Re: [therightkey] Principle of least privilege...

Nico Williams <nico@cryptonector.com> Thu, 02 April 2015 19:14 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3AD41A1DBC for <therightkey@ietfa.amsl.com>; Thu, 2 Apr 2015 12:14:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.666
X-Spam-Level:
X-Spam-Status: No, score=-1.666 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OSiu3hklcVQF for <therightkey@ietfa.amsl.com>; Thu, 2 Apr 2015 12:14:04 -0700 (PDT)
Received: from homiemail-a31.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id 392E01A1A30 for <therightkey@ietf.org>; Thu, 2 Apr 2015 12:14:04 -0700 (PDT)
Received: from homiemail-a31.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a31.g.dreamhost.com (Postfix) with ESMTP id 084E2202044; Thu, 2 Apr 2015 12:14:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h=date :from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=cryptonector.com; bh=+Y82WWV/DbdoSt 7lJnAb0/gUWRw=; b=NOnrxLKrwqusV+fgyFr4u3CEg/fqv73bZRUmQ/8Zk9eQ9B saZNxN+ji+149w0GRZhxKqmMJpudhAS+r3oIqGrs2ykigVZdYnaO+1dMPxcuKMpd AfyBmmvdYR7mbEhPv7aoNZ04mXUfC4VuiBsXBk2nBu45F1+plYpIBFx8jAujo=
Received: from localhost (108-207-244-174.lightspeed.austtx.sbcglobal.net [108.207.244.174]) (Authenticated sender: nico@cryptonector.com) by homiemail-a31.g.dreamhost.com (Postfix) with ESMTPA id 740C220203C; Thu, 2 Apr 2015 12:14:03 -0700 (PDT)
Date: Thu, 02 Apr 2015 14:14:02 -0500
From: Nico Williams <nico@cryptonector.com>
To: Phillip Hallam-Baker <phill@hallambaker.com>
Message-ID: <20150402191401.GI10960@localhost>
References: <CAMm+Lwjc+_VubsJ+Yfx_356YV+1bB3tChLU1HdAc8cekbnX=xQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAMm+Lwjc+_VubsJ+Yfx_356YV+1bB3tChLU1HdAc8cekbnX=xQ@mail.gmail.com>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: <http://mailarchive.ietf.org/arch/msg/therightkey/9Drvm_C6Z8WOMTj2N1q4Tl8y8bM>
Cc: "therightkey@ietf.org" <therightkey@ietf.org>
Subject: Re: [therightkey] Principle of least privilege...
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey/>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Apr 2015 19:14:05 -0000

On Thu, Apr 02, 2015 at 01:46:48PM -0400, Phillip Hallam-Baker wrote:
> As a matter of policy, no cert should ever issue for a private key
> that is not under the direct control of a CA unless one of the
> following apply to the corresponding cert:
> 
> 1) The other party has CP, CPS and full audit for operating a CA.
> 2) There is a name constraint.
> 3) It is an end entity certificate.

EE is a kind of name constraint.

(1) is a non-starter, or would have been had we had universal deployment
of name constraints.

> Further no private key should ever be in a network accessible device
> unless the following apply:
> 
> 1) There is a path length constraint that limits issue to EE certs.
> 2) It is an end entity certificate.

Well, no, some CAs need to be on-line, but then they should have an
online key and an off-line key signing the online key's cert.

Nico
--