[TLS] Re: [lamps] Re: [EXTERNAL] Re: Re: Re: Re: TLS Client Certificates; a survey

Nico Williams <nico@cryptonector.com> Thu, 02 April 2026 17:09 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 34D60D5A7171; Thu, 2 Apr 2026 10:09:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775149745; bh=i6Zh5EIhuu0CqvvnQUd5+H19JAni25cw9mUBKhjb398=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=N9hhSVvb5Eklc0KDFaIPJ3U6DOMISfk/afrHRhv5K8CbhoKBsDO3lJLGs8Ox3kRgg 3Dm2GQXjovmLo+uotfe8RnXMWs5lkW0Tei3nxgBVFfNgZ9yzaaSNIxiW9ZBSBG0Kyb 1Zzurtwx0paEmVnNU1/f+zogxeNR9ZmUIKyHPdCg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cryptonector.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k1HOV3U-jr5L; Thu, 2 Apr 2026 10:09:04 -0700 (PDT)
Received: from golden.apple.relay.mailchannels.net (golden.apple.relay.mailchannels.net [23.83.208.73]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 8866CD5A7169; Thu, 2 Apr 2026 10:09:04 -0700 (PDT)
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id 838398C1F30; Thu, 02 Apr 2026 17:08:57 +0000 (UTC)
Received: from pdx1-sub0-mail-a244.dreamhost.com (100-96-162-196.trex-nlb.outbound.svc.cluster.local [100.96.162.196]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id C3AEB8C1EA3; Thu, 02 Apr 2026 17:08:56 +0000 (UTC)
ARC-Seal: i=1; a=rsa-sha256; d=mailchannels.net; s=arc-2022; cv=none; t=1775149737; b=CVkqe1YUm8qJ9ycvGFwqpuifmPHzZxpZ7XRjotVP7Xy9A7ZOaixB1Pd/DrHNmUIkJUAiqv qLGWYAPxy7ZuQRVlip/2t+5DNhCcBaJYb4v8wOPkCLm4ko9jbEF4iuYTZV9ZdJ0Sh091k2 5kpFrSHWmA5n2I8pdrMxWYMk2b0r3Vj5jcGA4CEIXapLn2NAka9atMb9HNCsZcABmtMOi+ dFJjw52gAyBIdqcx8ngMeStEqnLGqMigT9HqDPrb+z9URwTDNU+ZZtLgT2XKl84LCfgdOS 6dNkGunnk7XST30RbT35x3pFtE3Qy7pSsD8EXWTxxrj7/Axci03JDO4KxfZ9jw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1775149737; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=BDSSCKU+yFxonqIl86quZwxQGLbryfhx7JJ6X/xD/9o=; b=Dhn6VPNxReozm1gug0YVEkm/wAlf2xsjGBxcB3vmoSXcU39vehGzkw+lFAf/HsPJqWJ61l XBk5DAzn3ZRw1gCBFyYaPMAg5+6PfGs8PC3W4VODyuRgDHndhOQqE0E/NOzOXLOLClVkS2 T8Ool0x24Ow8ozh1EskKDxcMs9ktBCBIiJzkjD5104gofJk7SjSLVA8Z4vnlGp3JA5C+Ns ZJBK0YqDlSrbIbhQc/YSaSmzSamNy530DUGQRFalfm71DRs5asI5GxaOTv1Yx5e+ZSad2w XgAhOIZGppKK3aDTDLSB1oXlQS/WWsPBV2AgYObBV5cdWMQ0k4cmxu6YxrYUHA==
ARC-Authentication-Results: i=1; rspamd-bd48b9d95-rh9vm; auth=pass smtp.auth=dreamhost smtp.mailfrom=nico@cryptonector.com
X-Sender-Id: dreamhost|x-authsender|nico@cryptonector.com
X-MC-Relay: Good
X-MailChannels-SenderId: dreamhost|x-authsender|nico@cryptonector.com
X-MailChannels-Auth-Id: dreamhost
X-Stupid-Turn: 1f1070d338c5d621_1775149737256_1875847456
X-MC-Loop-Signature: 1775149737256:1263800186
X-MC-Ingress-Time: 1775149737256
Received: from pdx1-sub0-mail-a244.dreamhost.com ([TEMPUNAVAIL]. [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.96.162.196 (trex/7.1.5); Thu, 02 Apr 2026 17:08:57 +0000
Received: from ubby (unknown [75.81.95.64]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by pdx1-sub0-mail-a244.dreamhost.com (Postfix) with ESMTPSA id 4fmpF32ZL4z1089; Thu, 2 Apr 2026 10:07:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cryptonector.com; s=dreamhost; t=1775149640; bh=BDSSCKU+yFxonqIl86quZwxQGLbryfhx7JJ6X/xD/9o=; h=Date:From:To:Cc:Subject:Content-Type; b=l09GLyL8pF850lKEpK30VfvtzTpjXKVYNymmIWsx1XA7Vvnc0gR2BKHc0/ycHq1rk VxkoofZ0b7Q3oqouSVu80tQIfeDWsdu+aCuWyEcURC1wQmwf8a0+mvf/ro+rYx6wFX iYahld1sW3307XL3A+46bKvb7npfGtZSLogsDdmXdO/Fwfa3xpDIMMe0MIgiC3F9WV 5mcte3n4dBS8sJoiDxg7KnN58Tsaub6OFx2aTBny3qV/W4M4A4Tfa/hj6fRRB8wmCb xEu2PnYlQgxzq3x0LzpMNFRvyn6AsdRJshnFQshSHTSQmjf0PE/1ckHjSG0YLSCl6H 6NQ3jQ2Cbvq3Q==
Date: Thu, 02 Apr 2026 12:07:03 -0500
From: Nico Williams <nico@cryptonector.com>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
Message-ID: <ac6iN4Z6UaUsARHt@ubby>
References: <MN2PR17MB40314193002D42E6ED4F465ACD4CA@MN2PR17MB4031.namprd17.prod.outlook.com> <MN2PR17MB40315028C6985BD9F4F0C886CD52A@MN2PR17MB4031.namprd17.prod.outlook.com> <acrfWoDSHUrYj1if@ubby> <CAKZgXHqKBwYqjB3SOexT1B3=P2m83esgQTV74PJtjk+LGwAhcA@mail.gmail.com> <CACf5n7-n6xj35ukPznkes8rDx9-QWi+CDntt2Z5jcM1L+uo1RQ@mail.gmail.com> <MEAPR01MB3654DAD44EEA7037763885D0EE50A@MEAPR01MB3654.ausprd01.prod.outlook.com> <LV0PR21MB66235C39FFCC9E350BC982DA8C50A@LV0PR21MB6623.namprd21.prod.outlook.com> <ac15yB5aylmUnjc6@ubby> <MEAPR01MB3654D313ADD0D83693FB21BCEE51A@MEAPR01MB3654.ausprd01.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <MEAPR01MB3654D313ADD0D83693FB21BCEE51A@MEAPR01MB3654.ausprd01.prod.outlook.com>
Message-ID-Hash: UYDBJTOLVYRBVHGT2GLHXZRNTT5J2YBB
X-Message-ID-Hash: UYDBJTOLVYRBVHGT2GLHXZRNTT5J2YBB
X-MailFrom: nico@cryptonector.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Andrei Popov <Andrei.Popov@microsoft.com>, Tls <tls@ietf.org>, "spasm@ietf.org" <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [lamps] Re: [EXTERNAL] Re: Re: Re: Re: TLS Client Certificates; a survey
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/K02ZsMQgZIIBIeNdr3U-czqo1-Q>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Thu, Apr 02, 2026 at 01:20:04PM +0000, Peter Gutmann wrote:
> Nico Williams <nico@cryptonector.com> writes:
> >Typically applications that support client certificates will have a list of
> >client _names_ that are allowed to access the service, or some other form of
> >authorization ultimately keyed by the client's authenticated name.
> 
> This is how rationally-written applications do things [*].  The problem is
> that, particularly under Windows, it's very easy to get drawn into trusting
> everything Windows trusts, which means in effect any cert issued by any public
> CA anywhere.  The example I like to give for this is a developer who
> inadvertently got access to USG systems with a GoDaddy cert they'd bought for
> testing, because what was at the other end trusted anything from a CA that
> Windows trusted.  I only know of the final end effect but I'm pretty sure the
> systems weren't originally set up to allow this, they just ended up in that
> state at some point.

Recall that we're talking about constraining client certificate use here
to just dNSName SAN certificates.  Since KB5014754 at least the mapping
of those to machine accounts from Active Directory should not be trivial
to spoof by WebPKI CAs anymore.  However, as we know it takes the USG
ages to upgrade and patch all their Windows installations, so... ok,
thanks -- I buy this.

I now support standardizing the survey's outcome, which is EKR's
proposal.

Nico
--