Re: [lamps] Preparing the shepherd write-up for rfc6844bis

Tim Hollebeek <tim.hollebeek@digicert.com> Wed, 28 November 2018 19:11 UTC

Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B996130DDA for <spasm@ietfa.amsl.com>; Wed, 28 Nov 2018 11:11:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.46
X-Spam-Level:
X-Spam-Status: No, score=-3.46 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.46, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i_Lo3UK93-lo for <spasm@ietfa.amsl.com>; Wed, 28 Nov 2018 11:11:26 -0800 (PST)
Received: from mail1.bemta23.messagelabs.com (mail1.bemta23.messagelabs.com [67.219.246.210]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5442B128A6E for <spasm@ietf.org>; Wed, 28 Nov 2018 11:11:26 -0800 (PST)
Received: from [67.219.247.52] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-3.bemta.az-d.us-east-1.aws.symcld.net id 53/55-08437-C58EEFB5; Wed, 28 Nov 2018 19:11:24 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTbUxTVxjHe+69vb24djmUIo/1lS77ArkdNQs 2wRiCS1Y/GE38YCKaebFX2qQtrLfE+rLEzZURQEMjjFJEXcWgdQuTgLJFUNkSHZsbIwRhzDEC kxfRMUdn7Abbvffgyz7c5H+e/+/8n+ecnMvRxhM6MycGA6LfJ3gs7DJmaF3HAX731GJhzm+3G fvlzgRln5ka1tkbBp6y9t/bmyh7eK4R2WPvn9PaTw/uy9c5+psbkePR40mto+9SgnI0Nz+lHA ujj7SOeMMo64j/PK/drtuldfuKSoJ7ta7+5EWq9H5+cOBBNzqKvthUiZZxDK6mYTE2oVMWRhy m4H44ichiFMFsRz1ViVI4FufAYNctSjFMOIQgXP+hStG4G8HolUpGodLwZpgcHGIVbcJvwUBs GhFdAF/fq1UZBr8OjyMP1VQD3gMd30VY0i6OoPqzhAql4Dxou3NODUJ4OTzp/VTdQOMM+Gnij KoBm2Dsx29ZotNhenxRS/jd0PRnj1zn5HomDHfwBFkN/Weq1KEB32Xhh4qLS3t5mKuro4neCq 11N1kCjSAob+6iSFAW3GnJJowHZiPjiOg1ED8+xhB+iIaP715bCl0FH8weWzKeaKHpl2l1aiN 2Qm28Z6lDDQ3z9/5lalBW9KXTRdV7PYugfjzJRtV7SoVvGiYYAvHwZfcNmui1cPXhKVnrZL0R 2p2kmgm1VWM6onOh/Ps/2LOIi6PcIr+72BXwCm4Pb8vJ4W229fLHv7neKhzindYyiRcFKcDbr MIBySod9O7zOK0+MdCG5LfpLH0lqxN93lLcg1ZwlCXdUBhYLDS+WlTiPOgSJNc7/jKPKPWgVR xnAUPepOyl+sViMbjf7ZEf+DMbOL3FZAgptkEqFbySu5hYvYjnToyEIrSR8ZX4RHOGIVuBsAK 5ynzPI579Jv1otTnNgDQajVFfKvq97sD//RmUwSFLmsGlpOjdvsDzTjPyEJQ8xGD4b2WIgPDC Mh9FOwuOrWiMlRsT569i7/AGaevbPv179q6FQ+HrkTeS5vrWttSTy89XREOmDb0jzEJeoiA3J VYQ74tOzSF3y5WPuK/+mivPbtmZoS+Ktx+uzvznyJ4jW8R3g61p2ezavs7Xar1V6Nf8ZPhCuF XTtrFi/7a+26GaWzs06Zs+KdmWPr/SwkguwZZF+yXhPyOIAeQhBAAA
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-17.tower-424.messagelabs.com!1543432283!2600568!1
X-Originating-IP: [216.32.181.119]
X-SYMC-ESS-Client-Auth: mailfrom-relay-check=pass
X-StarScan-Received:
X-StarScan-Version: 9.14.24; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 17697 invoked from network); 28 Nov 2018 19:11:23 -0000
Received: from mail-dm3nam05lp0119.outbound.protection.outlook.com (HELO NAM05-DM3-obe.outbound.protection.outlook.com) (216.32.181.119) by server-17.tower-424.messagelabs.com with AES256-SHA256 encrypted SMTP; 28 Nov 2018 19:11:23 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LAd8i+3chdh+nf2uAdL5SvvmDi+bz/kfmtdRNPptzJI=; b=bMlD0M6vA9XvOJmXSn7yLlgdTB4X7XXeQm8JJoPdW0W06DhyxkXle9j87iDeu2g8K5v1VIHzG/bRdIRzJOsdRdUMibO9C23LEJKrK4YM5D4qbgrR1PF5PxNlAB2eVYLvqjU2+91OjAm7N04EaYob5kXgs5CxSdUNE2QI9OCIowc=
Received: from BN6PR14MB1106.namprd14.prod.outlook.com (10.173.161.15) by BN6PR14MB1842.namprd14.prod.outlook.com (10.171.177.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1361.19; Wed, 28 Nov 2018 19:11:22 +0000
Received: from BN6PR14MB1106.namprd14.prod.outlook.com ([fe80::f900:1d08:93ec:2a66]) by BN6PR14MB1106.namprd14.prod.outlook.com ([fe80::f900:1d08:93ec:2a66%3]) with mapi id 15.20.1361.019; Wed, 28 Nov 2018 19:11:22 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Jacob Hoffman-Andrews <jsha@eff.org>, "fujiwara@jprs.co.jp" <fujiwara@jprs.co.jp>, "housley@vigilsec.com" <housley@vigilsec.com>
CC: "spasm@ietf.org" <spasm@ietf.org>, "jsha@letsencrypt.org" <jsha@letsencrypt.org>, "rob.stradling@comodo.com" <rob.stradling@comodo.com>, "phill@hallambaker.com" <phill@hallambaker.com>
Thread-Topic: [lamps] Preparing the shepherd write-up for rfc6844bis
Thread-Index: AQHUcHK01IE/ztbdkk6j+wugPJAzdqVhq4WAgAFXegCAArZacA==
Date: Wed, 28 Nov 2018 19:11:22 +0000
Message-ID: <BN6PR14MB11064C4AE7FA892254FD3B4183D10@BN6PR14MB1106.namprd14.prod.outlook.com>
References: <7FC03EEB-0D87-4454-805C-62DBCBA845C3@vigilsec.com> <20181126.140929.1660685088175275606.fujiwara@jprs.co.jp> <11295b14-5424-ba55-630e-6f22fa44b45d@eff.org>
In-Reply-To: <11295b14-5424-ba55-630e-6f22fa44b45d@eff.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [98.111.253.32]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; BN6PR14MB1842; 6:cvxSLCimx2xeR5VBciyqr/byHyoDFObkO/p/CuCf0Ku/ZUjmlTBoN/vPMUNbqegp4KOe/lwZ1UIhz6sAcPNRvnptNgymB3AL3lc1JONKMFYMGfV1bmhTLqmXlwS/lpBGp/QBfddHUAiwqZsxtw9QK3rTcawFBRdtAR3YsLbR+qwJbhVQ939aWnLZZKBJdg+zszLoTH9PLjVMlLLguPOs9I5pbxjyRz8NP0mnsMiwzYNdim8c93lKhWAFQGOnT+rySZQ8QZDOCMcPFnJoEtus6k9VSmEx8LbfR9CkKpsV+BiZ2mAWUfvPnoCZHZdNWvUgIxPk80j6EwmPjtBq/s62TY71fKCZQwWC0sBlAeHLk+iwkHxlhTGJvsVXo9UG6ZDWbwN6zeX44cJQ8aKn/vjo2Rc3P/YE4YLtXNYXKyBu9Wp8DosrnkBD+5hhUXDcOxJe7buAsuihEgvEMQHSRDxqtg==; 5:ehhYeGtKcIHWA3B5W2MR0MWHsRLu0UTF+v72heGRxsVrg3YES4iHQo07guZovesW0dFTTNUnFBbMIcb+3YVtVqNpT5iKA57rZisucrzVPfbCHjZcFGeqm4CTpJa68B/h88LxpELUVCf1EF07FvArX69Jwyrt2Nz9bwxz8RWqO84=; 7:/0GR5Rk11UK7Y8HDjKfhoDwI34a/1LpjwQhZQLBmNjUlDltLwHpXdkKUm6z7YD/VFGbhAdiGlMIqhe7UzLqCSrMpwsRfg6DSZ8XHM2p4qRJuS1lG3BteI4oaKBhHlbO0ExIOBrXSCTs256A8I7TztA==
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: ca0ee041-3de9-45b9-6cac-08d6556548e7
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390098)(7020095)(4652040)(8989299)(5600074)(711020)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7153060)(49563074)(7193020); SRVR:BN6PR14MB1842;
x-ms-traffictypediagnostic: BN6PR14MB1842:
x-microsoft-antispam-prvs: <BN6PR14MB1842FB8DB71CB9D962980E9783D10@BN6PR14MB1842.namprd14.prod.outlook.com>
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040522)(2401047)(5005006)(8121501046)(3002001)(10201501046)(93006095)(93001095)(3231443)(999002)(944501410)(4983020)(52105112)(148016)(149066)(150057)(6041310)(20161123560045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123562045)(201708071742011)(7699051)(76991095); SRVR:BN6PR14MB1842; BCL:0; PCL:0; RULEID:; SRVR:BN6PR14MB1842;
x-forefront-prvs: 0870212862
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(396003)(39860400002)(376002)(136003)(366004)(346002)(199004)(189003)(51914003)(256004)(478600001)(99286004)(68736007)(3846002)(7736002)(966005)(110136005)(229853002)(446003)(486006)(54906003)(476003)(11346002)(66066001)(316002)(6436002)(44832011)(74316002)(305945005)(2501003)(7696005)(186003)(6306002)(2906002)(53936002)(76176011)(106356001)(81166006)(8676002)(6246003)(81156014)(6116002)(102836004)(26005)(9686003)(55016002)(105586002)(6506007)(5660300001)(25786009)(4326008)(97736004)(71190400001)(2201001)(99936001)(86362001)(33656002)(8936002)(71200400001)(14454004); DIR:OUT; SFP:1102; SCL:1; SRVR:BN6PR14MB1842; H:BN6PR14MB1106.namprd14.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: h/XpW5XafbxBWt1bU0DDDrT4JYSVZInUUJAFuPwtMJ/879+Acbw9dUtrYgxQAjErCoZjedZPFkPhXGE701keKqNO0ekqFB2votM2gnH4XWcg1LTr3LYMpeMSR3OZgPr+Gx4mcjqu1Od/gkfZU1j2y62kHpE8KU/Z9SmSULG3potTNWbBdn9bOJCkP8SNqhsD/JExSE4P1WoQxH+juRimUSEqlAPJFyU+DrYwD6iH50Q0EwqZYCeAcA+9azLD5ISok6l2CyCmEaPMlkRI3eIX7BFVSuBuGDVLrZNlrQtlew+yZfy3PsCyQFQkaQErt/FUc1gBkbg/aMrvokQ+hCeLYncRkEMnaZ1OfoZ8FjCQEOY=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_0434_01D48724.37DF4AE0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ca0ee041-3de9-45b9-6cac-08d6556548e7
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Nov 2018 19:11:22.1336 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR14MB1842
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/SVwS-jJ6MlGUUobj3vMgOweOxKI>
Subject: Re: [lamps] Preparing the shepherd write-up for rfc6844bis
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Nov 2018 19:11:33 -0000

Jacob,

Thanks for the excellent analysis and timely analysis of 
the outstanding errata.  I agree with your analysis
except where noted inline.

> > 1. Before proceeding, please fix errata of RFC 6844.
> >     Most of them still remain.
> >
> >     See https://www.rfc-editor.org/errata/rfc6844
> 
> Related to IANA Considerations section:
> 
> https://www.rfc-editor.org/errata/eid3547
> https://www.rfc-editor.org/errata/eid3528
> https://www.rfc-editor.org/errata/eid3532
> 
> Addressed:
> https://www.rfc-editor.org/errata/eid3532

Copy/paste error: You meant eid5097 here.

>   - We no longer treat DNAME specially.
> 
> https://www.rfc-editor.org/errata/eid5200
>   - Parameters are now split by semicolons.
> 
> https://www.rfc-editor.org/errata/eid5244
>   - We added explicit wording about non-empty CAA RRsets.
> 
> https://www.rfc-editor.org/errata/eid5452
>   - We fixed the ABNF.
> 
> https://www.rfc-editor.org/errata/eid5065
>   - This was the discovery algorithm change.
> 
> https://www.rfc-editor.org/errata/eid5091
>   - This was obsoleted by the revised language we used for the discovery
> algorithm.
> 
> 
> Needs addressing:
> https://www.rfc-editor.org/errata/eid4062
> https://www.rfc-editor.org/errata/eid4070

eid5090?

-Tim