Re: [websec] Certificate Pinning via HSTS

SM <sm@resistor.net> Tue, 13 September 2011 00:52 UTC

Return-Path: <sm@resistor.net>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E565F21F8DC6 for <websec@ietfa.amsl.com>; Mon, 12 Sep 2011 17:52:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.578
X-Spam-Level:
X-Spam-Status: No, score=-102.578 tagged_above=-999 required=5 tests=[AWL=0.021, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G1bFpNCsgymD for <websec@ietfa.amsl.com>; Mon, 12 Sep 2011 17:52:33 -0700 (PDT)
Received: from mx.ipv6.elandsys.com (mx.ipv6.elandsys.com [IPv6:2001:470:f329:1::1]) by ietfa.amsl.com (Postfix) with ESMTP id 86C1021F8D8A for <websec@ietf.org>; Mon, 12 Sep 2011 17:52:31 -0700 (PDT)
Received: from SUBMAN.resistor.net (IDENT:sm@localhost [127.0.0.1]) by mx.elandsys.com (8.14.4/8.14.5) with ESMTP id p8D0sL4I016663; Mon, 12 Sep 2011 17:54:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=opendkim.org; s=mail2010; t=1315875268; bh=K/bCdDgFjOa5xjJDlTD3Nx8tlxZhFTSEcYkA3dYH+/o=; h=Message-Id:Date:To:From:Subject:Cc:In-Reply-To:References: Mime-Version:Content-Type; b=wkCBH+zMJ7pJVZRea4gd26za6jBDsGFdofBPcgx5CkV0P5SJzh58Ib92rTAj9oW// B3nPgwoNo4+IHw0DWa8khdRc32Kni5XxzD9/j7Two728PTGgAmXNz1v5tZJMDLO2GH 2UHm/TPROfVkc69RwLasm8VMD+IYfyJzG64nwiaA=
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=resistor.net; s=mail; t=1315875268; bh=K/bCdDgFjOa5xjJDlTD3Nx8tlxZhFTSEcYkA3dYH+/o=; h=Message-Id:Date:To:From:Subject:Cc:In-Reply-To:References: Mime-Version:Content-Type; b=c/XXwWhTkHnRxTR7GF5lGTxi1fi8tyYjOAMQd2Oq8SSSWiKoBR+C09vViSj+dvBEh aN8p3gJcoCoLbCeTI7ishCjXmwtJwpq4+2uKrRSYIVXHA1uMTBGZtB1lgROKOGrRZg kMCFmUVGl2kG0B8QCSnxok8+5MVu5+ylyuYiSvLQ=
Message-Id: <6.2.5.6.2.20110912174725.0a6aae28@resistor.net>
X-Mailer: QUALCOMM Windows Eudora Version 6.2.5.6
Date: Mon, 12 Sep 2011 17:51:17 -0700
To: Chris Palmer <palmer@google.com>
From: SM <sm@resistor.net>
In-Reply-To: <CAOuvq22p2qNnXRsK=PS=mxknnq4MrCWt0Np-N8su-iHXaWHqpg@mail.g mail.com>
References: <CAOuvq22p2qNnXRsK=PS=mxknnq4MrCWt0Np-N8su-iHXaWHqpg@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Cc: Chris Evans <cevans@google.com>, websec@ietf.org
Subject: Re: [websec] Certificate Pinning via HSTS
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Sep 2011 00:52:34 -0000

Hi Chris,
At 14:56 12-09-2011, Chris Palmer wrote:
>Chris Evans and I work at Google on the Chrome security team. We have
>devised this specification for a new extension to Strict Transport

[snip]

>We eagerly anticipate your comments, questions, concerns, et c. As you

Would it be possible for you to post the specification as an Internet-Draft?

Thanks,
-sm