Re: [lamps] CAA Semantics for S/MIME

Phillip Hallam-Baker <phill@hallambaker.com> Wed, 16 May 2018 01:23 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 20465126DEE for <spasm@ietfa.amsl.com>; Tue, 15 May 2018 18:23:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.399
X-Spam-Level:
X-Spam-Status: No, score=-1.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OGHRHf4E5bd5 for <spasm@ietfa.amsl.com>; Tue, 15 May 2018 18:23:53 -0700 (PDT)
Received: from mail-ot0-x22a.google.com (mail-ot0-x22a.google.com [IPv6:2607:f8b0:4003:c0f::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 54246126CD6 for <spasm@ietf.org>; Tue, 15 May 2018 18:23:53 -0700 (PDT)
Received: by mail-ot0-x22a.google.com with SMTP id y10-v6so2492233otg.10 for <spasm@ietf.org>; Tue, 15 May 2018 18:23:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=ymOhnk1r6I0nli5ljt5SdmE9MErcSl8gd/kBH1BrdHs=; b=hvGcid9OVFSo5ZNxUj69MaOTkEXBI4RBmXhUWjWeYaWQt1hGiDyrCKNHe86dlEYbKL N5Z0CqudWRIE/rogCUJ5iDD6FL4gQ0NKXnlxHWrUMkfxTH5gaPUUAKgb0PNFRb/XndQt MB9elejLzWenmK48UgA40snodoP8Dsp4DdRWyYYJ9U/hLtAdLx2wZn+sZmoMHYZJL5gj 6oiA36VXsFlf5ckYYXbdBkypV/DQJ4kiyll92hI/XPDzU3LTWaGwVqn6aV0kRFLWAOPo iypG8IwYQXKCxy7pbBMgbW2a8s09IkWMNfgGAEk0pgKg29jpciEXBLnPETun39Qmb95r o9xA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=ymOhnk1r6I0nli5ljt5SdmE9MErcSl8gd/kBH1BrdHs=; b=mTQz4sqIfK5AuqnYHOnV5UwYTjtnHGtwcXgpjdgro95AONMJe01bdLzW5cc9YvJ5BM nsz1IhSf9nfEY1n/vxfm1hmhmTwvkTD749KpgfUkPptfSKUodBtiqE3vUe3MQCZc0Kaa gzylR9Qrt7b/DVmqNcnZ71ji794+TOpjRYmTpw1hSCHt5yTS27I8tpbgOXtLaju7Yp/O RTNJ6a14DvKpKRiskDhnNyeCt0mwwgzAwcDsq317xzm77InbClHqSckyY6Z5Xoef9to4 Jw18yqfXI4+Memfbbn/yby2PTrez9JenWkjaznTvYE6CRvOS62/BA+snx/ZY+4IW9oMm PBpw==
X-Gm-Message-State: ALKqPwe9AH8Mjfi7GiA3v2tfVi/TjQVF1UrKmX25JxUcQvGNsnxwTKqS wWUfHkui3YRDFXzp5nAnceGdPcftDtI/SXaNkuA=
X-Google-Smtp-Source: AB8JxZrkLnk6LfFLCJ6NhpXnsbx4to2PrCxAxoXYThV1vXBV7fHs/FZKZpG0sfMpQDY/gHkqytsC5yB+Mg55hM8QgMQ=
X-Received: by 2002:a9d:14b9:: with SMTP id d54-v6mr13079108ote.380.1526433832751; Tue, 15 May 2018 18:23:52 -0700 (PDT)
MIME-Version: 1.0
Sender: hallam@gmail.com
Received: by 2002:a9d:23:0:0:0:0:0 with HTTP; Tue, 15 May 2018 18:23:52 -0700 (PDT)
In-Reply-To: <CAPh8bk-dtfqcf35m=Jwyv7Mm2mrFXe8xgiEKfvj7_W8PB-=+_A@mail.gmail.com>
References: <CAPh8bk-dtfqcf35m=Jwyv7Mm2mrFXe8xgiEKfvj7_W8PB-=+_A@mail.gmail.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Tue, 15 May 2018 21:23:52 -0400
X-Google-Sender-Auth: _wbC5QzPQ6TIQNhrETCVkjB0sG8
Message-ID: <CAMm+Lwi=7wTrKmVu6PJ2SaVXHML8H6Tx3BZnPcLx=t8qqD8Chg@mail.gmail.com>
To: Wayne Thayer <wthayer@gmail.com>
Cc: SPASM <spasm@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000005fd7e9056c48923b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/bJQUZqt_Yqis_WgHdVFIns-bEGI>
Subject: Re: [lamps] CAA Semantics for S/MIME
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 May 2018 01:23:55 -0000

I think the work would need to be deferred because it will take us a little
while to work out what to do....

But I have changed my mind on this. There is definitely a role for CAA in
client cert issue. I would strongly recommend a different tag but there is
certainly a role there.



On Tue, May 15, 2018 at 9:00 PM, Wayne Thayer <wthayer@gmail.com> wrote:

> There is a vigorous discussion about CAA and S/MIME certificates happening
> over on the mozilla.dev.security.policy list [1]. It has been proposed that
> this issue could be addressed as part of rfc6844bis, but I'm reading the
> LAMPS recharter as being too narrow in scope to permit this. Does this work
> need to be deferred to a future LAMPS recharter?
>
> - Wayne
>
> [1] https://groups.google.com/d/msg/mozilla.dev.security.
> policy/NIc2Nwa9Msg/RGx4A5HBBAAJ
>
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org
> https://www.ietf.org/mailman/listinfo/spasm
>
>