Re: [TLS] Authenticating the client-facing server with an IP-based certificate
Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 21 April 2021 02:03 UTC
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C2FB3A09F6 for <tls@ietfa.amsl.com>; Tue, 20 Apr 2021 19:03:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j7ukduLfD3Ci for <tls@ietfa.amsl.com>; Tue, 20 Apr 2021 19:03:34 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10113.outbound.protection.outlook.com [40.107.1.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EF9133A09EA for <tls@ietf.org>; Tue, 20 Apr 2021 19:03:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=jsn9mBejdcK9a+YCST2nocmH5NWepVSv8SDUonacdEFLuGF6TS2Xs+YDkO0a0LgtTg8viAWvXIaS7pD9M1HlybV1RcuUwUW0tZrw9CI7xt8u6G0AdOGP8ZjdiH031xxB2Zzbgo+EN4bL+Sk550P3jkrRElqd5GAmm5W4b3jw/sZ/xNHC2729kuyLFJwFLKIQOzM0VqxviH399uAgD6DyPiW1MGaabuG3g99VvjjVbh55ptSXkNiei4ZA/fknEkAjMVkcT312pgFsMnbq6zOILPbrben72GGBQXEZnREmw83d7IYHYV6WmYysN1O7RQXAZjDeWJda+1T1WudtiVQQBw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cnMEFaaFlce2r/0OQgIDFkRI4x+/OjzQFyvXjhbi6A0=; b=l1ajUx3TbKVF1FI8PFVOTM5LkL+xYToWja/eLLYVKDUvsk82Bvy4cOhQVyfPqi1OUh3DHIJABV8ttox+S7B5KAbhUwTXi8BYaNo0Ym+C5xsi1+VzU6jVASECVO/dOOpQYeUbwfW/wuPcip9VbqE+E19S1t++wxULdjSa7Z1m5DEpZPc2+eoTVYrSxaybF8szr6sRxqu9/b5mY2X+GU3Twv4aoxXZJBOnf6qFev8FI6nImA+4DkjH0nRZSnuwfgBSN0POmmhJg/7fRn46DBTT50TaYQqZEVGfwNVvAjm/Ji3bh7cEQr2zpAIVHgd40QYQnvOrlWUeAyN54kr8EE5NWg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cnMEFaaFlce2r/0OQgIDFkRI4x+/OjzQFyvXjhbi6A0=; b=dMNJkrCErcqYiPs1H+xbWYrJv471IwD0sTp0WETh0HomFmz1BsRyVtCjlVSmx5Uo4WoWdK1R3FzFoZBJEaYP1GGIYrjZc7BVdgZVI+H6IKeaPZiUeNewDNqLJUvclLyju3VREKHofD+BV4s/IbG236cLqwEr4p+mcU/SlGx7McuFPBXV8Riy9pn/T2VnQdhxTQke9wWSZ3+4k2aW2b2K7wRPuAMJI6yqqTxd5oJRmUXVXhxecTAo59EoYqgkXkDnVJo/2WtAx05dH0aRE1bUUCa9x94FUogJ3TiX1aBbqLSJUPHmwLrOZbCqO4GWOvKK0ONNuyah2331xsiC5czk+g==
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by DB9PR02MB7113.eurprd02.prod.outlook.com (2603:10a6:10:222::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4042.24; Wed, 21 Apr 2021 02:03:25 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::2d8d:9193:d3f3:6cc6]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::2d8d:9193:d3f3:6cc6%5]) with mapi id 15.20.4042.024; Wed, 21 Apr 2021 02:03:25 +0000
To: Carrick Bartle <cbartle891=40icloud.com@dmarc.ietf.org>, Martin Thomson <mt@lowentropy.net>
Cc: tls@ietf.org
References: <38f4c969-90d8-478e-9c3d-0bdf538dabed@www.fastmail.com> <37c84b96-324b-46a6-a3c0-57eb275f439b@www.fastmail.com> <674A5578-85C8-4134-B9AA-E9D287131701@icloud.com> <4837796a-4528-4df4-aa8b-383ff3229cb6@www.fastmail.com> <53B5686F-0A64-426B-8EC4-6A996F169EAC@icloud.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Message-ID: <7f1f6634-4895-3989-1960-30e617e3e81b@cs.tcd.ie>
Date: Wed, 21 Apr 2021 03:03:22 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.7.1
In-Reply-To: <53B5686F-0A64-426B-8EC4-6A996F169EAC@icloud.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="FZaAeGy5xLBxKpMJgHMpodwBDMbskgSlt"
X-Originating-IP: [2001:bb6:5e5e:b458:d434:7f5b:99fd:e7e5]
X-ClientProxiedBy: DU2PR04CA0084.eurprd04.prod.outlook.com (2603:10a6:10:232::29) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [IPv6:2001:bb6:5e5e:b458:d434:7f5b:99fd:e7e5] (2001:bb6:5e5e:b458:d434:7f5b:99fd:e7e5) by DU2PR04CA0084.eurprd04.prod.outlook.com (2603:10a6:10:232::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4065.21 via Frontend Transport; Wed, 21 Apr 2021 02:03:24 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 27ed623f-b79d-4715-c1bd-08d90469a5c6
X-MS-TrafficTypeDiagnostic: DB9PR02MB7113:
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-Microsoft-Antispam-PRVS: <DB9PR02MB71137D3FD1BF3C19708433DEA8479@DB9PR02MB7113.eurprd02.prod.outlook.com>
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Oob-TLC-OOBClassifiers: OLM:4502;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: eZredEw3pQfCKEJxrSzzDcJijPjtT3iTtWhcfFZxEYV0V3lUpziWSfMXFSw8VztvmjonHzsjncZSTeflHu0FbMsSraLdI7BLwLahOCk9VXlW417CABQ3yB2Rp5a1LGlAF5sN+tcuKuM3YobJUZKmh4ZVDuEvn+XdDimTLtIdhVr0xEJKnTrnWahZkRdmBSxVkI531W7T0FPlkvLdPPv1urw2XkPi/CeDDmN8KjM6qhZDIJhmjh/jQSpjQ0UG+zAltDl+/ruwUpzQWTrZG7HC7ysiRwnHwdgoc3XItDE6bpSL+K4XvoixsWm1gbxwWxtfpOZpw94ihjc3YJI2sZLo7p1yUj/TBiHTvSDWruMQm8cUT5Bp8pEOQ77nRRq8uiNPHrlCI25Qiabucm6vsEYX4HY37zYfHaMPG9WibJfcFeY8vMi0YgEdXEM25+hDRGhDgW0X425ZLfOc8V4zcpTj8lqJmPKbLLuQLNyAu0n7gOgYL3IHhAMYaOSSeev195vjtEyabuleIsUH64G+ys7/KYEBCAO6yP/a36vUo23X+j/9XCPTTGDy4ilABbDhZ/hQNfuVxZx72v4FRS8Q2zk00WETCMcyCpVynrCAYKS+hb77Fja9ufVvSbBViBoTtfasveY/mr1eT12ycjqR0Rz1jR4YNQTWiNyS79MU79GYNof4Fhak2WJbAIpvqhJqZWBS
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(376002)(136003)(346002)(39860400002)(396003)(366004)(4326008)(66556008)(478600001)(31696002)(235185007)(66616009)(86362001)(5660300002)(186003)(66476007)(8936002)(33964004)(52116002)(83380400001)(6486002)(110136005)(2616005)(16526019)(8676002)(2906002)(66946007)(31686004)(53546011)(316002)(44832011)(21480400003)(786003)(36756003)(38100700002)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData: WoC2Vkdm46xmDflVnaLsicE/CsSt7wBI6R8CHBDfHRUuZMeVpQOuQN7GNEDFzOG6apHib7oqrqTORXWdF4Sy2aypy55mzPS8/n/uL5Dpd6ou0Qz7EVYVjK9TQFhWOY58bf0elpVYIPBMuY78fkyCn6H7SmxpwoWrmqQ3md5zDLtkVGuWBgl0+r2/mw2FihldVGJDybF0AWYnpEWkqUZNAMuZltQs+CDOrOH0nSYjThgbhSR9l0pPL0uH2oVPMqPLS37JF7dVotLRXVzjYB9UOfmqAk/YSqUX9O5XFJ37+xUQN7ILkGYr1io5Uhwys0J2+X7yIt/L9pk/Zn7HYFhCWf3DfviT6abCYLJcx3do5Ck604xheDCNiYLYqUyHNuLtYD0TQm0J2aLim1rH+HkccrYe0sPkbMfWwH31n3kBAYfJ45d78abjaj8ydQDZeB0IUDns+lyzxNDPW2pMlMEEFtFAJljyrRwgkQIhuUNgsjlGzPvhvr8D4Ug9J5RsnMU8i8KR6u0fT3DNF9ZU3EqqzvVI4eZjGtB6iHePqMAji/0ziF1UmvVUmQX3o8RXa92UhmLxaYktR/mNGcPI8QHB+32XuBScIU67SH4rNLqe7watsMfpsSX+lhVXA6k+l1CtoDemF7JNwfzPDO9Wjp4w1/JRPcmeBjd/TMvC4FDEb498tAWwTAeNFTeA6n88UjpCO0Us9NsWWOD2pDGSGN4Xuppc+J5mkC4mVPRq7jMn4ph8HZqdv18bxnoOIGrF4uiTZM2axN3lrn11JEpZ1okan9E4u/l12hwmozVR2Bs3cWpAetmzFCyOjco4hFFXCo+KWq6gfdZAmwo83HcflFT36zRmKDFHlF8UeSTkpAA5pqDRmtZOmjJEgi+Jj/xVLHJtFxv95NhpOtmOlTyYwOyX+lDF6T8cAC+K9jUiAbeOF4kiqy6vFkwL9LNT/eX8tN0NitVnlcQCY7gReMXGMyq2hFKdt0nJKH5hYAbBV838f8nyQtbPNe1k1eT4v8hsDWJpaHGUZT9zrv5PgYpkm12I471O/BC8TmpeVHEB7l4xZT1SaTd1rDiMqTw/kVWzi/DB1OwrcznMp7aSicfAkvokDCMIVqaVRKrE+7A0ZDwNX8RTLxRQTr44FuEnpa9NBq4rxF+VyjYRO09nQ9kZUazh1zqYlg8nPAyKwhInkj9lLjzTDDJA2YrUGyWeHAW0gctvRf31mzmbXJW5165OD7oWZO4uKlnllk7nTaF7ld90VKQuRJXs190qWA8ubUZAT10JchoF4ju+yZavmIgnQQ5ehYT5CqWbMcfabwDGJpzD+W8OneNqyHsB39aRLCY16Vji3rxy3pk6KcdNTl+ZI1zQEn4d0e1C0/gjC9D+upLjHDizF3WONne7+8ztuVFlW78h
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: 27ed623f-b79d-4715-c1bd-08d90469a5c6
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Apr 2021 02:03:25.2557 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 3cUivTDVn1Rcb1WnF3PM1m8iHnJbpN+1W43D18WjoWD4FIEvRZ2Rk2venORMj6/k
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR02MB7113
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/-214bRrxfx8b_DOx3Nv3weH1kLs>
Subject: Re: [TLS] Authenticating the client-facing server with an IP-based certificate
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2021 02:03:39 -0000
Hiya, To answer Chris' initial question: I can't currently think of a real use-case where the client would need to authenticate an IP address for a client-facing server in the event that ECH decryption has been tried and failed. And, I very much sympathise with Martin's goal of simplifying if we can. (E.g. leave the public_name as-is and as we've got implemented, but drop the extensions field entirely - I don't think there's a shortage of code points for new extensions if the first ECH one doesn't quite do what's needed.) But I'm likely not the right person to ask - I'd guess that the people who might have a use-case for this are smaller hosters where the default listener on 443 is very minimal. I don't know how common those are, but I'd suspect they are fairly rare. And likely those with certs that have the exactly right IP address are even rarer. On 21/04/2021 02:48, Carrick Bartle wrote: >> I'm not sure what you are implying might be impossible. Are you >> suggesting that it might be impossible to get a name for which you >> could get a certificate? > No. I'm implying that if we don't allow clients to authenticate > client-facing servers with an IP-based certificate, ECH won't be > possible in cases where the client-facing server doesn't have a > name. In general, I'd prefer we get ECH deployed for some major use cases and not try fill in every possible niche at this point. ISTM the overall win here is that we end up with ECH working in many cases, but don't need all cases. And there's a danger that we get zero cases if we make it too complex. Cheers, S. > >
- [TLS] Authenticating the client-facing server wit… Christopher Wood
- Re: [TLS] Authenticating the client-facing server… Martin Thomson
- Re: [TLS] Authenticating the client-facing server… Carrick Bartle
- Re: [TLS] Authenticating the client-facing server… Martin Thomson
- Re: [TLS] Authenticating the client-facing server… Martin Thomson
- Re: [TLS] Authenticating the client-facing server… Carrick Bartle
- Re: [TLS] Authenticating the client-facing server… Stephen Farrell
- Re: [TLS] Authenticating the client-facing server… Carrick Bartle
- Re: [TLS] Authenticating the client-facing server… Carrick Bartle
- Re: [TLS] Authenticating the client-facing server… Salz, Rich
- Re: [TLS] Authenticating the client-facing server… Peter Saint-Andre