Re: [Trans] Certificate verification

Matt Palmer <mpalmer@hezmatt.org> Mon, 20 October 2014 21:51 UTC

Return-Path: <mpalmer@hezmatt.org>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1149B1ACF57 for <trans@ietfa.amsl.com>; Mon, 20 Oct 2014 14:51:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.979
X-Spam-Level:
X-Spam-Status: No, score=-0.979 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_MISMATCH_ORG=0.611, HOST_MISMATCH_NET=0.311, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id krQP5NsLZyfu for <trans@ietfa.amsl.com>; Mon, 20 Oct 2014 14:51:29 -0700 (PDT)
Received: from mail.hezmatt.org (mpalmer-1-pt.tunnel.tserv8.dal1.ipv6.he.net [IPv6:2001:470:1f0e:9e6::2]) by ietfa.amsl.com (Postfix) with ESMTP id 907BF1ACF5D for <trans@ietf.org>; Mon, 20 Oct 2014 14:51:28 -0700 (PDT)
Received: from mistress.home.hezmatt.org (unknown [10.6.66.6]) by mail.hezmatt.org (Postfix) with ESMTP id EDA92282E37 for <trans@ietf.org>; Tue, 21 Oct 2014 08:51:27 +1100 (EST)
Received: by mistress.home.hezmatt.org (Postfix, from userid 1000) id 66DF8A5312; Tue, 21 Oct 2014 08:51:23 +1100 (EST)
Date: Tue, 21 Oct 2014 08:51:23 +1100
From: Matt Palmer <mpalmer@hezmatt.org>
To: trans@ietf.org
Message-ID: <20141020215123.GO16429@hezmatt.org>
References: <871tq6uaf1.fsf@nordberg.se> <CABrd9STBA9jh6oHXBzEgUD73rWDRbgrFZc69H5tHOzD4Cw=WHg@mail.gmail.com> <87ppdmhqg7.fsf@nordberg.se> <alpine.LFD.2.10.1410201340380.1071@bofh.nohats.ca>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <alpine.LFD.2.10.1410201340380.1071@bofh.nohats.ca>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: http://mailarchive.ietf.org/arch/msg/trans/cgy47aSPV9fWUKjoV_dXWsQYd8I
Subject: Re: [Trans] Certificate verification
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Oct 2014 21:51:33 -0000

On Mon, Oct 20, 2014 at 01:44:57PM -0400, Paul Wouters wrote:
> On Mon, 20 Oct 2014, Linus Nordberg wrote:
> 
> as individual without chair hat...
> 
> >  Logs MUST verify that the submitted end-entity certificate or
> 
> >My intention was to make the specification less restrictive by changing
> >
> >                              Logs MAY accept certificates that have
> >  expired, are not yet valid, have been revoked, or are otherwise not
> >  fully valid according to X.509 verification rules in order to
> >  accommodate quirks of CA certificate-issuing software.
> 
> That seems to bring up the topic a bit too broadly I think? How about:
> 
> 	Logs MUST protect themselves against spam. They MAY require a
> 	fully validated X.509 certification chain to one of their configured
> 	trusted root CA's.

I prefer a more broad wording:

    Logs MAY reject certificate submissions which would compromise the
    integrity or availability of the log.  An example of a valid reason to
    reject a submission would be an attempt to "spam" the log with large
    numbers of certificates, consuming all its storage space and/or
    processing capacity.  Logs MUST NOT reject certificates for any other
    reason.

I'm willing to compromise a little on that last sentence, but I've seen some
comments recently that suggest that some people think CT logs are a
validation checker, not an activity log, so it'd be nice to clarify that in
the spec.

- Matt

-- 
[An ad for Microsoft] uses the musical theme of the "Confutatis Maledictis"
from Mozart's Requiem. "Where do you want to go today?" is on the screen,
while the chorus sings "Confutatis maledictis, flammis acribus addictis,".
Translation: "The damned and accursed are convicted to the flames of hell."