Re: [websec] HSTS: pinning certs, other changes to TLS server authentication
Thomas Roessler <tlr@w3.org> Thu, 24 March 2011 12:02 UTC
Return-Path: <tlr@w3.org>
X-Original-To: websec@core3.amsl.com
Delivered-To: websec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3F42C3A6879 for <websec@core3.amsl.com>; Thu, 24 Mar 2011 05:02:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rd8X5spo7jG7 for <websec@core3.amsl.com>; Thu, 24 Mar 2011 05:02:23 -0700 (PDT)
Received: from jay.w3.org (ssh.w3.org [128.30.52.60]) by core3.amsl.com (Postfix) with ESMTP id 55F543A6864 for <websec@ietf.org>; Thu, 24 Mar 2011 05:02:22 -0700 (PDT)
Received: from [88.207.144.203] (helo=[192.168.2.114]) by jay.w3.org with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.69) (envelope-from <tlr@w3.org>) id 1Q2jGa-0001Ik-Ie; Thu, 24 Mar 2011 08:03:52 -0400
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: text/plain; charset="us-ascii"
From: Thomas Roessler <tlr@w3.org>
In-Reply-To: <1300938889.2117.239.camel@localhost>
Date: Thu, 24 Mar 2011 13:03:49 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <0C57AABE-3A40-4900-83D2-E59170EF020E@w3.org>
References: <1300937463.2117.224.camel@localhost> <AANLkTikdUn8sfLs18oUmBk4oeB13MLstn+Fgi5BbSRNM@mail.gmail.com> <1300938889.2117.239.camel@localhost>
To: Matt McCutchen <matt@mattmccutchen.net>
X-Mailer: Apple Mail (2.1084)
Cc: websec@ietf.org
Subject: Re: [websec] HSTS: pinning certs, other changes to TLS server authentication
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Mar 2011 12:02:24 -0000
On 24 Mar 2011, at 04:54, Matt McCutchen wrote: > On Wed, 2011-03-23 at 20:36 -0700, Adam Barth wrote: >> Thanks for forwarding the thread. There have been a bunch of people >> asking for the ability to pin a certificate (or a CA certificate) >> using HSTS. In light of recent events, that's sounding more and more >> like something we should consider. > > Maybe. Pinning certs is a stopgap; it obviously doesn't work on the > first connection, and it places potentially significant operational > constraints on the web site. I have a hard time seeing it as a step > toward a coherent server authentication scheme that solves the problems > we are facing today. Stephen Farrell looked at parts of the problem a while ago and came up with a mechanism for cert switch-overs that he documented in RFC 5697. Perhaps useful here.
- [websec] HSTS: pinning certs, other changes to TL… Matt McCutchen
- Re: [websec] HSTS: pinning certs, other changes t… Adam Barth
- Re: [websec] HSTS: pinning certs, other changes t… Matt McCutchen
- Re: [websec] HSTS: pinning certs, other changes t… Thomas Roessler
- Re: [websec] HSTS: pinning certs, other changes t… Tobias Gondrom
- Re: [websec] HSTS: pinning certs, other changes t… Adam Barth
- Re: [websec] HSTS: pinning certs, other changes t… =JeffH
- Re: [websec] HSTS: pinning certs, other changes t… Thomas Roessler
- Re: [websec] HSTS: pinning certs, other changes t… Adam Barth
- Re: [websec] HSTS: pinning certs, other changes t… =JeffH