Re: [lamps] CAA Simplification draft

Jacob Hoffman-Andrews <jsha@eff.org> Wed, 20 September 2017 16:10 UTC

Return-Path: <jsha@eff.org>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E1B8D133158 for <spasm@ietfa.amsl.com>; Wed, 20 Sep 2017 09:10:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.001
X-Spam-Level:
X-Spam-Status: No, score=-7.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=eff.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y3FRk03S9QyF for <spasm@ietfa.amsl.com>; Wed, 20 Sep 2017 09:10:48 -0700 (PDT)
Received: from mail2.eff.org (mail2.eff.org [173.239.79.204]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EFFAC132D18 for <spasm@ietf.org>; Wed, 20 Sep 2017 09:10:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=eff.org; s=mail2; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:From:References:To:Subject; bh=C15VB3HhCy1Bsq2fpllBzr2rWZhBOHnmwyYUt/uA8j8=; b=m3eW4pPkhjUOKhTOknqeZsnb8U+AWP+FaHPra4As81UBFsOAT+cPrREzWIHGcZLDPHjRUbHkTD5SPdxzu4gsFzFe6mM5zThAj3URo4ZpG9cE+o1SFe5gNh3jEEcrzIfCaY85CmSa76WKYThkqR9gh8L6ivMw8QgbJEM2Fq9zRJY=;
Received: ; Wed, 20 Sep 2017 09:10:45 -0700
To: spasm@ietf.org
References: <02d4e149-b777-5b5c-1cd0-a2c2aae49311@eff.org> <20170919.192008.787143344501911357.fujiwara@jprs.co.jp>
From: Jacob Hoffman-Andrews <jsha@eff.org>
Message-ID: <44fd171d-4487-99f4-5cb4-4279c069a203@eff.org>
Date: Wed, 20 Sep 2017 09:10:47 -0700
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <20170919.192008.787143344501911357.fujiwara@jprs.co.jp>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Received-SPF: skipped for local relay
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/ezTb0bLvF7R3TGMphjZnO8UqFOA>
Subject: Re: [lamps] CAA Simplification draft
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Sep 2017 16:10:49 -0000

On 09/19/2017 03:20 AM, fujiwara@jprs.co.jp wrote:
> - Current document still contain "tree climing" and checks CAA RR in TLDs.

Yes, the goal is to remove tree climbing on the targets of aliases,
which causes known problems (discussed earlier on this list), but keep
tree climbing on the actual hostname being checked, which provides
useful properties as Phillip mentioned.

Thanks for pointing out the formatting mistakes, I'll fix those.