Re: [lamps] CAA tags

Tim Hollebeek <tim.hollebeek@digicert.com> Tue, 19 December 2017 14:50 UTC

Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F1D01241FC for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:50:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PBiNwq_suGtz for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:50:48 -0800 (PST)
Received: from mail1.bemta8.messagelabs.com (mail1.bemta8.messagelabs.com [216.82.243.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D1451126FB3 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:50:47 -0800 (PST)
Received: from [216.82.242.36] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-12.bemta-8.messagelabs.com id 99/D2-01246-647293A5; Tue, 19 Dec 2017 14:50:46 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTf0xTVxTHe9+P9ok8cy0oZxWW2EScKA2oxKo zGqMJizNI5h+kmuirvLVP+4O8VwyyZCNOI4IaweJGY4cywiKziTEzLkON/FAcaAxgCIqKzGYK qEQYYhnBvddbnf5z87nne875nntzL0cbywwmTizyibJHcJn1ccwdy8856RsXrrRlBF9brdV3I 3prZX8QWX/q2bWOzn45+pTNrquLUNnfNzYyW2gbK3ns3qKdrPOPg5sKRqWiS2e6DCWoJr8MxX EMHqGgMnTWoG2M2E/Bq5PjDNm0Iqh9/oQuQzM4Pc6AnittlMaJOBUGfrjFakzjTfD20X5G4wS cAgMPGmmS8ymcbhpnCa+C6p5WvcYMXgAlJ9qiOTzeDk9PHWOJWS2CN1XXo0kzcC7cqvs1Wozw XJhoP0cRsyS4H66JMuBEGOjs0BOeA4NPplnCZugLvUGEU6CrphxpBoCbDdD3rDcmWOBixQuVO ZU3Q+TlUpJTj6B3YjgWT4OKyVwyw3YIjjXHvPbAL6FeA+FVUFrRxpLaFhpqr4UNpDYZ+oPLSf wfFs6Nd0eHM+J88DeQRgnYBA/vHkbH0aLAB2cLqDU0rkEQCbdQgegtzYY/q8MMSbLB2daGGKd BVWgoxouh/swwHVC9abwIbnSbPw5rvBp+nGzSE54P/vIBA+EsGL7+Cp1GMxvQZ4oo7xXl9GXL LHZZcjh9bkFypWdmWC1uUVEEh+gS7Ipll9d9Aamv8DudDv2OJlu3NaNPOMo8h7/tt9qMs+ze/ H1OQXHukAtdotKMkjnODPzm1JU242xZdIhFX0su9Sm/k4GLNyfyeQtUmVcKBLciOYjUjtZyU5 fvT1Hc+XsP1fVqdP27eriENjIer0c0JfEBrSvWypyFnvdN332RLpRiSuCRTqczxheIslvyfaw PoSQOmRN4ndYlXvL43nsPqWNR6lhVeSu0sXzC/5KpBB2YehYeRPvPv7Yc+etCMT/y2P5b55e7 c9onO4yOyCHW+6j+yPrisa3WmyNfTKcsebtlNW7i/NtSLweXZG4IZ2VJOzr35l7qS2qZ6P62m JaXzpoq/6rym4uH66Yj80PBwtLFtvo14f6Oz/9tcBxkW+btm85rL1iT440bK/XMTB49mjVoZh SnkJlGy4rwH+uHxq4dBAAA
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-14.tower-94.messagelabs.com!1513695045!201762065!1
X-Originating-IP: [207.46.163.79]
X-StarScan-Received:
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 22047 invoked from network); 19 Dec 2017 14:50:45 -0000
Received: from mail-bl2nam02lp0079.outbound.protection.outlook.com (HELO NAM02-BL2-obe.outbound.protection.outlook.com) (207.46.163.79) by server-14.tower-94.messagelabs.com with AES256-SHA256 encrypted SMTP; 19 Dec 2017 14:50:45 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=L2fTVf8oKpKK7vSXWmSA6V05Re6DpLw9ZuwBsbhrC2A=; b=jaSKz22QHbXOY9uyLSFVqrWxTYaxEtL2ryysa6/vH2sBsS8jwbbzHxkLiyCz4cEHD/nkJK7mH6i+J5Ao0rjo25xPUWapVqxtV0qUXoL0Mp8IibI62k1b0qp6o64b7T63okkpDBvhnvEA/FRvdP9z8poSpBcXkYoi8Sq06CHQm+s=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1290.namprd14.prod.outlook.com (10.173.132.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Tue, 19 Dec 2017 14:50:45 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Tue, 19 Dec 2017 14:50:44 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
CC: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwArdI8AAAC/MGA=
Date: Tue, 19 Dec 2017 14:50:44 +0000
Message-ID: <DM5PR14MB12894853413B1055CEF6FA74830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
In-Reply-To: <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1290; 6:VrWTlD0H0mZJs7c+zp1aMIC/YLfVtajA456zRngEMtskx3INia4YQICUdNUpZALFYIerFtM+3qCeS7ShID6tyvJFaD3cFvbaNXBUQxhyEayop9pKAf6b0k7JGtIPfejWrSI9RzDwYe2ktkA2HhaHd2II1fAZ1H4v1HpnByVP/EfQzD3MAgFDZjGinUf/NaPiD2wQyLpM2n0LGDMImET6mLy6D1b4rN5KGnzals1XLTlFn7gTZf1J3i89R5IyqjAbUI1qQMVpOmTL8ZuIJ5ykh8Vz7vMb3GndtZgQaqySC5kAlFTvIYjWHNCgyXA65lqGZmX/9+rKLCACvRFB11Vt2uih4SjjNGVwqw1AbH9MIhQ=; 5:LEXWG2eP0XXboUokNfyoIvPz0t6UWAmska+EDInWicM1Gpl3eCHjOK+GqnhdqC4b8DRpro+XAuWqTxSADNRxMMuzekzVYJOY1RcNjQxss4mbKeP//dFfhyYWPvHZ6FTh5nwcToopursu2ah0wcySufnswXXBtB8Em/IJZNcbHg4=; 24:5CgfKskZNk6kBo2tk6yAa2a4jjudAiM8jqzWQT46c4LLmPKxY5UveWZfEzB5KL0zD578XmQBSEksAdlDotRMljP4b0jsvFsEQjpEuhBUaHI=; 7:IB8WeQaedOmlT43PrH4fYDy/mo/iVPD7pGqoItbA88S2fjbAsoicaKfgL6OawgYaFIJAjOEu/hjnfuGEPxyUFlmlqdiIJFeC1oV64xzs10rWSkF36kEdsxi4VgtK1K89QJN2aWsr3vjgDrocP2dwSQrNSrcSMoJTsxPs1bP+x4RuB8lm9a/whm0gVQBjc/yHgh9gZHojTYGbQWxRVrWLC39hZX1zYs+3kQWEMUUV15FAt9Yj5yR233ePzTvJrZ+k
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: fa70d60b-a14b-4b5b-bc5c-08d546efe21d
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1290;
x-ms-traffictypediagnostic: DM5PR14MB1290:
x-microsoft-antispam-prvs: <DM5PR14MB1290DC716D5177B596D0CC75830F0@DM5PR14MB1290.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(8121501046)(5005006)(3002001)(3231023)(10201501046)(93006095)(93001095)(6041248)(20161123562025)(20161123555025)(20161123564025)(2016111802025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123560025)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1290; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1290;
x-forefront-prvs: 052670E5A4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39860400002)(366004)(396003)(376002)(346002)(24454002)(199004)(189003)(55016002)(5660300001)(3280700002)(1680700002)(53936002)(8676002)(561944003)(6246003)(25786009)(53386004)(6916009)(2950100002)(97736004)(74316002)(81166006)(86362001)(81156014)(33656002)(2900100001)(102836003)(7736002)(99936001)(4326008)(66066001)(790700001)(6116002)(2906002)(3846002)(54906003)(105586002)(3660700001)(6306002)(68736007)(106356001)(316002)(8936002)(14454004)(606006)(54896002)(229853002)(478600001)(77096006)(53546011)(99286004)(7696005)(6436002)(9686003)(6506007)(76176011)(236005); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1290; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_05C8_01D3789E.0F00E880"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: fa70d60b-a14b-4b5b-bc5c-08d546efe21d
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Dec 2017 14:50:44.6270 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1290
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/eke7V1_HGK7nxUKH-tP-hhZVKTE>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 14:50:49 -0000

As I noted in the preface to my initial email in this thread [1], one other person has pointed out the same thing to me.  I noted that not only is this an option, but it solves two problems with the original proposal, so I’m personally leaning towards it.  We’ll see what other CAs think.

 

That is, why is the set of policy not

 

CAA issue 0 "example.com <http://example.com> "

CAA issue 0 "example.net <http://example.net> "

CAA validation 128 "type=EV method=1,2,3,4"

 

On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek <tim.hollebeek@digicert.com <mailto:tim.hollebeek@digicert.com> > wrote:

Note that it has been privately pointed out to me that one possible solution to the criticality problem and the scaling problem is to use top-level tags that are independent of the issue records:

CAA 0 issue “a.example.com <http://a.example.com> ”

CAA 0 issue “b.example.com <http://b.example.com> ”

CAA 128 validation “Phone”