Re: [Uta] WGLC for draft-ietf-uta-rfc6125bis-06

Peter Saint-Andre <stpeter@stpeter.im> Wed, 06 July 2022 13:42 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 901ADC14CF10; Wed, 6 Jul 2022 06:42:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.983
X-Spam-Level:
X-Spam-Status: No, score=-8.983 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-1.876, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=stpeter.im header.b=dzIKgl3B; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=VhiQJ2xa
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fk3iNEiT_r1g; Wed, 6 Jul 2022 06:42:39 -0700 (PDT)
Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8817C14F73F; Wed, 6 Jul 2022 06:42:39 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.nyi.internal (Postfix) with ESMTP id B2D045C011A; Wed, 6 Jul 2022 09:42:38 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Wed, 06 Jul 2022 09:42:38 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=stpeter.im; h=cc :cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:sender:subject:subject:to:to; s=fm1; t=1657114958; x= 1657201358; bh=5FIaNcoGVLacBnZsxJUN33uhe9DV6B3JHpENa/T6QBE=; b=d zIKgl3BxWNCPj2LhTl1oSULNtuA7gsm1TD4avR4dtqa+M+UMydkZ12dxbZ+qunnz ujTx4NPhq1qgzBaK0Cr/6A7s3n/ac5hc1v58gbkWdQLrWnY0rPxfA9XoxkfjjrhU xasDdhkwoDjQzlWbf/2JU43HnKGFCdPWueYIEK2R+qOonT4DGJZIUK1DGbVc331Y Gjkd2aE2ukM2LyRbEuEwQgyhmCpEshKF5F3RVxXR/E42U5itNUFXQg+2/nmNbp9Q qoLprb9GVPgyPJrhYJfRyjvpXMWv6qjhVgfJIaLq3Yvir7c3vBlMXqpg/qFWIe5m nUVWFkujmg0ty9e4Ba2Zw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:sender:subject:subject:to:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1657114958; x= 1657201358; bh=5FIaNcoGVLacBnZsxJUN33uhe9DV6B3JHpENa/T6QBE=; b=V hiQJ2xa7C/SgjpI1Tpf+akI1AHenZ0Llt3Hg98/E0rJ6WRyzgAz+SgIzVZbp0/Dx Qcp2vZ3OOw1lskOl2NiqZ0tVaH/lHlMKvycAmRcP6NQM2VmY+/cT6FqnlXqMIGKc 6Mh/Zoo2ANNeXL7X7rS5Ytu4PMmOSET5NDEwel00OppftexGhiHiMce6U4koo10r 6vcboXDdHFGbBwKdLxteLJ1PBQjAC3XbT+8FjusfiXg+to0qFzgE7XuaUg9Q9deJ cZiRB048IBAbo8NEUrjz6AulGplMJ4t29DijboDIvezdguJYiEOdZ1LvcqWXyRCC bQcfrhEDbr62PNu+ehezg==
X-ME-Sender: <xms:TpHFYl8olCQ0TAPkvmtCLWrNOm9g5JfwVDzn1NZp3PYL5dD1v0gPZA> <xme:TpHFYpum5JCl04MwwCpCvb-qysMbMA45GE2CT9EFQowQCLzR7xNTVrM8OcLd0Hpzv UY2Ki8lLgW_1kcnAw>
X-ME-Received: <xmr:TpHFYjCKThfOeRAfe8qPcMD6-LtsynYdN_QbzUXfU-oYffMBEiTDXWfE_foi>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvfedrudeifedgieeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepkfffgggfvfevfhfhufgjtgfgsehtjeertddtfeejnecuhfhrohhmpefrvght vghrucfurghinhhtqdetnhgurhgvuceoshhtphgvthgvrhesshhtphgvthgvrhdrihhmqe enucggtffrrghtthgvrhhnpeejhfejveetfffggeeiudeuudektdeugfegvddvhfekleff hfefveelfeeviefggeenucffohhmrghinhephhhtthhprhhftggrshgrughvihhsvghfoh hrphhrohhtohgtohhlshhthhgrthhsuhhpphhorhhtihhprgguughrvghsshgvshdrihhs pdhgihhthhhusgdrtghomhenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmh grihhlfhhrohhmpehsthhpvghtvghrsehsthhpvghtvghrrdhimh
X-ME-Proxy: <xmx:TpHFYpdiu8Us6lfVFMycixHrYUPEaBCxCfvLdld7tIN6Cxh9Rh_00A> <xmx:TpHFYqNo1JxK8ZElJnMgzWetarQd1pnfeT4xPUk_aDXmIkTUaasyWQ> <xmx:TpHFYrmbne2sZrWYCXiEsLPmkVdzoBBGUc8xSJKgdQtyIh0OxCRIOg> <xmx:TpHFYnpfbtP7wI3eFFYQhlVkaNv92CD5ZXozkmj2IRuX2oXTU68jGQ>
Feedback-ID: i24394279:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 6 Jul 2022 09:42:37 -0400 (EDT)
Message-ID: <6afa428d-271d-43be-3652-9c9729ce110c@stpeter.im>
Date: Wed, 06 Jul 2022 07:42:36 -0600
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:91.0) Gecko/20100101 Thunderbird/91.11.0
Content-Language: en-US
To: Valery Smyslov <valery@smyslov.net>, 'Martin Thomson' <mt@lowentropy.net>, uta@ietf.org
Cc: uta-chairs@ietf.org
References: <002e01d87e9c$78a002e0$69e008a0$@smyslov.net> <152a5c9d-3142-419e-81dd-aa19bc2c8a02@beta.fastmail.com> <A8121C94-7881-4BA1-8A3D-C70291020FA6@akamai.com> <53fb3bb0-6414-3e1b-5ef5-2204522528f8@stpeter.im> <ED51AE33-23D2-4D40-91CD-155877E0ABAC@akamai.com> <03e601d88d54$65876150$309623f0$@gmail.com> <617eb543-e898-4716-8bda-77000e6d55b7@beta.fastmail.com> <05ce01d89103$6718fd50$354af7f0$@smyslov.net>
From: Peter Saint-Andre <stpeter@stpeter.im>
In-Reply-To: <05ce01d89103$6718fd50$354af7f0$@smyslov.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/3FmjFQhEY-wthkstB1btBKTUwp0>
Subject: Re: [Uta] WGLC for draft-ietf-uta-rfc6125bis-06
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Jul 2022 13:42:44 -0000

On 7/6/22 12:41 AM, Valery Smyslov wrote:
> Hi Martin,
> 
>>> The chairs think that the rough consensus is to limit the scope of the
>>> draft to domain names
>>> (with the pointer to the HTTP RFC as advise for protocols that support
>>> IP addresses).
>>
>> Is this the consensus of the chairs, or was there some discussion that I missed?
> 
> We discussed this with Leif going back to the history of RFC 6125.
> The text explicitly limiting the scope of the document to domain names
> first appeared in draft-saintandre-tls-server-id-check-05 back in 2010
> and was kept in RFC 6125. At the time the 6125bis draft was adopted
> there was no intention to widen the scope of RFC 6125.
> 
>> I agree that there is no consensus to include changes, but I don't see any input other than from Rich (and
>> I guess now yourself).
> 
> Peter also participated in the discussion and from our point of view he supported Rich's position.
> We also waited a bit for others to chime in.

I'm actually not opposed to adding support for IP addresses - my only 
concern was performing major surgery on the document, so I wanted to 
think about what changes we would need to make. At the time that Jeff 
and I worked on RFC 6125, we were not aware of widespread use of IP 
addresses in PKIX certificates. If the deployment situation has changed 
(as indicated by RFC 9110), then I am open to adding IP-IDs to 6125bis.

> Just to reiterate the chairs' position. We think that describing the handling of non-domain based names
> (like IP-ID) is a good idea, but at the same time we think that it would require quite a lot
> of changes to the current document, 

Martin sketched that out here:

https://github.com/richsalz/draft-ietf-uta-rfc6125bis/pull/54/files

I don't think it's *too* bad.

> that would slow down its progress. 

What's the hurry? It's been 10+ years since we published RFC 6125, I 
don't think a few more weeks will make a big difference.

Peter