[lamps] CAA processing for email addresses

Corey Bonnell <Corey.Bonnell@digicert.com> Wed, 30 November 2022 17:17 UTC

Return-Path: <Corey.Bonnell@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E81D5C1522D0 for <spasm@ietfa.amsl.com>; Wed, 30 Nov 2022 09:17:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=digicert.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pBZf8uNiCCO3 for <spasm@ietfa.amsl.com>; Wed, 30 Nov 2022 09:17:46 -0800 (PST)
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on20713.outbound.protection.outlook.com [IPv6:2a01:111:f400:7e88::713]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 19AFFC1522CF for <spasm@ietf.org>; Wed, 30 Nov 2022 09:17:45 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=B0o+BlXIDYyuE63ju50GoUR7J0kf987T3WeMZh2MviOOXqK+T4vhOBCk6s2/CZZ5K2PFTdh803ImYefb3ccBHRKNaa0wE2dcMEJI8AaJ6vsrTs6ayzaYrdMp/nVc/UjwSorxsUpWoT0Kpvij2BCnPAmVL/mQtUpdbQkIw+fvsm44eQuTsp3Lg51/Ii+lwSam9pSA2FaG/ofSdvNQIBa1hy4C3Q9TFatnpr83EVsGQYQX+LyCyoWwb5cceSj3t78QslyzuioJ+zr6a5fYXYuRi/n4dWj+iUMq6mJJ7EkpHIKFB6X9h65mJmuDE+3TcJ2Sk13M5GZIohKcOPMzb/gRbg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=JO6njNLrVoA0mKTHz/17ZzjMjoPbseW5ipGFUGFbpcg=; b=QHH3m8suVkeMzhrCbSqK53F4PUGxVLFX2wbOVtX4Qym0M91LqzHaMDWaqqge7H/uFxxtWbTPU0FKBdvEwwcDhUocci0e0PvH0U2q6rinyGtLh59KsOHQXYCKrdYzgKQM7Y2Excjt1GqNu5yHjJ0z2VlbrtP5s4Nxaxy7vvkKtXBLkcsoTDhA9PcU+xQxRgF4Sa6EiU/pu4zXQJnD1S/ArQsyvPeZnHlnp8ID8Z7DnTUpVvhDLoMFUi3AOoST9Peb/8jGZ88oqCimPJVkBXD+KBZIgWpX8GJ4TTYHSNcA5AweU4aG6wNFKPus9eK+v0nnWmqr3/TVL9HiVzMACsHfLQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=digicert.com; dmarc=pass action=none header.from=digicert.com; dkim=pass header.d=digicert.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=JO6njNLrVoA0mKTHz/17ZzjMjoPbseW5ipGFUGFbpcg=; b=JOPe5MpWYdRm0CRfh/ubiWteiq5iBZ5MyQePAWRo4nZQzwPdoZtnr/71W70/IMCChCRaYCQdl3Lqc5ZKvkpUhngc+vBztFnubEPtW5Z2PHNj3AvwxtUbq3iQ+iQCf/6+I1LNY6HckFeZ1Zc0akVS8P88GCqI/NhXQu5BekDV2itikpST/WuGSkPiI+qLPz4v8Qvg8NjzHYm+flGnaHZh6B80+quryE9VS7DpZLAzeLfgYJtyso6nd18izpUR5WXbK4OCdrxw+IOebETz1CHdZYISUoOF75MKyeIXke/G8sUR+OuEEPWEfZhzfHlcKCgsd+gmfTas86gXxkJcQKH7Xg==
Received: from DM6PR14MB2186.namprd14.prod.outlook.com (2603:10b6:5:b6::16) by SN7PR14MB4349.namprd14.prod.outlook.com (2603:10b6:806:103::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5880.8; Wed, 30 Nov 2022 17:17:43 +0000
Received: from DM6PR14MB2186.namprd14.prod.outlook.com ([fe80::c2c2:a770:a20b:58cf]) by DM6PR14MB2186.namprd14.prod.outlook.com ([fe80::c2c2:a770:a20b:58cf%5]) with mapi id 15.20.5880.008; Wed, 30 Nov 2022 17:17:42 +0000
From: Corey Bonnell <Corey.Bonnell@digicert.com>
To: LAMPS WG <spasm@ietf.org>
Thread-Topic: CAA processing for email addresses
Thread-Index: AdkE3JItxNBB7kz6RsOpvMkCMg4ICA==
Date: Wed, 30 Nov 2022 17:17:42 +0000
Message-ID: <DM6PR14MB2186A5E0A82D87085564B90D92159@DM6PR14MB2186.namprd14.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=digicert.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM6PR14MB2186:EE_|SN7PR14MB4349:EE_
x-ms-office365-filtering-correlation-id: 34e640e1-ec19-42e6-db8e-08dad2f6ca7c
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 0JBQqCfTv4rwrBX2QRQ6BhtoB/E4tjx6Mm/Y76yCV5xCMpizj+fBRlusGZS/Q48IdAnKf9/uDHJOyTsRZOiWvOyfuG1DXsx0WKHAFLKGLlfp5y+J6JUUh9MbrE62QXo1mY/vNJ4ww0HRT65wu0ZmsMx/FIhpTLZgfIfZXT8RG8i6dzcLp52QFIjU3Fyq9F14KnLqao6tayCpKa3hscs2EPLU7j0111/n6SrrnkNdkzCTFCkfXydzXbmSj5Cq6oydJsSfc1OqdaOt8TL+R9qiJrjm286gn9oJbSL3IEklmDAFWCFN7CCrJj/sUbE50WrpWb/FSoKgbbX9YeoUgnLCk1Mltc9YS6HD5O0ISNEHiA+D46ZaM4GeX5P0XDMJEgL02fvv2q8D6fUNTghXQtUndGyrpgzX0MsQzl51BYb5hlgU9noeqyEsNHqcMoqnIZq9ckI5GdTzSWgRjl7ns94dxZJDt5AQp0teVHfgVq0g3kEEkF9XQQIbrcchgKbegz2Sm2fMF6lFD4vzccsd5SroiDj4dRdrgW6X0LgCnfIprQMx2wJkVCaTbO63Gv+BgBHI0fm59AHJOdRpemDm2TlEeZzGvUE3PVKuSXVaXZQRGGuuC+h3KOtfgEYLyFDyQBuQdAuevNKmd01GtT3sPQcFNaYHJd0rIxTJjKyp9Ilf/zeXwxtErg6ttjrTSMU1f/5bFjnmQAvY158+wHYU2E5Gb7TJF/MjJjZq9lIWZQ6YGmMTTdWU9h8vYkUoZb9UJDHuoJroD2m74CNm4DeOokURrA3SFgL+ryckGq/5mJVK5lAEIgZj21qAo7gMiiBWG5I+
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR14MB2186.namprd14.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(136003)(376002)(396003)(346002)(39860400002)(366004)(451199015)(2906002)(83380400001)(7696005)(26005)(6506007)(9686003)(86362001)(71200400001)(122000001)(38070700005)(21615005)(5660300002)(478600001)(99936003)(6916009)(966005)(38100700002)(52536014)(316002)(8676002)(8936002)(66446008)(64756008)(9326002)(66476007)(76116006)(186003)(66556008)(66946007)(166002)(66574015)(33656002)(41300700001)(55016003)(533714002)(199583001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Mh4iwinea8gu360AY2ds6WVI6OHcK5ookFL0526jdryPIooy/mMjwm2Qo6+phfokt+a0WvTKvJKEjhGuJ5vE8yn4B11gkDIpm1tIYY7ZhWsUXon1BO+iJQ6VsvuK9lzCN/BO4CtLwTaeK9Z9x0RlP04m8Ss3SENk0rkIxWAMUiQgI75rrt5alfjRRAXUG3dStaidA/yp1G/PzhWpjMhZX+EE4eq8tj4Ve+Fc3nu7PTW3zEWQfKcAQE8wzvKV1InE18i5lxs4WPqS8CJaQ4/0/Mc5OYuq7UNWqDy7EmyxNUy4rkvsK4OqGgViBY8wcLhD4k+tHnBouDjpz7E7KHqlP8IBhp/9kUIEy/LKFx43wPnkmqB8Gzg0C5FUOTlsYu1Z4JajcyhigZz9oj0ubDNexkqwbLTAMNZUh8qOSUzgCXYZFhX9JU0f5Lrh7RADU7O4JqHb9/z72o/7CAEAs6VAugm86hKjY1K40rEFlyvWzB40cOahgHpg3QUcpN3BfqYcN9orpBuxx0FZO4piU+MCstJTyPD8CiqtVsEAOvZLyzNE5Izhsv9rNjn5pklC1eKqLkQURxx+HRv6D+RmYliOO8Gg+uJmHMi91dM0j3XdE3GpkSi3jvvOYL2XG5GLw1qeieg8/aoaHWDfDYwsfrvxAjuO5YrjzUp6Op2gEhG/1sKWGkCbdbNdMfDkTcFr8Zz221G8etpxOI/4F9oYSjLV1Vj5r31/3u9vIqSo+3rW2JLauGpZlmJct0PRTj+N/+daQIrJyhVRKN8zuP4VpNz5RdrBoPTtlXteiRFqpAIU5IbARAzMJqVGKSHP5sl9JTr5jWfNysGB0vNaAz8jjLaIS3Fr0n2r6Wd5cfkhDnGQ8O52cgo1d76P9bPUu96sV85EzlDW0KoAn/mA9Vnv7uTSfBtlZ91dKjxv1Gstg2ITlOxyPXgn2xwETapVGpDSc9esPCIlUahl2VSjRltFiy/bftZvToHZnfRLhAyI+4gNGxAQhZPj2hQNTo2HFN+GDaRPddiYqQ4qGc3VCPQEBfOiengVGHYfNTJH5MjPOkGI8boSiyN898JpHkmCaW/0qr8S/pIcys0i2OqatpBx6HT5AZ3xXH/WZOsLWIUjcR8BpNnMGZaHDP+Vc/XgtpTCEnTO6cC/F0H2ctDZeIfcTITUp6g16LHjWGVpoE9ZdDrjFz5HamLVI2UtjnjFDJsmyztJDtGwkCXgrPGagn8kyNyNAzZ0llkH8jbrj7uTnrsZGkwUdc+1c5p77nVXnLx7G55G6Qad7EwHgA+A2w6JQFsNW1NpndYbYaiWE6OvViWeArv02X64DvPMWPQCOkh2w4Kbki5XxjUdq5MBBVEcUsoqjzK6LYxqxmnofvrUZ2tvfEKi3N1ihc198qzgVYAn4Wh4pNqY2LLA4C5KQ4QNc5/+A5PdN95K4OF3BE+jeDSsHuf6mVYYlbzhWX7aXy5o3MmAndvx2oIFS46o0Bg4MoI7qPye8jUq7JM5W9AQHX8cVG+uousBCEMfYflWY3Sd5hkjvPdxSgmmYgJjhqTJkPHsQP4VClBFcrpkUSoitfGRqlZnnFfsnOG2vPeGz+j5Rofas6KKLcJSiwiGABUsynv7fA==
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_022E_01D904B5.BE6BFC80"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR14MB2186.namprd14.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 34e640e1-ec19-42e6-db8e-08dad2f6ca7c
X-MS-Exchange-CrossTenant-originalarrivaltime: 30 Nov 2022 17:17:42.6689 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: /956LE1g8jfNfmORgNHq1CnhI24W8ZZSK5+2L4haLrvLz21ZTUTe8s6LIvGQ3JgNIDEEGT1dA6nPsDCSwNfGA3HUQeWMqUZObJgbyXT1iH8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN7PR14MB4349
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/chcrIZEit6HcdGyFGNzyiL7Dg6k>
Subject: [lamps] CAA processing for email addresses
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Nov 2022 17:17:51 -0000

Hello,

Over the past several years, there have been discussions [1][2][3] on
extending CAA such that it can be used for domains to express restrictions
on the issuance of certificates for email addresses (e.g., S/MIME
certificates, etc.). With the recent passage of the initial version of the
CA/Browser Forum S/MIME Baseline Requirements, there is a renewed interest
in mandating that publicly trusted CAs process CAA records prior to the
issuance of S/MIME certificates in an upcoming version of the requirements.
In order to provide a full specification for CAA processing for email
addresses, I drafted an I-D for a new CAA property tag:
https://www.ietf.org/archive/id/draft-bonnell-caa-issuemail-00.html. I am
hopeful that such a specification can be reviewed here such that any update
to the S/MIME Baseline Requirements that mandates CAA processing can
directly reference the specification.

 

Given that CAA is a topic that is firmly within the scope of this WG, I
wanted to circulate the draft here and would appreciate feedback and
comments.

 

Thanks,

Corey

 

[1] https://groups.google.com/g/mozilla.dev.security.policy/c/NIc2Nwa9Msg

[2] https://github.com/mozilla/pkipolicy/issues/135

[3]
https://lists.cabforum.org/pipermail/smcwg-public/2020-October/000040.html