[Web-bot-auth] Re: DNS-rooted key discovery for Signature-Agent: a DANE/TLSA complement to the .well-known directory
Kaveh Ranjbar <kaveh@whisper.security> Thu, 09 July 2026 20:24 UTC
Return-Path: <kaveh@whisper.security>
X-Original-To: web-bot-auth@mail2.ietf.org
Delivered-To: web-bot-auth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AF2021143773A for <web-bot-auth@mail2.ietf.org>; Thu, 9 Jul 2026 13:24:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783628671; bh=YrBiIeBCE7dRzpZOzCfgnh984IuF05KLEn9jgGqkrmA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=TzXBw2ZNm31/+NXZllJjTH5xc5jQgk1oEXGrNSFBWk3wnlJ/OqN+s1AkoQ8DG3QhP SttjWZGVyrQf1K3+i9Vbz3uiag/qpgU/aRtkw5mRw2qtOOvGphO21fkyE3UL8CiyRH s609Ng+6BTt7HD8kba+/Ho5qUixLeEDmGQhY6zeU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=whisper.security
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GIqwwP61z_5a for <web-bot-auth@mail2.ietf.org>; Thu, 9 Jul 2026 13:24:31 -0700 (PDT)
Received: from mail-ed1-x52a.google.com (mail-ed1-x52a.google.com [IPv6:2a00:1450:4864:20::52a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1F7A811437733 for <web-bot-auth@ietf.org>; Thu, 9 Jul 2026 13:24:31 -0700 (PDT)
Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-69a50b818c8so401944a12.2 for <web-bot-auth@ietf.org>; Thu, 09 Jul 2026 13:24:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783628670; cv=none; d=google.com; s=arc-20260327; b=BqGl9Zt8oMq07MgX4DJzUa82gBQ82Z6R+FmOhwrxCBFPKqgFGmRffB9ECeyHu2RI5w ek0jDDLLxJ+EusZ63iGsywQe3Gs3+6fJZ1unieiOl1khSphs7lX8kh6SGO5GMQGcB6Wy nD5qASSTS3kbT3VDE7mNsu7gW+Astre+EJqV51U7RnRSkYQ3IrbV9uaWOy4WTuke1avn WNVXcaxzWC8mFWGYotmGRX92bHp2ZTbeyCdjaCOmkC0gZgZwGrSR9KNWIzK63dMHxww3 YTDh8/6IxpqF6sQ1F7WK34daZFVCz+LWgQzqSDPpCUsGy1/UIqDuAIWFn/uFwNlF4I2T b+Ug==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Rba0xMs2bTm9CGS4upqoA7LuA18dOt4p+eG0aVB1Gyo=; fh=ITKjBlMrQ2yDR0RrwQkWKmy0yq0UlUlfs33IrFfuZUg=; b=JljZkLXQReJagsin1gCXgP6g9gizXmsKt2atjeVGtEliqo3XAzzDe1iqXXj10AiU4+ kM1D1mSW3ZCVRFCZNKT8c+0p7sf1XuPm7XbtxgUfTQKDpZMZytZXAvqo+CIMsjaBQ3MI XJ2ca2e2uKMj/g3hqkkbz2yoc6URSGA4KhovyBgYBv23wmXB90n32mMSbnClmo8XYv8L MmH2vo0qXxMdArbiHW7hGGi77MO3OF59MWd68anT4DdwZ1WONCzHbx0wQgNWGOZj+d2D aklgkw8AVGJ1mnW0Cf3uOZ5Yt7+oLcqh6yWxnNe2TJ4jCn6yPETHfnQHGxmmADm3ycxo zXCQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=whisper.security; s=whisper; t=1783628670; x=1784233470; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Rba0xMs2bTm9CGS4upqoA7LuA18dOt4p+eG0aVB1Gyo=; b=H+sI3B9ayVqgEXYddqLALvaUwJyncGKOMqouDx8vd4toD7E4VMD4GpcZGl22XeSdqU s0zpAG8VwGOGYPuZdW3m+aLNu2slezi8KqBvv54KoIgvM9vwYCEowbQeS2tX7U1RQCTt lXiXtOcnBq2DtlV5rjeYa5ytMNuHHFFAzYuWif8ME6CiJbtli66A0i6SGOYSX1sJH+o4 h0wYDaSWBtCDdP0iQ8Aqt55w2fA1YXnc4oZ6IbSXfUhasod+izACmZukYVPc6bVonniH Q/PhUo/0xO74jwekLesbf68hz3rgjlh05rnaXE4ae41EGyTSVEMaZB7Un04ta+twitAG L/Zw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783628670; x=1784233470; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Rba0xMs2bTm9CGS4upqoA7LuA18dOt4p+eG0aVB1Gyo=; b=pr/oSF5NnUnGYYQui/nBSTVjEV8BwRAly2wre9p0nmx0qMwkLXwSuq5MX0y0Sg9coE QKg3tVBPo1xRLQmnPHCoO9sv/jucJWNxRucq03GICfEtPEHNsSRbDktpdA0hJ1RM7YIJ 9+N8jU/PkqsrazcahNpIWrxnuHHvkn28QxCi8GtXZkmeePVD4EoqFDCWhGWxWlQrlgbL ikVh8o7blBAp9T+1i2RY513oNdi19kpzuDxnvHiActxQQzC568VxEwj+EMD4yIn/P+Bt 3/4Zy3Qg6STUS31VSzW77oOnwHrhX3QiYpJpvnJDkPZVbw+WOJazpa75QZHIWTaResez jEcg==
X-Gm-Message-State: AOJu0Yylhb6mffIU1DWZAhVNczlXweiD1TS0+ctsSmA1Ib13DLJZDPAb anAw7KQys1v4N6CiKVKStKTqwCGijDfZWtdlM/6di48JkR0ng9j2vgDHjw7n7CnSkZfc+ilWj2g s/frfwthyxzC0+VostsdQBeoPSDmNK4fHQTRairc6KhIy3136uA3WhRedLzIm
X-Gm-Gg: AfdE7cnAs9MKBDg9tMQ37FOgQLP6QgBXMcqsKL4aX0mN7to7TqfhP5OesyGLWSebq1B Xvfvq0hyxneYp6lV9MDAtfyBzbz4oQ5HI7GIAI5Bk8uUUkH9qmtrQviRXl133tl71LnqwpL4lM2 YcoypSbAKwgZFoQ5zkFNo0SxHN6f7O4mXYD6MLQNzkP0V9KYF65C3xLPLc2Z8qrQHNoK4LqYc3Q jpN8JcuZrY6smPM/B0ZhXRKGXB2n/PISxACw217HSJz8iBt4tgO4nEf1YvSgog70RnSF6oDC2Cx d+IS5xGaOhiMgxQiNngNFZm4PvxO8GeFR1/BsOw1+oy+dpL8K0g/VhxCDNIBbA==
X-Received: by 2002:a17:907:9454:b0:c15:b9b6:6b17 with SMTP id a640c23a62f3a-c15cdec7abfmr447474066b.4.1783628670012; Thu, 09 Jul 2026 13:24:30 -0700 (PDT)
MIME-Version: 1.0
References: <CA+kObRKEUSffjN-ECkFmV+7jjny87LzfVN=YMO6gTF6xkJT64w@mail.gmail.com> <CAOdQrVMdE9u5t24Z-NeBDOcT4Sf9GA4YF=nXyhX=J_X3XnP1BQ@mail.gmail.com> <CABcZeBNzrYtySpEJK6n3cX7ngyYu2oxrdWq1kxZeNRXRK-bF2w@mail.gmail.com> <CA+kObR+_V=US7eNbdRQiXbfqsXi3-Gc_ZNCY+S49mZQ7eHnB8Q@mail.gmail.com> <CABcZeBM-rFpQJoasnSb2K6RJfhDRZ5ZOV61wxYtqXFjsWC8K0A@mail.gmail.com>
In-Reply-To: <CABcZeBM-rFpQJoasnSb2K6RJfhDRZ5ZOV61wxYtqXFjsWC8K0A@mail.gmail.com>
From: Kaveh Ranjbar <kaveh@whisper.security>
Date: Thu, 09 Jul 2026 21:24:18 +0100
X-Gm-Features: AVVi8CcFf742enKcUGjB8EtWQBx9rVMLpTOALEoVIiH32Z0PjE27lmzqu7f33Sc
Message-ID: <CA+kObR+aVb7gCo6Cvd=hzQRf+-Wa5a33e1v_N5kpYW9tS_BwgQ@mail.gmail.com>
To: web-bot-auth@ietf.org
Content-Type: multipart/alternative; boundary="000000000000499fa606563369fe"
Message-ID-Hash: UB2FXSH7KYTTVZCL6NBVXT4FWR3XWOA2
X-Message-ID-Hash: UB2FXSH7KYTTVZCL6NBVXT4FWR3XWOA2
X-MailFrom: kaveh@whisper.security
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: ekr@rtfm.com, bemasc@meta.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Web-bot-auth] Re: DNS-rooted key discovery for Signature-Agent: a DANE/TLSA complement to the .well-known directory
List-Id: Authentication of non-human users to human-oriented Web sites <web-bot-auth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/web-bot-auth/YiKHshSpp9LQ-e1wOkRT3Rs3QVA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/web-bot-auth>
List-Help: <mailto:web-bot-auth-request@ietf.org?subject=help>
List-Owner: <mailto:web-bot-auth-owner@ietf.org>
List-Post: <mailto:web-bot-auth@ietf.org>
List-Subscribe: <mailto:web-bot-auth-join@ietf.org>
List-Unsubscribe: <mailto:web-bot-auth-leave@ietf.org>
Ekr, you will get no argument from me on the numbers. I publish the DNSSEC scorecard at https://state-of-dnssec.whisper.security/ , so I am a critic of DNSSEC deployment before I am an advocate for it. That is exactly why I do not think second-level signing rates bear on this scheme. The deployment unit here is not the agent, it is the operator's zone, signed once. An operator stands up one DNSSEC-signed zone and mints any number of identities as names under it. Our agents all live under a single signed agents.whisper.online, not one signed domain per agent. So the shape is not "most agents deploy DNSSEC first"; it is one operator signs one zone once, as part of the same deliberate act of standing up verifiable identity, and the unsigned 95% of .com is a population we ask to do nothing. Adoption at large is the wrong denominator: this is opt-in for parties provisioning specifically to be independently verifiable, not a migration of the existing web. On "might as well use .well-known": for a web bot whose verifier already sits inside WebPKI, you are right, and I conceded exactly that to Ben, the DNS path earns little there. Where they are not equivalent is the verifier that is not in a WebPKI context, agent-to-agent, out of band of any TLS transaction. There, /.well-known over HTTPS reintroduces the WebPKI and web-endpoint dependency that the DANE record removes, so the two are not interchangeable. That verifier is who this is for, not the web bot. So: a complement scoped to the non-web verifier, not a replacement for /.well-known, and nothing the unsigned web is asked to adopt. Thanks for pressing, it sharpened the scoping. The record-type and venue question belongs in DANCE, and I will carry it there. Kaveh On Thu, Jul 09, 2026 08:17 PM, Eric Rescorla <ekr@rtfm.com> wrote: > > > On Thu, Jul 9, 2026 at 12:08 PM Kaveh Ranjbar <kaveh@whisper.security> > wrote: > >> >> On DNSSEC, and I want to be careful not to relitigate deployment, because >> I think adoption rate is the wrong axis for this design. "Limited >> deployment" measures how many resolvers validate, which is a verifier-side >> property, and here validation is opt-in per verifier. >> > > I'm not talking about how many resolvers validate, but about how many > domains actually have signed records (note that this is a distinct number > from the number of domains signed by the parent). At present this is about > 5% of .com and .net [0]. So what you're proposing is that most agents who > want to participate need to deploy DNSSEC first. This is a lot more of a > list than just standing up something on /.well-known. > > > >> . The scheme never predicates on global adoption because it never asks >> anyone else to validate, only the party who chose to rely on it. For >> verifiers who do not want that dependency, the .well-known path is >> untouched. >> > > In which case you might as well just use /.well-known. > > -Ekr > > [0] https://dl.acm.org/doi/abs/10.1145/3730567.3764428 >
- [Web-bot-auth] DNS-rooted key discovery for Signa… Kaveh Ranjbar
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Ben Schwartz
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Eric Rescorla
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Kaveh Ranjbar
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Eric Rescorla
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Kaveh Ranjbar
- [Web-bot-auth] Re: DNS-rooted key discovery for S… Blake