[TLS] Re: [lamps] [EXTERNAL] Re: Re: Re: Re: TLS Client Certificates; a survey

Andrei Popov <Andrei.Popov@microsoft.com> Wed, 01 April 2026 22:16 UTC

Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6D937D5232FD; Wed, 1 Apr 2026 15:16:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775081761; bh=SQzSv2mwgg5Zmntds63rIoz9USaiuAiF9jIU2hGA6BM=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=O1+iwP6EeBWcvSRJq3bw8iGdho8DuLKkK+HXu+pnCqisRPMLyVDBv0b8lTpajEUpb GvSaPH0Mr/DPR2Q3AgxL0J+3Dg0EBmaDkhY0ysOI+wLMOi9p7mswHaj9kWEMmw2x1Z mG0pXKi8NSjnuN6BeGL9+3ygLAMu9n2pw1Madt38=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2APGTOnwsWEl; Wed, 1 Apr 2026 15:16:01 -0700 (PDT)
Received: from DM1PR04CU001.outbound.protection.outlook.com (mail-centralusazon11020111.outbound.protection.outlook.com [52.101.61.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EE97DD5232DF; Wed, 1 Apr 2026 15:16:00 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=iOIUuiFnbqb3uTczKu2gfMW+Vwsvd9QqTRPc4FE7Vz6gAkqV0PO6JHt1do1OUSjbiXwnyPSitYXRKFztL8SPHDTm7wwOH09wZVRnj/OLd9b9R23siAmkDAbhqHZT+AuEdkutb51fgnQTrdgmGAWhMepTNgGF/0ZUziNe8QlMdodwobYfbR/E7iLpXZKawFya/mRukLQBc9z+ZyYkAcSMNL42tDKcx2liZRNfjTc0Mz0trIjsW6oT8AEnLZHQGaO4FImpeMGMg280lZHrpbPhRINC8eFFxfnBgTEos0ZadCfllbvkkDyT7c/4KoByfYoYA+T7xjbWUoUPycDYIv8hwQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SQzSv2mwgg5Zmntds63rIoz9USaiuAiF9jIU2hGA6BM=; b=PXm9iDaVretrANZNN20qpSzqtiiM3d+NeHPOTVHKhuf9Jef7SxdujOZUSMt4Hk+ZWg2hm0G/MtGf94LL13onsPWpvC2TPLn5vJnBKVh4qpVFo9SipntI30MfEF2cf0CYrjqIfbe2XV2S2RcmReGufGM1VXKY+UiViNcMVdAi3xt9RcVGg+Zl61nET8biLiNel76w8qCQ7lNrDQnS9ytI+oz9XWsxXr2HhUXfOBmqHQQ1nSyiFEtPd77lmUyeeiQAiakiRkBq14Xz1oB1Gw/ABq4SuiZID/xXzvBU33xzVbVjupIt8OroBA8A1EsXi8joUV/0oiPfJhxveTqByN9yQg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SQzSv2mwgg5Zmntds63rIoz9USaiuAiF9jIU2hGA6BM=; b=KY7T8c3OZ+teEK6IpiojnB2fhzlsgkMJ/tst1o36gKuyRa2M5xTYrkzVGZL3A/TQ1LYs9KZfekmLwG4kPjuI4g9xf7ajk+AV5ytAoOMI5dAL+OMzi+9FAvR9aGrDnZ1sfW5Gk+anrgK9QuCqGnJg1D6+4nFPIm8Fy3SAUNY/F5k=
Received: from LV0PR21MB6623.namprd21.prod.outlook.com (2603:10b6:408:332::23) by LV9PR21MB5623.namprd21.prod.outlook.com (2603:10b6:408:2ec::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9769.15; Wed, 1 Apr 2026 22:15:52 +0000
Received: from LV0PR21MB6623.namprd21.prod.outlook.com ([fe80::f1c5:29c7:254:49c6]) by LV0PR21MB6623.namprd21.prod.outlook.com ([fe80::f1c5:29c7:254:49c6%4]) with mapi id 15.20.9769.014; Wed, 1 Apr 2026 22:15:52 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: Russ Housley <housley@vigilsec.com>
Thread-Topic: [lamps] [EXTERNAL] [TLS] Re: Re: Re: Re: TLS Client Certificates; a survey
Thread-Index: AQHcwgnFO+vlsEpdf02Q2alb7ejSILXKw08A
Date: Wed, 01 Apr 2026 22:15:52 +0000
Message-ID: <LV0PR21MB6623C8F4A0644B04F57E93418C50A@LV0PR21MB6623.namprd21.prod.outlook.com>
References: <MN2PR17MB40314193002D42E6ED4F465ACD4CA@MN2PR17MB4031.namprd17.prod.outlook.com> <MN2PR17MB40315028C6985BD9F4F0C886CD52A@MN2PR17MB4031.namprd17.prod.outlook.com> <acrfWoDSHUrYj1if@ubby> <CAKZgXHqKBwYqjB3SOexT1B3=P2m83esgQTV74PJtjk+LGwAhcA@mail.gmail.com> <CACf5n7-n6xj35ukPznkes8rDx9-QWi+CDntt2Z5jcM1L+uo1RQ@mail.gmail.com> <MEAPR01MB3654DAD44EEA7037763885D0EE50A@MEAPR01MB3654.ausprd01.prod.outlook.com> <LV0PR21MB66235C39FFCC9E350BC982DA8C50A@LV0PR21MB6623.namprd21.prod.outlook.com> <AE27DD88-67C5-43DE-B23E-A2DD84714F36@vigilsec.com>
In-Reply-To: <AE27DD88-67C5-43DE-B23E-A2DD84714F36@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=51a2b967-2ea4-4e5c-befa-260dd0113402;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2026-04-01T22:05:47Z;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Tag=10, 3, 0, 1;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LV0PR21MB6623:EE_|LV9PR21MB5623:EE_
x-ms-office365-filtering-correlation-id: fb287eb3-9a21-47a4-6333-08de903c3cee
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|4022899009|1800799024|376014|38070700021|56012099003|22082099003|18002099003;
x-microsoft-antispam-message-info: rot5+gxyplKpTA9NgJONx8ufzTbiWpYZO8WG9uUH17Xj0rvf10aqeFmXGQBWd4qF9Rf9wTuGu60k3MeRuj53AxoOaOm+7ZGxkrC3eKkUHUA1yPOrF18iecqtDAiobKxcogJoz25gWK4ko8MxQXbMysicNVWhwlrB271jdiYKt6vjhwubpEHjbqzAPZs6QYUnsEaUlJNwYIzhpHvRBYmVpVgX12j+cwqYTmm6QhaJszh7xLGbg3ouq5yN2v2wUAgED0Ta77h4eN08dbbJkw9XmctX5DVoQQ03p6U1B90vXCdSLwLLCnQ877L0pLwnlzI/WOeI98hPL17VLkLKfjv7HPKYLPRqwWtXF/aNxAiZ24kS+RDaLGPpcLwm6AAWib/hAFb2ofQ0+LBZZzcbGewaogpTcPyFedTL8T2MDqBt9NORzX7WzJrF+sudk0MLK0kZBSSmN7utwGDjzHasZb29X7vs7KkfyIbo6BPUCTLPa4YsYIxO/5efZSag7rDe8MZ4Zdo3cvAq+D588mIzA3TtvtZS5WZTCjBaR/pk8e9y85qRyrS7QyHjM64TWCXSeXesohfC784PSd2+pXxBknthHqNXniBL7oKYtQ3y/CaJe8kIiwcbKzVkeIWSG9AZTKUuRMpGTGKZvX3g4M8pBkzII8tWzD11FonM3X4fFZpxbb+0vzvswGD4hsejGbaIfd99nO1CkaQPOCRGLOGKBumivTcnee2ODrqMeHRWrRL+h8kj8pR9XvcaU6NHoV69uVHiU2TrVE5r8CEIP0mL6WxGswdu6HxM1cvoDB6F4tr0tb4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LV0PR21MB6623.namprd21.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(4022899009)(1800799024)(376014)(38070700021)(56012099003)(22082099003)(18002099003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 3ygvyG7ORf94AtGuoXZ3V/z4MdcV8HRThB2In1OdBvzy57mRbZAAGba0iF8Ycw6XPwcZ/cFDX35H5oPPufgIPO1SCJ8r6mk/GHK6FbcQm96kf/TDMKqHpVOkUeLVT+ikZBQkDL57esH09Kl/XeMYII1Gw3+1NJb341TRETR+H1hmS3ruAQGxBmTuunfkgPKPV+GKH7xWQTgLWaZ7Y/Cpp9EJ5fyRnpxq7E9G9R5KlpHiNUgFc8+Rljdcx38DNrXb4rYmCX9D4hLG0Qe4ETMJDSQmLTjRElBRCWXtcqWlcOO7NDvxIQHeG+q2MjM63pdL1PLwarsGYCf7Zt6Exw8KMJFTeikqFOdpn/8zUrOJ/acENlfqdkSMilDw+Kpj+KnQIEZVwBk4+Pgqg0fVmE9e/fe2D9raXcbuwYPl5221I9yQkXKlo++SEv0v7L8gA+2FXLI5rAM+MG+CEIkI7la6iZKL1S1e0A0/0823D5Q7RnPAcLRlRu9f5hp6kSkt48hEtQwffyT3xh+7kEBOdl7FeBIg8zIEs1S2nkfUW/V0yg0oNq2yREwlf7C4n5BGx3yAtEoy7HCDKTxZ35q8Gxo70J/r2hNT9rBUevRu/qK3Tl302g4tHrL/rpNIJUoMA90Qmuu0w0bgUKUwd2TR5Wd+5sKe1hO4DxQ9T6sT1DddrXcpAhqID5coBZGEKs6QigluH2LfL8yTKeWbWbQtZKAdaTFf1gXdT9g8g0WRixkCYyOE7J19lePdXRsmWjaiX6nUaXo/vP0gUXdfNZIiYqOIktV+6D1ncI8FNkKHmdLVjeFpiZyQ2ZTx16yXEk1ySoS4T4u/OdMrx+JuAfWvJumXNHKo8c6OlM8lswYHdcvOrDl62O2D1J5ky0tsgcRds0PVam1v0rc9B9nPI8hrJeWvR10F8s+L4yKzU7LSM7WMS0sSqG1VuEG0+Hmn4VE75hgNPbZ2/DjY/0SNuT+GnvBljhl5Y2yCokEOCezZoSBSR9H1GADxgOtG+VSQghtfCwFY4ItzqgYjzoFaB+OQaabmXCKar/Dp6qIHYReOacuGzRPWStF80isVwO8CrYPzsrQq9GhflO/9AWq5bAyWKDzXmoEyXmiU1BRPrTP53ARMQz0IRSV5fahnx32kFT4taRIULHpj++uJwL1bHxsLhgtEccL5Ct/4+nChsRQjV5VdgfErxvEI/M4KUoLN0v96dcYcdkjFUSE/Vpj/v0dxoEiCFR6gWFvb6K56F8FAZ5D4LG6XtWB2vKbbLYwtEOPuCFnwJGj1Ht2cdYFwah92p/rzy9yH5Ng7jL8II4jAoR83W+tlJpqdy5ujlPEzldDBvwCUVAVLNndjH7uSdKfyLMRIIRbqHac3BmfEOncgkWV2G/rGsZFZSb1Mrc80sokNxpX+UyiXc8twQtFmFvrF/MHWB3qD3T/8Nh2ENA2J5LCJnm+duWFESMfII4J9+2xG0lVabkhf7UfbQgBie4RUXYvkwj6asY/ML+U7j9sQPCiRMuvloG5XbAtv+1YzJiGbRbKPUB2S//fD0YEeM1xObYhn48QGAL4D1iwVXTDRUklkm7TT1s4nCr3ygaPs26s+vPvsvHt/o9YeErjXx7a4HVbnPhORFi+iWPA5g30OoC80HsMMHNI3rXKEjnrGnl0XzHHThgMSfk604qW4id0Vcj64ptb+SAFPrikEEat6TYcREiCZA+UZhkkg1VyTYynwRyJj
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LV0PR21MB6623.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: fb287eb3-9a21-47a4-6333-08de903c3cee
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Apr 2026 22:15:52.7407 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 6xNLsOLfSQITWGX2Cf99CoI72dpoPL7P/IlRvQGqYWZwSrrqqRbolqOidiWOTJzPEDyWgmACP5M0403dKvM9Dw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: LV9PR21MB5623
Message-ID-Hash: D7ZVZPVMIUNYHIP5YFWX4FYCNEIWYDXP
X-Message-ID-Hash: D7ZVZPVMIUNYHIP5YFWX4FYCNEIWYDXP
X-MailFrom: Andrei.Popov@microsoft.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Tls <tls@ietf.org>, "spasm@ietf.org" <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [lamps] [EXTERNAL] Re: Re: Re: Re: TLS Client Certificates; a survey
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/y6c73jIXe5JhILyJ6hmigYxsM-Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> It seems like the proposed policy is forcing such certificates to be under a separate root.
Got it, thanks Russ. Would you say that this is an inconvenience/configuration change or a blocking issue?

> While this is not the WebPKI, the Internet email system is not a private PKI.
It is unfortunate that a change intended for the Web scenarios affects unrelated use-cases. Perhaps this is where improvement can be made (although this seems to be CA/B forum territory).

Cheers,

Andrei

-----Original Message-----
From: Russ Housley <housley@vigilsec.com> 
Sent: Wednesday, April 1, 2026 12:00 PM
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: David Adrian <davadria@umich.edu>; Tls <tls@ietf.org>; spasm@ietf.org
Subject: Re: [lamps] [EXTERNAL] [TLS] Re: Re: Re: Re: TLS Client Certificates; a survey

Andrei:

To protect a connection between two SMTP servers with TLS, one certificate should have cliantAuth and the other should have serverAuth.  The simple solution is for both certificate to have both cliantAuth and serverAuth. so that either SMTO cserver can start the TLS session.  While this is not the WebPKI, the Internet email system is not a private PKI.  It seems like the proposed policy is forcing such certificates to be under a separate root.

Russ

> On Apr 1, 2026, at 2:52 PM, Andrei Popov <Andrei.Popov=40microsoft.com@dmarc.ietf.org> wrote:
> 
>> So what actual problem was disallowing clientAuth intended to solve?
> I would invert this: what problem does a public CA-issued client cert solve? When is it OK for a TLS server app or service to trust every client cert issued by an arbitrary root in a SW vendor's TRP?
> 
> Cheers,
> 
> Andrei
> 
> -----Original Message-----
> From: Peter Gutmann <pgut001=40cs.auckland.ac.nz@dmarc.ietf.org>
> Sent: Wednesday, April 1, 2026 3:02 AM
> To: David Adrian <davadria@umich.edu>; Mike Ounsworth 
> <ounsworth+ietf@gmail.com>
> Cc: Salz, Rich <rsalz=40akamai.com@dmarc.ietf.org>; Tls 
> <tls@ietf.org>; spasm@ietf.org
> Subject: [EXTERNAL] [TLS] Re: [lamps] Re: Re: Re: TLS Client 
> Certificates; a survey
> 
> David Adrian <davadria@umich.edu> writes:
> 
>> History has taught us that commingling PKI use cases causes more harm 
>> than good. It is a consistent security problem when PKI hierarchies 
>> intended for public web sites get entangled in non-web use cases. As 
>> an example, such behavior slowed the deprecation of SHA-1 in 2018 
>> because payment card terminal implementations and their corresponding 
>> root stores could not be updated.
> 
> So what actual problem was disallowing clientAuth intended to solve?  I can't imagine any situation where doing this is a good thing, but as others have pointed out there are numerous situations where it's a bad thing.
> 
> Also, for users of said certs, is the eKU in them critical or not?  Its usage has changed over time from the original "non-critical = advisory only, used to select the right certificate" to the more recent "both non-critical and critical are to be treated as per the critical text".  I'm not sure if this newer interpretation was a unilateral decision on behalf of the RFC authors (it looks like the non-critical text portion just got dropped from the doc) but when PKIX debated it there was, as was typical for PKIX, a 50:50 split as to whether it was strictly enforced or advisory only.
> 
> Peter.
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org 
> _______________________________________________
> Spasm mailing list -- spasm@ietf.org
> To unsubscribe send an email to spasm-leave@ietf.org