Re: [xmpp] Fwd: I-D Action: draft-miller-xmpp-dnssec-prooftype-01.txt

Philipp Hancke <fippo@goodadvice.pages.de> Wed, 27 June 2012 15:16 UTC

Return-Path: <fippo@goodadvice.pages.de>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2CAD221F873C for <xmpp@ietfa.amsl.com>; Wed, 27 Jun 2012 08:16:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L4zQRFzdnYfc for <xmpp@ietfa.amsl.com>; Wed, 27 Jun 2012 08:16:48 -0700 (PDT)
Received: from lo.psyced.org (lost.IN.psyced.org [188.40.42.221]) by ietfa.amsl.com (Postfix) with ESMTP id 67D4021F8737 for <xmpp@ietf.org>; Wed, 27 Jun 2012 08:16:47 -0700 (PDT)
Received: from lo.psyced.org (localhost [127.0.0.1]) by lo.psyced.org (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id q5RFGgQa018457 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 27 Jun 2012 17:16:42 +0200
Received: from localhost (fippo@localhost) by lo.psyced.org (8.14.3/8.14.3/Submit) with ESMTP id q5RFGeo2018453; Wed, 27 Jun 2012 17:16:40 +0200
X-Authentication-Warning: lo.psyced.org: fippo owned process doing -bs
Date: Wed, 27 Jun 2012 17:16:40 +0200
From: Philipp Hancke <fippo@goodadvice.pages.de>
X-X-Sender: fippo@lo.psyced.org
To: Matt Miller <mamille2@cisco.com>
In-Reply-To: <A14A8C98-F762-4C96-9895-50DB6DFEF973@cisco.com>
Message-ID: <alpine.DEB.1.10.1206271649070.17671@lo.psyced.org>
References: <20120608202212.8859.65155.idtracker@ietfa.amsl.com> <A14A8C98-F762-4C96-9895-50DB6DFEF973@cisco.com>
User-Agent: Alpine 1.10 (DEB 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
X-Mailman-Approved-At: Thu, 28 Jun 2012 15:04:51 -0700
Cc: XMPP Working Group <xmpp@ietf.org>
Subject: Re: [xmpp] Fwd: I-D Action: draft-miller-xmpp-dnssec-prooftype-01.txt
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Jun 2012 15:16:49 -0000

i'm pondering on the proof name. The prooftype is using dnssec, but uses 
it to extend the 6125 to allow secure delegation.
I.e. it either explains how to do delegation within a PKI prooftype or is 
a proof PKI-Delegation proof.

DNSSEC alone might (mostly in the context of s2s and server dialback) be a 
different proof (used by the connecting server instead of dialbacks 
current faith in insecure dns).

Thoughts?