Re: [websec] I-D Action: draft-ietf-websec-key-pinning-15.txt

Yoav Nir <ynir.ietf@gmail.com> Wed, 18 June 2014 21:13 UTC

Return-Path: <ynir.ietf@gmail.com>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C3C821A0195 for <websec@ietfa.amsl.com>; Wed, 18 Jun 2014 14:13:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qKfpqyZt73Th for <websec@ietfa.amsl.com>; Wed, 18 Jun 2014 14:13:09 -0700 (PDT)
Received: from mail-wi0-x229.google.com (mail-wi0-x229.google.com [IPv6:2a00:1450:400c:c05::229]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC0881A0319 for <websec@ietf.org>; Wed, 18 Jun 2014 14:12:59 -0700 (PDT)
Received: by mail-wi0-f169.google.com with SMTP id hi2so9135720wib.2 for <websec@ietf.org>; Wed, 18 Jun 2014 14:12:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:content-type:message-id:mime-version:subject:date:references :to:in-reply-to; bh=FvBXRR3ZTZrwhtzOMyD27IMzS2V7skZOjpAMPmPDaeA=; b=pJg5GmNhADYMUuqk2vLuZtJgmrl8GLL48zY1PRzj4LbDtDmCQPkFE8xwNcYrf6lncm n0FFDKUhNPbQsF+2/tMCSV72r0BZgzknzceho4fWV5Fav1IyhQ74x9+rpvskWmzWY00w HfobgMaEEzsnfeODQXXTO6GOJSV+8y6Z1PEqSBUi8USyZp6RnY4a3KK8XDYxBmb5URzn QgmcBKu8imjDko2SIyt2VC3w5ld5+2vAZOUpbI+ywF7ZKdXMI9DWhvKevPgJwY0n0kz1 Pw0If4WVtyomp+6DKG9OUDFIUFp1a8XZFbyKzr3HW+MMCvpZZkbwHBofoKOdZTYk7uuD azjA==
X-Received: by 10.180.210.134 with SMTP id mu6mr847475wic.18.1403125976184; Wed, 18 Jun 2014 14:12:56 -0700 (PDT)
Received: from [192.168.1.102] (bzq-84-109-50-18.red.bezeqint.net. [84.109.50.18]) by mx.google.com with ESMTPSA id e11sm5685464wiw.19.2014.06.18.14.12.55 for <websec@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 18 Jun 2014 14:12:55 -0700 (PDT)
From: Yoav Nir <ynir.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_51D117BB-7EFA-4F02-B63A-5DDB23F1D7B3"
Message-Id: <B8AE3408-EE64-4028-ABB2-D60E16ABAFD6@gmail.com>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
Date: Thu, 19 Jun 2014 00:12:52 +0300
References: <20140616233355.16550.96950.idtracker@ietfa.amsl.com>
To: IETF WebSec WG <websec@ietf.org>
In-Reply-To: <20140616233355.16550.96950.idtracker@ietfa.amsl.com>
X-Mailer: Apple Mail (2.1878.2)
Archived-At: http://mailarchive.ietf.org/arch/msg/websec/42-NMBzGa8yEOEN_W0E0FA6FeP0
Subject: Re: [websec] I-D Action: draft-ietf-websec-key-pinning-15.txt
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec/>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jun 2014 21:13:13 -0000

Thanks to Ryan and the Chrises for getting this done.

Folks, it seem to us that this working group has done as much as we can for this document. We could keep discussing this for another year, but we believe at this point this would be counter-productive. 

So, we intend to send this to Barry next week. Please take the time to make sure that no huge mistakes have been added in the last two iterations. For your convenience, here are links to the diffs:
http://www.ietf.org/rfcdiff?url2=draft-ietf-websec-key-pinning-14
http://www.ietf.org/rfcdiff?url2=draft-ietf-websec-key-pinning-15

Thanks again to the authors and people on the list for all the efforts. I believe we have come up with a document that is implementable and adds a scalable way to mitigate the threat of mis-issued certificates.

As you know, the journey is not quite done, as we still have AD review, IETF last call, the IESG, and the RFC editor. See you all around.

Tobias and Yoav

On Jun 17, 2014, at 2:33 AM, internet-drafts@ietf.org wrote:

> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Web Security Working Group of the IETF.
> 
>        Title           : Public Key Pinning Extension for HTTP
>        Authors         : Chris Evans
>                          Chris Palmer
>                          Ryan Sleevi
> 	Filename        : draft-ietf-websec-key-pinning-15.txt
> 	Pages           : 26
> 	Date            : 2014-06-16
> 
> Abstract:
>   This memo describes an extension to the HTTP protocol allowing web
>   host operators to instruct user agents to remember ("pin") the hosts'
>   cryptographic identities for a given period of time.  During that
>   time, UAs will require that the host present a certificate chain
>   including at least one Subject Public Key Info structure whose
>   fingerprint matches one of the pinned fingerprints for that host.  By
>   effectively reducing the number of authorities who can authenticate
>   the domain during the lifetime of the pin, pinning may reduce the
>   incidence of man-in-the-middle attacks due to compromised
>   Certification Authorities.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-websec-key-pinning/
> 
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-websec-key-pinning-15
> 
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-websec-key-pinning-15
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/