Re: [Trans] Relaxing section 5.1
Peter Bowen <pzbowen@gmail.com> Fri, 04 November 2016 14:07 UTC
Return-Path: <pzbowen@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F3011294FE for <trans@ietfa.amsl.com>; Fri, 4 Nov 2016 07:07:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rNTm5EaT-pgA for <trans@ietfa.amsl.com>; Fri, 4 Nov 2016 07:07:52 -0700 (PDT)
Received: from mail-yb0-x22b.google.com (mail-yb0-x22b.google.com [IPv6:2607:f8b0:4002:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 43615129495 for <trans@ietf.org>; Fri, 4 Nov 2016 07:07:52 -0700 (PDT)
Received: by mail-yb0-x22b.google.com with SMTP id d128so31094144ybh.2 for <trans@ietf.org>; Fri, 04 Nov 2016 07:07:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=rox/k2TptN5JOKZoxWSQlNUdIsdZrxq63pkyzysm5A4=; b=jM4fJSmgP4DIeQ6oM7VEXghxOtRrR0M0U4tpelvAv+47RikVJo0KH5T+/lLfYzsUAk fMCPhG+d2RksvgALzdHExCKdFf3ym1g9RqzVZ070UnnAK8fiwTdjPI69Fys/fslGxEWU IdWeCisDnl7GhdcLkh77YZ02uN7fNduAE5Jwudxmn8QfCmJcpLP0dP5lC+E9H56KBNfM nRmKd9U+RnUJrmL/2LtZdKn9oe61IVxdaGVDTN7iF35j2v89ucEE8eF6G4TkoZz1LDqr HNkjd7AWyGwYBupBo1jtHysRmfQgHkUo45WAlF51TOqXl7ijlahk1htc8fzZDmK3z9mu 4cJQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=rox/k2TptN5JOKZoxWSQlNUdIsdZrxq63pkyzysm5A4=; b=LSBGtswsjL2XtlOoTBe1JSN3/qxslve1Ix3KtQ0uVQl1aFw7NI6tDb+5Pzyag5s9jH rJoArNus9zlbVs8M3kmGqu/p5f2mT0Tt5/e2+mibP5VVPue/iQUkK7PrdJKD09LJQXtl aBPeiH0+4m6fe3RKXESEjaOtmiDKXWq3X7fmjEzinVyFuQa1ISZ59lJApyEgHOUn8sKR D/w3Mw6zBIK3tBRfgNiMfVROzXS6BrHrX66xxvmUv0ThhV9I9OJGni2BzhnurEbte58J fm1ZVIkptLAOX2/NbL4zgnsnIdL06wrhg3Pp94IvOxOjRWo6E3QKsmKO8Enyljcz1+J8 n0yA==
X-Gm-Message-State: ABUngvfZRtp034KyN48DkfEQuvU77kyKjObo1nSBc2NWRwd7WyubAUvdv2RxQ7q4XfYdBkWi/B8dKWreB30+GQ==
X-Received: by 10.36.106.76 with SMTP id l73mr1946849itc.115.1478268471285; Fri, 04 Nov 2016 07:07:51 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.64.39.68 with HTTP; Fri, 4 Nov 2016 07:07:50 -0700 (PDT)
In-Reply-To: <CABrd9SQnFApjrn2zOekHcfgvV6NyFFTr9ObwUdncsUggc7cFNg@mail.gmail.com>
References: <CAK6vND8_4OQ0du0MC8Z5=NJR5ho1EpT-8H41O+Te9tvM3YeNcg@mail.gmail.com> <CALzYgEcuf+WoUVy=vsPYJ7t49ASe_5Tc7ySOuKoYJMzpODHtSA@mail.gmail.com> <1c7240d7-f38d-2011-ad45-587843e0f1f8@gmail.com> <CAK6vND_XeyQsO=4pP12e3HL+r8Cdw_M7Gm1SB5zoQKGHbKUP7w@mail.gmail.com> <CABrd9SQ506fFGvrEj=Sknb-Lm3HESGwOvcuG84xovttxwirYSw@mail.gmail.com> <CAK6vND9b4oEOnZR=PtWw-znbsu785Gps87jumAXgFjkro-tptg@mail.gmail.com> <CABrd9SQnFApjrn2zOekHcfgvV6NyFFTr9ObwUdncsUggc7cFNg@mail.gmail.com>
From: Peter Bowen <pzbowen@gmail.com>
Date: Fri, 04 Nov 2016 07:07:50 -0700
Message-ID: <CAK6vND-sy2vCP4dufSBV0_-tT3BU1EOj-T4MJnObOQaeO3V2xg@mail.gmail.com>
To: Ben Laurie <benl@google.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/ue4MQL141s4N0hT5xbJHl5V_O3M>
Cc: Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] Relaxing section 5.1
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 04 Nov 2016 14:07:53 -0000
On Fri, Nov 4, 2016 at 6:33 AM, Ben Laurie <benl@google.com> wrote: > > The bit you didn't quote does say they the log has to accept valid > certs, tho: "Logs MUST accept certificates and precertificates that > are fully valid according to RFC 5280 [RFC5280] verification rules and > are submitted with such a chain." Sorry about that. So the three MUSTs together are: - Logs MUST verify that each submitted certificate or precertificate has a valid signature chain to an accepted trust anchor, using the chain of intermediate CA certificates provided by the submitter. - Logs MUST reject submissions without a valid signature chain to an accepted trust anchor. - Logs MUST accept certificates and precertificates that are fully valid according to RFC 5280 verification rules and are submitted with such a chain. When I read these together, I read that Logs must accept _any_ certificate that is fully valid according to RFC 5280 verification rules and chains to any root the log trusts and logs must _only_ log such certificates (and no others). If this is accurate, we need to account for all types of certificates being logged, as a log cannot choose to reject certificates for usages other than server authentication and the log cannot reject certificates that have personal information (e.g. an server authentication certificate that states which human requested the certificate in the subject). This seems like a very strong assertion of policy rather than a technical discussion of how the CT protocol works. I would again ask the WG to reconsider the requirement levels specified in this section. Thanks, Peter
- [Trans] Relaxing section 5.1 Peter Bowen
- Re: [Trans] Relaxing section 5.1 Eran Messeri
- Re: [Trans] Relaxing section 5.1 Melinda Shore
- Re: [Trans] Relaxing section 5.1 Peter Bowen
- Re: [Trans] Relaxing section 5.1 Ryan Sleevi
- Re: [Trans] Relaxing section 5.1 Brian Smith
- Re: [Trans] Relaxing section 5.1 Peter Bowen
- Re: [Trans] Relaxing section 5.1 Eran Messeri
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Peter Bowen
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Peter Bowen
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Eran Messeri
- Re: [Trans] Relaxing section 5.1 Ben Laurie
- Re: [Trans] Relaxing section 5.1 Eran Messeri
- Re: [Trans] Relaxing section 5.1 Rob Stradling