Re: [Trans] draft-ietf-trans-rfc6962-bis-28: "no security implications"

Rob Stradling <Rob@ComodoCA.com> Fri, 20 April 2018 21:07 UTC

Return-Path: <rob@comodoca.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FDCB12D72F for <trans@ietfa.amsl.com>; Fri, 20 Apr 2018 14:07:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=comodoca.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kf35P4M_GDuR for <trans@ietfa.amsl.com>; Fri, 20 Apr 2018 14:07:49 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0072.outbound.protection.outlook.com [104.47.42.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53A5712D885 for <trans@ietf.org>; Fri, 20 Apr 2018 14:07:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comodoca.onmicrosoft.com; s=selector1-comodoca-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=7VAf9CEQCHpM9eQNFRvl4TQyGzKvSOOsd+FM9j97MjI=; b=zsyGT5bafXeNHxtSNhBjDwjxA61EwMpiM3hTHF93fW+S1c8uQq+4ynW7AeGDQ0hlqNhMBxPEjPYpNUDRAiXu6bzc2IF6X6WeV5h+zkScE1qC8O+HQMtTW5ZdR4ytlUsSqbyZEv3pmcE/FEl7hjTWDADJOl+w7WBIZeWtV1wLEqU=
Received: from [192.168.1.81] (51.6.119.163) by BY2PR17MB0295.namprd17.prod.outlook.com (2a01:111:e400:58e6::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.675.14; Fri, 20 Apr 2018 21:07:46 +0000
From: Rob Stradling <Rob@ComodoCA.com>
To: trans@ietf.org
Cc: Andrew Ayer <agwa@andrewayer.name>
References: <20180320151249.ef2e85feaf05de8edac24479@andrewayer.name>
Message-ID: <08ec0e15-2244-ac90-3acf-d3e4153bcf75@ComodoCA.com>
Date: Fri, 20 Apr 2018 22:07:36 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0
MIME-Version: 1.0
In-Reply-To: <20180320151249.ef2e85feaf05de8edac24479@andrewayer.name>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Originating-IP: [51.6.119.163]
X-ClientProxiedBy: DB6PR04CA0008.eurprd04.prod.outlook.com (2603:10a6:6::21) To BY2PR17MB0295.namprd17.prod.outlook.com (2a01:111:e400:58e6::21)
X-MS-PublicTrafficType: Email
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:BY2PR17MB0295;
X-Microsoft-Exchange-Diagnostics: 1; BY2PR17MB0295; 3:hQqubChSLg6XpoVF3lsMvjbWQaGoAEqSqCUL//XPiPyvYzX9cQFAZ05lFazNkELlKk8g8VUKEH1s3qYgGsbC/hCPihDiEeHixs9KJJmwWCfcJ1/b0s56OWwvsuSlqfkkzC12+3dBBiWqa+sS5VPZXVn7GKK3ELs59NvHAgUcp9BC803F3Mq6VOl1Tgu3EdYoJS6GGzJEKl/zO66K3l+plUx0o85zhUVYz6qvivP7uM8Xr3IfVDzZxOcrai4V/44A; 25:rs/MgSjMe8Bkk8mdiOgH3nLbvAPXZbLaCmyrYrP3h5G8KrfflHjN5VLBRNcWSCH1c/szeAOgcB+ZLfDbdhZWFTGLUZoxUPTcAoXys+RFcGSZ5LDHMUdg4whCcM5O1by6U+0vZKyrWcb88BGkArxkodKOlVhtc5vodJZvG9sbH1nL074LJGtuZL7Ln/c3vonWZCCVMJcz8Oor2A3xiKbHaXqQHRRjczxeCHjytL2gM1K7yux41gkNSkREoN8FNqsypN2lQE+iyrkfdzFyPRaNAXrJP+3vJISkhbW8wmkOKUKdifJXi98E6AIopIr7ku4fRZAOfEWCoCPURV1nFZNDnw==; 31:GucfTJx5rNJUhVMS9oFd1wgHFGevPEjCO1yrnWrt5pzjlag2bHvY2Ks2r3J/FVmJOFiqxpqjnHHNEAgcBuXnYH3grv/OJT3fguBcnVInLCwfENjrpVCOkuK39yfDATK5QYNmISPgZd420iZShqpgSCyjzGgttTwuzcWwxiDk8WytjKCSMZZ3vmuMfhPzQc6foOB3OdDfe7VrDg17Hom+Rrek43uVU0P+p3hOk3oJ2l0=
X-MS-TrafficTypeDiagnostic: BY2PR17MB0295:
Authentication-Results: outbound.protection.outlook.com; spf=skipped (originating message); dkim=none (message not signed) header.d=none; dmarc=none action=none header.from=ComodoCA.com;
X-Microsoft-Antispam-PRVS: <BY2PR17MB029517F010DC6DF7B14B1280CDB40@BY2PR17MB0295.namprd17.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(166708455590820)(192374486261705);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(8121501046)(5005006)(3002001)(3231232)(944501398)(52105095)(10201501046)(93006095)(93001095)(6041310)(20161123558120)(20161123560045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123562045)(20161123564045)(6072148)(201708071742011); SRVR:BY2PR17MB0295; BCL:0; PCL:0; RULEID:; SRVR:BY2PR17MB0295;
X-Microsoft-Exchange-Diagnostics: 1; BY2PR17MB0295; 4:RQ/JYGZQWjEHiDrwdvDO/bTwWOTXfACpd9rAe3e4qWS1TesvnkVeLQPbW7rnvvkR42Pcc7Lx4oWVvc36T+wbvgVrTF3VPDet8Aw3zi1t6GM5IqkWRsK7Ne/7tCO5ctMIQO+nG5Lc8VE+34b1Q69V6l/3bQA9kSnpngJKFPeVzZmi/lsjafQpK9A8pOJSMoyeiGEBnoMu8a3mEQ2tWy2stvtKn7nPeIsetVOKOua2dwO7R9gNNV/FZU64ySWYW+FMR5FGOeirqDXAtX8uPG/Da+HJilUd9vNKZzJJsLNOXpuuq9hlsMbBcAXxyr0hMMZ27yLLfoBqes22nZ6uPPoOspSTbXV57q9OTutKamB28iA=
X-Forefront-PRVS: 0648FCFFA8
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(39850400004)(396003)(366004)(376002)(346002)(39380400002)(252514010)(478600001)(4326008)(2361001)(25786009)(5660300001)(966005)(59450400001)(117156002)(7736002)(305945005)(67846002)(316002)(230700001)(3846002)(31696002)(2906002)(86362001)(81166006)(6306002)(6486002)(2351001)(47776003)(8936002)(66066001)(23676004)(6116002)(6246003)(2486003)(8676002)(229853002)(53936002)(52116002)(76176011)(31686004)(386003)(52146003)(476003)(53546011)(2616005)(956004)(11346002)(186003)(15650500001)(6666003)(16576012)(77096007)(16526019)(446003)(6916009)(50466002)(65826007)(26005)(36756003); DIR:OUT; SFP:1101; SCL:1; SRVR:BY2PR17MB0295; H:[192.168.1.81]; FPR:; SPF:None; LANG:en; MLV:sfv;
X-Microsoft-Exchange-Diagnostics: 1;BY2PR17MB0295;23:eP5qcxmB47y5VF2k3xvFTL18h9LjXhhFsiUVozeolxESKrXtnHw4H/P8G0pQdBkzq1dnzbWU6ApeYI/eovnPJlpHoSb1xfcKN4f1vEcGZ8xNuYBUzCVQve72/T0k0Wymy1jdbKFXWAE7ViD8H+rAKXII8PjvTztWfWD/KyUXBKmFpghu7cgvy1jBUHVICEogIIwZXn7Xf8cCU0Dm5Po+mXsfMWhSsWMcw7zJrY8yJ/O9/JEqL/PEgUfnqTyBJYJ34YZg6OUKuqNgmVv4slhYOlZLbIvKaDgih/2e9ShJVweykHlcF1LyMf08GnJt+FRPdZ/fzOW4Rzwy2L8B/E4tJRYbnXHh0qlsQkaIjC6BR/RBk+hsWJW7SrSl5lh55bnHvR1rC7cdcP2YqA3SRjK+h6ob849nqKTengz5D2Xkyy8TKAonb3bwqFxMu3dM6mffGPMDQwCuy/Xa6gCDjtCe52599K76YddAOZQfyWL5ckiL0jclZuqoDmTiAzH8B5qPH1oEevWV7z8/ao7Wqpvf65Wv8kMjEvKqwUS+TdRu3AZ044E3vxmbn+xHumgZkRaIW/unJ4VSzVc4z5LyqvccJSvKLicWe6ZBDJEw495907eo6gYlqnc/tWz5x7inKcl/KvYJukx1d6vDCQszRIMNm0n8fFN2OPmEpHUqngXRDejKFSkmV6qCAL1MtgT4od6CoRLBDNSjntUPhNzLF7ER1sE5H7uYXh5N3r2pYogqgrd4CgJVGabvklr6mbe8OHxtEhHkUZ3sxvqoQ0FtlP0apYteHxCURFw9Pk1oTi9H+PAXTydLwdEAdc60k+KqwZ2O3ONC+KF53pDIlsxROSPdxzGP1TO9JgHGfFlDMXjsny4fZNaXgWnIkrpj+a7swQ+Wh4wruvCNR5CVVhb0BiWRmv6R5OITM5H26pdav1Xiv+88qXpo4CFGVoKK4GaFKYCn7rIm+Z0WNWhecgo6/vYwdcyBXc5J6sMvuTMKnUfDdL6vlNy9dLmXQTWLLgf2NVozkxMr5q5wR2tWRA8IR5HzP1r05UQQkt6seZX8HpGyzu5RTdm7RP6iE6Wi7I5RfC6yp2wXgSGXJxd+tlYBKgfzOY4y6UPnVoMvtkwAklwA8ZdC28yTMnlCn2Jpdr8VyZgVeT907i/ZuDLNaYF9mTz/zH2vFILZX2FW9nQUGXuvoh0kWsKYzsUjIEgrcbxBLVkWrYBB5+PEN5298KRDhKP38CyPrEtYBVGQ4oc4mvHaJIEKZX7/JSu/n55ZIzDy7C+o/cW8YxRrEIF5NYNORgqS13onRvA0b6b3NxsYxE28iNaW2ewjKbM1FawTvJZmxxlX
X-Microsoft-Antispam-Message-Info: sOICUpIT/iqs6mA0P6E3AsKed1Bb7doYAqG71GBn35XU+XLqvx6G6OMO8+ALUc02W79KTb2SyVukuMmnw3IBUR7NXzeyl95Gp1J1nIkt2exJuAAk/NlaGJrF56zUA/4vk7Tj9QG5HM6ZzF82/w/LUFUdQkHGEPUg7eVd2AQgbC2UxPGEkW/jqfO20lsUglBc
X-Microsoft-Exchange-Diagnostics: 1; BY2PR17MB0295; 6:7EUUD3seyHP6B4gO+VAKlyEtUoopkJjNKB+zJ6q+2R2AMffIZ/4QHqjv0BBVHKyedqL631TD6btzGmUtWjCQZlUpEDibm1TJzrOyE9VLodgUkK1+Bdsrs47rQC8hWd5EZ4cPxw1dv/wQfbwJlJgqDteiLE2r5GFAsX+acigflNqRIeoNSGhj/mv+/89tCnYksJaav4NgydaOGi/DokirERldPb6LX98V7lEmphV4YEiVs8QQdGLRLAmanzw4PtvGip9PfjWX7TRL2Zm3WHsdgQ7vGh9sRNbMw5KyGIh2ax5Ry7LFPZG2VLEUIh3/BznxaN8oDzw1hPoDNeI9KPcWXJh+3iNyUb1frxsGWwUtc5VbA/g+dHqbuOwVepa5/7owNAx6atwaa6DzfOdDfjKc9qWlOCOvjx/EXVvftk7ac/zeQC6E0wUDdFu7CVD6PZ6/kxXqoWzF63QkupbbzHEDgg==; 5:FlFyyJQt+o/UItKcIH3jAGsw7OzFKiAlaFEwn/1MYNWILZbnGDVIILBpFQAAS9q7FJUVahStX2YqstY1hcALSbdyQmzgo2YMOjpWZqe/nYMvIqLhOHbb6dNI0GJVEflVVm6gMQiTUCq8ZvXGD7yrc9aqdwmzMiYQGe6U6kAPQ78=; 24:ERaHBBwWZ23UaA3c3iwgyFEy4xlc+R5nLnsau+gsnf7+jmqm0C1cCFetlZUYHx9uABuFFIbxzIApmJ37o++l0If9bHzsLaQDvdI63Hs8sRw=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; BY2PR17MB0295; 7:mFINuQM6FoDsM2DQIlmE9xsLcLop+NWepbpZ7Bnboarbx1oZDabgFiwB2TFO8QB3bwPtdaC7WfmX/jynXNEKh0WygP3EBaw2V3+BARcFr99qlJxdgzUOMNlAOMNL6PWhr3hsTuGHtuPHuo1wbfUlu8eldmTHnYVPCskmjUjkQcLJMTydNPt6HZZAF3uaSFpFbqMjn4+Ct4P7wsQ4m1SgnHrF/pG7qBvxa9c15E81YHx+4Ox0+9Kd+moudPXlSRZ3
X-MS-Office365-Filtering-Correlation-Id: 8c12fb7e-8382-41b6-0280-08d5a702c46e
X-OriginatorOrg: comodoca.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Apr 2018 21:07:46.2609 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 8c12fb7e-8382-41b6-0280-08d5a702c46e
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 0e9c4894-6caa-465d-9660-4b6968b49fb7
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2PR17MB0295
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/q9p33Kmzrt3gAKWM4qr8eODqBrQ>
Subject: Re: [Trans] draft-ietf-trans-rfc6962-bis-28: "no security implications"
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Apr 2018 21:07:51 -0000

I think this is a good change.  I've posted a PR here:
https://github.com/google/certificate-transparency-rfcs/pull/296

Anyone have any objections?

On 20/03/18 22:12, Andrew Ayer wrote:
> draft-ietf-trans-rfc6962-bis-28 added the following text to
> section 4.2:
> 
> "While there are no security implications to a log accepting
> a submission that does not chain to one of its accepted trust
> anchors..."
> 
> This isn't true.  The certificate chain enables the logged certificate
> to be attributed to a known trust anchor.  This is security-sensitive,
> as without the chain, monitors and trust store operators can't respond
> to a misissued certificate because they don't know which trust anchor
> should be sanctioned/distrusted for misissuing the certificate.[1]
> 
> Therefore, this text should be removed.
> 
> It might also be a good idea, to avoid any future confusion about this
> requirement, to add "to ensure that logged certificates are attributable
> to a known trust anchor" to the sentence at the beginning of 4.2 that
> explains why the requirement exists.
> 
> Regards,
> Andrew
> 
> 
> [1] In the general case, a monitor could probably construct the chain
> using its own store of intermediate certificates.  But this fails if
> the intermediate isn't known, which might happen in the adversarial
> case where an intermediate certificate is issued for the sole purpose
> of evading responsibility for a misissued certificate.
> 
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
> 

-- 
Rob Stradling
Senior Research & Development Scientist
Email: Rob@ComodoCA.com