1hm+LA1AHcZ277U4QMSM1Dlf9ZMG1FgGmvopb7iBtiLZoz8wlkQkGq1gFRDvHYPLIKprVosN/n2L7slLVDdoRhRFyMz6dgaGXOuNcTgDq86e5+9M42PUBvK3pcCLwjHczcUirht3lNb5yItujJiOXrC8IRHIGU55IkX8hhyddM3AqtqLmWTndgyG4WCv2nNjZhTijVqYBbxWLp9zOcQopXQj74nSD28vI9XEiT3NNMo9ChCXba423WZwBvRsWQABvO2tyeqMotsHrYHiE6gofVeNq/va3mPsVPQpc7ouPrtKorPZbdgItkPm6rt3wt9vB2oSha/CT0jsyWFJaz5kx7MKdhNsUJNG8fzmIPYNTsWzlNf3pMc9X+dAuS1IRkU+jF45xv19w62MZJW6u7YdcMVNaXnpRCItqUdt2rMW+matDGdSOyzHr0eO47FpccHsl/ARi93lMs+cd97w+oJLb1h4iZY86V1YWYuQQRHMBqc/MHdAe2suF/fpdh1kPY9VmJ80SlGX5qBEE4w6sH/d1a+akuZhdcjZyYHrEtfcWNJfFTx0hgmqnspFY7i5Q93/9KtJrjkp6/xAPi4M7I26Yha6dprQRRvLhkF5yGjEtGAPyMCca/IW9uYo2yV0xrUhxnTBBqrVVAIh2RZnuWvpShx/EMZ0Rf8M7c3b8d0hBOKfD1/Ht7sbva21xwrdTXuPsq09wWcGcepTOlNDPTHPMk97MF1rqOUf1Ehep8IQL8jEOOivMexdEk28jX25OvSoZiokdBJE+vAYAUnJ62BFKd3swsb6eglwOPA/b/tlKPRjt8KvdPuJwDut+9+wy1IpXT6vrHchf+ecIKwxk73MkFwt52bCmd24g9/ptJqXvREQuyks2uvkiM1LpZQZk1KsOe70JwujXsvA8jpNNn6co00jAAcVlACwPQ7hupnpM0IzKfqS7kW3o4fpx5DpnuStrMVAWRJk8AAqcPfZYqpnPF51M0ispLcRSKnPvU+zMSplSh3wWFtR6PQ+Nop3xuEdKqELblXXX+0+LnyHhbtt9Ae1L9Rmo/Q/DRlC5RdPIQik2icyejENEekS
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: 6df92d1b-97f8-4e2c-9a76-08dad3293bee
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Nov 2022 23:18:48.0052 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: Qd/9rqBd8EMXPFHdYjdonAILPip+BVQ8N2++FUVn/JVLKdcqrmdiT1l+cQeLOPAa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR02MB9532
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/RxD0l_zjypAN8CL4llQUX3D7Qh0>
Subject: Re: [lamps] CAA processing for email addresses
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Nov 2022 23:19:08 -0000

Hiya,

On 30/11/2022 23:12, Stephen Farrell wrote:
> I guess I should go and read the draft now:-)

Just did that - it's nice and short:-)

I'm not liking the idea tbh. But I have a question: how
many email providers/operators have been involved in
developing this approach and how many of those have
experience deploying smime or other applications that
call for certs containing email addresses?

As you might guess from the question I think such
involvement is kinda needed as there are so many odd
corner cases in email services as they've grown up
over the last half century.

Thanks,
S.