
From nobody Fri Dec  8 10:16:33 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ACFBE128ACA for <spasm@ietfa.amsl.com>; Fri,  8 Dec 2017 10:16:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S1wAlbpSRwN0 for <spasm@ietfa.amsl.com>; Fri,  8 Dec 2017 10:16:28 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0BC2F127601 for <spasm@ietf.org>; Fri,  8 Dec 2017 10:16:28 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 59C7E3005E0 for <spasm@ietf.org>; Fri,  8 Dec 2017 13:16:27 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 5tcrgK09ZZNG for <spasm@ietf.org>; Fri,  8 Dec 2017 13:16:25 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id B4B4D300293 for <spasm@ietf.org>; Fri,  8 Dec 2017 13:16:25 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_3772C9CF-50C3-4EAA-BC43-9B254DE91AEF"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com>
References: <20171208180055.ACB1EB81ACE@rfc-editor.org>
To: SPASM <spasm@ietf.org>
Date: Fri, 8 Dec 2017 13:16:29 -0500
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/37eevTE1Vm_Dbv9dYa9HKXJ-Ayc>
Subject: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Dec 2017 18:16:31 -0000

--Apple-Mail=_3772C9CF-50C3-4EAA-BC43-9B254DE91AEF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii



> From: RFC Errata System <rfc-editor@rfc-editor.org>
> Subject: [pkix] [Technical Errata Reported] RFC6844 (5200)
> Date: December 8, 2017 at 1:00:55 PM EST
> To: philliph@comodo.com, rob.stradling@comodo.com, =
Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, kent@bbn.com, =
stefan@aaa-sec.com
> Cc: pkix@ietf.org, richard.j.gibson@oracle.com, =
rfc-editor@rfc-editor.org
>=20
> The following errata report has been submitted for RFC6844,
> "DNS Certification Authority Authorization (CAA) Resource Record".
>=20
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata/eid5200
>=20
> --------------------------------------
> Type: Technical
> Reported by: Richard Gibson <richard.j.gibson@oracle.com>
>=20
> Section: 3
>=20
> Original Text
> -------------
> <Issuer Domain Name> [; <name>=3D<value> ]*
>=20
> Corrected Text
> --------------
> <Issuer Domain Name> [; [ <name>=3D<value> ]* ]
>=20
> Notes
> -----
> For values of the "issue" and "issuewild" property tags, section 3 =
specifies [; <name>=3D<value> ]* (which seems to indicate that every =
parameter is preceded by a semicolon) but the grammar in section 5.2 =
specifies [";" *(space parameter) space] (in which parameters are =
separated by whitespace and the entire list is preceded by a single =
semicolon). Presumably, the formal grammar is definitive and the =
preceding shorthand should be updated to better express it.
>=20
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party =20
> can log in to change the status and edit the report, if necessary.=20
>=20
> --------------------------------------
> RFC6844 (draft-ietf-pkix-caa-15)
> --------------------------------------
> Title               : DNS Certification Authority Authorization (CAA) =
Resource Record
> Publication Date    : January 2013
> Author(s)           : P. Hallam-Baker, R. Stradling
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>=20


--Apple-Mail=_3772C9CF-50C3-4EAA-BC43-9B254DE91AEF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px;" class=3D""><span =
style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">From: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D"">RFC Errata System &lt;<a =
href=3D"mailto:rfc-editor@rfc-editor.org" =
class=3D"">rfc-editor@rfc-editor.org</a>&gt;<br =
class=3D""></span></div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span =
style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">Subject: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D""><b class=3D"">[pkix] [Technical =
Errata Reported] RFC6844 (5200)</b><br class=3D""></span></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px;" class=3D""><span style=3D"font-family: =
-webkit-system-font, Helvetica Neue, Helvetica, sans-serif; =
color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">Date: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D"">December 8, 2017 at 1:00:55 PM =
EST<br class=3D""></span></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span=
 style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">To: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D""><a =
href=3D"mailto:philliph@comodo.com" class=3D"">philliph@comodo.com</a>, =
<a href=3D"mailto:rob.stradling@comodo.com" =
class=3D"">rob.stradling@comodo.com</a>, <a =
href=3D"mailto:Kathleen.Moriarty.ietf@gmail.com" =
class=3D"">Kathleen.Moriarty.ietf@gmail.com</a>, <a =
href=3D"mailto:ekr@rtfm.com" class=3D"">ekr@rtfm.com</a>, <a =
href=3D"mailto:kent@bbn.com" class=3D"">kent@bbn.com</a>, <a =
href=3D"mailto:stefan@aaa-sec.com" class=3D"">stefan@aaa-sec.com</a><br =
class=3D""></span></div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span =
style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">Cc: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D""><a href=3D"mailto:pkix@ietf.org" =
class=3D"">pkix@ietf.org</a>, <a =
href=3D"mailto:richard.j.gibson@oracle.com" =
class=3D"">richard.j.gibson@oracle.com</a>, <a =
href=3D"mailto:rfc-editor@rfc-editor.org" =
class=3D"">rfc-editor@rfc-editor.org</a><br class=3D""></span></div><br =
class=3D""><div class=3D""><div class=3D"">The following errata report =
has been submitted for RFC6844,<br class=3D"">"DNS Certification =
Authority Authorization (CAA) Resource Record".<br class=3D""><br =
class=3D"">--------------------------------------<br class=3D"">You may =
review the report below and at:<br class=3D""><a =
href=3D"http://www.rfc-editor.org/errata/eid5200" =
class=3D"">http://www.rfc-editor.org/errata/eid5200</a><br class=3D""><br =
class=3D"">--------------------------------------<br class=3D"">Type: =
Technical<br class=3D"">Reported by: Richard Gibson =
&lt;richard.j.gibson@oracle.com&gt;<br class=3D""><br class=3D"">Section: =
3<br class=3D""><br class=3D"">Original Text<br =
class=3D"">-------------<br class=3D"">&lt;Issuer Domain Name&gt; [; =
&lt;name&gt;=3D&lt;value&gt; ]*<br class=3D""><br class=3D"">Corrected =
Text<br class=3D"">--------------<br class=3D"">&lt;Issuer Domain =
Name&gt; [; [ &lt;name&gt;=3D&lt;value&gt; ]* ]<br class=3D""><br =
class=3D"">Notes<br class=3D"">-----<br class=3D"">For values of the =
"issue" and "issuewild" property tags, section 3 specifies [; =
&lt;name&gt;=3D&lt;value&gt; ]* (which seems to indicate that every =
parameter is preceded by a semicolon) but the grammar in section 5.2 =
specifies [";" *(space parameter) space] (in which parameters are =
separated by whitespace and the entire list is preceded by a single =
semicolon). Presumably, the formal grammar is definitive and the =
preceding shorthand should be updated to better express it.<br =
class=3D""><br class=3D"">Instructions:<br class=3D"">-------------<br =
class=3D"">This erratum is currently posted as "Reported". If necessary, =
please<br class=3D"">use "Reply All" to discuss whether it should be =
verified or<br class=3D"">rejected. When a decision is reached, the =
verifying party &nbsp;<br class=3D"">can log in to change the status and =
edit the report, if necessary. <br class=3D""><br =
class=3D"">--------------------------------------<br class=3D"">RFC6844 =
(draft-ietf-pkix-caa-15)<br =
class=3D"">--------------------------------------<br class=3D"">Title =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;: DNS Certification Authority Authorization (CAA) Resource =
Record<br class=3D"">Publication Date &nbsp;&nbsp;&nbsp;: January =
2013<br class=3D"">Author(s) =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;: P. =
Hallam-Baker, R. Stradling<br class=3D"">Category =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;: =
PROPOSED STANDARD<br class=3D"">Source =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;: Public-Key Infrastructure (X.509)<br class=3D"">Area =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;: Security<br class=3D"">Stream =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;: IETF<br class=3D"">Verifying Party &nbsp;&nbsp;&nbsp;&nbsp;: =
IESG<br class=3D""><br class=3D""></div></div></blockquote></div><br =
class=3D""></body></html>=

--Apple-Mail=_3772C9CF-50C3-4EAA-BC43-9B254DE91AEF--


From nobody Fri Dec 15 07:09:55 2017
Return-Path: <scheitle@net.in.tum.de>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5807B1200CF for <spasm@ietfa.amsl.com>; Fri, 15 Dec 2017 07:09:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OtOAA8MvjqRK for <spasm@ietfa.amsl.com>; Fri, 15 Dec 2017 07:09:52 -0800 (PST)
Received: from mail-out1.informatik.tu-muenchen.de (mail-out1.informatik.tu-muenchen.de [131.159.0.8]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BD1CC128DF6 for <spasm@ietf.org>; Fri, 15 Dec 2017 07:09:33 -0800 (PST)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by mail.net.in.tum.de (Postfix) with ESMTPSA id 6E1; Fri, 15 Dec 2017 16:09:26 +0100 (CET)
From: Quirin Scheitle <scheitle@net.in.tum.de>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <61DCD88E-6716-4F15-A747-593C6F05E95A@net.in.tum.de>
Date: Fri, 15 Dec 2017 16:09:26 +0100
To: spasm@ietf.org, mozilla-dev-security-policy@lists.mozilla.org
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/qBHYaNpNrMOqe4UVsyF1ll8NNr8>
Subject: [lamps] Dashboard and Study on CAA Adoption
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Dec 2017 15:09:54 -0000

Dear all,

some colleagues and I want to share an academic study on CAA we have =
been working on in the past months.=20
We hope that our findings can provide quantitative data to assist =
further discussion, such as the =E2=80=9CCAA-simplification=E2=80=9D =
draft at IETF and work at the validation-wg at CABF.
We also give specific recommendations how *we think* that CAA can be =
improved.

The results, paper, and a dashboard tracking CAA adoption are available =
under=20

https://caastudy.github.io/

[Please note that the paper discusses facts as of Nov 30]
We will be happy to elaborate some aspects further, the paper does not =
discuss all the details.=20
We have discussed previous drafts with various individuals in this =
community and thank them for their inputs.

Kind regards
Quirin and team



From nobody Fri Dec 15 20:06:08 2017
Return-Path: <jsha@eff.org>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10A88124D85 for <spasm@ietfa.amsl.com>; Fri, 15 Dec 2017 20:06:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7
X-Spam-Level: 
X-Spam-Status: No, score=-7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=eff.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v6hnrVREzRBE for <spasm@ietfa.amsl.com>; Fri, 15 Dec 2017 20:06:03 -0800 (PST)
Received: from mail2.eff.org (mail2.eff.org [173.239.79.204]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E6F621270A3 for <spasm@ietf.org>; Fri, 15 Dec 2017 20:06:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=eff.org; s=mail2;  h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:From:References:To:Subject; bh=cEmvLm5bKtX98TB/5y25IgNRq+Q9RRTZXCS9f2gNHAQ=;  b=m7HlNl61pyOwnUoU5+w9Cfgcg+qE47n6efFb7WOaBnSgjb5xc96fKsN12uEsNx2nXIiRL6+FOPNedFAKV6QIHrvbOvSHNdpGrK68YXYEqxYof+MRlw0OqM4y67wC52cEMqB8vIqVEOStNg1kTv3D8NEjBrYRj0zBdyoCPn0qaD0=;
Received: ; Fri, 15 Dec 2017 20:05:59 -0800
To: spasm@ietf.org
References: <20171208180055.ACB1EB81ACE@rfc-editor.org> <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com>
From: Jacob Hoffman-Andrews <jsha@eff.org>
Message-ID: <ad5b6045-84ba-32b3-7739-b2464fc40c2f@eff.org>
Date: Fri, 15 Dec 2017 20:05:57 -0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com>
Content-Type: text/plain; charset=windows-1252
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/QW06wKAk43gwi9reJlJf27n75E0>
Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Dec 2017 04:06:06 -0000

On 12/08/2017 10:16 AM, Russ Housley wrote:
> http://www.rfc-editor.org/errata/eid5200

The question here is whether CAA records with property tags should look
like:

example.com. IN CAA 0 issue "example.net; foo=bar bar=qux"

or:

example.com. IN CAA 0 issue "example.net; foo=bar; bar=qux"

(note the second semicolon)

I think the original text is ambiguous on the point, and since property
tags are not yet widely deployed this is a somewhat free choice. I think
the version where property tags are separated by semicolons makes more
sense and is less error prone. It also happens to be what Hugo Landau's
draft for CAA Record Extensions uses:
https://tools.ietf.org/html/draft-ietf-acme-caa-03#page-9

And what was briefly implemented in Let's Encrypt's Boulder (since
rolled back due to a bug):

https://github.com/letsencrypt/boulder/pull/3145/files#diff-3efab53f2bcc543ac2e771ec882c57c1L310

So my feeling is we should reject this erratum and clarify in the other
direction, requiring semicolons between property tags. Thoughts?


From nobody Mon Dec 18 06:41:00 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A5A91252BA for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 06:40:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.102
X-Spam-Level: 
X-Spam-Status: No, score=-0.102 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l8K5keVN1xSo for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 06:40:57 -0800 (PST)
Received: from mail1.bemta8.messagelabs.com (mail1.bemta8.messagelabs.com [216.82.243.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 09CB0124B17 for <spasm@ietf.org>; Mon, 18 Dec 2017 06:40:56 -0800 (PST)
Received: from [216.82.242.46] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-1.bemta-8.messagelabs.com id 64/B4-05333-773D73A5; Mon, 18 Dec 2017 14:40:55 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WSe0hTYRjG951zNo/lkeO8vS27DcILTFZmSf5 RUJRhQUVJWWBnedpG25RzVqyCtHJZWnSb0oY1pWEl2UWQLqTUMsoLSWpWrqTSNLWrQRfptp1v 3f778T7P+z3v9/LSpLJToaJ5m5UXLJxJrRhHPZpaH6HZ2jknW3v2cWKas+urIu1k98b5RMbb0 UF5hsfzlVhOZMuNFl2ebYPc4BlpCMk/kGlr9dmpQvRlUQkKpSn2HQHtDiHAStZBQEd5fAka5+ cmBM39txQBQcFqobvhDhHgKDYTus+XSfVIP++yv5bj+lK4WtyOMM+F+rIxhAOmQ5Vnn+Rh2PX wvfMwwgEVCI6d9khCKJsOxQerpAbExsDnlnNSGMnGQk+/W2Jgo+D5/VYF5mgY6vshx/71cOKj N1hXg6/2C8I8CTrcpVIYsN4QaCvHUwCbDPVH3gRNy+D4ubdBUzWCTy8fklhIgrvevUHTZqgtL qEwp0OlvY7EDbdI8D2oC5rioK+plMLCoByOOloovNVccNR4gwtTwdOu/QhzHLx60iA/jBJc/3 zV5e8nWTcC74CddElLi4BmZz+FTRq41niDxDwFLr+pCHI6HB+7qcA8DRylz0Mwp8LI7Q+oEtE 1KEHkha28oJk1M1knGPUGq5kzmjQztGnJZl4UOT1v4nRi8sY8cx3yn1aBTIauoKHqdV40gSbU 0Yxz/OxsZbguL3ebgRMNOcIWEy96URxNq4FJ7ZiTrYwQeD1v22Q0+e/ztwx0mDqK2R2QGTGfM 4tGPZZaUApd0dDzjaAHnCOFpJKy5Fl4VSwzPmBlA1bDFsufh37fegeapIpkkEwmU4bl84LZaP 1fH0axNFJHMosDr4QZLdY/ecP+UQj/KGVrpFGs3F9JVYiKvi3wuC9lFskeLd5j16zaGZL1ZG1 uQU3OKq26oNxYIzbvWzNwb1rooaxMWduL6rFw97NR37yfvRNLJ8QvPFXUeGFZapdrd2VSypkj SqdPMNRelK1e2TcYPVm7PWYnu0K0XLqg2xHxIt+V0XffVrREn9Wzjhnt7b2ui9dHhr+/eChRT YkGbkYSKYjcL1iQsZjmAwAA
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-9.tower-96.messagelabs.com!1513608053!116492779!1
X-Originating-IP: [216.32.181.17]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 10001 invoked from network); 18 Dec 2017 14:40:54 -0000
Received: from mail-co1nam03lp0017.outbound.protection.outlook.com (HELO NAM03-CO1-obe.outbound.protection.outlook.com) (216.32.181.17) by server-9.tower-96.messagelabs.com with AES256-SHA256 encrypted SMTP; 18 Dec 2017 14:40:54 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=1QMM+WvYLR5bAPSC5UoKWPE54+PAUtt3YP9XZ5NreNQ=; b=j9EwkK12EHUlgGONCSL5nawTDu8KJcX8QR58N56GL0slrjmP6Q8PLb4n9n74vaie1ZGFFw6PIRgwPOgv8y3VxqOmLViTx5YJoI2O5Abo0keAp7iD4le0+Gaec/io08fbKZRcZcX6/m2g3o8M2NLw2wHtpXXHf0NP5euTGR+ae7U=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Mon, 18 Dec 2017 14:40:52 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Mon, 18 Dec 2017 14:40:52 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
Thread-Index: AQHTcFCyWaXtVbwstEuAXIDvoZy1oKNFZbiAgAPSpGA=
Date: Mon, 18 Dec 2017 14:40:51 +0000
Message-ID: <DM5PR14MB128950E8291574FAA0161BC8830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <20171208180055.ACB1EB81ACE@rfc-editor.org> <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com> <ad5b6045-84ba-32b3-7739-b2464fc40c2f@eff.org>
In-Reply-To: <ad5b6045-84ba-32b3-7739-b2464fc40c2f@eff.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1289; 6:aamBnmgtrJWehw0A+FlmDteTC48W50z/Camy9IOfRblZCqPzXiGHOImsAptuxoXQ/WFbfUCpwU/vZfitcWjuHv34Kvkdt3rLO/jZXiErHYPfsBcTGo5ZhLGA8bKezwko5yDHze2Knkk3U+l0PBkJPo74LKc1PQgsa41DT1h8XKp0cMyCR/9sbMh4ziNhI5UN8Y7b/QAOluoZh6ivqs73F3+4MshESKjcntjOUF8CfrT8Xhth9QGg7WvrNq0Y/jIjtDTpkAtGhZdmDbAT7kXNVVAsZdKZ/vqdkGyAgZdERGieXwxliWZsQErIJuWd8fkirWUuQvRLiOQqcgFV+DAnUdungb0VTaGA9nieIYBTu/U=; 5:KrDrwHFuVrHujwPjuSb7n/6PdC7FmMGICxOd0Bf/pGLemyE3/SDX0a4Nwtk/OhkkJm78rzGw5qBKfFvjMCAAxGmmdG/cNfcrMEXHKWSHAdwqv/k02I7HlFWOrvtDJStUhJBgewdLk2Hb1Thf4fvv6cLwvHoUlIE8af45zX5PCjw=; 24:rC42hMgkHLP6EbCZZk42b5rSyabq0w3lL+xp8cZfBboudUYlKxngI16MAjzL67FSTg0Ntx57odnegmKitDN7OxfUwMCpxzex86fwHNHYPsY=; 7:OKJtp8UvXdQ/X4YOycQv7Y16O6gWbU51GiviPUHHva0tkd34WOQLz2dG4IIzrn4IdCSd/KZqiNeL4LZjw7MjgBGM9ayHDUdfsbrctn+O0PfHKmJGKKML2mwRwieZejC239Oeaf1pEnhpIxj/ERfNA6vDCIWqRwJgLU+DAaZ+meRKGBrQP/8uhdp3xxqf1ZpiqACDud97M59UuxQ2PWwd4639xAHLImRSjwpaFLkSFtAFHJVNnyaX1oq0hMdpPyG2
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 09b4aaaa-4963-4a4f-24db-08d546255673
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1289; 
x-ms-traffictypediagnostic: DM5PR14MB1289:
x-microsoft-antispam-prvs: <DM5PR14MB128983B89D9280FD7F1C9807830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(166708455590820);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(3002001)(3231023)(93006095)(93001095)(10201501046)(6041248)(20161123560025)(20161123564025)(20161123555025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(2016111802025)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1289; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1289; 
x-forefront-prvs: 0525BB0ADF
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39850400004)(376002)(396003)(366004)(346002)(24454002)(199004)(189003)(13464003)(6246003)(305945005)(105586002)(106356001)(9686003)(110136005)(6306002)(55016002)(8676002)(7736002)(53936002)(68736007)(2906002)(86362001)(316002)(3280700002)(3660700001)(81166006)(81156014)(99936001)(33656002)(8936002)(6116002)(3846002)(102836003)(66066001)(74316002)(561944003)(2950100002)(99286004)(2900100001)(966005)(6506007)(14454004)(97736004)(77096006)(1720100001)(7696005)(2501003)(5660300001)(59450400001)(76176011)(25786009)(53546011)(6436002)(478600001)(229853002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1289; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_04EB_01D377D3.8357CAD0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 09b4aaaa-4963-4a4f-24db-08d546255673
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Dec 2017 14:40:51.8257 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1289
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/1jtqNBag3IvoZpcOwRDuFtsPWwI>
Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 14:40:59 -0000

------=_NextPart_000_04EB_01D377D3.8357CAD0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

As pointed out on the cabf_validation list, the original text isn't just
ambiguous, the RFC contradicts itself.  I don't feel too strongly either
way, as long as it gets resolved soon, as property tags are about to become
commonly deployed (there were several proposed uses discussed at the Taipei
face-to-face meeting of the CA/Browser forum).

I do however have a slight preference for only having a single separator
(whitespace), not two in order to avoid confusion about what to do about
whitespace after semicolons and around = signs.

The semicolon doesn't really serve a useful purpose, though we do have to
keep one since there are existing CAA records out there that use it.  I'd
like the grammar to essentially be:

    domain ; [name = value]+

with the clarification that whitespace is ignored.

So my personal preference is the first style you mentioned, in line with the
submitted errata:

    example.com. IN CAA 0 issue "example.net; foo=bar bar=qux"

It's the style I used in my proposal for industry standard property tag
names on cabf_validation last week.

-Tim

> -----Original Message-----
> From: Spasm [mailto:spasm-bounces@ietf.org] On Behalf Of Jacob Hoffman-
> Andrews
> Sent: Friday, December 15, 2017 9:06 PM
> To: spasm@ietf.org
> Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844
(5200)
> 
> On 12/08/2017 10:16 AM, Russ Housley wrote:
> > http://www.rfc-editor.org/errata/eid5200
> 
> The question here is whether CAA records with property tags should look
> like:
> 
> example.com. IN CAA 0 issue "example.net; foo=bar bar=qux"
> 
> or:
> 
> example.com. IN CAA 0 issue "example.net; foo=bar; bar=qux"
> 
> (note the second semicolon)
> 
> I think the original text is ambiguous on the point, and since property
tags are
> not yet widely deployed this is a somewhat free choice. I think the
version
> where property tags are separated by semicolons makes more sense and is
> less error prone. It also happens to be what Hugo Landau's draft for CAA
> Record Extensions uses:
> https://tools.ietf.org/html/draft-ietf-acme-caa-03#page-9
> 
> And what was briefly implemented in Let's Encrypt's Boulder (since rolled
> back due to a bug):
> 
> https://github.com/letsencrypt/boulder/pull/3145/files#diff-
> 3efab53f2bcc543ac2e771ec882c57c1L310
> 
> So my feeling is we should reject this erratum and clarify in the other
> direction, requiring semicolons between property tags. Thoughts?
> 
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org
> https://www.ietf.org/mailman/listinfo/spasm

------=_NextPart_000_04EB_01D377D3.8357CAD0
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE4MTQ0MDQ0WjAvBgkqhkiG9w0BCQQxIgQg93bg9LxedDHvj1IzBkdyUBvLIpv/
Gi3uQ4LZH8vc3aEwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAJWftlR/zFQBqYvPUxt1oz8p4IGOfRBVxRCPBIyH1mC8mlxIeqsBe0xWA2qsjUOvGB0py7v+
PbxtNm1cnRjToB7pMwuYtV70JvuC2LGbfIc9gYcSOtDhHlv9SWdx72MT+xAwdih0uhE/uU/jbp71
yVPFCgVIn2WAcvinXJqH0kCVajFiqyHlMZINytkY2nuD8kdxt7SNGJFwz0OTwrVUzIiJCRkVo6aj
a6LsF2Y6DQxOlV4TRxq4MfEs+sebGhPEKFE0O7tYdnTXer+Pt2fc1k3WyIV8HjM4pjO9m6AdeUP3
w1h+4uaiEBAGNxFwpT4Fd5SvH+RQ18mhHfqx4Sc3NcEAAAAAAAA=

------=_NextPart_000_04EB_01D377D3.8357CAD0--


From nobody Mon Dec 18 09:41:58 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80CD8124B18 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 09:41:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.012
X-Spam-Level: *
X-Spam-Status: No, score=1.012 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, TRACKER_ID=1.102, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NiEzmosJlN1T for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 09:41:53 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 906141200F1 for <spasm@ietf.org>; Mon, 18 Dec 2017 09:41:53 -0800 (PST)
Received: from [216.82.249.212] by server-14.bemta-12.messagelabs.com id EA/D4-03539-1EDF73A5; Mon, 18 Dec 2017 17:41:53 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTW0zTYBiG97frqLCaMoZ8LqBY4wF1UzRDEr3 wRsOFJsYLD4jBopVVtrG008wzmogwJCERDaCAKGjEM9FgEBQneIxRkGBAiRIMInhCo4Ii2u4f ijd/nrzv+7Vvv/ylScP+IBMteNyC5OTtnC5Y+9hy0m1+9Wt+4pz650R8YcugLr6kdcMiIuHD5 zdUQnn5ILGcSKREZ0q6Zz1l+9F9hXR9O0N4Dv1ckoFacwkvGkNr2Y8E3CtOU9nA5hPQUDnWi4 IVbkBwt7FHpxo6dg601t31DxhZD1w68EXRaTqMDYXcdwF5HHQdORtgC2Sca/FHtOwUGHixU5U ZNgnu7D2OVEZK/PuDc/44yUZA++tSPwNrhM6mhzrM4fC2a5jC+SQo/uIL6Bw8Pz+AMEdBc2kO UisD6wuCx8eaKGzMA29eLYWNyxSU33wamF4GNVkvddg4haAp97oWGzPgxPc6Um0NbBpcHE4ek bMaigicv01CeUl34NWR0NWQo8Wb2wj5lbheGGuCjpZshDkSel7UUfgzSxEU1EfjVYTC/cLX2j w0tWjUBopGxYpGxbCeCIMHMxFmM9TcqCcxT4Tq98cCPAsyXz4M8Ew4VdYX4AVQ8OOWDvMkyM/ pDMJshb7GfnQchVSi6bIgbRUk87w4S4okptrcDl60m2Nj51ocgizzqYKdT5EtG9IdVUi5ens0 GnQNPSpb60PjaYILZwpD4hINY1PSN26z8bItWdpiF2QfiqRpDpgg5YoaQiUhVfBsEu3K/R2xg dZzRoZVbUZ28Q5ZTMXWA7SYHqptHyLoS20dynnDf9bUXv1N0N2FfRmkQetMdwqmCKZrSBlm1W HbFuffR4/8Hc0oyhTGII1GY9C7BMkhuv/3e1EEjbgwJkqtoBed7r8NepVyhFLu8Gp/OTf/zzJ lIH2cZN0VM5sq1ptdvZmHtrYdTcjrb9EYiVWf2t5vr8jatzJa+pW9YrVcdcFIxnh3RVs7+ias 29Ne1j88a27F25kFxmfeEDGh2XXkXuzthclM/ORe8dlAcWf15neNS0NXxuwIf5Kk70kenLasx FcxZMpevCYu2HctbTdjtZ6O575ynFa28bEzSEnm/wD5YQqiGAQAAA==
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-3.tower-219.messagelabs.com!1513618907!200475936!1
X-Originating-IP: [207.46.163.116]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 15731 invoked from network); 18 Dec 2017 17:41:51 -0000
Received: from mail-sn1nam01lp0116.outbound.protection.outlook.com (HELO NAM01-SN1-obe.outbound.protection.outlook.com) (207.46.163.116) by server-3.tower-219.messagelabs.com with AES256-SHA256 encrypted SMTP; 18 Dec 2017 17:41:51 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=qHsqLQEdVECla885pE62dfX3kW7h5aWw9s0FJjZvFdM=; b=WUlsrX/XX89xyg6edFByyBJwnZ+XLFONPqLvLeD/xVLmmQtv91oKEjXDX6Jf+fQnMBhwdxmViKe+2DI6afKLQAwJtVSBZtVOL7Bq6QwQitN26rD1oWSf6smzat9g1QVeCYfdInNNTzF2F2xS7gyMlHO2Z4kvJFmrKhORa1t554k=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1291.namprd14.prod.outlook.com (10.173.132.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Mon, 18 Dec 2017 17:41:46 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Mon, 18 Dec 2017 17:41:45 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Tim Hollebeek <tim.hollebeek@digicert.com>, Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nw==
Date: Mon, 18 Dec 2017 17:41:45 +0000
Message-ID: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1291; 6:b2Zm0j4L5O7+EhzzFctqjm3U5cyJ0ZB5W+ws9nuNP2jeXTmtCnBgyQS+qqVKwNpL0m9V8YCfPP2Wp2jZc08YALKeq6xiICsnBvHFXqzbtfwLqG0KhtZ4V4GHfMpyGBYwbRabv/6AstejzKJTV/+6mJZayLnKs3nFtp96yU6d/u13ubDry5A7Bt6sIaQ3p4191eaGvjE6FecRUjXuotqBUYuR6MMeE8KNllThACgrCIdvt/+PwkQaEwzMog2gWE7brPxptiEm0QI2KSbbJBJIGqXfY6AtC0zMjxfOmOmzkFTNEoM+bZgmykzpnAYF1HdICbLQ7jAxIUTpb0H4IqHvNm7zeIWZtFXNa5IJAEI4wZ8=; 5:SpTLXpJp8P6tyKVOnoyP8gQHQq9oKuuCOibncwt40cqI0Snxtq/ckKHjhNgTz2XC/Gv5+YWUgWKersKmtxzrD382bqEIQeHskBpVrmK+9X2H52bQlg180oW4Pd1mICMfbTNVrgSbsCL0c3T5KOFrnuAXxolC9drI4sx6ZTk18mo=; 24:wlAblmdY0oRo7jkHN/pm+0K0cVR1LL8OHCf5btjBcFjGFNzJvBgzh2swlboHnKIIvn2aJfWB4GMLLCkkHTVHsnACLMaFCFGpB14Fc9mIkzo=; 7:qU9+P4cGO0gIrXmyALdoC9at4p/AXhKshz+l/xWmk31tWp/roXA8m6qNb2HYw0vjF84EmANPEFuf1xPxFwlwGr4IEsfI0AvmRHKa3x360jYr7YOyUDlssZTL4KtO90b4YZ8lJi0fu7pWSaLEJQS6skopw90CksKl/YM2VrPUnqk7RoLdBE/Kxm9OgiQLfrfgLq42SnIHp/RbnkcPXzO3YazJcTxJL6+BnqAavvgkppPphTpV7l4hg3UVWR9ZSAUp
x-ms-exchange-antispam-srfa-diagnostics: SSOS;SSOR;
x-forefront-antispam-report: SFV:SKI; SCL:-1; SFV:NSPM; SFS:(10019020)(39850400004)(366004)(376002)(396003)(346002)(199004)(189003)(9686003)(2501003)(3480700004)(99936001)(7736002)(6436002)(305945005)(74316002)(77096006)(53936002)(14454004)(561944003)(25786009)(33656002)(55016002)(68736007)(478600001)(99286004)(105586002)(97736004)(2900100001)(106356001)(59450400001)(7116003)(81166006)(81156014)(8676002)(6506007)(221733001)(7696005)(3280700002)(110136005)(316002)(3660700001)(5660300001)(2906002)(86362001)(6116002)(102836003)(8936002)(66066001)(3846002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1291; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
x-ms-office365-filtering-correlation-id: fb54147d-8af8-4ad1-be2a-08d5463e9bb1
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1291; 
x-ms-traffictypediagnostic: DM5PR14MB1291:
x-microsoft-antispam-prvs: <DM5PR14MB12915D0254180D083534A3D1830E0@DM5PR14MB1291.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(93006095)(93001095)(10201501046)(3231023)(3002001)(6041248)(2016111802025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123564025)(20161123555025)(20161123558100)(20161123562025)(6072148)(6043046)(201708071742011); SRVR:DM5PR14MB1291; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1291; 
x-forefront-prvs: 0525BB0ADF
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_0522_01D377EC.C88FF0A0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: fb54147d-8af8-4ad1-be2a-08d5463e9bb1
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Dec 2017 17:41:45.4483 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1291
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/Jse-FslACq3wair2B2_YSwpViNs>
Subject: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 17:41:56 -0000

------=_NextPart_000_0522_01D377EC.C88FF0A0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0523_01D377EC.C88FF0A0"


------=_NextPart_001_0523_01D377EC.C88FF0A0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Here is my tags proposal, in case others want to comment on it on this list.

 

Note that it has been privately pointed out to me that one possible solution
to the criticality problem and the scaling problem is to use top-level tags
that are independent of the issue records:

 

Something like:

 

CAA 0 issue "a.example.com"

CAA 0 issue "b.example.com"

CAA 128 validation "Phone"

 

-Tim

 

----------------------------------------------------------------------------
---------------------------------------------------------------------------


Introduction and Motivation


 

In addition to being able to specify which CA or CAs are allowed to issue
certificates for a given domain, RFC 6844 allows additional parameters, such
as the account number, that the CA can consume for a variety of uses.  RFC
6844 defines the format, but otherwise leaves the kinds of properties and
their meanings up to the issuer.

While this is appropriate for a technical standard, standardizing the names
and meanings of CAA properties across the CA industry has the following
benefits:

1.	Reduce user confusion when the same or similar property is used by
different CAs with different names and semantics
2.	Make it simpler to migrate from one CA to another while preserving
the CAA configuration
3.	Simplifying configuration and expression of CAA policies that allow
issuance from multiple CAs
4.	Allow CAA record creation tools to support creating CAA records that
contain properties that have been standardized


History


 

CAA property tags have been discussed at several CA/B Forum meetings, most
recently at the October meeting in Taipei.  Four were suggested: Acceptable
validation methods, an account identifier, certificate types (DV/OV/EV), and
ability to specify a brand.

 


Method of Adoption


 

Since these CAA properties are just a voluntary industry standard that any
CA could implement, they don't necessarily have to exist in a standards
document.  However, it seems like it would be helpful if the names and
semantics were agreed upon by the industry as a whole, so it is probably
best to include them in the Baseline Requirements as an optional feature CAs
MAY implement.

On the other hand, it might be desirable to reserve the names, and require
that if these particular property names are used, the semantics MUST be the
semantics specified in the Baseline Requirements.

 


Brands


 

I'm starting with this one because I'm going to argue it isn't necessary.
CAs can and do have multiple names that they accept in CAA records.  It is
hard to imagine a brand existing without the associated domain and website
also existing.  I'd suggest that CAs that maintain multiple brands simply
use a different domain name for each brand, e.g.

certs.example.com               CAA 0 issue "megaca.com"

catlover.example.com         CAA 0 issue "certsforcats.com"    #
certsforcats is a brand owned by MegaCA.

CAAs can also publicize examples of CAA records that allow for issuance by
all of their brands.


Acceptable Validation Methods


 

A list of acceptable validation methods can be specified using the
"validation" tag.

There are two challenges here, that have been discussed elsewhere in
relation to keeping records of which validation method was used for a
particular certificate.  The first is that validation methods can change
over time.  This seems to be less of a concern for issuance than it is for
historical validations, as a CAA record can and should be interpreted as
always requiring the version of the method that is enforced by the BRs at
issuance time.  However, this can cause the exact meaning of a CAA record to
change over time as the BRs evolve.  I don't think this is a big problem,
but wanted to note it.

The second issue is that it is possible that the numbering of the BR
validation methods could potentially change over time.  For that reason, I
think it might be reasonable to standardize on a label for each validation
method, that can be used in addition to the section number:


BR Section (BR v. 1.5.4)

Short Section

Validation method label


3.2.2.4.1

1

DomainContact


3.2.2.4.2

2

EmailOrSimilar


3.2.2.4.3

3

Phone


3.2.2.4.4

4

ConstructedEmail


3.2.2.4.5

5

DomainAuthorizationDocument


3.2.2.4.6

6

WebsiteChange


3.2.2.4.7

7

DNSChange


3.2.2.4.8

8

IPAddressLookup


3.2.2.4.9

9

TestCertificate


3.2.2.4.10

10

RandomValueInCertificate

 

Examples:

CAA 0 issue "ca.example.net; validation=3"                      # Call me
about all certificates

CAA 0 issue "ca.example.net; validation=Phone"             # Same as
previous example

CAA 0 issue "ca.example.net; validation=1,2,3,4,7,8,9,10"   # I don't like
DADs and website changes

CAA 0 issue "ca.example.net; validation=!5,6"                 # Same as
previous example.  Worth the trouble?


Account Identifier


 

This one is relatively straightforward, as the identifier is going to be
CA-specific anyway.  Use the "account" keyword:

CAA 0 issue "ca.example.net; account=8675309"

The format and values of the account specifier is up to the individual CA.


Acceptable Certificate Types


 

This one also seems to be relatively straightforward.  I've chosen to make
the categories disjoint, so if you're ok with more than one type, you have
to specify more than one.  Use the "type" keyword.

CAA 0 issue "ca.example.net; type=EV"                         # EV only

CAA 0 issue "ca.example.net; type=DV"                         # DV only

CAA 0 issue "ca.example.net; type=OV,EV"                   # No DV


Lack of Property Tag Value Criticality


 

Supporting the various properties is optional.  Unlike the CAA "issue"
property, these properties do not have to be ubiquitously supported to have
value, because Domain holders can restrict their issue records to only
include CAs that have publicly stated that they support the desired property
tags.

For example, if CAs A, B, and C support the "type=EV" tag, then the
following will prevent non-EV issuance:

CAA issue 0 "A.com; type=EV"

CAA issue 0 "B.com; type=EV"

CAA issue 0 "C.com; type=EV"

Unfortunately, this does scale poorly with a large number of CAs.

The problem is that RFC 6844 supports "Critical" for property tags (like
"issue"), but there is no way to mark a parameter tag is "Critical".  I
intend to bring this up with the IETF WG.

Any easy solution is to use reserved bit #1 for property tag criticality:


CAA issue 64 "A.com; type=EV"            # type=EV tag must be respected;
                                                                    # cannot
issue if you don't understand or enforce it.


 


Multiple Tags


 

Just for completeness, these individual features can also be used together:

CAA issue 0 "ca.example.com; type=EV validation=Phone account=8675309"

 

 


------=_NextPart_001_0523_01D377EC.C88FF0A0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 15 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"Calibri Light";
	panose-1:2 15 3 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	margin-top:12.0pt;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:0in;
	margin-bottom:.0001pt;
	line-height:106%;
	page-break-after:avoid;
	font-size:16.0pt;
	font-family:"Calibri Light",sans-serif;
	color:#2F5496;
	font-weight:normal;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:8.0pt;
	margin-left:.5in;
	mso-add-space:auto;
	line-height:106%;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, =
div.MsoListParagraphCxSpFirst
	{mso-style-priority:34;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	line-height:106%;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, =
div.MsoListParagraphCxSpMiddle
	{mso-style-priority:34;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	line-height:106%;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, =
div.MsoListParagraphCxSpLast
	{mso-style-priority:34;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:8.0pt;
	margin-left:.5in;
	mso-add-space:auto;
	line-height:106%;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri",sans-serif;}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Calibri Light",sans-serif;
	color:#2F5496;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 129.75pt 1.0in 129.7pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:2054579048;
	mso-list-type:hybrid;
	mso-list-template-ids:1082130962 67698703 67698713 67698715 67698703 =
67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US =
link=3D"#0563C1" vlink=3D"#954F72"><div class=3DWordSection1><p =
class=3DMsoPlainText>Here is my tags proposal, in case others want to =
comment on it on this list.<o:p></o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p><p class=3DMsoPlainText>Note =
that it has been privately pointed out to me that one possible solution =
to the criticality problem and the scaling problem is to use top-level =
tags that are independent of the issue records:<o:p></o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p><p =
class=3DMsoPlainText>Something like:<o:p></o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>CAA 0 =
issue &#8220;a.example.com&#8221;<o:p></o:p></p><p class=3DMsoNormal>CAA =
0 issue &#8220;b.example.com&#8221;<o:p></o:p></p><p =
class=3DMsoPlainText>CAA 128 validation =
&#8220;Phone&#8221;<o:p></o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p><p =
class=3DMsoPlainText>-Tim<o:p></o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p><p =
class=3DMsoPlainText>----------------------------------------------------=
-------------------------------------------------------------------------=
--------------------------<o:p></o:p></p><h1>Introduction and =
Motivation<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>In addition to being able to specify which CA or CAs =
are allowed to issue certificates for a given domain, RFC 6844 allows =
additional parameters, such as the account number, that the CA can =
consume for a variety of uses.&nbsp; RFC 6844 defines the format, but =
otherwise leaves the kinds of properties and their meanings up to the =
issuer.<o:p></o:p></p><p class=3DMsoNormal>While this is appropriate for =
a technical standard, standardizing the names and meanings of CAA =
properties across the CA industry has the following =
benefits:<o:p></o:p></p><ol style=3D'margin-top:0in' start=3D1 =
type=3D1><li class=3DMsoListParagraphCxSpFirst =
style=3D'margin-left:0in;mso-add-space:auto;mso-list:l0 level1 =
lfo1'>Reduce user confusion when the same or similar property is used by =
different CAs with different names and semantics<o:p></o:p></li><li =
class=3DMsoListParagraphCxSpMiddle =
style=3D'margin-left:0in;mso-add-space:auto;mso-list:l0 level1 =
lfo1'>Make it simpler to migrate from one CA to another while preserving =
the CAA configuration<o:p></o:p></li><li =
class=3DMsoListParagraphCxSpMiddle =
style=3D'margin-left:0in;mso-add-space:auto;mso-list:l0 level1 =
lfo1'>Simplifying configuration and expression of CAA policies that =
allow issuance from multiple CAs<o:p></o:p></li><li =
class=3DMsoListParagraphCxSpLast =
style=3D'margin-left:0in;mso-add-space:auto;mso-list:l0 level1 =
lfo1'>Allow CAA record creation tools to support creating CAA records =
that contain properties that have been =
standardized<o:p></o:p></li></ol><h1>History<o:p></o:p></h1><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>CAA property =
tags have been discussed at several CA/B Forum meetings, most recently =
at the October meeting in Taipei.&nbsp; Four were suggested: Acceptable =
validation methods, an account identifier, certificate types (DV/OV/EV), =
and ability to specify a brand.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><h1>Method of =
Adoption<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Since these CAA properties are just a voluntary =
industry standard that any CA could implement, they don&#8217;t =
necessarily have to exist in a standards document.&nbsp; However, it =
seems like it would be helpful if the names and semantics were agreed =
upon by the industry as a whole, so it is probably best to include them =
in the Baseline Requirements as an optional feature CAs MAY =
implement.<o:p></o:p></p><p class=3DMsoNormal>On the other hand, it =
might be desirable to reserve the names, and require that if these =
particular property names are used, the semantics MUST be the semantics =
specified in the Baseline Requirements.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><h1>Brands<o:p></o:p></h1><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>I&#8217;m =
starting with this one because I&#8217;m going to argue it isn&#8217;t =
necessary.&nbsp; CAs can and do have multiple names that they accept in =
CAA records.&nbsp; It is hard to imagine a brand existing without the =
associated domain and website also existing.&nbsp; I&#8217;d suggest =
that CAs that maintain multiple brands simply use a different domain =
name for each brand, e.g.<o:p></o:p></p><p =
class=3DMsoNormal>certs.example.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CAA 0 issue =
&#8220;megaca.com&#8221;<o:p></o:p></p><p =
class=3DMsoNormal>catlover.example.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp; CAA 0 issue =
&#8220;certsforcats.com&#8221;&nbsp;&nbsp;&nbsp; # certsforcats is a =
brand owned by MegaCA.<o:p></o:p></p><p class=3DMsoNormal>CAAs can also =
publicize examples of CAA records that allow for issuance by all of =
their brands.<o:p></o:p></p><h1>Acceptable Validation =
Methods<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>A list of acceptable validation methods can be =
specified using the &#8220;validation&#8221; tag.<o:p></o:p></p><p =
class=3DMsoNormal>There are two challenges here, that have been =
discussed elsewhere in relation to keeping records of which validation =
method was used for a particular certificate.&nbsp; The first is that =
validation methods can change over time.&nbsp; This seems to be less of =
a concern for issuance than it is for historical validations, as a CAA =
record can and should be interpreted as always requiring the version of =
the method that is enforced by the BRs at issuance time.&nbsp; However, =
this can cause the exact meaning of a CAA record to change over time as =
the BRs evolve.&nbsp; I don&#8217;t think this is a big problem, but =
wanted to note it.<o:p></o:p></p><p class=3DMsoNormal>The second issue =
is that it is possible that the numbering of the BR validation methods =
could potentially change over time.&nbsp; For that reason, I think it =
might be reasonable to standardize on a label for each validation =
method, that can be used in addition to the section =
number:<o:p></o:p></p><table class=3DMsoTableGrid border=3D1 =
cellspacing=3D0 cellpadding=3D0 =
style=3D'border-collapse:collapse;border:none'><tr><td width=3D196 =
valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;padding:0in 5.4pt 0in 5.4pt'><p class=3DMsoNormal><b>BR Section =
(BR v. 1.5.4)<o:p></o:p></b></p></td><td width=3D104 valign=3Dtop =
style=3D'width:77.65pt;border:solid windowtext =
1.0pt;border-left:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal><b>Short Section<o:p></o:p></b></p></td><td =
width=3D324 valign=3Dtop style=3D'width:242.75pt;border:solid windowtext =
1.0pt;border-left:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal><b>Validation method =
label<o:p></o:p></b></p></td></tr><tr><td width=3D196 valign=3Dtop =
style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.1<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>1<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>DomainContact<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.2<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>2<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>EmailOrSimilar<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.3<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>3<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>Phone<o:p></o:p></p></td></tr><tr><td width=3D196 =
valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.4<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>4<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>ConstructedEmail<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.5<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>5<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>DomainAuthorizationDocument<o:p></o:p></p></td></tr><tr=
><td width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid =
windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.6<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>6<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>WebsiteChange<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.7<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>7<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>DNSChange<o:p></o:p></p></td></tr><tr><td width=3D196 =
valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.8<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>8<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>IPAddressLookup<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.9<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>9<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>TestCertificate<o:p></o:p></p></td></tr><tr><td =
width=3D196 valign=3Dtop style=3D'width:147.1pt;border:solid windowtext =
1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>3.2.2.4.10<o:p></o:p></p></td><td width=3D104 =
valign=3Dtop =
style=3D'width:77.65pt;border-top:none;border-left:none;border-bottom:sol=
id windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p class=3DMsoNormal>10<o:p></o:p></p></td><td =
width=3D324 valign=3Dtop =
style=3D'width:242.75pt;border-top:none;border-left:none;border-bottom:so=
lid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt'><p =
class=3DMsoNormal>RandomValueInCertificate<o:p></o:p></p></td></tr></tabl=
e><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Examples:<o:p></o:p></p><p class=3DMsoNormal>CAA 0 =
issue &#8220;ca.example.net; =
validation=3D3&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; # Call me about all certificates<o:p></o:p></p><p =
class=3DMsoNormal>CAA 0 issue &#8220;ca.example.net; =
validation=3DPhone&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; # Same as previous example<o:p></o:p></p><p =
class=3DMsoNormal>CAA 0 issue &#8220;ca.example.net; =
validation=3D1,2,3,4,7,8,9,10&#8221;&nbsp;&nbsp; # I don&#8217;t like =
DADs and website changes<o:p></o:p></p><p class=3DMsoNormal>CAA 0 issue =
&#8220;ca.example.net; =
validation=3D!5,6&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # Same as previous =
example.&nbsp; Worth the trouble?<o:p></o:p></p><h1>Account =
Identifier<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>This one is relatively straightforward, as the =
identifier is going to be CA-specific anyway.&nbsp; Use the =
&#8220;account&#8221; keyword:<o:p></o:p></p><p class=3DMsoNormal>CAA 0 =
issue &#8220;ca.example.net; account=3D8675309&#8221;<o:p></o:p></p><p =
class=3DMsoNormal>The format and values of the account specifier is up =
to the individual CA.<o:p></o:p></p><h1>Acceptable Certificate =
Types<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>This one also seems to be relatively =
straightforward.&nbsp; I&#8217;ve chosen to make the categories =
disjoint, so if you&#8217;re ok with more than one type, you have to =
specify more than one.&nbsp; Use the &#8220;type&#8221; =
keyword.<o:p></o:p></p><p class=3DMsoNormal>CAA 0 issue =
&#8220;ca.example.net; =
type=3DEV&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; # EV only<o:p></o:p></p><p class=3DMsoNormal>CAA 0 issue =
&#8220;ca.example.net; =
type=3DDV&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; # DV only<o:p></o:p></p><p class=3DMsoNormal>CAA 0 issue =
&#8220;ca.example.net; =
type=3DOV,EV&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # No =
DV<o:p></o:p></p><h1>Lack of Property Tag Value =
Criticality<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Supporting the various properties is optional.&nbsp; =
Unlike the CAA &#8220;issue&#8221; property, these properties do not =
have to be ubiquitously supported to have value, because Domain holders =
can restrict their issue records to only include CAs that have publicly =
stated that they support the desired property tags.<o:p></o:p></p><p =
class=3DMsoNormal>For example, if CAs A, B, and C support the =
&#8220;type=3DEV&#8221; tag, then the following will prevent non-EV =
issuance:<o:p></o:p></p><p class=3DMsoNormal>CAA issue 0 &#8220;A.com; =
type=3DEV&#8221;<o:p></o:p></p><p class=3DMsoNormal>CAA issue 0 =
&#8220;B.com; type=3DEV&#8221;<o:p></o:p></p><p class=3DMsoNormal>CAA =
issue 0 &#8220;C.com; type=3DEV&#8221;<o:p></o:p></p><p =
class=3DMsoNormal>Unfortunately, this does scale poorly with a large =
number of CAs.<o:p></o:p></p><p class=3DMsoNormal>The problem is that =
RFC 6844 supports &#8220;Critical&#8221; for property tags (like =
&#8220;issue&#8221;), but there is no way to mark a parameter tag is =
&#8220;Critical&#8221;.&nbsp; I intend to bring this up with the IETF =
WG.<o:p></o:p></p><p class=3DMsoNormal>Any easy solution is to use =
reserved bit #1 for property tag criticality:<o:p></o:p></p><h1><span =
style=3D'font-size:11.0pt;line-height:106%;font-family:"Calibri",sans-ser=
if;color:windowtext'>CAA issue 64 &#8220;A.com; =
type=3DEV&#8221;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; # type=3DEV tag must be =
respected;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # cannot issue if =
you don&#8217;t understand or enforce it.</span><o:p></o:p></h1><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><h1>Multiple =
Tags<o:p></o:p></h1><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Just for completeness, these individual features can =
also be used together:<o:p></o:p></p><p class=3DMsoNormal>CAA issue 0 =
&#8220;ca.example.com; type=3DEV validation=3DPhone =
account=3D8675309&#8221;<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoPlainText><o:p>&nbsp;</o:p></p></div></body></html>
------=_NextPart_001_0523_01D377EC.C88FF0A0--

------=_NextPart_000_0522_01D377EC.C88FF0A0
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE4MTc0MTM4WjAvBgkqhkiG9w0BCQQxIgQgq88Eq5uHjpuVf6fHZVJl/frs3iYR
vJ7W5pG8OJ5Dqw4wgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAHOTdUNZfSdPtabKveKXlxM2DxA8OZkxZBnRSYMANy2qaKAAeCWFfHDxry+wuvcSh31mKXxU
E+I3bzrWKMH09fidHsq0DtPm+I9WYDTY3ko/RFUbCHK0aQl4tpqGdybMWK4z+J+JZub0P4rCiY8N
2NBDHnny6pJKZzvXDxQR5i1mXCkPlNfwtSfYUMVrBczqbq/o9Pald58V7wcG1iz67fM+TzjREIpE
EVpJG00vzelXxyQr/91PND/XR4wU8WUNlaoN9RTxmSlSIoVdEGBlXi6tN2RP0TVnVlc3Ikd5S3US
lUBCNwJqS3WHGmViIBFWnCLie1MMutiEg6pKS2BiMjwAAAAAAAA=

------=_NextPart_000_0522_01D377EC.C88FF0A0--


From nobody Mon Dec 18 11:30:46 2017
Return-Path: <jsha@eff.org>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E47B126C83 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 11:30:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.111
X-Spam-Level: 
X-Spam-Status: No, score=-5.111 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=eff.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CGSOrHbZqhxp for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 11:30:42 -0800 (PST)
Received: from mail2.eff.org (mail2.eff.org [173.239.79.204]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 06B7C120454 for <spasm@ietf.org>; Mon, 18 Dec 2017 11:30:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=eff.org; s=mail2;  h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:From:References:To:Subject; bh=RWHji3OQbAeL5/wvN8DBigj9MCpcgEcD8fncVa5sNpc=;  b=s62jNtCoZNsXez/YhO7dHP9ktqKHpX7urWuvdJe324xZQm+rm2e1el+xx2BhmwCzBIuZAir+V14qGf9rSZ+NI/QthdZv4iELRLWAMJ7x0NkCfni6coJXwM6ZkkyfRWiIfRc3OjkiL3WDIyyRLVFWpyXvBQGZIBs1QOmPmbh8EMA=;
Received: ; Mon, 18 Dec 2017 11:30:37 -0800
To: spasm@ietf.org
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Jacob Hoffman-Andrews <jsha@eff.org>
Message-ID: <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org>
Date: Mon, 18 Dec 2017 11:30:40 -0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
Content-Type: text/plain; charset=windows-1252
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/6AKCMMYAgrCOKinSrQruuSqT6IM>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 19:30:45 -0000

I'm following up your the related validation@cabforum thread at
https://cabforum.org/pipermail/validation/2017-December/000686.html,
hoping to merge the streams a little bit. :-)

On 12/18/2017 11:10 AM, Tim Hollebeek via Validation wrote:
> I personally find OIDs very hard for non-technical users to grasp.

This is a good point, although most users should be using a CAA record
generator, which can help with this.

> readable text labels, like Validation=Phone?

My issue with validation=phone is that it is not precise enough; there's
one version of validation by phone defined in the BRs today, but what if
that changes significantly? One could solve this by defining a versioned
validation method, e.g. validation=phone-01, with an IANA registry to
register new ones as requirements change.

However, there does seem to be some interest in embedding information
about validation methods in certificates. It would be nice if there was
a correspondence between the namespace used in CAA and the one used in
certificates.

> I think account and account-uri are complimentary approaches.  I agree
> that CAs need the freedom to put whatever they want on the right hand
> side of these, and many CAs have existing customer identification
> schemes that are not URIs, so the account-uri field cannot be used.

It's easy to define a URI mapping for an existing account identifier.
For instance, if customers have a numeric id 123456, the CA can specify
that the corresponding account-uri is
https://ca.example.net/accounts/123456. There's no requirement that
account-uris are fetchable.

It seems inefficient to define the same mechanism under two different
names in two different places (account vs account-uri), and I think is
likely to lead to user error.


From nobody Mon Dec 18 12:11:00 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0616012420B for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:10:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.101
X-Spam-Level: 
X-Spam-Status: No, score=-0.101 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WYM7S9ZdfiQ9 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:10:57 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 843261205D3 for <spasm@ietf.org>; Mon, 18 Dec 2017 12:10:57 -0800 (PST)
Received: from [216.82.249.212] by server-17.bemta-12.messagelabs.com id E0/C0-10763-0D0283A5; Mon, 18 Dec 2017 20:10:56 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WSf0yMcRzH7/v8uB50PF2lj1s/uDLUOpIfR5s ZVg1tmB85WT3VU3dzd+V5jsUfZMZwhqZwLdXGYg2bREaFk+SySZckGRHyWypkae657xX+e30/ 7/f3+/58P/swpNIpVzF8joUXzJxRLR9NPdCc2hrZNFGrm/HuGa21tQzItcWtaQuJ+M/f3tLxp 08PECsIHW0wp2blpND6YutZlH0lNsf2YmUuerPoABrNUOwXAkqfN5LSQcnmE1Db00UcQKNchz oExUeRxHJ2BrTW3HXX/dhl0HqhQC6xLxsEnR3XSVwPhtJb/TTm+VCb53AzxU4GR2sNJbGCTYJ LpZ8JHHYQQVtfuTtgFBsD1Van24TY8fDDcc4dRrIB0N5V4mZg/aDzYaMcsz+8ezVEY38SnOy1 e+pqeHr+J8IcBM0lViSFAWv3gra3ZV5Y0MDlvE8eUwL01u+msakMwffXj0kshEODfa/HtAkcF zu9huv76goJfOE2CXt+V3pMgfCqzkphoYKGw49f03iQ6ZBfbvcMTAXPWvYjzIHQ3VFDH0FTC/ /5aqHrPsmWuGZvO04VuofmA/dsXRQ2RcK12psk5hCo+lTk4Rg48euWHPMkyLd2emGeDR/u9KB SxJSjqSIvbOWFyGitJlUwZOotJs5gjIyKmqkx8aLIZfJGLlXUpGWZKpBrtXbKZOgq6r6xwY4m MITaX2EbM0enHJualb5Nz4n6ZGGLkRftKJBh1KAQQrQ6pY/AZ/I5GQajaz+HZWC81X6KaZKsE LM5k2jIxJIDRTOD1e2DBPPG9iGXVFLmLDOvClDskqysZNVvMY88NLzrzShI5atAMplM6Z3NCy aD5X/9PQpgkNpXcVF6xdtgtozkvXe1QrhaKUicK7Vi4f5Kqlw0PSHszP1V3+OSI+KqQx6t67h 80hnet3JsSlrskmDON/TJUHpKhVHVsn6ZLqF/IHrc1YyI+K+rme03Nn9UFVUmP01Y3DauZy3q XuAd25C2dMesS/1TasJeNs0xEjMdBf7zdq7ZmNibXx/V0FeVvSfuelfVod2JZcWhxOQJ7csnV TiPOZPUlKjnosJJQeT+ANKbBSzmAwAA
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-8.tower-219.messagelabs.com!1513627855!200252163!1
X-Originating-IP: [207.46.163.118]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 20888 invoked from network); 18 Dec 2017 20:10:55 -0000
Received: from mail-sn1nam01lp0118.outbound.protection.outlook.com (HELO NAM01-SN1-obe.outbound.protection.outlook.com) (207.46.163.118) by server-8.tower-219.messagelabs.com with AES256-SHA256 encrypted SMTP; 18 Dec 2017 20:10:55 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=HsxzHPCCn8k0jthRPFw9G6SehKi/Rpc3e8wj2bxsGDc=; b=RCrCRgH1+jPbh8GUQNqnJrF3d+F+h8xQFxQJPNt3hKiO/d67Rl0gIzg5Vn0nuSbdga5uHx883Zb32hHWWoZklOimkTyh//5x1kisSTsljDvKclzacnFbhlKwF9lHoRVGUpLXNGJWAU5Ya5a2RRK4xQK2ROE2sUvOZSVLm1oqPCo=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Mon, 18 Dec 2017 20:10:54 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Mon, 18 Dec 2017 20:10:53 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwADzsgAAAD5epA=
Date: Mon, 18 Dec 2017 20:10:53 +0000
Message-ID: <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org>
In-Reply-To: <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1289; 6:oqr8DGCFmiKGqS9paazg5TqDYGfxPSfhItGcrGwQVSGl6baco57GtkZJwn0h+qShnovePaM0LxW5dNkzfgp31ms9QnEqt5IloxteMwVPTUHBC5S2GDlgH64XU4xOHsGzvgM6/lSiQ3LJ9QpPMU1Cc3TLjO7vEYFwUzDimDWnWyllbUA03S2UhEjxG/k9dN8zdkanzcZ0xOE7F2O9Y807Cb+7/n8GX75Qk3c0k4X0NDHue41qFadiItdSyoPswHLGKQJHr+uQB6H/4rjbfa3Icz4rzHC2h4sG82440Jk3ohr34q/cAzgt8bbYCe2RPtqq8dgjK3S6ui25M+A+D8ODxv/Kob6yoQFFvKlJ+FLuOQI=; 5:vp4EvnpBEKbOLWN0msZ9JyIDnawDyhhvfbcGRSTPGjk9Eqevc4MMI/y0ORuhzC3lwzbpz7nWr2jJPBYKJfuU9fySSCeUG5KAFpUK98bYgrxjw1L35l8TyKU2wkLAynG1n1r61HFPc445Sz1nXeCmGK9256370OMc4QKhwMDeRw4=; 24:X5rMyqtPRKMvM3KTOWDxN/lyvwqtSwDqjzGgBCkDo5nGUGZozLuyzKBmP8KRGGL6q2N/7WKL3Qlo0NqZRBQOm3nbGjDeM4I4RAu4IV8WuoA=; 7:gaKbE9q7LzYXNApRUyleYpBDLJagrH4+pIH9AoOAcIwx0NTzmJKyCKHQM4BW2xrcW2Isfa8FogqgtegO0Cg0lSFxmrxBwiHfc8ixYEz3OLM34x34UOVI92nK230BcEOPB6ezIw6pvA4Q9cxYcuzq8V9SSRkl2BKaIo+Nc5gst2M8MxNArYymBdpa4W17u6qU83qVIRsLukTKNSkuGfesjidc4k779qT1Poic1aN6qkjia27iDuskk8ace+uqUJso
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: d8391c76-d36f-4ab5-e295-08d54653714d
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1289; 
x-ms-traffictypediagnostic: DM5PR14MB1289:
x-microsoft-antispam-prvs: <DM5PR14MB1289219B2F9B244099BD4208830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(3002001)(3231023)(93006095)(93001095)(10201501046)(6041248)(20161123558100)(20161123560025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123562025)(2016111802025)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1289; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1289; 
x-forefront-prvs: 0525BB0ADF
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(346002)(366004)(396003)(39860400002)(376002)(189003)(199004)(3660700001)(6246003)(105586002)(305945005)(9686003)(110136005)(6306002)(106356001)(55016002)(8676002)(7736002)(53936002)(68736007)(316002)(2906002)(86362001)(81156014)(3280700002)(81166006)(6116002)(99936001)(33656002)(8936002)(3846002)(102836003)(66066001)(74316002)(99286004)(2950100002)(2900100001)(966005)(14454004)(6506007)(77096006)(97736004)(7696005)(2501003)(5660300001)(25786009)(76176011)(59450400001)(6436002)(229853002)(478600001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1289; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_0589_01D37801.9DE446C0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d8391c76-d36f-4ab5-e295-08d54653714d
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Dec 2017 20:10:53.8546 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1289
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/VKoEi7jhvlseF5J2FB2ieKYtEr4>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 20:10:59 -0000

------=_NextPart_000_0589_01D37801.9DE446C0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit



> > readable text labels, like Validation=Phone?
> 
> My issue with validation=phone is that it is not precise enough; there's
one
> version of validation by phone defined in the BRs today, but what if that
> changes significantly? One could solve this by defining a versioned
validation
> method, e.g. validation=phone-01, with an IANA registry to register new
ones
> as requirements change.

The lack of precision bothered me a bit too when I was proposing it,
especially since some people have discussed breaking up some of the 
larger catch-all ones.  I like the version number, but I think we have to be

a bit careful.  Is the version just a minimum version?  If I have CAA set to

validation=phone-01, do I have to update my CAA record every time the 
BR validation methods are changed?  How big of a change requires revving 
the version number of the validation method?

Should the BR version number be used instead?  E.g. validation=phone-1.5.4?
This might make more sense as the BR version number does get bumped on
every validation rev (and non-validation rev ...).

> However, there does seem to be some interest in embedding information
> about validation methods in certificates. It would be nice if there was a
> correspondence between the namespace used in CAA and the one used in
> certificates.

That would be nice.  Maybe an IANA registry for validation methods might
make sense, but I'm unfamiliar with how easy/difficult that is to set up/
modify.

> It's easy to define a URI mapping for an existing account identifier.
> For instance, if customers have a numeric id 123456, the CA can specify
that
> the corresponding account-uri is https://ca.example.net/accounts/123456.
> There's no requirement that account-uris are fetchable.

I get that, but a URI is longer and more complicated.  Quirin's research
shows that a significant fraction of CAA users CANNOT SPELL THEIR CA'S
NAME.  I shudder to think how they will manage to mangle a URI ...

-Tim


------=_NextPart_000_0589_01D37801.9DE446C0
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE4MjAxMDQ2WjAvBgkqhkiG9w0BCQQxIgQgRxSFsgOtP+cTc2duNTIM3fUMFMsW
aYl973FijenSGGUwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBALvbYM7czPwvkx0zMvZTMyE677Q6/TOz/ZpEOIGGfD0VTApW8LL+cigda0KYjkBpOdPpim53
KvfLlngdficvlaJyKqaQ8QXh+O29+CSqYU2g8qjKL+JrGNDmcDa9qqjmo+Hc0v4dSRKRDZgq0rfj
RTIvVLfXSoCrAfsS2hCdSkFCQgHH5NBM5yXnnlH0bajopxobYzZfGnVZiiH774EeXKdFNpwDAti5
gncAuxiTmkJahUM074zfJxDgd6g4I1vM1ie4vKzuQDpF/fap7cB34dAlXUFK6yI2jDOOQHpMVKDl
Uu4AAAdn44RI/lx71THcYTsbXPaqjq9jmDW9G5nwAV8AAAAAAAA=

------=_NextPart_000_0589_01D37801.9DE446C0--


From nobody Mon Dec 18 12:42:10 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16AA312D851 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:42:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.099
X-Spam-Level: 
X-Spam-Status: No, score=-0.099 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Soz4G-02gWnu for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:42:07 -0800 (PST)
Received: from homiemail-a111.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E25C1200FC for <spasm@ietf.org>; Mon, 18 Dec 2017 12:42:07 -0800 (PST)
Received: from homiemail-a111.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a111.g.dreamhost.com (Postfix) with ESMTP id 05F263C001C17 for <spasm@ietf.org>; Mon, 18 Dec 2017 12:42:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=SkiWCfGo3CcseF/w6fp9l0tv4sE=; b= PgMu9ddJFt67zUop3EMFk3o/sYhDXBzJum1/lVMaNWazHi8nM9CaFGg8w/ZRrbjJ jUX70b9QhM26ArtoqZs4YI7RFe9XoDDQK+d0HY63TO6ZAoZJMa4IUGDFriJQ6Lsz oMtJmdTll7MoYYKZFL6bRZPuJxy7/UV/DexbSeXaL6M=
Received: from mail-it0-f46.google.com (mail-it0-f46.google.com [209.85.214.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a111.g.dreamhost.com (Postfix) with ESMTPSA id E02DF3C001C18 for <spasm@ietf.org>; Mon, 18 Dec 2017 12:42:06 -0800 (PST)
Received: by mail-it0-f46.google.com with SMTP id p139so240008itb.1 for <spasm@ietf.org>; Mon, 18 Dec 2017 12:42:06 -0800 (PST)
X-Gm-Message-State: AKGB3mLGCfnyFVtBOkZhMsOOMbRM/K2g0hLx8nAS2l/xw5zdJiOqS0lh +qmqeOOfk1WXGLXCtV8cHRr1CM4fORDTSp2HDzI=
X-Google-Smtp-Source: ACJfBot9+h/+72ollqG23UJ07CrSEVehg16KQgjrRGzXyE7xkOQltun1iaM0heFn/GZ2SBws/XayvtJUbPiL/xO/jYo=
X-Received: by 10.36.61.149 with SMTP id n143mr459320itn.67.1513629726159; Mon, 18 Dec 2017 12:42:06 -0800 (PST)
MIME-Version: 1.0
Received: by 10.2.78.70 with HTTP; Mon, 18 Dec 2017 12:42:05 -0800 (PST)
In-Reply-To: <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Mon, 18 Dec 2017 15:42:05 -0500
X-Gmail-Original-Message-ID: <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
Message-ID: <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Content-Type: multipart/alternative; boundary="001a1144452e2645c10560a36229"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/NcLgldGMuyTL4JTNv2avoawFsTw>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 20:42:09 -0000

--001a1144452e2645c10560a36229
Content-Type: text/plain; charset="UTF-8"

On Mon, Dec 18, 2017 at 3:10 PM, Tim Hollebeek <tim.hollebeek@digicert.com>
wrote:

>
>
> > > readable text labels, like Validation=Phone?
> >
> > My issue with validation=phone is that it is not precise enough; there's
> one
> > version of validation by phone defined in the BRs today, but what if that
> > changes significantly? One could solve this by defining a versioned
> validation
> > method, e.g. validation=phone-01, with an IANA registry to register new
> ones
> > as requirements change.
>
> The lack of precision bothered me a bit too when I was proposing it,
> especially since some people have discussed breaking up some of the
> larger catch-all ones.  I like the version number, but I think we have to
> be
>
> a bit careful.  Is the version just a minimum version?  If I have CAA set
> to
>
> validation=phone-01, do I have to update my CAA record every time the
> BR validation methods are changed?  How big of a change requires revving
> the version number of the validation method?
>

> Should the BR version number be used instead?  E.g. validation=phone-1.5.4?
> This might make more sense as the BR version number does get bumped on
> every validation rev (and non-validation rev ...).
>
> > However, there does seem to be some interest in embedding information
> > about validation methods in certificates. It would be nice if there was a
> > correspondence between the namespace used in CAA and the one used in
> > certificates.
>
> That would be nice.  Maybe an IANA registry for validation methods might
> make sense, but I'm unfamiliar with how easy/difficult that is to set up/
> modify.
>

It'd be great if there was a spec writeup for discussion - or is this a
pre-spec seeds of thoughts?

I think Jacob's suggestion of OIDs is not at all unreasonable, and avoids
the ambiguities you raise and allows them to be addressed by policy in the
Forum.


> > It's easy to define a URI mapping for an existing account identifier.
> > For instance, if customers have a numeric id 123456, the CA can specify
> that
> > the corresponding account-uri is https://ca.example.net/accounts/123456.
> > There's no requirement that account-uris are fetchable.
>
> I get that, but a URI is longer and more complicated.  Quirin's research
> shows that a significant fraction of CAA users CANNOT SPELL THEIR CA'S
> NAME.  I shudder to think how they will manage to mangle a URI ...
>

I also agree with Jacob's suggestion here, and prefer a single, canonical
representation.

--001a1144452e2645c10560a36229
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Mon, Dec 18, 2017 at 3:10 PM, Tim Hollebeek <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:tim.hollebeek@digicert.com" target=3D"_blank">tim.hollebeek=
@digicert.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span=
 class=3D""><br>
<br>
&gt; &gt; readable text labels, like Validation=3DPhone?<br>
&gt;<br>
&gt; My issue with validation=3Dphone is that it is not precise enough; the=
re&#39;s<br>
one<br>
&gt; version of validation by phone defined in the BRs today, but what if t=
hat<br>
&gt; changes significantly? One could solve this by defining a versioned<br=
>
validation<br>
&gt; method, e.g. validation=3Dphone-01, with an IANA registry to register =
new<br>
ones<br>
&gt; as requirements change.<br>
<br>
</span>The lack of precision bothered me a bit too when I was proposing it,=
<br>
especially since some people have discussed breaking up some of the<br>
larger catch-all ones.=C2=A0 I like the version number, but I think we have=
 to be<br>
<br>
a bit careful.=C2=A0 Is the version just a minimum version?=C2=A0 If I have=
 CAA set to<br>
<br>
validation=3Dphone-01, do I have to update my CAA record every time the<br>
BR validation methods are changed?=C2=A0 How big of a change requires revvi=
ng<br>
the version number of the validation method?<br></blockquote><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p=
adding-left:1ex"><br>
Should the BR version number be used instead?=C2=A0 E.g. validation=3Dphone=
-1.5.4?<br>
This might make more sense as the BR version number does get bumped on<br>
every validation rev (and non-validation rev ...).<br>
<span class=3D""><br>
&gt; However, there does seem to be some interest in embedding information<=
br>
&gt; about validation methods in certificates. It would be nice if there wa=
s a<br>
&gt; correspondence between the namespace used in CAA and the one used in<b=
r>
&gt; certificates.<br>
<br>
</span>That would be nice.=C2=A0 Maybe an IANA registry for validation meth=
ods might<br>
make sense, but I&#39;m unfamiliar with how easy/difficult that is to set u=
p/<br>
modify.<br></blockquote><div><br></div><div>It&#39;d be great if there was =
a spec writeup for discussion - or is this a pre-spec seeds of thoughts?</d=
iv><div><br></div><div>I think Jacob&#39;s suggestion of OIDs is not at all=
 unreasonable, and avoids the ambiguities you raise and allows them to be a=
ddressed by policy in the Forum.</div><div>=C2=A0</div><blockquote class=3D=
"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding=
-left:1ex"><span class=3D"">
&gt; It&#39;s easy to define a URI mapping for an existing account identifi=
er.<br>
&gt; For instance, if customers have a numeric id 123456, the CA can specif=
y<br>
that<br>
&gt; the corresponding account-uri is <a href=3D"https://ca.example.net/acc=
ounts/123456" rel=3D"noreferrer" target=3D"_blank">https://ca.example.net/<=
wbr>accounts/123456</a>.<br>
&gt; There&#39;s no requirement that account-uris are fetchable.<br>
<br>
</span>I get that, but a URI is longer and more complicated.=C2=A0 Quirin&#=
39;s research<br>
shows that a significant fraction of CAA users CANNOT SPELL THEIR CA&#39;S<=
br>
NAME.=C2=A0 I shudder to think how they will manage to mangle a URI ...<br>=
</blockquote><div><br></div><div>I also agree with Jacob&#39;s suggestion h=
ere, and prefer a single, canonical representation.=C2=A0</div></div></div>=
</div>

--001a1144452e2645c10560a36229--


From nobody Mon Dec 18 12:45:52 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D9D0126CD8 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:45:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.101
X-Spam-Level: 
X-Spam-Status: No, score=-0.101 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j0-_Y7LLGvjq for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 12:45:48 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 585BF1200FC for <spasm@ietf.org>; Mon, 18 Dec 2017 12:45:48 -0800 (PST)
Received: from [216.82.251.38] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-13.bemta-12.messagelabs.com id 7B/43-24474-BF8283A5; Mon, 18 Dec 2017 20:45:47 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupml+JIrShJLcpLzFFi42K5obCFX/e3hkW UwdYtrBYzr/xks5h0fy6jxbxryQ7MHu8+PWf1WLLkJ5NH8+7dLAHMUayZeUn5FQmsGYc+/WMt +N7CWDH1/AKWBsa9VV2MnBwsAu+ZJH5sqOti5OIQEpjCJPHg6QwmkISQwBFGif9zWUBsNgEDi Wt7j4PFRQTUJB5OP8MKYjMLeEv8v9cEViMsICvx8M5uZogaOYkFB7+yQthuEj0/djBCLFOV+L f1KDuIzSsQIzFv4TkmiMVLmCQ29h0HS3AKBEpM3vMAzGYUEJP4fmoNE8QycYlbT+aD2RICIhI PL55mg7BFJV4+/scKYStJ3F77gxHClpW4NL+bEWSBhMAhdok5u+9AJfQktk58C2X7Smxbe5oF omgZo8SN76+BEhxAjpbExF+BEEfESMz9fAhqWbbEnofnoWwriY6Jx1kheg8zS3T8aGeBSMhIP D7SDTV0GpvEhvOfWSBhmiIxZRXEJGEBKYm7VzoZJzBqzkLy3SygHmaB+YwSvd37WWeBw0lQ4u TMJywQRVESC2ZuYIewtSSmrn0FFdeWWLbwNfMsoMOZBTQljl1WQhUGsa0lZvw6yAZhK0pM6X4 INcZU4vXRj4wLGLlXMaoXpxaVpRbpmuolFWWmZ5TkJmbm6BoaGunlphYXJ6an5iQmFesl5+du YgQmw3oGBsYdjMv++RxilORgUhLlnaVsESXEl5SfUpmRWJwRX1Sak1p8iFGGg0NJgnedOlBOs Cg1PbUiLTMHmJZh0hIcPEoivM/VgNK8xQWJucWZ6RCpU4z2HHP23vrDxLHh5l0guQ9MPpv5uo FZiCUvPy9VSpy3BWSqAEhbRmke3FBYHrnEKCslzMvIwMAgxFOQWpSbWYIq/4pRnINRSZh3Ocg Unsy8Erjdr4DOYgI6a2qEOchZJYkIKakGxsiQgC9Cqw2FzJOSHrcaTf62K5cjnPWlyD3OtSYC scExwsU8kXzRnseTXzvmbwq5rqjjWqygmWjlNCHnjLH+4fxmZYb75ae8z0oYCrvocrIcO3kpR erf8vl6VvmyT54XHAtK8zp+TY1x1+8Vc0ozyi6HFfzZyd/wb0PK7udc7ht/x9R5LYxQYinOSD TUYi4qTgQA1qq1hR4EAAA=
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-6.tower-163.messagelabs.com!1513629946!169685907!1
X-Originating-IP: [216.32.180.15]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 122225 invoked from network); 18 Dec 2017 20:45:46 -0000
Received: from mail-sn1nam02lp0015.outbound.protection.outlook.com (HELO NAM02-SN1-obe.outbound.protection.outlook.com) (216.32.180.15) by server-6.tower-163.messagelabs.com with AES256-SHA256 encrypted SMTP; 18 Dec 2017 20:45:46 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=rh1GqczHFsgic5cbwFtQwl4MpT7b5ZFLs3C+YXyOHlU=; b=JkiQq4Rwy5Cl1Yxb/LJjDsXFbmcXKneJrM0Z2zcNv93/AyZLfL6ay3aroDKFYFmxl+QtkKzH1Sm8V7KMdjrB4Y6h4hHlwP17VEkaDgrpaKQ2dujJ1rex+p2ru2QNdsOE71nLD2QgplpGT+C/wG3kAm2A8wd+rTl1CenVBYINce8=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1290.namprd14.prod.outlook.com (10.173.132.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Mon, 18 Dec 2017 20:45:45 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Mon, 18 Dec 2017 20:45:45 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
CC: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwADzsgAAAD5epAAAYUKgAAAB/wg
Date: Mon, 18 Dec 2017 20:45:45 +0000
Message-ID: <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
In-Reply-To: <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1290; 6:9Nta9C/iaa+2E/lbOlKhu52wGm9vWt+LWyhrEkMDeLnK4/TwPRnlgNSVoIUR/f0IdGt6VPie9ziXhYD67Q/OOiSMbZWA6efm0Oqo9myDD/H4LjFizHg6dYxDjnIgE0/+teorsaKDMwKby30tcVwVxDvmCm6IW5PGH7f+hKivPD0MTC6Hzeb+e/D4mWtrSzCVj5t+q3MpehZG6VnuKQc2Ah2xHxa4edMnTxcWydOr+rKF85B2VEVdXgy4zMEJ761qckP2faBKnTP4hBs61u+PXsMEeOq+LzbI3+DEEPZlOuozEwdiK1koiEmJl/s1p7XeUsLFZyWZ2IYzT/gZULHeWM4gXdZFJPGiyUjqbek+g4k=; 5:Vdwnr1yTzcvI5WwAJFj2sGNIpuYMk0uFandMm/WVqen+acpRxaPAQGlaO/f208xpBzTX2kW78H7rzwiwFkuGZVPJI0hHEpUEuE3l6GRjNqTztHtpax3W1TZTQcohaF+iyW+QRdjBg/JlOAYdiKWdWoDVU4Fc+cfvUtH9g+JN0EM=; 24:dogrzIaltGwA55ps6IVCZ/AZZkCbKa2oYTCrr/fMs4Fv67UiRzs1AWkhNnOXxFUP8AGDMxc1aZG0giGsKN5WPFpOtX+5VcFql/P/vMt+PbQ=; 7:CXiiy6Ug2PPxo/PteHgbEvuvsZAMxw9lmC4MSx4iwsl29cst/MRMGSxN3v6J7qGShZ7HutE3p5MDWWdp58lZ8/1wGuwWEpNs+p5kWOeDpnHP+hbdmo4TLky8AD0N+XjYBO9IT/I3E8oqTOf5FoUvdcyCAYszrYEk7XFh73Sfb/RFJimfw2N7aiD9ahK8+5lKkcUTrbIq9ahO3J5PjSZYq45fkjZ5OmJEwjVhob+60JxizNj28DMq26fIAGsxyRwL
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 8ef6eb37-dc38-426e-42bf-08d546584fd0
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1290; 
x-ms-traffictypediagnostic: DM5PR14MB1290:
x-microsoft-antispam-prvs: <DM5PR14MB1290A88CB3DAC22E4971A8BD830E0@DM5PR14MB1290.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(3002001)(3231023)(10201501046)(93006095)(93001095)(6041248)(20161123558100)(2016111802025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123560025)(20161123555025)(20161123562025)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1290; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1290; 
x-forefront-prvs: 0525BB0ADF
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(396003)(346002)(39860400002)(376002)(366004)(45074003)(199004)(189003)(24454002)(55016002)(14454004)(59450400001)(6306002)(68736007)(3660700001)(93886005)(105586002)(106356001)(6506007)(6436002)(236005)(478600001)(14971765001)(99286004)(966005)(54896002)(54906003)(606006)(53546011)(229853002)(7696005)(9686003)(76176011)(77096006)(316002)(8676002)(3280700002)(97736004)(6916009)(6246003)(25786009)(2950100002)(8936002)(53936002)(5660300001)(4326008)(3846002)(790700001)(6116002)(102836003)(7736002)(2906002)(66066001)(74316002)(99936001)(86362001)(2900100001)(33656002)(81156014)(81166006)(19400905002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1290; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_0598_01D37806.7CC29460"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8ef6eb37-dc38-426e-42bf-08d546584fd0
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Dec 2017 20:45:45.1814 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1290
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/dtuLx90qMf9CzmB_6R5G9_IxWf8>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 20:45:51 -0000

------=_NextPart_000_0598_01D37806.7CC29460
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0599_01D37806.7CC29460"


------=_NextPart_001_0599_01D37806.7CC29460
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Pre-spec for discussion.  It=E2=80=99s current status is =E2=80=9CI sat =
down for an hour, reviewed meeting minutes and read some stuff, and =
circulated some notes=E2=80=9D.

=20

-Tim

=20

From: Ryan Sleevi [mailto:ryan-ietf@sleevi.com]=20
Sent: Monday, December 18, 2017 1:42 PM
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: Jacob Hoffman-Andrews <jsha@eff.org>; spasm@ietf.org
Subject: Re: [lamps] CAA tags

=20

=20

=20

On Mon, Dec 18, 2017 at 3:10 PM, Tim Hollebeek =
<tim.hollebeek@digicert.com <mailto:tim.hollebeek@digicert.com> > wrote:



> > readable text labels, like Validation=3DPhone?
>
> My issue with validation=3Dphone is that it is not precise enough; =
there's
one
> version of validation by phone defined in the BRs today, but what if =
that
> changes significantly? One could solve this by defining a versioned
validation
> method, e.g. validation=3Dphone-01, with an IANA registry to register =
new
ones
> as requirements change.

The lack of precision bothered me a bit too when I was proposing it,
especially since some people have discussed breaking up some of the
larger catch-all ones.  I like the version number, but I think we have =
to be

a bit careful.  Is the version just a minimum version?  If I have CAA =
set to

validation=3Dphone-01, do I have to update my CAA record every time the
BR validation methods are changed?  How big of a change requires revving
the version number of the validation method?


Should the BR version number be used instead?  E.g. =
validation=3Dphone-1.5.4?
This might make more sense as the BR version number does get bumped on
every validation rev (and non-validation rev ...).

> However, there does seem to be some interest in embedding information
> about validation methods in certificates. It would be nice if there =
was a
> correspondence between the namespace used in CAA and the one used in
> certificates.

That would be nice.  Maybe an IANA registry for validation methods might
make sense, but I'm unfamiliar with how easy/difficult that is to set =
up/
modify.

=20

It'd be great if there was a spec writeup for discussion - or is this a =
pre-spec seeds of thoughts?

=20

I think Jacob's suggestion of OIDs is not at all unreasonable, and =
avoids the ambiguities you raise and allows them to be addressed by =
policy in the Forum.

=20

> It's easy to define a URI mapping for an existing account identifier.
> For instance, if customers have a numeric id 123456, the CA can =
specify
that
> the corresponding account-uri is =
https://ca.example.net/accounts/123456.
> There's no requirement that account-uris are fetchable.

I get that, but a URI is longer and more complicated.  Quirin's research
shows that a significant fraction of CAA users CANNOT SPELL THEIR CA'S
NAME.  I shudder to think how they will manage to mangle a URI ...

=20

I also agree with Jacob's suggestion here, and prefer a single, =
canonical representation.=20


------=_NextPart_001_0599_01D37806.7CC29460
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal>Pre-spec =
for discussion.=C2=A0 It=E2=80=99s current status is =E2=80=9CI sat down =
for an hour, reviewed meeting minutes and read some stuff, and =
circulated some notes=E2=80=9D.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>-Tim<o:p></o:p></p><p class=3DMsoNormal><a =
name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a></p><span =
style=3D'mso-bookmark:_MailEndCompose'></span><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #E1E1E1 =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b>From:</b> Ryan =
Sleevi [mailto:ryan-ietf@sleevi.com] <br><b>Sent:</b> Monday, December =
18, 2017 1:42 PM<br><b>To:</b> Tim Hollebeek =
&lt;tim.hollebeek@digicert.com&gt;<br><b>Cc:</b> Jacob Hoffman-Andrews =
&lt;jsha@eff.org&gt;; spasm@ietf.org<br><b>Subject:</b> Re: [lamps] CAA =
tags<o:p></o:p></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>On Mon, =
Dec 18, 2017 at 3:10 PM, Tim Hollebeek &lt;<a =
href=3D"mailto:tim.hollebeek@digicert.com" =
target=3D"_blank">tim.hollebeek@digicert.com</a>&gt; =
wrote:<o:p></o:p></p><blockquote style=3D'border:none;border-left:solid =
#CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><p =
class=3DMsoNormal><br><br>&gt; &gt; readable text labels, like =
Validation=3DPhone?<br>&gt;<br>&gt; My issue with validation=3Dphone is =
that it is not precise enough; there's<br>one<br>&gt; version of =
validation by phone defined in the BRs today, but what if that<br>&gt; =
changes significantly? One could solve this by defining a =
versioned<br>validation<br>&gt; method, e.g. validation=3Dphone-01, with =
an IANA registry to register new<br>ones<br>&gt; as requirements =
change.<br><br>The lack of precision bothered me a bit too when I was =
proposing it,<br>especially since some people have discussed breaking up =
some of the<br>larger catch-all ones.&nbsp; I like the version number, =
but I think we have to be<br><br>a bit careful.&nbsp; Is the version =
just a minimum version?&nbsp; If I have CAA set =
to<br><br>validation=3Dphone-01, do I have to update my CAA record every =
time the<br>BR validation methods are changed?&nbsp; How big of a change =
requires revving<br>the version number of the validation =
method?<o:p></o:p></p></blockquote><blockquote =
style=3D'border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><p =
class=3DMsoNormal><br>Should the BR version number be used =
instead?&nbsp; E.g. validation=3Dphone-1.5.4?<br>This might make more =
sense as the BR version number does get bumped on<br>every validation =
rev (and non-validation rev ...).<br><br>&gt; However, there does seem =
to be some interest in embedding information<br>&gt; about validation =
methods in certificates. It would be nice if there was a<br>&gt; =
correspondence between the namespace used in CAA and the one used =
in<br>&gt; certificates.<br><br>That would be nice.&nbsp; Maybe an IANA =
registry for validation methods might<br>make sense, but I'm unfamiliar =
with how easy/difficult that is to set =
up/<br>modify.<o:p></o:p></p></blockquote><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>It'd be great if there was a spec writeup for =
discussion - or is this a pre-spec seeds of =
thoughts?<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=3DMsoNormal>I =
think Jacob's suggestion of OIDs is not at all unreasonable, and avoids =
the ambiguities you raise and allows them to be addressed by policy in =
the Forum.<o:p></o:p></p></div><div><p =
class=3DMsoNormal>&nbsp;<o:p></o:p></p></div><blockquote =
style=3D'border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><p class=3DMsoNormal>&gt; It's =
easy to define a URI mapping for an existing account identifier.<br>&gt; =
For instance, if customers have a numeric id 123456, the CA can =
specify<br>that<br>&gt; the corresponding account-uri is <a =
href=3D"https://ca.example.net/accounts/123456" =
target=3D"_blank">https://ca.example.net/accounts/123456</a>.<br>&gt; =
There's no requirement that account-uris are fetchable.<br><br>I get =
that, but a URI is longer and more complicated.&nbsp; Quirin's =
research<br>shows that a significant fraction of CAA users CANNOT SPELL =
THEIR CA'S<br>NAME.&nbsp; I shudder to think how they will manage to =
mangle a URI ...<o:p></o:p></p></blockquote><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=3DMsoNormal>I =
also agree with Jacob's suggestion here, and prefer a single, canonical =
representation.&nbsp;<o:p></o:p></p></div></div></div></div></div></div><=
/body></html>
------=_NextPart_001_0599_01D37806.7CC29460--

------=_NextPart_000_0598_01D37806.7CC29460
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE4MjA0NTM4WjAvBgkqhkiG9w0BCQQxIgQghEFMAto+qAgK5Vtq+/hp6bm06ozV
B+62N02ahj/GRbUwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAHGZbeoEIVX+FGmoiI3aoacQ7ibz//HIH0LPVvVbnpwQ75iXo7hP8W32FISTVOKf6XLFqki6
8NqUNKh48Wje/kQNH+gUknTKul0armm6JwAVxUqgS6MmnRD75OTfWzSYdDKaF1BBQbZoqafn1MIH
jYL0fZLIBlJuGi3mGqU9co5qaDyHaLT5yCQiy7XyNU1OM24t/Snm0UURT/7i4n9ruePtdjXH5pRc
kmwPRTPo+S2hzNdPKYvF7Nb+BlI87trVRzpvtsv0sJX9geOCPAzXkXHOgBQLs4Adm9bTcIdKsZpM
fptzdBpLJRGeL0w2kWkI3qkaPnmVx7y5qInsUnWHfJoAAAAAAAA=

------=_NextPart_000_0598_01D37806.7CC29460--


From nobody Mon Dec 18 14:02:13 2017
Return-Path: <rob.stradling@comodo.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 100A512AF83 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 14:02:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1BTxnsft_uAy for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 14:02:08 -0800 (PST)
Received: from mmextmx2.mcr.colo.comodoca.net (mmextmx2.mcr.colo.comodoca.net [IPv6:2a02:1788:402:c00::c0a8:9cd6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6ADAF124B0A for <spasm@ietf.org>; Mon, 18 Dec 2017 14:02:08 -0800 (PST)
Received: (qmail 18039 invoked by uid 1004); 18 Dec 2017 22:02:06 -0000
Received: from rmdccgwarp1.reyn.mcr.dc.comodo.net (HELO maileu.comodo.net) (10.1.72.82) by mmextmx2.mcr.colo.comodoca.net (qpsmtpd/0.84) with ESMTP; Mon, 18 Dec 2017 22:02:06 +0000
Received: from [192.168.0.72] ([178.255.87.226]) by maileu.comodo.net (IceWarp 11.4.6.0 DEB8 x64) with ASMTP (SSL) id 201712182202069492 for <spasm@ietf.org>; Mon, 18 Dec 2017 22:02:06 +0000
To: spasm@ietf.org
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
From: Rob Stradling <rob.stradling@comodo.com>
Message-ID: <7531d7e2-2bdd-559a-2e40-286a3fe4a4f2@comodo.com>
Date: Mon, 18 Dec 2017 22:02:05 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/6MvCO0UyEN2VlH7CtmFIfnTGE30>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 22:02:11 -0000

On 18/12/17 20:42, Ryan Sleevi wrote:
<snip>
> I think Jacob's suggestion of OIDs is not at all unreasonable, and 
> avoids the ambiguities you raise and allows them to be addressed by 
> policy in the Forum.

We had policy OIDs in early versions of the I-D [1] that later became 
RFC6844, but we had to strip this out in favour of domain names when the 
document was adopted by PKIX.  WG consensus and all that.

I'm not sure what that decision might mean for any other proposals to 
use OIDs with CAA.


[1] https://www.ietf.org/archive/id/draft-hallambaker-donotissue-04.txt

-- 
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online


From nobody Mon Dec 18 22:24:01 2017
Return-Path: <hallam@gmail.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A00EA1205F0 for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 22:24:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.398
X-Spam-Level: 
X-Spam-Status: No, score=-1.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0pVE8qoMNwQE for <spasm@ietfa.amsl.com>; Mon, 18 Dec 2017 22:23:59 -0800 (PST)
Received: from mail-ot0-x229.google.com (mail-ot0-x229.google.com [IPv6:2607:f8b0:4003:c0f::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D77341241FC for <spasm@ietf.org>; Mon, 18 Dec 2017 22:23:58 -0800 (PST)
Received: by mail-ot0-x229.google.com with SMTP id p31so9133239ota.4 for <spasm@ietf.org>; Mon, 18 Dec 2017 22:23:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=Z1C4UuHiEftLyJG3SvumKmgIB+Oq5XPP0IXRvx1tdRM=; b=JIDAYlL9mdBKUSVZT/gCOWvsi35SrVxGwJVGfRqAwdRcFxH2evcpPEWtLXHZPcrEh4 6y/mkVbJB6PAcrqjGA0R2/iDNuSjQnP9DjKCZdeWLW4CIh1e0GyhXQaCYr3SEw0gFzCu jwIZwbPz/byLJ/svUFsi3n6p0BCaVDCWTnktmGmywrQ/mhN/m5SjzbJMf52rEfYAMGi7 539ov52PnDPDEKH0kDq6c5qFrEAWujZ0plAmSsRWTj8c/qGX52U3ni54gi/2QlsqAaIR v1nHz72ZbuVVAroB2AaAY9qIvmGWvd3e+JlTU88ayo8/vHao19M5zwElScNpiL3DCr8l tFUg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=Z1C4UuHiEftLyJG3SvumKmgIB+Oq5XPP0IXRvx1tdRM=; b=ZbGmxPUV9qOFxHywKgHDpLsxYTN7FncTAibQDsMm94sagj1DNjQmvlK42QSgsei6oA hbn9olxy6IzpGwe7acP4skSFeGPBl9yRrZMZxZMsTkZsZ2YdgKHkVCqj2DydYslAu0bT U0YtBlhkQxttz9p8JRIVKf6LZ2uQV0b8b5SNBeXQdfJIZWBlod1h+SfiG7NSBpVLvBk3 gtqPUKpcgeEx6D9V4cWQ+kDp/McUbxMdTaeG1YabSuE23iksNcQHjiRBFM4+ySObc3GT 0Qhutclmfj1VAKHM10CRmvji71+qzK484HhDh9IhpFjXG8GZSQbsQoR39AOULo/Vnpyk VoJA==
X-Gm-Message-State: AKGB3mJf5jApeXeFw0GxijqOtom531PwlZWUD0KSe5jZf4K90eQypgKT 5wgupgOfu+J7BrYqc3BRw7y1ak2KkQZB+0t41Io=
X-Google-Smtp-Source: ACJfBotcyXnXOx1h+09ezvVzDfQgqMf2bdRt+MgTwDPGYNbiFS1V2/9xAbEAOo/QSJh6Qnr72xMd2Tehtn6HA0wj67k=
X-Received: by 10.157.26.36 with SMTP id a33mr1768387ote.149.1513664638139; Mon, 18 Dec 2017 22:23:58 -0800 (PST)
MIME-Version: 1.0
Sender: hallam@gmail.com
Received: by 10.157.49.87 with HTTP; Mon, 18 Dec 2017 22:23:57 -0800 (PST)
In-Reply-To: <7531d7e2-2bdd-559a-2e40-286a3fe4a4f2@comodo.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com> <7531d7e2-2bdd-559a-2e40-286a3fe4a4f2@comodo.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Tue, 19 Dec 2017 01:23:57 -0500
X-Google-Sender-Auth: COOl-ehJyAkVagckQbvL5yjZrwE
Message-ID: <CAMm+Lwg1+qt0sJfTY_ih+VjY9L7oMzX=ZRd0mxU7NR2Fxv8kQA@mail.gmail.com>
To: Rob Stradling <rob.stradling@comodo.com>
Cc: SPASM <spasm@ietf.org>
Content-Type: multipart/alternative; boundary="001a1141fb7c10c11c0560ab8305"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/K3DZxN9TKhOyoPbU3zQKiYQghp0>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 06:24:00 -0000

--001a1141fb7c10c11c0560ab8305
Content-Type: text/plain; charset="UTF-8"

We did indeed start with OIDs. But the reason I agreed to Domain Names was
that the suggestion (I seem to remember it was Paul Hoffman) was obviously
the right one.

Most of the things people want to do with tags can be done with domain
names. More importantly, it can be done outside the IETF. If you want 'any
EV' issuer, get the CABForum to approve ev.cabforum.com for the purpose.

Restricting to specific validation methods is interesting and might be a
justified use for the criticality flag.

The other point to ponder is how a server that needs a cert discovers where
the cert issuing service is. The idea was that if the CAA record specifies
chosenca.com, a server would then be able to use that information to work
out how to get a cert and automate the whole process.


Remember that at the time, there was this idea that DNS records should not
make use of prefixes and should not make use of additional parsing beyond
DNS record markers. At this point, I think we can safely ignore both
notions as broken and if I was to do it again would suggest it just be a
TXT type record. But we can't that's water under the bridge now, sorry.





On Mon, Dec 18, 2017 at 5:02 PM, Rob Stradling <rob.stradling@comodo.com>
wrote:

> On 18/12/17 20:42, Ryan Sleevi wrote:
> <snip>
>
>> I think Jacob's suggestion of OIDs is not at all unreasonable, and avoids
>> the ambiguities you raise and allows them to be addressed by policy in the
>> Forum.
>>
>
> We had policy OIDs in early versions of the I-D [1] that later became
> RFC6844, but we had to strip this out in favour of domain names when the
> document was adopted by PKIX.  WG consensus and all that.
>
> I'm not sure what that decision might mean for any other proposals to use
> OIDs with CAA.
>
>
> [1] https://www.ietf.org/archive/id/draft-hallambaker-donotissue-04.txt
>
> --
> Rob Stradling
> Senior Research & Development Scientist
> COMODO - Creating Trust Online
>
>
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org
> https://www.ietf.org/mailman/listinfo/spasm
>

--001a1141fb7c10c11c0560ab8305
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">We =
did indeed start with OIDs. But the reason I agreed to Domain Names was tha=
t the suggestion (I seem to remember it was Paul Hoffman) was obviously the=
 right one.=C2=A0</div><div class=3D"gmail_default" style=3D"font-size:smal=
l"><br></div><div class=3D"gmail_default" style=3D"font-size:small">Most of=
 the things people want to do with tags can be done with domain names. More=
 importantly, it can be done outside the IETF. If you want &#39;any EV&#39;=
 issuer, get the CABForum to approve <a href=3D"http://ev.cabforum.com">ev.=
cabforum.com</a> for the purpose.</div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small">Restricting to specific validation methods is interesting and mi=
ght be a justified use for the criticality flag.=C2=A0</div><div class=3D"g=
mail_default" style=3D"font-size:small"><br></div><div class=3D"gmail_defau=
lt" style=3D"font-size:small">The other point to ponder is how a server tha=
t needs a cert discovers where the cert issuing service is. The idea was th=
at if the CAA record specifies <a href=3D"http://chosenca.com">chosenca.com=
</a>, a server would then be able to use that information to work out how t=
o get a cert and automate the whole process.</div><div class=3D"gmail_defau=
lt" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small">Remember that at the time, there was this idea that DNS records =
should not make use of prefixes and should not make use of additional parsi=
ng beyond DNS record markers. At this point, I think we can safely ignore b=
oth notions as broken and if I was to do it again would suggest it just be =
a TXT type record. But we can&#39;t that&#39;s water under the bridge now, =
sorry.</div><div class=3D"gmail_default" style=3D"font-size:small"><br></di=
v><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div cla=
ss=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"gmai=
l_default" style=3D"font-size:small"><br></div></div><div class=3D"gmail_ex=
tra"><br><div class=3D"gmail_quote">On Mon, Dec 18, 2017 at 5:02 PM, Rob St=
radling <span dir=3D"ltr">&lt;<a href=3D"mailto:rob.stradling@comodo.com" t=
arget=3D"_blank">rob.stradling@comodo.com</a>&gt;</span> wrote:<br><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc s=
olid;padding-left:1ex">On 18/12/17 20:42, Ryan Sleevi wrote:<br>
&lt;snip&gt;<span class=3D""><br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
I think Jacob&#39;s suggestion of OIDs is not at all unreasonable, and avoi=
ds the ambiguities you raise and allows them to be addressed by policy in t=
he Forum.<br>
</blockquote>
<br></span>
We had policy OIDs in early versions of the I-D [1] that later became RFC68=
44, but we had to strip this out in favour of domain names when the documen=
t was adopted by PKIX.=C2=A0 WG consensus and all that.<br>
<br>
I&#39;m not sure what that decision might mean for any other proposals to u=
se OIDs with CAA.<br>
<br>
<br>
[1] <a href=3D"https://www.ietf.org/archive/id/draft-hallambaker-donotissue=
-04.txt" rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/archive/=
i<wbr>d/draft-hallambaker-donotissue<wbr>-04.txt</a><span class=3D"HOEnZb">=
<font color=3D"#888888"><br>
<br>
-- <br>
Rob Stradling<br>
Senior Research &amp; Development Scientist<br>
COMODO - Creating Trust Online</font></span><div class=3D"HOEnZb"><div clas=
s=3D"h5"><br>
<br>
______________________________<wbr>_________________<br>
Spasm mailing list<br>
<a href=3D"mailto:Spasm@ietf.org" target=3D"_blank">Spasm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/spasm" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/spasm</a><br>
</div></div></blockquote></div><br></div>

--001a1141fb7c10c11c0560ab8305--


From nobody Tue Dec 19 04:13:37 2017
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D4B012426E for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 04:13:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.311
X-Spam-Level: 
X-Spam-Status: No, score=-4.311 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RDbsYat1XVWI for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 04:13:34 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91A8F12422F for <spasm@ietf.org>; Tue, 19 Dec 2017 04:13:34 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 55757BE2F; Tue, 19 Dec 2017 12:13:32 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IOfabxGveZ28; Tue, 19 Dec 2017 12:13:32 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 07DB8BE77; Tue, 19 Dec 2017 12:13:23 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1513685604; bh=U7xiuzckn47l5uGLk0O+PiF8/VzQ+AdwsMT9pyKhD8k=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From; b=GObFit53gEpxo6P+ffm+wsBvBDWcHouTGfnUuczmj/GWHQ4YaMt58nlPNI93iE4NK Z0L3ryk7sMVDCKWMDtlpB/9OOXYdtucYuyXV4D/7UxRl4LaRMWYcesokv+9nmXSFtx uSVoE1iOhZvmgz/W6U+eRimJMgDH5cMx9gHYWf+w=
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: "spasm@ietf.org" <spasm@ietf.org>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com> <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie>
Date: Tue, 19 Dec 2017 12:13:22 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="BtEoc1ebOBDuBTbGnJIEnUmDffT646xdS"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/koK9Cgr40MkgCrkaZ6gu57PQZzQ>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 12:13:36 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--BtEoc1ebOBDuBTbGnJIEnUmDffT646xdS
Content-Type: multipart/mixed; boundary="jHi0cebXX8EARRFbLsGOP2SooTon2krCO";
 protected-headers="v1"
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: "spasm@ietf.org" <spasm@ietf.org>
Message-ID: <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie>
Subject: Re: [lamps] CAA tags
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
 <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org>
 <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
 <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
 <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
In-Reply-To: <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>

--jHi0cebXX8EARRFbLsGOP2SooTon2krCO
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: quoted-printable


Hiya,

I've not been following this closely but since you
said:

On 18/12/17 20:45, Tim Hollebeek wrote:
> Pre-spec for discussion.  It=E2=80=99s current status is =E2=80=9CI sat=
 down for an
> hour, reviewed meeting minutes and read some stuff, and circulated
> some notes=E2=80=9D.
I guess it may be ok to throw in a requirement to
keep an aspect of the status quo:

I'd like to ensure it remains possible for a whole
bunch of DNS domains to use the same CAA RR value
and for that to continue to make sense. I've no
problem if optional things can be added that are
domain-specific so long as I don't have to create
custom CAA values for every domain.

My reason for wanting that is that I deal with
sets of domains who can all currently sensibly use
the same CAA value and that's easy to handle. If
I had to go changing the value for each, esp if
that had to be re-done regularly, or even worse,
sporadically, that'd be a PITA.

Apologies for the interruption if this is already
taken as a given, but I wasn't sure based on the
recent mails about phone numbers etc.

Thanks,
S.


--jHi0cebXX8EARRFbLsGOP2SooTon2krCO--

--BtEoc1ebOBDuBTbGnJIEnUmDffT646xdS
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEcBAEBCAAGBQJaOQJiAAoJEC88hzaAX42imPwH/30H4Lu3xxKDQFar8M9EjtJZ
wsJJpXn2ezU8uLrfm2NOwEmiOCYaA2Me0XILua1Vf9f9aPvDLTj8wS/Y4fRGELhk
JGqXX5Dw4Vw26Wn63NOjYHdFxOOMySqzgVv6hFd7Un0KytLij+jS6XCrWFvWAEOm
+Au6jj6j+ABijeq0R+smIuGIWCHzYHhPVaP+0TAIXqKzx2ujbhzzTD/Yg92jPRu7
Fa20Zb9g8cxmYewqW7Caz+S6DRKJtCy2jfiil7NdB801iH8uQg72ymL6IvqzGRTY
NGwQMlLszBpYCvydQuauYPDaWjRF3ZSr2eimMdCkz7KLIbJIOR1TeZASt8ttIXA=
=hz5b
-----END PGP SIGNATURE-----

--BtEoc1ebOBDuBTbGnJIEnUmDffT646xdS--


From nobody Tue Dec 19 06:26:01 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D7891270A7 for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:25:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.246
X-Spam-Level: 
X-Spam-Status: No, score=0.246 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_BL=0.01, RCVD_IN_MSPIKE_L3=0.918, TRACKER_ID=1.306, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZjCgNLqoHiHH for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:25:57 -0800 (PST)
Received: from homiemail-a87.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13D27126CD8 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:25:57 -0800 (PST)
Received: from homiemail-a87.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a87.g.dreamhost.com (Postfix) with ESMTP id 74576C009F58 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:25:56 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=KAKHOZgoDndl9r8zM3QFmaWbC9M=; b= kH2Rhvze5/U7Xc+qxRpV1y7JkTXZMxWh5wBQJ1xKT+qRFTrNA7an+eauo43gv4w+ /LbqRcSEy6qniaMH6T6kUMJxiRpyjgtzvSajcew2JG3pY7UW4uoFoi2GZt0Tj5dt eZad5/5f37ppjO25yEfsZg8Ik/b5Zm5KYpq/yLDwuYA=
Received: from mail-io0-f172.google.com (mail-io0-f172.google.com [209.85.223.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a87.g.dreamhost.com (Postfix) with ESMTPSA id 4B225C009F53 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:25:56 -0800 (PST)
Received: by mail-io0-f172.google.com with SMTP id x129so13775584iod.13 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:25:56 -0800 (PST)
X-Gm-Message-State: AKGB3mK80kUMO4E8FFA0JnVnIl7ma0nwLzJe0jUrlCcZ7/d8ZoGdgwUz HAzmjB9bdulf8PgCCxXralar+WDth21G6E8mX+o=
X-Google-Smtp-Source: ACJfBovdw0Ha1NXQIxCTMuAtsj2CeNvoLz6M7gNV5hbA3JE2ApG0d0O13EK6ZRm7ytAIUT8d0sNvXZ5IhuvSMFlIEb4=
X-Received: by 10.107.46.169 with SMTP id u41mr4115727iou.303.1513693555308; Tue, 19 Dec 2017 06:25:55 -0800 (PST)
MIME-Version: 1.0
Received: by 10.2.78.70 with HTTP; Tue, 19 Dec 2017 06:25:54 -0800 (PST)
In-Reply-To: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Tue, 19 Dec 2017 09:25:54 -0500
X-Gmail-Original-Message-ID: <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
Message-ID: <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Content-Type: multipart/alternative; boundary="001a11c146eea9c1120560b23e05"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/S4AZd2LXAjza6rpwuSgx7ywEY3w>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 14:25:59 -0000

--001a11c146eea9c1120560b23e05
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Tim,

>From a design consideration, if/as you look to write this up, it would be
useful to understand why you pursued the route of issuer-specific
parameters, rather than as new properties.

That is, why is the set of policy not

CAA issue 0 "example.com"
CAA issue 0 "example.net"
CAA validation 128 "type=3DEV method=3D1,2,3,4"

Which limits issuance to example.com and example.net, iff the validation
method of domain control employs methods 1, 2, 3, or 4, and the resultant
process uses the EV process? [*]

This obviously precludes the notion of 'account' - but I think that's
illustrative of the point; something like 'account' is inherently
CA-specific, while the validation methods or types are CA agnostic.

The benefit of this, for a Subscriber, is they might omit the publication
of an issue tag, thus not constraining per-CA, but still scoping the
validation methods.

Understandably, this design could also be accounted for with the CABForum
declaring some pseudo-domain to express such CA-agnostic properties, such
as:

CAA issue 0 "example.com; type=3DDV,EV method=3D1,2,3,4"        # If exampl=
e.com
is issuing, support for both DV and EV, using methods 1-4
CAA issue 0 "validation.cabforum.org; type=3DEV method=3D1,2,3" # Otherwise=
,
support for EV only using methods 1-3

There are both strengths and weaknesses of both proposals, so it'd be great
to see a discussion about the problem statement and desired workflows.

[*] I provide these for simplicity of typing - but I think any restriction
of both 'type' and 'method' needs to be versioned, as the CABF documents do
change

On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek <tim.hollebeek@digicert.com=
>
wrote:

> Here is my tags proposal, in case others want to comment on it on this
> list.
>
>
>
> Note that it has been privately pointed out to me that one possible
> solution to the criticality problem and the scaling problem is to use
> top-level tags that are independent of the issue records:
>
>
>
> Something like:
>
>
>
> CAA 0 issue =E2=80=9Ca.example.com=E2=80=9D
>
> CAA 0 issue =E2=80=9Cb.example.com=E2=80=9D
>
> CAA 128 validation =E2=80=9CPhone=E2=80=9D
>
>
>
> -Tim
>
>
>
> ------------------------------------------------------------
> ------------------------------------------------------------
> -------------------------------
> Introduction and Motivation
>
>
>
> In addition to being able to specify which CA or CAs are allowed to issue
> certificates for a given domain, RFC 6844 allows additional parameters,
> such as the account number, that the CA can consume for a variety of uses=
.
> RFC 6844 defines the format, but otherwise leaves the kinds of properties
> and their meanings up to the issuer.
>
> While this is appropriate for a technical standard, standardizing the
> names and meanings of CAA properties across the CA industry has the
> following benefits:
>
>    1. Reduce user confusion when the same or similar property is used by
>    different CAs with different names and semantics
>    2. Make it simpler to migrate from one CA to another while preserving
>    the CAA configuration
>    3. Simplifying configuration and expression of CAA policies that allow
>    issuance from multiple CAs
>    4. Allow CAA record creation tools to support creating CAA records
>    that contain properties that have been standardized
>
> History
>
>
>
> CAA property tags have been discussed at several CA/B Forum meetings, mos=
t
> recently at the October meeting in Taipei.  Four were suggested: Acceptab=
le
> validation methods, an account identifier, certificate types (DV/OV/EV),
> and ability to specify a brand.
>
>
> Method of Adoption
>
>
>
> Since these CAA properties are just a voluntary industry standard that an=
y
> CA could implement, they don=E2=80=99t necessarily have to exist in a sta=
ndards
> document.  However, it seems like it would be helpful if the names and
> semantics were agreed upon by the industry as a whole, so it is probably
> best to include them in the Baseline Requirements as an optional feature
> CAs MAY implement.
>
> On the other hand, it might be desirable to reserve the names, and requir=
e
> that if these particular property names are used, the semantics MUST be t=
he
> semantics specified in the Baseline Requirements.
>
>
> Brands
>
>
>
> I=E2=80=99m starting with this one because I=E2=80=99m going to argue it =
isn=E2=80=99t necessary.
> CAs can and do have multiple names that they accept in CAA records.  It i=
s
> hard to imagine a brand existing without the associated domain and websit=
e
> also existing.  I=E2=80=99d suggest that CAs that maintain multiple brand=
s simply
> use a different domain name for each brand, e.g.
>
> certs.example.com               CAA 0 issue =E2=80=9Cmegaca.com=E2=80=9D
>
> catlover.example.com         CAA 0 issue =E2=80=9Ccertsforcats.com=E2=80=
=9D    #
> certsforcats is a brand owned by MegaCA.
>
> CAAs can also publicize examples of CAA records that allow for issuance b=
y
> all of their brands.
> Acceptable Validation Methods
>
>
>
> A list of acceptable validation methods can be specified using the
> =E2=80=9Cvalidation=E2=80=9D tag.
>
> There are two challenges here, that have been discussed elsewhere in
> relation to keeping records of which validation method was used for a
> particular certificate.  The first is that validation methods can change
> over time.  This seems to be less of a concern for issuance than it is fo=
r
> historical validations, as a CAA record can and should be interpreted as
> always requiring the version of the method that is enforced by the BRs at
> issuance time.  However, this can cause the exact meaning of a CAA record
> to change over time as the BRs evolve.  I don=E2=80=99t think this is a b=
ig
> problem, but wanted to note it.
>
> The second issue is that it is possible that the numbering of the BR
> validation methods could potentially change over time.  For that reason, =
I
> think it might be reasonable to standardize on a label for each validatio=
n
> method, that can be used in addition to the section number:
>
> *BR Section (BR v. 1.5.4)*
>
> *Short Section*
>
> *Validation method label*
>
> 3.2.2.4.1
>
> 1
>
> DomainContact
>
> 3.2.2.4.2
>
> 2
>
> EmailOrSimilar
>
> 3.2.2.4.3
>
> 3
>
> Phone
>
> 3.2.2.4.4
>
> 4
>
> ConstructedEmail
>
> 3.2.2.4.5
>
> 5
>
> DomainAuthorizationDocument
>
> 3.2.2.4.6
>
> 6
>
> WebsiteChange
>
> 3.2.2.4.7
>
> 7
>
> DNSChange
>
> 3.2.2.4.8
>
> 8
>
> IPAddressLookup
>
> 3.2.2.4.9
>
> 9
>
> TestCertificate
>
> 3.2.2.4.10
>
> 10
>
> RandomValueInCertificate
>
>
>
> Examples:
>
> CAA 0 issue =E2=80=9Cca.example.net; validation=3D3=E2=80=9D             =
         # Call me
> about all certificates
>
> CAA 0 issue =E2=80=9Cca.example.net; validation=3DPhone=E2=80=9D         =
    # Same as
> previous example
>
> CAA 0 issue =E2=80=9Cca.example.net; validation=3D1,2,3,4,7,8,9,10=E2=80=
=9D   # I don=E2=80=99t
> like DADs and website changes
>
> CAA 0 issue =E2=80=9Cca.example.net; validation=3D!5,6=E2=80=9D          =
       # Same as
> previous example.  Worth the trouble?
> Account Identifier
>
>
>
> This one is relatively straightforward, as the identifier is going to be
> CA-specific anyway.  Use the =E2=80=9Caccount=E2=80=9D keyword:
>
> CAA 0 issue =E2=80=9Cca.example.net; account=3D8675309=E2=80=9D
>
> The format and values of the account specifier is up to the individual CA=
.
> Acceptable Certificate Types
>
>
>
> This one also seems to be relatively straightforward.  I=E2=80=99ve chose=
n to make
> the categories disjoint, so if you=E2=80=99re ok with more than one type,=
 you have
> to specify more than one.  Use the =E2=80=9Ctype=E2=80=9D keyword.
>
> CAA 0 issue =E2=80=9Cca.example.net; type=3DEV=E2=80=9D                  =
       # EV only
>
> CAA 0 issue =E2=80=9Cca.example.net; type=3DDV=E2=80=9D                  =
       # DV only
>
> CAA 0 issue =E2=80=9Cca.example.net; type=3DOV,EV=E2=80=9D               =
    # No DV
> Lack of Property Tag Value Criticality
>
>
>
> Supporting the various properties is optional.  Unlike the CAA =E2=80=9Ci=
ssue=E2=80=9D
> property, these properties do not have to be ubiquitously supported to ha=
ve
> value, because Domain holders can restrict their issue records to only
> include CAs that have publicly stated that they support the desired
> property tags.
>
> For example, if CAs A, B, and C support the =E2=80=9Ctype=3DEV=E2=80=9D t=
ag, then the
> following will prevent non-EV issuance:
>
> CAA issue 0 =E2=80=9CA.com; type=3DEV=E2=80=9D
>
> CAA issue 0 =E2=80=9CB.com; type=3DEV=E2=80=9D
>
> CAA issue 0 =E2=80=9CC.com; type=3DEV=E2=80=9D
>
> Unfortunately, this does scale poorly with a large number of CAs.
>
> The problem is that RFC 6844 supports =E2=80=9CCritical=E2=80=9D for prop=
erty tags (like
> =E2=80=9Cissue=E2=80=9D), but there is no way to mark a parameter tag is =
=E2=80=9CCritical=E2=80=9D.  I
> intend to bring this up with the IETF WG.
>
> Any easy solution is to use reserved bit #1 for property tag criticality:
> CAA issue 64 =E2=80=9CA.com; type=3DEV=E2=80=9D            # type=3DEV ta=
g must be respected;
>                                                                     #
> cannot issue if you don=E2=80=99t understand or enforce it.
>
>
> Multiple Tags
>
>
>
> Just for completeness, these individual features can also be used togethe=
r:
>
> CAA issue 0 =E2=80=9Cca.example.com; type=3DEV validation=3DPhone account=
=3D8675309=E2=80=9D
>
>
>
>
>
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org
> https://www.ietf.org/mailman/listinfo/spasm
>
>

--001a11c146eea9c1120560b23e05
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Tim,<div><br></div><div>From a design consideration, if/as=
 you look to write this up, it would be useful to understand why you pursue=
d the route of issuer-specific parameters, rather than as new properties.</=
div><div><br></div><div>That is, why is the set of policy not</div><div><br=
></div><div>CAA issue 0 &quot;<a href=3D"http://example.com">example.com</a=
>&quot;</div><div>CAA issue 0 &quot;<a href=3D"http://example.net">example.=
net</a>&quot;</div><div>CAA validation 128 &quot;type=3DEV method=3D1,2,3,4=
&quot;</div><div><br></div><div>Which limits issuance to <a href=3D"http://=
example.com">example.com</a> and <a href=3D"http://example.net">example.net=
</a>, iff the validation method of domain control employs methods 1, 2, 3, =
or 4, and the resultant process uses the EV process? [*]</div><div><br></di=
v><div>This obviously precludes the notion of &#39;account&#39; - but I thi=
nk that&#39;s illustrative of the point; something like &#39;account&#39; i=
s inherently CA-specific, while the validation methods or types are CA agno=
stic.=C2=A0</div><div><br></div><div>The benefit of this, for a Subscriber,=
 is they might omit the publication of an issue tag, thus not constraining =
per-CA, but still scoping the validation methods.</div><div><br></div><div>=
Understandably, this design could also be accounted for with the CABForum d=
eclaring some pseudo-domain to express such CA-agnostic properties, such as=
:</div><div><br></div><div>CAA issue 0 &quot;<a href=3D"http://example.com"=
>example.com</a>; type=3DDV,EV method=3D1,2,3,4&quot;=C2=A0 =C2=A0 =C2=A0 =
=C2=A0 # If <a href=3D"http://example.com">example.com</a> is issuing, supp=
ort for both DV and EV, using methods 1-4</div><div>CAA issue 0 &quot;<a hr=
ef=3D"http://validation.cabforum.org">validation.cabforum.org</a>; type=3DE=
V method=3D1,2,3&quot; # Otherwise, support for EV only using methods 1-3</=
div><div><br></div><div>There are both strengths and weaknesses of both pro=
posals, so it&#39;d be great to see a discussion about the problem statemen=
t and desired workflows.</div><div><br></div><div>[*] I provide these for s=
implicity of typing - but I think any restriction of both &#39;type&#39; an=
d &#39;method&#39; needs to be versioned, as the CABF documents do change</=
div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Mon,=
 Dec 18, 2017 at 12:41 PM, Tim Hollebeek <span dir=3D"ltr">&lt;<a href=3D"m=
ailto:tim.hollebeek@digicert.com" target=3D"_blank">tim.hollebeek@digicert.=
com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang=3D"EN=
-US" link=3D"#0563C1" vlink=3D"#954F72"><div class=3D"m_764002793901663091W=
ordSection1"><p class=3D"m_764002793901663091MsoPlainText">Here is my tags =
proposal, in case others want to comment on it on this list.<u></u><u></u><=
/p><p class=3D"m_764002793901663091MsoPlainText"><u></u>=C2=A0<u></u></p><p=
 class=3D"m_764002793901663091MsoPlainText">Note that it has been privately=
 pointed out to me that one possible solution to the criticality problem an=
d the scaling problem is to use top-level tags that are independent of the =
issue records:<u></u><u></u></p><p class=3D"m_764002793901663091MsoPlainTex=
t"><u></u>=C2=A0<u></u></p><p class=3D"m_764002793901663091MsoPlainText">So=
mething like:<u></u><u></u></p><p class=3D"m_764002793901663091MsoPlainText=
"><u></u>=C2=A0<u></u></p><p class=3D"MsoNormal">CAA 0 issue =E2=80=9C<a hr=
ef=3D"http://a.example.com" target=3D"_blank">a.example.com</a>=E2=80=9D<u>=
</u><u></u></p><p class=3D"MsoNormal">CAA 0 issue =E2=80=9C<a href=3D"http:=
//b.example.com" target=3D"_blank">b.example.com</a>=E2=80=9D<u></u><u></u>=
</p><p class=3D"m_764002793901663091MsoPlainText">CAA 128 validation =E2=80=
=9CPhone=E2=80=9D<u></u><u></u></p><p class=3D"m_764002793901663091MsoPlain=
Text"><u></u>=C2=A0<u></u></p><p class=3D"m_764002793901663091MsoPlainText"=
>-Tim<u></u><u></u></p><p class=3D"m_764002793901663091MsoPlainText"><u></u=
>=C2=A0<u></u></p><p class=3D"m_764002793901663091MsoPlainText">-----------=
-------------------<wbr>------------------------------<wbr>----------------=
--------------<wbr>------------------------------<wbr>---------------------=
---------<wbr>-<u></u><u></u></p><h1>Introduction and Motivation<u></u><u><=
/u></h1><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"MsoNorma=
l">In addition to being able to specify which CA or CAs are allowed to issu=
e certificates for a given domain, RFC 6844 allows additional parameters, s=
uch as the account number, that the CA can consume for a variety of uses.=
=C2=A0 RFC 6844 defines the format, but otherwise leaves the kinds of prope=
rties and their meanings up to the issuer.<u></u><u></u></p><p class=3D"Mso=
Normal">While this is appropriate for a technical standard, standardizing t=
he names and meanings of CAA properties across the CA industry has the foll=
owing benefits:<u></u><u></u></p><ol style=3D"margin-top:0in" start=3D"1" t=
ype=3D"1"><li class=3D"m_764002793901663091MsoListParagraphCxSpFirst" style=
=3D"margin-left:0in">Reduce user confusion when the same or similar propert=
y is used by different CAs with different names and semantics<u></u><u></u>=
</li><li class=3D"m_764002793901663091MsoListParagraphCxSpMiddle" style=3D"=
margin-left:0in">Make it simpler to migrate from one CA to another while pr=
eserving the CAA configuration<u></u><u></u></li><li class=3D"m_76400279390=
1663091MsoListParagraphCxSpMiddle" style=3D"margin-left:0in">Simplifying co=
nfiguration and expression of CAA policies that allow issuance from multipl=
e CAs<u></u><u></u></li><li class=3D"m_764002793901663091MsoListParagraphCx=
SpLast" style=3D"margin-left:0in">Allow CAA record creation tools to suppor=
t creating CAA records that contain properties that have been standardized<=
u></u><u></u></li></ol><h1>History<u></u><u></u></h1><p class=3D"MsoNormal"=
><u></u>=C2=A0<u></u></p><p class=3D"MsoNormal">CAA property tags have been=
 discussed at several CA/B Forum meetings, most recently at the October mee=
ting in Taipei.=C2=A0 Four were suggested: Acceptable validation methods, a=
n account identifier, certificate types (DV/OV/EV), and ability to specify =
a brand.<u></u><u></u></p><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><h=
1>Method of Adoption<u></u><u></u></h1><p class=3D"MsoNormal"><u></u>=C2=A0=
<u></u></p><p class=3D"MsoNormal">Since these CAA properties are just a vol=
untary industry standard that any CA could implement, they don=E2=80=99t ne=
cessarily have to exist in a standards document.=C2=A0 However, it seems li=
ke it would be helpful if the names and semantics were agreed upon by the i=
ndustry as a whole, so it is probably best to include them in the Baseline =
Requirements as an optional feature CAs MAY implement.<u></u><u></u></p><p =
class=3D"MsoNormal">On the other hand, it might be desirable to reserve the=
 names, and require that if these particular property names are used, the s=
emantics MUST be the semantics specified in the Baseline Requirements.<u></=
u><u></u></p><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><h1>Brands<u></=
u><u></u></h1><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"Ms=
oNormal">I=E2=80=99m starting with this one because I=E2=80=99m going to ar=
gue it isn=E2=80=99t necessary.=C2=A0 CAs can and do have multiple names th=
at they accept in CAA records.=C2=A0 It is hard to imagine a brand existing=
 without the associated domain and website also existing.=C2=A0 I=E2=80=99d=
 suggest that CAs that maintain multiple brands simply use a different doma=
in name for each brand, e.g.<u></u><u></u></p><p class=3D"MsoNormal"><a hre=
f=3D"http://certs.example.com" target=3D"_blank">certs.example.com</a>=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
<wbr>=C2=A0 CAA 0 issue =E2=80=9C<a href=3D"http://megaca.com" target=3D"_b=
lank">megaca.com</a>=E2=80=9D<u></u><u></u></p><p class=3D"MsoNormal"><a hr=
ef=3D"http://catlover.example.com" target=3D"_blank">catlover.example.com</=
a>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 CAA 0 issue =E2=80=9C<a =
href=3D"http://certsforcats.com" target=3D"_blank">certsforcats.com</a>=E2=
=80=9D=C2=A0=C2=A0=C2=A0 # certsforcats is a brand owned by MegaCA.<u></u><=
u></u></p><p class=3D"MsoNormal">CAAs can also publicize examples of CAA re=
cords that allow for issuance by all of their brands.<u></u><u></u></p><h1>=
Acceptable Validation Methods<u></u><u></u></h1><p class=3D"MsoNormal"><u><=
/u>=C2=A0<u></u></p><p class=3D"MsoNormal">A list of acceptable validation =
methods can be specified using the =E2=80=9Cvalidation=E2=80=9D tag.<u></u>=
<u></u></p><p class=3D"MsoNormal">There are two challenges here, that have =
been discussed elsewhere in relation to keeping records of which validation=
 method was used for a particular certificate.=C2=A0 The first is that vali=
dation methods can change over time.=C2=A0 This seems to be less of a conce=
rn for issuance than it is for historical validations, as a CAA record can =
and should be interpreted as always requiring the version of the method tha=
t is enforced by the BRs at issuance time.=C2=A0 However, this can cause th=
e exact meaning of a CAA record to change over time as the BRs evolve.=C2=
=A0 I don=E2=80=99t think this is a big problem, but wanted to note it.<u><=
/u><u></u></p><p class=3D"MsoNormal">The second issue is that it is possibl=
e that the numbering of the BR validation methods could potentially change =
over time.=C2=A0 For that reason, I think it might be reasonable to standar=
dize on a label for each validation method, that can be used in addition to=
 the section number:<u></u><u></u></p><table class=3D"m_764002793901663091M=
soTableGrid" border=3D"1" cellspacing=3D"0" cellpadding=3D"0" style=3D"bord=
er-collapse:collapse;border:none"><tbody><tr><td width=3D"196" valign=3D"to=
p" style=3D"width:147.1pt;border:solid windowtext 1.0pt;padding:0in 5.4pt 0=
in 5.4pt"><p class=3D"MsoNormal"><b>BR Section (BR v. 1.5.4)<u></u><u></u><=
/b></p></td><td width=3D"104" valign=3D"top" style=3D"width:77.65pt;border:=
solid windowtext 1.0pt;border-left:none;padding:0in 5.4pt 0in 5.4pt"><p cla=
ss=3D"MsoNormal"><b>Short Section<u></u><u></u></b></p></td><td width=3D"32=
4" valign=3D"top" style=3D"width:242.75pt;border:solid windowtext 1.0pt;bor=
der-left:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal"><b>Valida=
tion method label<u></u><u></u></b></p></td></tr><tr><td width=3D"196" vali=
gn=3D"top" style=3D"width:147.1pt;border:solid windowtext 1.0pt;border-top:=
none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.2.4.1<u></u><u=
></u></p></td><td width=3D"104" valign=3D"top" style=3D"width:77.65pt;borde=
r-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-rig=
ht:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNorma=
l">1<u></u><u></u></p></td><td width=3D"324" valign=3D"top" style=3D"width:=
242.75pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.=
0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p cla=
ss=3D"MsoNormal">DomainContact<u></u><u></u></p></td></tr><tr><td width=3D"=
196" valign=3D"top" style=3D"width:147.1pt;border:solid windowtext 1.0pt;bo=
rder-top:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.2.4.2=
<u></u><u></u></p></td><td width=3D"104" valign=3D"top" style=3D"width:77.6=
5pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;b=
order-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D=
"MsoNormal">2<u></u><u></u></p></td><td width=3D"324" valign=3D"top" style=
=3D"width:242.75pt;border-top:none;border-left:none;border-bottom:solid win=
dowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4=
pt"><p class=3D"MsoNormal">EmailOrSimilar<u></u><u></u></p></td></tr><tr><t=
d width=3D"196" valign=3D"top" style=3D"width:147.1pt;border:solid windowte=
xt 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal=
">3.2.2.4.3<u></u><u></u></p></td><td width=3D"104" valign=3D"top" style=3D=
"width:77.65pt;border-top:none;border-left:none;border-bottom:solid windowt=
ext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt">=
<p class=3D"MsoNormal">3<u></u><u></u></p></td><td width=3D"324" valign=3D"=
top" style=3D"width:242.75pt;border-top:none;border-left:none;border-bottom=
:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4=
pt 0in 5.4pt"><p class=3D"MsoNormal">Phone<u></u><u></u></p></td></tr><tr><=
td width=3D"196" valign=3D"top" style=3D"width:147.1pt;border:solid windowt=
ext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNorma=
l">3.2.2.4.4<u></u><u></u></p></td><td width=3D"104" valign=3D"top" style=
=3D"width:77.65pt;border-top:none;border-left:none;border-bottom:solid wind=
owtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4p=
t"><p class=3D"MsoNormal">4<u></u><u></u></p></td><td width=3D"324" valign=
=3D"top" style=3D"width:242.75pt;border-top:none;border-left:none;border-bo=
ttom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in=
 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">ConstructedEmail<u></u><u></u></p>=
</td></tr><tr><td width=3D"196" valign=3D"top" style=3D"width:147.1pt;borde=
r:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt"><p cl=
ass=3D"MsoNormal">3.2.2.4.5<u></u><u></u></p></td><td width=3D"104" valign=
=3D"top" style=3D"width:77.65pt;border-top:none;border-left:none;border-bot=
tom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in =
5.4pt 0in 5.4pt"><p class=3D"MsoNormal">5<u></u><u></u></p></td><td width=
=3D"324" valign=3D"top" style=3D"width:242.75pt;border-top:none;border-left=
:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.=
0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">DomainAuthorization=
Document<u></u><u></u></p></td></tr><tr><td width=3D"196" valign=3D"top" st=
yle=3D"width:147.1pt;border:solid windowtext 1.0pt;border-top:none;padding:=
0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.2.4.6<u></u><u></u></p></td=
><td width=3D"104" valign=3D"top" style=3D"width:77.65pt;border-top:none;bo=
rder-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid wind=
owtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">6<u></u><u=
></u></p></td><td width=3D"324" valign=3D"top" style=3D"width:242.75pt;bord=
er-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-ri=
ght:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNorm=
al">WebsiteChange<u></u><u></u></p></td></tr><tr><td width=3D"196" valign=
=3D"top" style=3D"width:147.1pt;border:solid windowtext 1.0pt;border-top:no=
ne;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.2.4.7<u></u><u><=
/u></p></td><td width=3D"104" valign=3D"top" style=3D"width:77.65pt;border-=
top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right=
:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal"=
>7<u></u><u></u></p></td><td width=3D"324" valign=3D"top" style=3D"width:24=
2.75pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0p=
t;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=
=3D"MsoNormal">DNSChange<u></u><u></u></p></td></tr><tr><td width=3D"196" v=
align=3D"top" style=3D"width:147.1pt;border:solid windowtext 1.0pt;border-t=
op:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.2.4.8<u></u=
><u></u></p></td><td width=3D"104" valign=3D"top" style=3D"width:77.65pt;bo=
rder-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-=
right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNo=
rmal">8<u></u><u></u></p></td><td width=3D"324" valign=3D"top" style=3D"wid=
th:242.75pt;border-top:none;border-left:none;border-bottom:solid windowtext=
 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p =
class=3D"MsoNormal">IPAddressLookup<u></u><u></u></p></td></tr><tr><td widt=
h=3D"196" valign=3D"top" style=3D"width:147.1pt;border:solid windowtext 1.0=
pt;border-top:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">3.2.=
2.4.9<u></u><u></u></p></td><td width=3D"104" valign=3D"top" style=3D"width=
:77.65pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.=
0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt"><p cla=
ss=3D"MsoNormal">9<u></u><u></u></p></td><td width=3D"324" valign=3D"top" s=
tyle=3D"width:242.75pt;border-top:none;border-left:none;border-bottom:solid=
 windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in=
 5.4pt"><p class=3D"MsoNormal">TestCertificate<u></u><u></u></p></td></tr><=
tr><td width=3D"196" valign=3D"top" style=3D"width:147.1pt;border:solid win=
dowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt"><p class=3D"MsoN=
ormal">3.2.2.4.10<u></u><u></u></p></td><td width=3D"104" valign=3D"top" st=
yle=3D"width:77.65pt;border-top:none;border-left:none;border-bottom:solid w=
indowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5=
.4pt"><p class=3D"MsoNormal">10<u></u><u></u></p></td><td width=3D"324" val=
ign=3D"top" style=3D"width:242.75pt;border-top:none;border-left:none;border=
-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:=
0in 5.4pt 0in 5.4pt"><p class=3D"MsoNormal">RandomValueInCertificate<u></u>=
<u></u></p></td></tr></tbody></table><p class=3D"MsoNormal"><u></u>=C2=A0<u=
></u></p><p class=3D"MsoNormal">Examples:<u></u><u></u></p><p class=3D"MsoN=
ormal">CAA 0 issue =E2=80=9C<a href=3D"http://ca.example.net" target=3D"_bl=
ank">ca.example.net</a>; validation=3D3=E2=80=9D=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
<wbr>=C2=A0=C2=A0=C2=A0=C2=A0 # Call me about all certificates<u></u><u></u=
></p><p class=3D"MsoNormal">CAA 0 issue =E2=80=9C<a href=3D"http://ca.examp=
le.net" target=3D"_blank">ca.example.net</a>; validation=3DPhone=E2=80=9D=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # =
Same as previous example<u></u><u></u></p><p class=3D"MsoNormal">CAA 0 issu=
e =E2=80=9C<a href=3D"http://ca.example.net" target=3D"_blank">ca.example.n=
et</a>; validation=3D1,2,3,4,7,8,9,10=E2=80=9D=C2=A0=C2=A0 # I don=E2=80=99=
t like DADs and website changes<u></u><u></u></p><p class=3D"MsoNormal">CAA=
 0 issue =E2=80=9C<a href=3D"http://ca.example.net" target=3D"_blank">ca.ex=
ample.net</a>; validation=3D!5,6=E2=80=9D=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<wbr>=C2=A0=C2=A0 # Same=
 as previous example.=C2=A0 Worth the trouble?<u></u><u></u></p><h1>Account=
 Identifier<u></u><u></u></h1><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></=
p><p class=3D"MsoNormal">This one is relatively straightforward, as the ide=
ntifier is going to be CA-specific anyway.=C2=A0 Use the =E2=80=9Caccount=
=E2=80=9D keyword:<u></u><u></u></p><p class=3D"MsoNormal">CAA 0 issue =E2=
=80=9C<a href=3D"http://ca.example.net" target=3D"_blank">ca.example.net</a=
>; account=3D8675309=E2=80=9D<u></u><u></u></p><p class=3D"MsoNormal">The f=
ormat and values of the account specifier is up to the individual CA.<u></u=
><u></u></p><h1>Acceptable Certificate Types<u></u><u></u></h1><p class=3D"=
MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"MsoNormal">This one also see=
ms to be relatively straightforward.=C2=A0 I=E2=80=99ve chosen to make the =
categories disjoint, so if you=E2=80=99re ok with more than one type, you h=
ave to specify more than one.=C2=A0 Use the =E2=80=9Ctype=E2=80=9D keyword.=
<u></u><u></u></p><p class=3D"MsoNormal">CAA 0 issue =E2=80=9C<a href=3D"ht=
tp://ca.example.net" target=3D"_blank">ca.example.net</a>; type=3DEV=E2=80=
=9D=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<wbr>=C2=A0=C2=
=A0 # EV only<u></u><u></u></p><p class=3D"MsoNormal">CAA 0 issue =E2=80=9C=
<a href=3D"http://ca.example.net" target=3D"_blank">ca.example.net</a>; typ=
e=3DDV=E2=80=9D=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<wb=
r>=C2=A0=C2=A0 # DV only<u></u><u></u></p><p class=3D"MsoNormal">CAA 0 issu=
e =E2=80=9C<a href=3D"http://ca.example.net" target=3D"_blank">ca.example.n=
et</a>; type=3DOV,EV=E2=80=9D=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # No DV<u><=
/u><u></u></p><h1>Lack of Property Tag Value Criticality<u></u><u></u></h1>=
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"MsoNormal">Suppo=
rting the various properties is optional.=C2=A0 Unlike the CAA =E2=80=9Ciss=
ue=E2=80=9D property, these properties do not have to be ubiquitously suppo=
rted to have value, because Domain holders can restrict their issue records=
 to only include CAs that have publicly stated that they support the desire=
d property tags.<u></u><u></u></p><p class=3D"MsoNormal">For example, if CA=
s A, B, and C support the =E2=80=9Ctype=3DEV=E2=80=9D tag, then the followi=
ng will prevent non-EV issuance:<u></u><u></u></p><p class=3D"MsoNormal">CA=
A issue 0 =E2=80=9CA.com; type=3DEV=E2=80=9D<u></u><u></u></p><p class=3D"M=
soNormal">CAA issue 0 =E2=80=9CB.com; type=3DEV=E2=80=9D<u></u><u></u></p><=
p class=3D"MsoNormal">CAA issue 0 =E2=80=9CC.com; type=3DEV=E2=80=9D<u></u>=
<u></u></p><p class=3D"MsoNormal">Unfortunately, this does scale poorly wit=
h a large number of CAs.<u></u><u></u></p><p class=3D"MsoNormal">The proble=
m is that RFC 6844 supports =E2=80=9CCritical=E2=80=9D for property tags (l=
ike =E2=80=9Cissue=E2=80=9D), but there is no way to mark a parameter tag i=
s =E2=80=9CCritical=E2=80=9D.=C2=A0 I intend to bring this up with the IETF=
 WG.<u></u><u></u></p><p class=3D"MsoNormal">Any easy solution is to use re=
served bit #1 for property tag criticality:<u></u><u></u></p><h1><span styl=
e=3D"font-size:11.0pt;line-height:106%;font-family:&quot;Calibri&quot;,sans=
-serif;color:windowtext">CAA issue 64 =E2=80=9CA.com; type=3DEV=E2=80=9D=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # type=3DEV=
 tag must be respected;<br>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0<wbr>=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0<wbr>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 # cannot =
issue if you don=E2=80=99t understand or enforce it.</span><u></u><u></u></=
h1><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><h1>Multiple Tags<u></u><=
u></u></h1><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"MsoNo=
rmal">Just for completeness, these individual features can also be used tog=
ether:<u></u><u></u></p><p class=3D"MsoNormal">CAA issue 0 =E2=80=9C<a href=
=3D"http://ca.example.com" target=3D"_blank">ca.example.com</a>; type=3DEV =
validation=3DPhone account=3D8675309=E2=80=9D<u></u><u></u></p><p class=3D"=
MsoNormal"><u></u>=C2=A0<u></u></p><p class=3D"m_764002793901663091MsoPlain=
Text"><u></u>=C2=A0<u></u></p></div></div><br>_____________________________=
_<wbr>_________________<br>
Spasm mailing list<br>
<a href=3D"mailto:Spasm@ietf.org">Spasm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/spasm" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/spasm</a><br>
<br></blockquote></div><br></div>

--001a11c146eea9c1120560b23e05--


From nobody Tue Dec 19 06:47:17 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AC91B12704A for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:47:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mPFhrmPA3pRC for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:47:09 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 95A1A12D72F for <spasm@ietf.org>; Tue, 19 Dec 2017 06:47:09 -0800 (PST)
Received: from [216.82.251.38] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-17.bemta-12.messagelabs.com id C0/BC-10763-C66293A5; Tue, 19 Dec 2017 14:47:08 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1VSa2xLYRjud057emY7fO3GXmUuDcJmZYvLRoS EH8wsErIszRJO52g7bbf0FPPL3BLUMOo2q80lmJoJc53KLlhMzLZQhm0W28QWWRiGIM7pN7c/ J8/3Ppf3+U4+lta2MDpWyHEJTgdv0zODlM/GlM+MtU1INE697OUSjgUyEg75A+p51MJS9xNm4 alTX6mllFFldZiyclaqLLsqGpjswPycbWfFXHRz3k40iFXiXgru72lTyQct9lBQ0tqqJoc7CN rvFTE7UQjL4KkQ8NdSMo7AU8B/uV4tYxqPB+/uQqWMw3EUtL+soIlmFBRXfZJSWQmnQm9Xijx WSvJOX03QyuF0qLywjyG7ztLwzvMmmB+C58CWktZgJsLDoL/uPEV2RcLzjqIgBhwB7Y0PGIKH wtvXP1VEnw7evuqBuR5elH5BBEdBU5EbycsAV6vhxtUaFSEMcCX/HZKLAl4CrY9iiOY0gsa8C iXRRMOJfj9N8BqoaXAPeGeB72YXQww1NPg6D6lJ0Eho804j8zsquFhZH2ytxavAc460C8c6aH m8A+1Fkwr+uVyB5KFxEYIzuxqYguBv0sD9Ix1KIoqGA6XdAzgGTh/voQmeDYe/VTEEjwWPu11 N8HToufseFSP2HJooCs51gjM2frrB5LSaLS47b7XFxsXFG+yCKPJmwcabRENGlv0Skh7WRoUC XUflm5Kq0XCW0g/lHnoSjNrBpqxVGyy8aFnhXGsTxGo0kmX1wJ0Yn2jUapyCWchZbbVJr/M3D WyYPoJLk2lOzObtotVMqDo0ly30P/9OsRf7X0nfriM9uTR7rPbzZlqrdGQ5BF0kd022YdlmWe v4E/r71TehKF04hxQKhTYsW3Dara7/+W4UySJ9OLddTgmzOlx/dndLtSip1oG0mXItF/+X0uW ikzPy+yxJHVEz1nem/vw85KV3XFVhWn5oSsNypnnr6BGBx8bsB5s+viqb3LROW/fxQoZvUdOw Dyv2Hz0ZmOBLadbcSrIbKn9cLZuvSG5e/CE0/6ndLJTjzGd5mfajCw4mtuTZxNCukrbXs/vct zW4Of1Fr8kSvyRZlXbb8Ha4pnPZAr1StPBx0bRT5H8BaHcxFPADAAA=
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-12.tower-163.messagelabs.com!1513694827!161865725!1
X-Originating-IP: [216.32.180.55]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 71465 invoked from network); 19 Dec 2017 14:47:08 -0000
Received: from mail-by2nam03lp0055.outbound.protection.outlook.com (HELO NAM03-BY2-obe.outbound.protection.outlook.com) (216.32.180.55) by server-12.tower-163.messagelabs.com with AES256-SHA256 encrypted SMTP; 19 Dec 2017 14:47:08 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=e5AaFoqA/3ZtAWuEGHCuWHsIHQ5uTsYCj26uAmElkwg=; b=MVdZX2ExjwbvTjA1HxQRmjAoUJDy9WNfoDuz8vCd2Er6ln3TIEkJubMGzCASxC1oAImZQi+xc7XjNhpdaM6Ey+5YOBWDpR8dkBhu6CWJhxRs2tX1EtW0P5jl8OvQlD1ZFxyV65E+RtxSQrpJDaKcjm/hlofvnyOrll1/xtz2+4Y=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1291.namprd14.prod.outlook.com (10.173.132.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Tue, 19 Dec 2017 14:47:07 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Tue, 19 Dec 2017 14:47:06 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
CC: "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwADzsgAAAD5epAAAYUKgAAAB/wgACB+VwAABVMhEA==
Date: Tue, 19 Dec 2017 14:47:06 +0000
Message-ID: <DM5PR14MB12893477D1F843E48CD3D088830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com> <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie>
In-Reply-To: <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1291; 6:5MICqsZcIL6m3/HseX4JnNfpXo6FWjjCshxOQCqCB2GW9ba8lZK0QBvo/VsnNPcgJR79vGREAv2+v9Y4k6NCHX5TAS03Rm+aJPAkWF2y2TC8J4Q3lEZPvenOKaB9rhad65x2mR4+pD9xsUwM8Nnz30uOhM8CJDXcfa8SxF03Qaf3lzqD6xBVHkmFnIgosEOp7FLzqGrWrPnafhTrIvUxXCOpAGj5zRCUC1VpTGBg3aaYJWJWx0ePGTw15IdGUCrSLHAWi55Mhzc97iWZhS8FT3j9WiISPBmICjaWLved+dsfSBSt5044ODUtZ2uc+fAXXdxqTFhLJ4PeoZJ9S4h8LtyzIVgbHXvqzaV3MMcrSqA=; 5:IP6kkPmSxRviil2CSZVy2oB1BQfLIptTJAstHsV7qBti2C/eQpWb94+FXI3oDnrfmD0nEMYjga4p9CaDJOMgoLWQbirBnXf8oULvY5TFlaDGcZSU5wu47VlLhvfijPB9JrvH/vsJz3KsRXKLKAM801u3mHY9X/O8UdiZX0nf35Q=; 24:ZY4XT617VMNSx7dizqquO/tOKELGUzjhvES7N8YS8ikfq0BeVfOwXeMvZ4DcWACIrCQuHhoQF2mRHjFEnN2QpWPjBDSpvlA+/NQ3J7KDtDc=; 7:GXEdB4a29DlanhOoCwiJ5FB7dA/W7x4FN7HJYiVau0GcaJIzo5CHIDjaXVIs+iad6NP5EFzjZKMNNCrRvBHyN6U0qgoFdePRNq/YM890z7d9/JGKsnF830yEJbNs8bd2Uj/Ei0iwPPDngExefgWHNnyoPnS8Jclcw4UHPlhrTQo+1+dobSdn9WjEklJTqbk58LwPAbmkrlyRYVbghOx3E40Gc9NldtITsW1XYfinszAjWHfrdYdXCmWJevqPtiGX
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: c12c519a-a40a-4d7d-bb84-08d546ef602f
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1291; 
x-ms-traffictypediagnostic: DM5PR14MB1291:
x-microsoft-antispam-prvs: <DM5PR14MB1291728515490C1B718F55A1830F0@DM5PR14MB1291.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(32856632585715);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(93006095)(93001095)(10201501046)(3231023)(3002001)(6041248)(20161123562025)(20161123564025)(2016111802025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123558100)(20161123560025)(6072148)(6043046)(201708071742011); SRVR:DM5PR14MB1291; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1291; 
x-forefront-prvs: 052670E5A4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(366004)(39860400002)(376002)(346002)(396003)(199004)(189003)(24454002)(45074003)(13464003)(81166006)(2906002)(9686003)(229853002)(4326008)(99936001)(6436002)(74316002)(6246003)(305945005)(53936002)(68736007)(25786009)(77096006)(97736004)(105586002)(33656002)(55016002)(14454004)(99286004)(478600001)(2900100001)(106356001)(93886005)(76176011)(8676002)(81156014)(6506007)(2950100002)(7696005)(6916009)(316002)(3280700002)(3660700001)(7736002)(5660300001)(86362001)(66066001)(3846002)(53546011)(102836003)(6116002)(8936002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1291; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_05C4_01D3789D.8D277BD0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c12c519a-a40a-4d7d-bb84-08d546ef602f
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Dec 2017 14:47:06.5474 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1291
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/2vtZaEW6kW8oeW3loIrevWNm2k8>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 14:47:16 -0000

------=_NextPart_000_05C4_01D3789D.8D277BD0
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

If you don't want to use these tags, you don't have to.  They're purely =
optional and completely backwards compatible.  They simply transmit =
additional information to the CA about the desired certificate.

> -----Original Message-----
> From: Stephen Farrell [mailto:stephen.farrell@cs.tcd.ie]
> Sent: Tuesday, December 19, 2017 5:13 AM
> To: Tim Hollebeek <tim.hollebeek@digicert.com>
> Cc: spasm@ietf.org
> Subject: Re: [lamps] CAA tags
>=20
>=20
> Hiya,
>=20
> I've not been following this closely but since you
> said:
>=20
> On 18/12/17 20:45, Tim Hollebeek wrote:
> > Pre-spec for discussion.  It=E2=80=99s current status is =E2=80=9CI =
sat down for an
> > hour, reviewed meeting minutes and read some stuff, and circulated
> > some notes=E2=80=9D.
> I guess it may be ok to throw in a requirement to keep an aspect of =
the status
> quo:
>=20
> I'd like to ensure it remains possible for a whole bunch of DNS =
domains to use
> the same CAA RR value and for that to continue to make sense. I've no
> problem if optional things can be added that are domain-specific so =
long as I
> don't have to create custom CAA values for every domain.
>=20
> My reason for wanting that is that I deal with sets of domains who can =
all
> currently sensibly use the same CAA value and that's easy to handle. =
If I had to
> go changing the value for each, esp if that had to be re-done =
regularly, or even
> worse, sporadically, that'd be a PITA.
>=20
> Apologies for the interruption if this is already taken as a given, =
but I wasn't
> sure based on the recent mails about phone numbers etc.
>=20
> Thanks,
> S.


------=_NextPart_000_05C4_01D3789D.8D277BD0
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE5MTQ0NjU5WjAvBgkqhkiG9w0BCQQxIgQg7Uq63VCtaWHkFPHoSuahhSBgaDJJ
wAWkyvsfcTPIYwwwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAAVTM72okiiYxnwuoOEIvA+EGQ6mOZQGxV9ZR7/n5uSyVcWXa5JZQdDLxKz4nfkx5f0d9u7p
gQ7cEjzLzoYK6RRicRUINA4WWCq1DjxP6hnP07jGyZo4Y5dtgRtoLXXe8SJEsEYRiv/EE/SJojG3
idhM+qymGC7UMj7bOMI/ERodTj7hWrSbFDZzebgMGcHyo6INk2DmRDG+4AMKx+pFRjALrudTcUBx
VXG1S6630sX9RiAmi6YXjDcR956VCOtB1XK0ZCajVEZUMDTdXYHhHM02gvS1z6JVA0KPmXC9uv1Z
rMbnwyJpJQSU/eS8C5qLp5qYh9Axyc/2hC2OaNZ0bmEAAAAAAAA=

------=_NextPart_000_05C4_01D3789D.8D277BD0--


From nobody Tue Dec 19 06:50:50 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F1D01241FC for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:50:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PBiNwq_suGtz for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:50:48 -0800 (PST)
Received: from mail1.bemta8.messagelabs.com (mail1.bemta8.messagelabs.com [216.82.243.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D1451126FB3 for <spasm@ietf.org>; Tue, 19 Dec 2017 06:50:47 -0800 (PST)
Received: from [216.82.242.36] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-12.bemta-8.messagelabs.com id 99/D2-01246-647293A5; Tue, 19 Dec 2017 14:50:46 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTf0xTVxTHe9+P9ok8cy0oZxWW2EScKA2oxKo zGqMJizNI5h+kmuirvLVP+4O8VwyyZCNOI4IaweJGY4cywiKziTEzLkON/FAcaAxgCIqKzGYK qEQYYhnBvddbnf5z87nne875nntzL0cbywwmTizyibJHcJn1ccwdy8856RsXrrRlBF9brdV3I 3prZX8QWX/q2bWOzn45+pTNrquLUNnfNzYyW2gbK3ns3qKdrPOPg5sKRqWiS2e6DCWoJr8MxX EMHqGgMnTWoG2M2E/Bq5PjDNm0Iqh9/oQuQzM4Pc6AnittlMaJOBUGfrjFakzjTfD20X5G4wS cAgMPGmmS8ymcbhpnCa+C6p5WvcYMXgAlJ9qiOTzeDk9PHWOJWS2CN1XXo0kzcC7cqvs1Wozw XJhoP0cRsyS4H66JMuBEGOjs0BOeA4NPplnCZugLvUGEU6CrphxpBoCbDdD3rDcmWOBixQuVO ZU3Q+TlUpJTj6B3YjgWT4OKyVwyw3YIjjXHvPbAL6FeA+FVUFrRxpLaFhpqr4UNpDYZ+oPLSf wfFs6Nd0eHM+J88DeQRgnYBA/vHkbH0aLAB2cLqDU0rkEQCbdQgegtzYY/q8MMSbLB2daGGKd BVWgoxouh/swwHVC9abwIbnSbPw5rvBp+nGzSE54P/vIBA+EsGL7+Cp1GMxvQZ4oo7xXl9GXL LHZZcjh9bkFypWdmWC1uUVEEh+gS7Ipll9d9Aamv8DudDv2OJlu3NaNPOMo8h7/tt9qMs+ze/ H1OQXHukAtdotKMkjnODPzm1JU242xZdIhFX0su9Sm/k4GLNyfyeQtUmVcKBLciOYjUjtZyU5 fvT1Hc+XsP1fVqdP27eriENjIer0c0JfEBrSvWypyFnvdN332RLpRiSuCRTqczxheIslvyfaw PoSQOmRN4ndYlXvL43nsPqWNR6lhVeSu0sXzC/5KpBB2YehYeRPvPv7Yc+etCMT/y2P5b55e7 c9onO4yOyCHW+6j+yPrisa3WmyNfTKcsebtlNW7i/NtSLweXZG4IZ2VJOzr35l7qS2qZ6P62m JaXzpoq/6rym4uH66Yj80PBwtLFtvo14f6Oz/9tcBxkW+btm85rL1iT440bK/XMTB49mjVoZh SnkJlGy4rwH+uHxq4dBAAA
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-14.tower-94.messagelabs.com!1513695045!201762065!1
X-Originating-IP: [207.46.163.79]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 22047 invoked from network); 19 Dec 2017 14:50:45 -0000
Received: from mail-bl2nam02lp0079.outbound.protection.outlook.com (HELO NAM02-BL2-obe.outbound.protection.outlook.com) (207.46.163.79) by server-14.tower-94.messagelabs.com with AES256-SHA256 encrypted SMTP; 19 Dec 2017 14:50:45 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=L2fTVf8oKpKK7vSXWmSA6V05Re6DpLw9ZuwBsbhrC2A=; b=jaSKz22QHbXOY9uyLSFVqrWxTYaxEtL2ryysa6/vH2sBsS8jwbbzHxkLiyCz4cEHD/nkJK7mH6i+J5Ao0rjo25xPUWapVqxtV0qUXoL0Mp8IibI62k1b0qp6o64b7T63okkpDBvhnvEA/FRvdP9z8poSpBcXkYoi8Sq06CHQm+s=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1290.namprd14.prod.outlook.com (10.173.132.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Tue, 19 Dec 2017 14:50:45 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Tue, 19 Dec 2017 14:50:44 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
CC: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwArdI8AAAC/MGA=
Date: Tue, 19 Dec 2017 14:50:44 +0000
Message-ID: <DM5PR14MB12894853413B1055CEF6FA74830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
In-Reply-To: <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1290; 6:VrWTlD0H0mZJs7c+zp1aMIC/YLfVtajA456zRngEMtskx3INia4YQICUdNUpZALFYIerFtM+3qCeS7ShID6tyvJFaD3cFvbaNXBUQxhyEayop9pKAf6b0k7JGtIPfejWrSI9RzDwYe2ktkA2HhaHd2II1fAZ1H4v1HpnByVP/EfQzD3MAgFDZjGinUf/NaPiD2wQyLpM2n0LGDMImET6mLy6D1b4rN5KGnzals1XLTlFn7gTZf1J3i89R5IyqjAbUI1qQMVpOmTL8ZuIJ5ykh8Vz7vMb3GndtZgQaqySC5kAlFTvIYjWHNCgyXA65lqGZmX/9+rKLCACvRFB11Vt2uih4SjjNGVwqw1AbH9MIhQ=; 5:LEXWG2eP0XXboUokNfyoIvPz0t6UWAmska+EDInWicM1Gpl3eCHjOK+GqnhdqC4b8DRpro+XAuWqTxSADNRxMMuzekzVYJOY1RcNjQxss4mbKeP//dFfhyYWPvHZ6FTh5nwcToopursu2ah0wcySufnswXXBtB8Em/IJZNcbHg4=; 24:5CgfKskZNk6kBo2tk6yAa2a4jjudAiM8jqzWQT46c4LLmPKxY5UveWZfEzB5KL0zD578XmQBSEksAdlDotRMljP4b0jsvFsEQjpEuhBUaHI=; 7:IB8WeQaedOmlT43PrH4fYDy/mo/iVPD7pGqoItbA88S2fjbAsoicaKfgL6OawgYaFIJAjOEu/hjnfuGEPxyUFlmlqdiIJFeC1oV64xzs10rWSkF36kEdsxi4VgtK1K89QJN2aWsr3vjgDrocP2dwSQrNSrcSMoJTsxPs1bP+x4RuB8lm9a/whm0gVQBjc/yHgh9gZHojTYGbQWxRVrWLC39hZX1zYs+3kQWEMUUV15FAt9Yj5yR233ePzTvJrZ+k
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: fa70d60b-a14b-4b5b-bc5c-08d546efe21d
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1290; 
x-ms-traffictypediagnostic: DM5PR14MB1290:
x-microsoft-antispam-prvs: <DM5PR14MB1290DC716D5177B596D0CC75830F0@DM5PR14MB1290.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(8121501046)(5005006)(3002001)(3231023)(10201501046)(93006095)(93001095)(6041248)(20161123562025)(20161123555025)(20161123564025)(2016111802025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123560025)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1290; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1290; 
x-forefront-prvs: 052670E5A4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39860400002)(366004)(396003)(376002)(346002)(24454002)(199004)(189003)(55016002)(5660300001)(3280700002)(1680700002)(53936002)(8676002)(561944003)(6246003)(25786009)(53386004)(6916009)(2950100002)(97736004)(74316002)(81166006)(86362001)(81156014)(33656002)(2900100001)(102836003)(7736002)(99936001)(4326008)(66066001)(790700001)(6116002)(2906002)(3846002)(54906003)(105586002)(3660700001)(6306002)(68736007)(106356001)(316002)(8936002)(14454004)(606006)(54896002)(229853002)(478600001)(77096006)(53546011)(99286004)(7696005)(6436002)(9686003)(6506007)(76176011)(236005); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1290; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_05C8_01D3789E.0F00E880"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: fa70d60b-a14b-4b5b-bc5c-08d546efe21d
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Dec 2017 14:50:44.6270 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1290
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/eke7V1_HGK7nxUKH-tP-hhZVKTE>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 14:50:49 -0000

------=_NextPart_000_05C8_01D3789E.0F00E880
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_05C9_01D3789E.0F00E880"


------=_NextPart_001_05C9_01D3789E.0F00E880
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

As I noted in the preface to my initial email in this thread [1], one =
other person has pointed out the same thing to me.  I noted that not =
only is this an option, but it solves two problems with the original =
proposal, so I=E2=80=99m personally leaning towards it.  We=E2=80=99ll =
see what other CAs think.

=20

That is, why is the set of policy not

=20

CAA issue 0 "example.com <http://example.com> "

CAA issue 0 "example.net <http://example.net> "

CAA validation 128 "type=3DEV method=3D1,2,3,4"

=20

On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek =
<tim.hollebeek@digicert.com <mailto:tim.hollebeek@digicert.com> > wrote:

Note that it has been privately pointed out to me that one possible =
solution to the criticality problem and the scaling problem is to use =
top-level tags that are independent of the issue records:

CAA 0 issue =E2=80=9Ca.example.com <http://a.example.com> =E2=80=9D

CAA 0 issue =E2=80=9Cb.example.com <http://b.example.com> =E2=80=9D

CAA 128 validation =E2=80=9CPhone=E2=80=9D


------=_NextPart_001_05C9_01D3789E.0F00E880
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:24.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.m764002793901663091msoplaintext, li.m764002793901663091msoplaintext, =
div.m764002793901663091msoplaintext
	{mso-style-name:m_764002793901663091msoplaintext;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Calibri Light",sans-serif;
	color:#2F5496;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1438328750;
	mso-list-template-ids:-145878656;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><a =
name=3D"_MailEndCompose">As I noted in the preface to my initial email =
in this thread [1], one other person has pointed out the same thing to =
me.=C2=A0 I noted that not only is this an option, but it solves two =
problems with the original proposal, so I=E2=80=99m personally leaning =
towards it.=C2=A0 We=E2=80=99ll see what other CAs =
think.<o:p></o:p></a></p><p class=3DMsoNormal><span =
style=3D'mso-bookmark:_MailEndCompose'><o:p>&nbsp;</o:p></span></p><span =
style=3D'mso-bookmark:_MailEndCompose'></span><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div><p class=3DMsoNormal>That is, why is the set of policy =
not<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>CAA issue 0 &quot;<a =
href=3D"http://example.com">example.com</a>&quot;<o:p></o:p></p></div><di=
v><p class=3DMsoNormal>CAA issue 0 &quot;<a =
href=3D"http://example.net">example.net</a>&quot;<o:p></o:p></p></div><di=
v><p class=3DMsoNormal>CAA validation 128 &quot;type=3DEV =
method=3D1,2,3,4&quot;<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div><div><div><p =
class=3DMsoNormal>On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek &lt;<a =
href=3D"mailto:tim.hollebeek@digicert.com" =
target=3D"_blank">tim.hollebeek@digicert.com</a>&gt; =
wrote:<o:p></o:p></p><blockquote style=3D'border:none;border-left:solid =
#CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><div><div><p =
class=3Dm764002793901663091msoplaintext>Note that it has been privately =
pointed out to me that one possible solution to the criticality problem =
and the scaling problem is to use top-level tags that are independent of =
the issue records:<o:p></o:p></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'background:yellow;mso-highlight:yellow'>CAA 0 issue =E2=80=9C<a =
href=3D"http://a.example.com" =
target=3D"_blank">a.example.com</a>=E2=80=9D<o:p></o:p></span></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'background:yellow;mso-highlight:yellow'>CAA 0 issue =E2=80=9C<a =
href=3D"http://b.example.com" =
target=3D"_blank">b.example.com</a>=E2=80=9D<o:p></o:p></span></p><p =
class=3Dm764002793901663091msoplaintext><span =
style=3D'background:yellow;mso-highlight:yellow'>CAA 128 validation =
=E2=80=9CPhone=E2=80=9D</span><o:p></o:p></p></div></div></blockquote></d=
iv></div></div></div></body></html>
------=_NextPart_001_05C9_01D3789E.0F00E880--

------=_NextPart_000_05C8_01D3789E.0F00E880
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE5MTQ1MDM3WjAvBgkqhkiG9w0BCQQxIgQg3Ss89H+P+vuHus6U6WhHDAzKLqH+
ZN2NdmXko4JM+GUwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAFMd/wG5bn6l4srKPPanKmVrs6/xdteFU+OUSnonZlXcu0Dj2pIKZlsSbHkRGppuV5lOKT6T
IYCEtY69y4Xod6oCcEq5mVoqqAA+561E9Na/4rFnACmMCF1FqdAmhvM6BrUXNCLNAuyb8B0KKKZp
Y3nZQRijCWnmDoeAQJRFVGpezNwv7lu+Y3M743H/sxR2EXzNlUFOZQ4gKtNCJbtkHewPeYC5XhWd
u6a72/4mcrenZlY/kIKhUX2vIFbt7g6mWnDhLQEKKpbAvIHv82dc5MGGSJGo6TtQSB/Wn7SoJsNj
yCiOKsJyUw0oIEJVVI0t1eXWZyTFp4gcMVmmaSNTwQ0AAAAAAAA=

------=_NextPart_000_05C8_01D3789E.0F00E880--


From nobody Tue Dec 19 06:54:05 2017
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EB87126FB3 for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:54:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.311
X-Spam-Level: 
X-Spam-Status: No, score=-4.311 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0rVNpcD8g2os for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 06:54:01 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 587C01241FC for <spasm@ietf.org>; Tue, 19 Dec 2017 06:54:01 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 60D16BE39; Tue, 19 Dec 2017 14:53:59 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hqh_TJvHS2sw; Tue, 19 Dec 2017 14:53:59 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id F0307BE2F; Tue, 19 Dec 2017 14:53:58 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1513695239; bh=8Aqfk0ppwzVgk0lSscW9PdGVlPWyiVDRNdBvD8esA2c=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From; b=H+tqovBSBudtzYnfYyI+UbxvDFjiQF8qFgPba/wmaWQ1stjUH7YpvApLuY1axXw8U 58jssmSt3CNlywkDptuJ44Ji861WnveudNbW3s9XBKPaJV4WNVab8twRVlfLdB4xzx Q9iC4NqgViB3FUn19XsfpgQSaNU7tLy+jhWlbOX8=
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: "spasm@ietf.org" <spasm@ietf.org>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com> <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie> <DM5PR14MB12893477D1F843E48CD3D088830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <b22edb33-2279-bfe9-035c-dd0e10b1212c@cs.tcd.ie>
Date: Tue, 19 Dec 2017 14:53:57 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <DM5PR14MB12893477D1F843E48CD3D088830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="SVMhPh4l3COgcjdO1SeL0mwrBhCmvPnXd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/aWHwFEaJJprM7kw3BgUPOSBMX_w>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 14:54:03 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--SVMhPh4l3COgcjdO1SeL0mwrBhCmvPnXd
Content-Type: multipart/mixed; boundary="TNmwcEeEN44U27QuGUmV4PaMkfFXKojgT";
 protected-headers="v1"
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: "spasm@ietf.org" <spasm@ietf.org>
Message-ID: <b22edb33-2279-bfe9-035c-dd0e10b1212c@cs.tcd.ie>
Subject: Re: [lamps] CAA tags
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
 <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org>
 <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
 <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com>
 <DM5PR14MB1289520C260D1634FBF5C1E4830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
 <ca3d070f-2fb1-32e2-f6d4-70a7809525a8@cs.tcd.ie>
 <DM5PR14MB12893477D1F843E48CD3D088830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
In-Reply-To: <DM5PR14MB12893477D1F843E48CD3D088830F0@DM5PR14MB1289.namprd14.prod.outlook.com>

--TNmwcEeEN44U27QuGUmV4PaMkfFXKojgT
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: quoted-printable



On 19/12/17 14:47, Tim Hollebeek wrote:
> If you don't want to use these tags, you don't have to.  They're
> purely optional and completely backwards compatible.  They simply
> transmit additional information to the CA about the desired
> certificate.

Great, as long as that stays the same, I'm happy to
go back to watching from the side-lines:-)

Thanks,
S.



--TNmwcEeEN44U27QuGUmV4PaMkfFXKojgT--

--SVMhPh4l3COgcjdO1SeL0mwrBhCmvPnXd
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEcBAEBCAAGBQJaOSgFAAoJEC88hzaAX42i4sgH/jFWttuZBbC2BCyFEmpvv3O1
CR1Zsl4JMWMflb4T/ZSw1bUfDhPfoNkjXzarujmVqh+fK8IXyk0jvNIb5y4k5nhz
9aEqDkxwS737QvpqSO+UVUaQ7zUoRJqTVoCinZAcz+h8q7XmkDvSp4riOZ1JtRp8
ki+3TJI6xECCaLasoQhIyGwzEzyswY9mXFuV80mW2TGVaootR7yg71AE0eOyYiYI
4t3ckgF9tBqqd9rVno74PHp65KxEAAIXpLbi+6DBZe5v7YaWZMjaH7s601FuOtWE
OZEIlWS2cApbhpmxA8AfmvHzXYteQmO/TEVotY2SxmeYuL6OqgWCOd0LN7+aYKQ=
=5t+S
-----END PGP SIGNATURE-----

--SVMhPh4l3COgcjdO1SeL0mwrBhCmvPnXd--


From nobody Tue Dec 19 07:10:33 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E67C120727 for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 07:10:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qf9VGe9clBSa for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 07:10:29 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.8]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D8ED126CE8 for <spasm@ietf.org>; Tue, 19 Dec 2017 07:10:29 -0800 (PST)
Received: from [216.82.251.38] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-8.bemta-12.messagelabs.com id 07/F3-02572-4EB293A5; Tue, 19 Dec 2017 15:10:28 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTe0wTWRTGe2b6GJSaa0F7bMBojUEwNCASIZh I4sY0PhI1xmjFx6CztLEtpFMNmmzEiBLRimh9gVgeVXzGx7oGURup+8hCDMqyVVGURkSFFXyh iKzrTKe6+s/N757vu+c7c3OHoTUulY7h8p2cw85a9cph8mZDzfzEzsnppqRgX0Ra6ctySKveX KNIOxJYnUkbW7zlYLx1qp8yer0fqPm0SWGxZ+fmr1KYz564CHltRZD/8dOAqgCCPxXDMEZO+i i8ubOXFjca4qbQ1XdYJW1+BdxS5ZIXQwSjJEkYuPYHVQwME02W4SXvBLFMEx0+uhMAkaNILAY fXKFFjiZjsbKhXyHxYizp6gl55GQi/uvpV4msJlk4sKc1HFxBo9c7GMqKIAuwfpuPEhnIaHzf eJqSwrTY1ukJMZJoDN5uUko8Cp8//qSQ/FlY8cYfruvx/pkBkDgWWzw7QAxD4lehq7FWLgkG/ KX0Rdg0Dwv9Q0rJdAyw9e1TlSQkYFPTQLjrWiysqQ6zDevPesJdb9DYcfRw6IqQxOCjiqlS/Y 0Cj1V1hBI0ZA26T0rjRQl31966HXZDfNk3X1cmnKGJB7DhfAldFrqnkfjnoU65ZDKhq6iIkjg B953pDtcnCxk9gp8ROB5//0v/fVnkDDw42KCUeDy6dwRVEqdiz2+voBKGn4RJPOdYzzkSU9IN 2Q5LjtlpYy3WxOTkKQYbx/NsDmdls3nD6lzbBRAe4iaZDOqguWqZH8YwlH6U+qY7zaQZkZ27Z oOZ5c0rHeusHO+HGIbRozorId2kGengcrj8Hy1W4TV/kZGJ1EerS+IFWc3nsTbekiNJjTCDGb raNkQx5+61C6svtHYd6imgNXJ7rp3TadV2sSsRj5nX2b82/fKXtECsLkoNMplME5nHOWwW5/d 6N2gZ0EepN4tdIi1259fsbmEsShhr35Jp4lhO9n9JVwAZ7Zfvxq1c/5/3eOXBwJzqcfV8x+y/ 67RHN9D7mboD7hMzl9eC6qFzRurCrS1duxYlDcY2GbW7Lk69vSnmZUbz3HfbbhQ927liue8y/ 88Rr68wU5vpj7P8UN72etbPKZG6Fb7S2u2vzr/ICsDeJ5X972lM7W5fGne97/m4lOm9Jb0bjX o5b2aTE2gHz34GMwMGgSAEAAA=
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-13.tower-163.messagelabs.com!1513696225!169730748!1
X-Originating-IP: [207.46.163.80]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 16144 invoked from network); 19 Dec 2017 15:10:28 -0000
Received: from mail-bl2nam02lp0080.outbound.protection.outlook.com (HELO NAM02-BL2-obe.outbound.protection.outlook.com) (207.46.163.80) by server-13.tower-163.messagelabs.com with AES256-SHA256 encrypted SMTP; 19 Dec 2017 15:10:28 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=ivEN6FIOrndAYWcLfPWXuseLK22/hd9rLMrNUf1KbZw=; b=a+O+J/mYeVyGhR6LRI8oCB4CeG8xJCflOYCOn9+FihfvRi+DwqWYI0eqB7cLkdzfXeIqbPIMbBOQY4XbmlO9kK6ssi5wQvlo0STwSwTwI2PaarPaLKn1HK117tn5FhoM0ObD7A7cB6H1qHG/uUXnSN//2TRf9fd6MhXpY8lsTRk=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1292.namprd14.prod.outlook.com (10.173.132.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Tue, 19 Dec 2017 15:10:24 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Tue, 19 Dec 2017 15:10:24 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Phillip Hallam-Baker <phill@hallambaker.com>, Rob Stradling <rob.stradling@comodo.com>
CC: SPASM <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwADzsgAAAD5epAAAYUKgAACy0KAABGHCYAAEl7wYA==
Date: Tue, 19 Dec 2017 15:10:24 +0000
Message-ID: <DM5PR14MB12895956E401233B008525C6830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <0ab8efa3-378c-ece7-4fa3-913308f81c22@eff.org> <DM5PR14MB12895320D99FC570E797373F830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HGMOVmvEoD=hy3rnTb=J1uQeu-SHrTn1JEeRnQuXzqg-Q@mail.gmail.com> <7531d7e2-2bdd-559a-2e40-286a3fe4a4f2@comodo.com> <CAMm+Lwg1+qt0sJfTY_ih+VjY9L7oMzX=ZRd0mxU7NR2Fxv8kQA@mail.gmail.com>
In-Reply-To: <CAMm+Lwg1+qt0sJfTY_ih+VjY9L7oMzX=ZRd0mxU7NR2Fxv8kQA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1292; 6:2Nx31ba5x734ywvkzjNSrR1C8SHlSwpIV4jwNQrFkF/H7KJ5z00Gcc128amvRs4eqoUJJ7M4bHaK2/bTFLz0MEX3aFEzsORGbdWq1R76hqgRtQ0Jih1uFI+rFJtvCAWsPSxyvyubRYrs10hcCIvTFx4YKD7D9XYIz7N3bPuDsRZsql4KhPMNzCbSnHnKO7lAVg99ZL9D0/AjIFfowzXY8G9YZ2q1qcoJoRt197ff7BNRXi9PZ/j2UrU/wFrmiHU9vGUz+WLG0fXdUxFAPvW6dRHAYtQ3jo8w0XqHu14aeGThJh26s0ROehUCzhBzzpztpFMKJBTjWXJi7hRII4X3Ox/4020KH8qtJGWH4dKjC8E=; 5:1suTRWEXy2WNgFAwELJfFeyOU1umTT2VZva9sCrbbhV8m4cSgkVn9guxgsjehwWEKDm8ey+4VZWytOMOsoGHHI7nyFLbXQPYgZym9nzLc9hKhf6Mp9I/IhO24Eq/EPxyBUqJ+hZPodq8Q4JHwLI0AzwrGqeHMr24pb961ol0MFU=; 24:Zw3OoIJqqB5dmEWveuhsmwLsyNEJmPU9UOjWP3kIvF5t2C+tIwdzEpMH30v3uSbmwFAwC6hAehiw1/XOLL2xTL2yn28/GxF/r6QuEVVB6jM=; 7:mW8QePE0gCHitCDwB/4tMVZLpDkic2z4ZPemXtCxdkAjHGx3JmOXfRoPSEBEBAiOcvWNDSK+yn3vaptDcZ4cIhy0LrEnDbfKtAWLklT6xoL0yLW5BkrU3E/AD4SbdIFswEqjVUAfEs/ME+gajM8J68ZYhxQVmWAZyG+oWQspcZBcln81kVumlepfS3aI0xFNeKOIWhdKFtEjaF/cEfPhAx3wB6M0KUSNjmxT7cOLFs0V3Js+zNH8Aqq26Dl7RfAB
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 512947db-6488-469e-5f41-08d546f2a166
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(49563074); SRVR:DM5PR14MB1292; 
x-ms-traffictypediagnostic: DM5PR14MB1292:
x-microsoft-antispam-prvs: <DM5PR14MB1292CDB8EC3B6DBB2E8526BD830F0@DM5PR14MB1292.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(209352067349851)(100405760836317)(21748063052155); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(8121501046)(5005006)(3231023)(3002001)(10201501046)(93006095)(93001095)(6041248)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123558100)(20161123560025)(2016111802025)(20161123562025)(6072148)(6043046)(201708071742011); SRVR:DM5PR14MB1292; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1292; 
x-forefront-prvs: 052670E5A4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(376002)(366004)(39860400002)(396003)(346002)(24454002)(199004)(189003)(7736002)(6306002)(110136005)(6436002)(68736007)(97736004)(14454004)(53936002)(6506007)(81166006)(2906002)(478600001)(53546011)(86362001)(76176011)(99286004)(6246003)(7696005)(74316002)(316002)(8936002)(966005)(93886005)(54896002)(236005)(3660700001)(9686003)(66066001)(229853002)(25786009)(81156014)(77096006)(106356001)(99936001)(105586002)(606006)(2950100002)(33656002)(1680700002)(3846002)(6116002)(3280700002)(53386004)(8676002)(4326008)(2900100001)(102836003)(790700001)(55016002)(5660300001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1292; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_05E5_01D378A0.CE5DF180"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 512947db-6488-469e-5f41-08d546f2a166
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Dec 2017 15:10:24.5570 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1292
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/1rOfydh7EsxqbkHlOUxkFvCfrGo>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 15:10:31 -0000

------=_NextPart_000_05E5_01D378A0.CE5DF180
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_05E6_01D378A0.CE5DF180"


------=_NextPart_001_05E6_01D378A0.CE5DF180
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Hmm, domain names as tags is an interesting idea I had not considered.  =
I=E2=80=99ll keep it in mind.  Thanks.

=20

-Tim

=20

From: Spasm [mailto:spasm-bounces@ietf.org] On Behalf Of Phillip =
Hallam-Baker
Sent: Monday, December 18, 2017 11:24 PM
To: Rob Stradling <rob.stradling@comodo.com>
Cc: SPASM <spasm@ietf.org>
Subject: Re: [lamps] CAA tags

=20

We did indeed start with OIDs. But the reason I agreed to Domain Names =
was that the suggestion (I seem to remember it was Paul Hoffman) was =
obviously the right one.=20

=20

Most of the things people want to do with tags can be done with domain =
names. More importantly, it can be done outside the IETF. If you want =
'any EV' issuer, get the CABForum to approve ev.cabforum.com =
<http://ev.cabforum.com>  for the purpose.

=20

Restricting to specific validation methods is interesting and might be a =
justified use for the criticality flag.=20

=20

The other point to ponder is how a server that needs a cert discovers =
where the cert issuing service is. The idea was that if the CAA record =
specifies chosenca.com <http://chosenca.com> , a server would then be =
able to use that information to work out how to get a cert and automate =
the whole process.

=20

=20

Remember that at the time, there was this idea that DNS records should =
not make use of prefixes and should not make use of additional parsing =
beyond DNS record markers. At this point, I think we can safely ignore =
both notions as broken and if I was to do it again would suggest it just =
be a TXT type record. But we can't that's water under the bridge now, =
sorry.

=20

=20

=20

=20

=20

On Mon, Dec 18, 2017 at 5:02 PM, Rob Stradling <rob.stradling@comodo.com =
<mailto:rob.stradling@comodo.com> > wrote:

On 18/12/17 20:42, Ryan Sleevi wrote:
<snip>

I think Jacob's suggestion of OIDs is not at all unreasonable, and =
avoids the ambiguities you raise and allows them to be addressed by =
policy in the Forum.


We had policy OIDs in early versions of the I-D [1] that later became =
RFC6844, but we had to strip this out in favour of domain names when the =
document was adopted by PKIX.  WG consensus and all that.

I'm not sure what that decision might mean for any other proposals to =
use OIDs with CAA.


[1] https://www.ietf.org/archive/id/draft-hallambaker-donotissue-04.txt

--=20
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online



_______________________________________________
Spasm mailing list
Spasm@ietf.org <mailto:Spasm@ietf.org>=20
https://www.ietf.org/mailman/listinfo/spasm

=20


------=_NextPart_001_05E6_01D378A0.CE5DF180
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.hoenzb
	{mso-style-name:hoenzb;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal>Hmm, =
domain names as tags is an interesting idea I had not considered.=C2=A0 =
I=E2=80=99ll keep it in mind.=C2=A0 Thanks.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>-Tim<o:p></o:p></p><p class=3DMsoNormal><a =
name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a></p><span =
style=3D'mso-bookmark:_MailEndCompose'></span><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #E1E1E1 =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b>From:</b> Spasm =
[mailto:spasm-bounces@ietf.org] <b>On Behalf Of </b>Phillip =
Hallam-Baker<br><b>Sent:</b> Monday, December 18, 2017 11:24 =
PM<br><b>To:</b> Rob Stradling =
&lt;rob.stradling@comodo.com&gt;<br><b>Cc:</b> SPASM =
&lt;spasm@ietf.org&gt;<br><b>Subject:</b> Re: [lamps] CAA =
tags<o:p></o:p></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>We did indeed start =
with OIDs. But the reason I agreed to Domain Names was that the =
suggestion (I seem to remember it was Paul Hoffman) was obviously the =
right one.&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>Most of the things =
people want to do with tags can be done with domain names. More =
importantly, it can be done outside the IETF. If you want 'any EV' =
issuer, get the CABForum to approve <a =
href=3D"http://ev.cabforum.com">ev.cabforum.com</a> for the =
purpose.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>Restricting to =
specific validation methods is interesting and might be a justified use =
for the criticality flag.&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>The other point to =
ponder is how a server that needs a cert discovers where the cert =
issuing service is. The idea was that if the CAA record specifies <a =
href=3D"http://chosenca.com">chosenca.com</a>, a server would then be =
able to use that information to work out how to get a cert and automate =
the whole process.<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>Remember that at the =
time, there was this idea that DNS records should not make use of =
prefixes and should not make use of additional parsing beyond DNS record =
markers. At this point, I think we can safely ignore both notions as =
broken and if I was to do it again would suggest it just be a TXT type =
record. But we can't that's water under the bridge now, =
sorry.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></p></div></div><div><=
p class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>On =
Mon, Dec 18, 2017 at 5:02 PM, Rob Stradling &lt;<a =
href=3D"mailto:rob.stradling@comodo.com" =
target=3D"_blank">rob.stradling@comodo.com</a>&gt; =
wrote:<o:p></o:p></p><blockquote style=3D'border:none;border-left:solid =
#CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><p class=3DMsoNormal>On =
18/12/17 20:42, Ryan Sleevi =
wrote:<br>&lt;snip&gt;<o:p></o:p></p><blockquote =
style=3D'border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-right:0in'><p class=3DMsoNormal>I think =
Jacob's suggestion of OIDs is not at all unreasonable, and avoids the =
ambiguities you raise and allows them to be addressed by policy in the =
Forum.<o:p></o:p></p></blockquote><p class=3DMsoNormal><br>We had policy =
OIDs in early versions of the I-D [1] that later became RFC6844, but we =
had to strip this out in favour of domain names when the document was =
adopted by PKIX.&nbsp; WG consensus and all that.<br><br>I'm not sure =
what that decision might mean for any other proposals to use OIDs with =
CAA.<br><br><br>[1] <a =
href=3D"https://www.ietf.org/archive/id/draft-hallambaker-donotissue-04.t=
xt" =
target=3D"_blank">https://www.ietf.org/archive/id/draft-hallambaker-donot=
issue-04.txt</a><span style=3D'color:#888888'><br><br><span =
class=3Dhoenzb>-- </span><br><span class=3Dhoenzb>Rob =
Stradling</span><br><span class=3Dhoenzb>Senior Research &amp; =
Development Scientist</span><br><span class=3Dhoenzb>COMODO - Creating =
Trust Online</span></span><o:p></o:p></p><div><div><p =
class=3DMsoNormal><br><br>_______________________________________________=
<br>Spasm mailing list<br><a href=3D"mailto:Spasm@ietf.org" =
target=3D"_blank">Spasm@ietf.org</a><br><a =
href=3D"https://www.ietf.org/mailman/listinfo/spasm" =
target=3D"_blank">https://www.ietf.org/mailman/listinfo/spasm</a><o:p></o=
:p></p></div></div></blockquote></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></div></body></html>
------=_NextPart_001_05E6_01D378A0.CE5DF180--

------=_NextPart_000_05E5_01D378A0.CE5DF180
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE5MTUxMDE3WjAvBgkqhkiG9w0BCQQxIgQgpHSf3QfyBjaESV9l2RQQCA5NOngi
wCqfmbKKPpWJQpAwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAEjxhhSsDOZCTLrNxlzFv4mRLWUFz/S77iacGs9AsT7Ht1zAJCugUbAoY31HLT0IRzYqTquo
qlaPdTf0qZU3d+0saRHSXPKA2gcdDgaQH5VkqwrhlF1aD+1EUqE6sVqAUM8gwV7bio7wNdvUSDMG
3ywYPJDf/5zYn738WV0gnobSaPpF4Lrxe7T4wwfvYxwkETyA0hP2VvTawdv8oJDYPzL40UGq34Ac
5n7Psn1iR/QLCNr3LJ6wCqa3RSrRO1tc5QrwdqDWxq9wz949c5BPCHLEQKgP5K0IRrK8PWl+rOyi
yh2DzGsq41z3vXVPn+nbAgBkElSoVd1usW/ilTAwynEAAAAAAAA=

------=_NextPart_000_05E5_01D378A0.CE5DF180--


From nobody Tue Dec 19 11:15:55 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC684126DED for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 11:15:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.498
X-Spam-Level: 
X-Spam-Status: No, score=-0.498 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_SORBS_WEB=1.5, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fzRoUCnsVLoC for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 11:15:52 -0800 (PST)
Received: from homiemail-a111.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C065D1200F1 for <spasm@ietf.org>; Tue, 19 Dec 2017 11:15:52 -0800 (PST)
Received: from homiemail-a111.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a111.g.dreamhost.com (Postfix) with ESMTP id 8BAB33C001C15 for <spasm@ietf.org>; Tue, 19 Dec 2017 11:15:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=Saz5B1a6A7joWFl16G3n9zVvFlU=; b= JaIpTqrZ5UnVuhYlTKK3qv5RmloiER9rNaPLgoAE2YKEBDbtvzmTyK7eGvwuc0kL Xm/8wYHu28VQcNwVmukQXtADAR2JcYI8d3d4vqh9b5K78uAJ8UkZDolvHumZzBXZ 6KHM9Gp7tzDELe8zgwT622hkvJ+AQAOdGQ9AMu4MPZg=
Received: from mail-it0-f45.google.com (mail-it0-f45.google.com [209.85.214.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a111.g.dreamhost.com (Postfix) with ESMTPSA id 7C6333C001C17 for <spasm@ietf.org>; Tue, 19 Dec 2017 11:15:52 -0800 (PST)
Received: by mail-it0-f45.google.com with SMTP id r6so4037099itr.3 for <spasm@ietf.org>; Tue, 19 Dec 2017 11:15:52 -0800 (PST)
X-Gm-Message-State: AKGB3mJ/FFfu0RWD4w3kghMxAs4XXRCInTeYFPFRgDstFEh1rvNwJ6/E +Mhogr7MeZDdTJhx3FhCsuLwQuWJYPTpIdaOEeQ=
X-Google-Smtp-Source: ACJfBoszJw4JeYTdNw2NiZk5OZxHVYK+vbSPd2vAYKZBsE1/4fx9vKrMmEiu3eIkjWHM5H86kyLzoAZRLXfN/S96Bro=
X-Received: by 10.36.74.134 with SMTP id k128mr4557747itb.93.1513710951667; Tue, 19 Dec 2017 11:15:51 -0800 (PST)
MIME-Version: 1.0
Received: by 10.2.78.70 with HTTP; Tue, 19 Dec 2017 11:15:50 -0800 (PST)
In-Reply-To: <DM5PR14MB12894853413B1055CEF6FA74830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com> <DM5PR14MB12894853413B1055CEF6FA74830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Tue, 19 Dec 2017 14:15:50 -0500
X-Gmail-Original-Message-ID: <CAErg=HG1S9LHhW03KeakaX50+eX5ztjH_uosvV1O4wcnPP83YA@mail.gmail.com>
Message-ID: <CAErg=HG1S9LHhW03KeakaX50+eX5ztjH_uosvV1O4wcnPP83YA@mail.gmail.com>
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: Ryan Sleevi <ryan-ietf@sleevi.com>, Jacob Hoffman-Andrews <jsha@eff.org>,  "spasm@ietf.org" <spasm@ietf.org>
Content-Type: multipart/alternative; boundary="001a1144918e9141820560b64b44"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/5mF_Huz5x1f7IJI6TatnJwU4MKg>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 19:15:54 -0000

--001a1144918e9141820560b64b44
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks for clarifying. From your original e-mail, it wasn't clear if you
were taking a particular position on the property tags vs parameters,
and/or what considerations fed into such discussions. That's where having
the problem statement (or 'explainer', as its called in some SDO circles)
and use cases is useful to explore these tradeoffs :)

On Tue, Dec 19, 2017 at 9:50 AM, Tim Hollebeek <tim.hollebeek@digicert.com>
wrote:

> As I noted in the preface to my initial email in this thread [1], one
> other person has pointed out the same thing to me.  I noted that not only
> is this an option, but it solves two problems with the original proposal,
> so I=E2=80=99m personally leaning towards it.  We=E2=80=99ll see what oth=
er CAs think.
>
>
>
> That is, why is the set of policy not
>
>
>
> CAA issue 0 "example.com"
>
> CAA issue 0 "example.net"
>
> CAA validation 128 "type=3DEV method=3D1,2,3,4"
>
>
>
> On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek <
> tim.hollebeek@digicert.com> wrote:
>
> Note that it has been privately pointed out to me that one possible
> solution to the criticality problem and the scaling problem is to use
> top-level tags that are independent of the issue records:
>
> CAA 0 issue =E2=80=9Ca.example.com=E2=80=9D
>
> CAA 0 issue =E2=80=9Cb.example.com=E2=80=9D
>
> CAA 128 validation =E2=80=9CPhone=E2=80=9D
>
>

--001a1144918e9141820560b64b44
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thanks for clarifying. From your original e-mail, it wasn&=
#39;t clear if you were taking a particular position on the property tags v=
s parameters, and/or what considerations fed into such discussions. That&#3=
9;s where having the problem statement (or &#39;explainer&#39;, as its call=
ed in some SDO circles) and use cases is useful to explore these tradeoffs =
:)</div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Tue, D=
ec 19, 2017 at 9:50 AM, Tim Hollebeek <span dir=3D"ltr">&lt;<a href=3D"mail=
to:tim.hollebeek@digicert.com" target=3D"_blank">tim.hollebeek@digicert.com=
</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin=
:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang=3D"EN-US=
" link=3D"blue" vlink=3D"purple"><div class=3D"m_-9148047207995763975WordSe=
ction1"><p class=3D"MsoNormal"><a name=3D"m_-9148047207995763975__MailEndCo=
mpose">As I noted in the preface to my initial email in this thread [1], on=
e other person has pointed out the same thing to me.=C2=A0 I noted that not=
 only is this an option, but it solves two problems with the original propo=
sal, so I=E2=80=99m personally leaning towards it.=C2=A0 We=E2=80=99ll see =
what other CAs think.<u></u><u></u></a></p><p class=3D"MsoNormal"><span><u>=
</u>=C2=A0<u></u></span></p><span></span><div style=3D"border:none;border-l=
eft:solid blue 1.5pt;padding:0in 0in 0in 4.0pt"><span class=3D""><div><div>=
<p class=3D"MsoNormal">That is, why is the set of policy not<u></u><u></u><=
/p></div><div><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p></div><div><p =
class=3D"MsoNormal">CAA issue 0 &quot;<a href=3D"http://example.com" target=
=3D"_blank">example.com</a>&quot;<u></u><u></u></p></div><div><p class=3D"M=
soNormal">CAA issue 0 &quot;<a href=3D"http://example.net" target=3D"_blank=
">example.net</a>&quot;<u></u><u></u></p></div><div><p class=3D"MsoNormal">=
CAA validation 128 &quot;type=3DEV method=3D1,2,3,4&quot;<u></u><u></u></p>=
</div><div><p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p></div></div></spa=
n><div><div><span class=3D""><p class=3D"MsoNormal">On Mon, Dec 18, 2017 at=
 12:41 PM, Tim Hollebeek &lt;<a href=3D"mailto:tim.hollebeek@digicert.com" =
target=3D"_blank">tim.hollebeek@digicert.com</a>&gt; wrote:<u></u><u></u></=
p></span><blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;p=
adding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in"><div><div><spa=
n class=3D""><p class=3D"m_-9148047207995763975m764002793901663091msoplaint=
ext">Note that it has been privately pointed out to me that one possible so=
lution to the criticality problem and the scaling problem is to use top-lev=
el tags that are independent of the issue records:<u></u><u></u></p></span>=
<p class=3D"MsoNormal"><span style=3D"background:yellow">CAA 0 issue =E2=80=
=9C<a href=3D"http://a.example.com" target=3D"_blank">a.example.com</a>=E2=
=80=9D<u></u><u></u></span></p><span class=3D""><p class=3D"MsoNormal"><spa=
n style=3D"background:yellow">CAA 0 issue =E2=80=9C<a href=3D"http://b.exam=
ple.com" target=3D"_blank">b.example.com</a>=E2=80=9D<u></u><u></u></span><=
/p><p class=3D"m_-9148047207995763975m764002793901663091msoplaintext"><span=
 style=3D"background:yellow">CAA 128 validation =E2=80=9CPhone=E2=80=9D</sp=
an><u></u><u></u></p></span></div></div></blockquote></div></div></div></di=
v></div></blockquote></div><br></div>

--001a1144918e9141820560b64b44--


From nobody Tue Dec 19 12:10:06 2017
Return-Path: <session-request@ietf.org>
X-Original-To: spasm@ietf.org
Delivered-To: spasm@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4102F126BF6; Tue, 19 Dec 2017 12:10:04 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Meeting Session Request Tool <session-request@ietf.org>
To: <session-request@ietf.org>
Cc: spasm@ietf.org, lamps-chairs@ietf.org, ekr@rtfm.com, housley@vigilsec.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.68.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151371420423.7447.4203117666033580625.idtracker@ietfa.amsl.com>
Date: Tue, 19 Dec 2017 12:10:04 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/-ICohc_vEJMTiGFMzENaheLXbFE>
Subject: [lamps] lamps - New Meeting Session Request for IETF 101
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 20:10:04 -0000

A new meeting session request has just been submitted by Russ Housley, a Chair of the lamps working group.


---------------------------------------------------------
Working Group Name: Limited Additional Mechanisms for PKIX and SMIME
Area Name: Security Area
Session Requester: Russ Housley

Number of Sessions: 1
Length of Session(s):  1 Hour
Number of Attendees: 50
Conflicts to Avoid: 
 First Priority: rtcweb ace acme stir ipwave tls sipbrandy sidrops saag perc quic curdle suit
 Second Priority: cfrg dprive ecrit oauth sacm mile modern radext
 Third Priority: mtgvenue iasa20


People who must be present:
  Russ Housley
  Eric Rescorla
  Sean Turner
  Jim Schaad

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Tue Dec 19 13:54:37 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DABE412D85F for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 13:54:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5oLm4TFhj4qd for <spasm@ietfa.amsl.com>; Tue, 19 Dec 2017 13:54:33 -0800 (PST)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C40AA1200FC for <spasm@ietf.org>; Tue, 19 Dec 2017 13:54:33 -0800 (PST)
Received: from [216.82.249.212] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-3.bemta-12.messagelabs.com id 93/66-13004-99A893A5; Tue, 19 Dec 2017 21:54:33 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WTfUxNYRzH73Nebke6drqVfu7k5Q4jKwpTmWl mtFmG0awZztVx7+G+OeeyzB+12lAX85KpuIWMrXmfNtNuViiKlUpTSUU0txEpuqScc5/r7Z9n n+f3/f5enmfPw5BaZ4CO4dMdvGjlzHp1IPVi2u2YqPzc+NT5972hcQXNXnXciU4Xiitq2Z5IJ n0c6KWTLl70EknZ5eXUWjKVFqwGW/o22lRRPUrZ27NR+sOTRwMy0aP9uWgcQ7H9BNRW6HJRIK Nl8wgYHahXK4KWfYCgrmSFwmp2PrS4awiFQ9lZ0H36Ca0wya6GsVdZlMIhbAR0vywnsWcKnKs cojGvhPc/BwncbCb0V57xsYbdDP21lync+C4BWSUnkSKMY9fB0fMNvqKInQjfaq8QuFk4tPUU +xjYUOh+VqfGHAbv34zS2L8ZXF+q/HE9tF8dRpgjoLHYiZRmwFYFwL36cr8pGsqOf/CbkuHRi xIS83UEnzxTMUdCXd2w378LhrJbaMwJcOh4DY2L3ifhR1O7nMzIm8nQ6VqI44fV0Jjj9l9pGu SV4ulCWB10NOegY2hO4T+HK5RzSLYYQe63NrLQd03B8Ligh8KmVHidlU9jjoRTVz3++Fy4dL5 P9jMyz4HqJv3/YYWXQP73SjXm6ZDn7A7AvAj6Hn5G59D4UjRb4sW9vBgVGx9tEAWjyWHhBHNU TExstIWXJM7ImzmDFL3dZrmF5GeYoVKhO2h0MLkKTWIIfZimY2l8qnaCwZa2z8RJpq3iHjMvV aHJDKMHjZAja8Eib+TTdwhm+S3/loEJ0odqShVZI9k5iyQYsVSLljFn3W0jBHOjtUNeK3zru4 K+TFJLWW1WXheuWaCksUqaaY/1T9Hff6QRRehCNEilUmmD7LxoERz/6x4UziB9iGaVUiVIsDr +9PbIYxHyWKc2LVbGcnB/JV0myksZX3btbUXXUqY14868tLGk/iNrt3TtMsyot4c/ZbYZFy6v v/6zrME29cm0DSnVriIxMXCGrvQwTFox92bk2eTEkaALCQfUt3ceHPZkSCkFCcG7x4Qxr8vtj B268H39jY12QbvSSbifXz5Qk/jZO5J55euthiWu6rtp+1PW9LX32vSUZOJiIklR4n4BqmCNbh 4EAAA=
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-7.tower-219.messagelabs.com!1513720471!197665882!1
X-Originating-IP: [216.32.180.49]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 2309 invoked from network); 19 Dec 2017 21:54:32 -0000
Received: from mail-by2nam03lp0049.outbound.protection.outlook.com (HELO NAM03-BY2-obe.outbound.protection.outlook.com) (216.32.180.49) by server-7.tower-219.messagelabs.com with AES256-SHA256 encrypted SMTP; 19 Dec 2017 21:54:32 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=QNzCQp1yfY3qIcoOz2D5pvEqA5pUoIuNIhZpPlouDb4=; b=EiRHObds3/NBIhlXN14YeKkgbzdL4qkw5GVYpdjOPOsFwd1iXc2wzDKamHGQFxWzEVPQodAqNFiehM15LmNk5lcpozkve7PL7MgYVehqOF6QBeyi4nQkxWbPDaK35it5IXpQX8xfAEGXSSa47y4dJmhYQSF5vlrEOQyc1M8/1jU=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1292.namprd14.prod.outlook.com (10.173.132.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Tue, 19 Dec 2017 21:54:30 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Tue, 19 Dec 2017 21:54:30 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
CC: Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] CAA tags
Thread-Index: AdN4J3TZ60fppeKgRNaOHREkYP39nwArdI8AAAC/MGAACWEFAAAFdUWw
Date: Tue, 19 Dec 2017 21:54:30 +0000
Message-ID: <DM5PR14MB1289D721D278D96821FE305F830F0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <DM5PR14MB1289FA2B76543ABAF16FD0EF830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HEL93NpPjEZnAFQD3Epk5dHW41qmXJGOPA_7wvKvmsGJA@mail.gmail.com> <DM5PR14MB12894853413B1055CEF6FA74830F0@DM5PR14MB1289.namprd14.prod.outlook.com> <CAErg=HG1S9LHhW03KeakaX50+eX5ztjH_uosvV1O4wcnPP83YA@mail.gmail.com>
In-Reply-To: <CAErg=HG1S9LHhW03KeakaX50+eX5ztjH_uosvV1O4wcnPP83YA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1292; 6:EkMZcWQEGQBr1JGJAkWX+C7Qmo3O8lv/3avfWysd232jgcl0gMgT6t/XjHYf9fFq+vaMkho4uHU6axWyiHLX6oJNUcKb/uCX3T/O7yTaSH0t9Z6AtlySz+E+x4y/sREZvXsVYdr/Fd3jn6PV8EtoKMGUj5eMgkyJUMmoBWkWmqFDyyK20AALcR/hsyD9+4H7iARc2/5HvRCZuWoJJHfCVCkv7NClCW6Up4Cs9btYXgzvXhnfKo/+C/RCNfr/Ys/HS7ZB4R+u5PHSS2GBTeN60zjfXP23Ou0S4Y/lf6Jodxrj3pDq1PFzGADf47miUhELCFpM+p7/rji4TM4qX59cKBEYruB9D/XwB289v/GDJJk=; 5:9eklxcfLarT2Npum+PQikdJgJgrPQY4lAa04tORjkN60U4J0cck6RJdXUwiNAvJm3XXUzeXKD4G+Nu4jIzbX1g7IF8nrYn7mOWomRdudfW+kOg+rf8gXDDbz+VkQTULUpim8/2Jzsxq8/iv0Ft1M6HUYI8Erar6DuMj+JmRPRRk=; 24:IwAzTdU9R4jeOaZbgFLNt2aaJ6g8xyXxhQzD2zSwPBPLmFrXYE84beiBtfMhH+PGvgNOroshqU1AKjI+3lxwIxRm8rmgZzVsDxRy14AfQg4=; 7:3AYTRw7i4ukDI6QQJCerquMGF/qMT4lVsbd37YFFeEzSqFWRjpV38CsV7kWaQRReFVyxDREaz0XMfMxvYd5N1m3lv0olVWnZyf6cyZeZ2aqoV7v6eSUdh8685cIuOG09qGC8gc/zZU3Qujr/qjOe5+xV3dW7WDaSRWuip77J1ejjqsmSpJbS5Dtei6LUdCfQZZWowFvPd1FU+gRLRSPwHjoQIyrXzNog6Z4sHxOXiUA2xwG3nvB2bbdmAkXW4du2
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 663b6cbb-870f-401b-dce1-08d5472b1536
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(4534020)(4602075)(4603075)(4627115)(201702281549075)(5600026)(4604075)(2017052603307)(7153060)(49563074); SRVR:DM5PR14MB1292; 
x-ms-traffictypediagnostic: DM5PR14MB1292:
x-microsoft-antispam-prvs: <DM5PR14MB1292FDD4699C7612DD52320C830F0@DM5PR14MB1292.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040450)(2401047)(5005006)(8121501046)(3002001)(3231023)(10201501046)(93006095)(93001095)(6041248)(20161123558100)(20161123555025)(20161123564025)(20161123560025)(2016111802025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(6043046)(201708071742011); SRVR:DM5PR14MB1292; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1292; 
x-forefront-prvs: 052670E5A4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(346002)(396003)(366004)(39860400002)(376002)(189003)(199004)(24454002)(229853002)(66066001)(81156014)(106356001)(25786009)(77096006)(93886005)(3660700001)(9686003)(236005)(54896002)(2900100001)(53386004)(8676002)(3280700002)(4326008)(3846002)(55016002)(790700001)(5660300001)(102836003)(6116002)(99936001)(105586002)(33656002)(606006)(2950100002)(68736007)(2906002)(59450400001)(53546011)(478600001)(86362001)(97736004)(7736002)(6306002)(14454004)(54906003)(6436002)(76176011)(81166006)(6506007)(53936002)(8936002)(74316002)(316002)(99286004)(6246003)(7696005)(561944003)(6916009)(19400905002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1292; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_0718_01D378D9.41A2A1D0"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 663b6cbb-870f-401b-dce1-08d5472b1536
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Dec 2017 21:54:30.6782 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1292
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/17LEaVnYPbbrGahN1twWa_bXqgs>
Subject: Re: [lamps] CAA tags
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 21:54:36 -0000

------=_NextPart_000_0718_01D378D9.41A2A1D0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0719_01D378D9.41A2A1D0"


------=_NextPart_001_0719_01D378D9.41A2A1D0
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Yup.  That=E2=80=99s why I=E2=80=99m not writing a spec right now.  =
I=E2=80=99m always open to reasonable feedback on anything that makes my =
proposals better.  I rarely get things entirely right the first time!

=20

-Tim

=20

From: Ryan Sleevi [mailto:ryan-ietf@sleevi.com]=20
Sent: Tuesday, December 19, 2017 12:16 PM
To: Tim Hollebeek <tim.hollebeek@digicert.com>
Cc: Ryan Sleevi <ryan-ietf@sleevi.com>; Jacob Hoffman-Andrews =
<jsha@eff.org>; spasm@ietf.org
Subject: Re: [lamps] CAA tags

=20

Thanks for clarifying. From your original e-mail, it wasn't clear if you =
were taking a particular position on the property tags vs parameters, =
and/or what considerations fed into such discussions. That's where =
having the problem statement (or 'explainer', as its called in some SDO =
circles) and use cases is useful to explore these tradeoffs :)

=20

On Tue, Dec 19, 2017 at 9:50 AM, Tim Hollebeek =
<tim.hollebeek@digicert.com <mailto:tim.hollebeek@digicert.com> > wrote:

As I noted in the preface to my initial email in this thread [1], one =
other person has pointed out the same thing to me.  I noted that not =
only is this an option, but it solves two problems with the original =
proposal, so I=E2=80=99m personally leaning towards it.  We=E2=80=99ll =
see what other CAs think.

=20

That is, why is the set of policy not

=20

CAA issue 0 "example.com <http://example.com> "

CAA issue 0 "example.net <http://example.net> "

CAA validation 128 "type=3DEV method=3D1,2,3,4"

=20

On Mon, Dec 18, 2017 at 12:41 PM, Tim Hollebeek =
<tim.hollebeek@digicert.com <mailto:tim.hollebeek@digicert.com> > wrote:

Note that it has been privately pointed out to me that one possible =
solution to the criticality problem and the scaling problem is to use =
top-level tags that are independent of the issue records:

CAA 0 issue =E2=80=9C <http://a.example.com> a.example.com=E2=80=9D

CAA 0 issue =E2=80=9C <http://b.example.com> b.example.com=E2=80=9D

CAA 128 validation =E2=80=9CPhone=E2=80=9D

=20


------=_NextPart_001_0719_01D378D9.41A2A1D0
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
p.m-9148047207995763975m764002793901663091msoplaintext, =
li.m-9148047207995763975m764002793901663091msoplaintext, =
div.m-9148047207995763975m764002793901663091msoplaintext
	{mso-style-name:m_-9148047207995763975m764002793901663091msoplaintext;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal>Yup.=C2=A0 =
That=E2=80=99s why I=E2=80=99m not writing a spec right now.=C2=A0 =
I=E2=80=99m always open to reasonable feedback on anything that makes my =
proposals better. =C2=A0I rarely get things entirely right the first =
time!<o:p></o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>-Tim<o:p></o:p></p><p class=3DMsoNormal><a =
name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a></p><span =
style=3D'mso-bookmark:_MailEndCompose'></span><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #E1E1E1 =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b>From:</b> Ryan =
Sleevi [mailto:ryan-ietf@sleevi.com] <br><b>Sent:</b> Tuesday, December =
19, 2017 12:16 PM<br><b>To:</b> Tim Hollebeek =
&lt;tim.hollebeek@digicert.com&gt;<br><b>Cc:</b> Ryan Sleevi =
&lt;ryan-ietf@sleevi.com&gt;; Jacob Hoffman-Andrews =
&lt;jsha@eff.org&gt;; spasm@ietf.org<br><b>Subject:</b> Re: [lamps] CAA =
tags<o:p></o:p></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>Thanks =
for clarifying. From your original e-mail, it wasn't clear if you were =
taking a particular position on the property tags vs parameters, and/or =
what considerations fed into such discussions. That's where having the =
problem statement (or 'explainer', as its called in some SDO circles) =
and use cases is useful to explore these tradeoffs =
:)<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>On Tue, =
Dec 19, 2017 at 9:50 AM, Tim Hollebeek &lt;<a =
href=3D"mailto:tim.hollebeek@digicert.com" =
target=3D"_blank">tim.hollebeek@digicert.com</a>&gt; =
wrote:<o:p></o:p></p><blockquote style=3D'border:none;border-left:solid =
#CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5=
.0pt'><div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><a =
name=3D"m_-9148047207995763975__MailEndCompose">As I noted in the =
preface to my initial email in this thread [1], one other person has =
pointed out the same thing to me.&nbsp; I noted that not only is this an =
option, but it solves two problems with the original proposal, so =
I=E2=80=99m personally leaning towards it.&nbsp; We=E2=80=99ll see what =
other CAs think.</a><o:p></o:p></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p><div style=3D'border:none;border-left:solid blue =
1.5pt;padding:0in 0in 0in 4.0pt'><div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>That is, =
why is the set of policy not<o:p></o:p></p></div><div><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p></div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>CAA issue 0 =
&quot;<a href=3D"http://example.com" =
target=3D"_blank">example.com</a>&quot;<o:p></o:p></p></div><div><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>CAA issue 0 =
&quot;<a href=3D"http://example.net" =
target=3D"_blank">example.net</a>&quot;<o:p></o:p></p></div><div><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>CAA =
validation 128 &quot;type=3DEV =
method=3D1,2,3,4&quot;<o:p></o:p></p></div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p></div></div><div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>On Mon, Dec =
18, 2017 at 12:41 PM, Tim Hollebeek &lt;<a =
href=3D"mailto:tim.hollebeek@digicert.com" =
target=3D"_blank">tim.hollebeek@digicert.com</a>&gt; =
wrote:<o:p></o:p></p><blockquote style=3D'border:none;border-left:solid =
#CCCCCC 1.0pt;padding:0in 0in 0in =
6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5=
.0pt'><div><div><p =
class=3Dm-9148047207995763975m764002793901663091msoplaintext>Note that =
it has been privately pointed out to me that one possible solution to =
the criticality problem and the scaling problem is to use top-level tags =
that are independent of the issue records:<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'background:yellow'>CAA 0 issue =E2=80=9C</span><a =
href=3D"http://a.example.com" target=3D"_blank"><span =
style=3D'background:yellow'>a.example.com</span></a><span =
style=3D'background:yellow'>=E2=80=9D</span><o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'background:yellow'>CAA 0 issue =E2=80=9C</span><a =
href=3D"http://b.example.com" target=3D"_blank"><span =
style=3D'background:yellow'>b.example.com</span></a><span =
style=3D'background:yellow'>=E2=80=9D</span><o:p></o:p></p><p =
class=3Dm-9148047207995763975m764002793901663091msoplaintext><span =
style=3D'background:yellow'>CAA 128 validation =
=E2=80=9CPhone=E2=80=9D</span><o:p></o:p></p></div></div></blockquote></d=
iv></div></div></div></div></blockquote></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></div></body></html>
------=_NextPart_001_0719_01D378D9.41A2A1D0--

------=_NextPart_000_0718_01D378D9.41A2A1D0
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjE5MjE1NDIyWjAvBgkqhkiG9w0BCQQxIgQgCbvULL+Lgm8EN5YxB2g38tigoRnt
/XPboSPIvR43UucwgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBACxaaOOyWmyWoSl5VlloUNlMRx7ed08rE8t9vVwpGkekdbzTXniKizPmpf7CqfFPR3jDoUoR
5oRllIhEQ1qBjPev6jwjy3Aum+1KEWCCLfhWrzo7oDfRRIVcBdn3Kwd/JNl1osToIXokw+JlwRCB
b1uDXDJJxDs15cJPi7dCdJUWyEleipyqyL+Q4qR7OyLdjJMJuXXzISxKqaeO9wc59rWU1hK26xNB
SvePebQ5WqkdfTC0icy0ElxTDnO6IohOJowKPCcPW+jrXN0Buno9vN2CUdBQkvRBGGspMVhJ0BPx
Iv7ClKQ2Dfs+5Rmz/2696PZxwpv8MjHhoy1liGZzO30AAAAAAAA=

------=_NextPart_000_0718_01D378D9.41A2A1D0--


From nobody Wed Dec 20 08:03:42 2017
Return-Path: <CBonnell@trustwave.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 980E512711E for <spasm@ietfa.amsl.com>; Wed, 20 Dec 2017 08:03:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level: 
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B7U64MoEhO5U for <spasm@ietfa.amsl.com>; Wed, 20 Dec 2017 08:03:38 -0800 (PST)
Received: from seg-node-chi-01.trustwave.com (seg-node-chi-01.trustwave.com [204.13.200.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64DDA1270A7 for <spasm@ietf.org>; Wed, 20 Dec 2017 08:03:38 -0800 (PST)
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (Not Verified[207.46.163.54]) by seg-node-chi-01.trustwave.com with Trustwave SEG (v7, 5, 7, 10058) (using TLS: TLSv1.2, AES256-SHA256) id <B5a3a89d60004>; Wed, 20 Dec 2017 10:03:35 -0600
Received: from CY4PR07MB3575.namprd07.prod.outlook.com (10.171.253.14) by CY4PR07MB3574.namprd07.prod.outlook.com (10.171.253.13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.345.14; Wed, 20 Dec 2017 16:03:31 +0000
Received: from CY4PR07MB3575.namprd07.prod.outlook.com ([10.171.253.14]) by CY4PR07MB3575.namprd07.prod.outlook.com ([10.171.253.14]) with mapi id 15.20.0345.013; Wed, 20 Dec 2017 16:03:31 +0000
From: Corey Bonnell <CBonnell@trustwave.com>
To: Tim Hollebeek <tim.hollebeek@digicert.com>, Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
Thread-Index: AQHTcFCvZLA3Ba+SlEGgXjxULsQnaqNFZbiAgAPWDYCAAufvAA==
Date: Wed, 20 Dec 2017 16:03:31 +0000
Message-ID: <B94567AD-1DB4-4508-B629-F7F760237A15@trustwave.com>
References: <20171208180055.ACB1EB81ACE@rfc-editor.org> <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com> <ad5b6045-84ba-32b3-7739-b2464fc40c2f@eff.org> <DM5PR14MB128950E8291574FAA0161BC8830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
In-Reply-To: <DM5PR14MB128950E8291574FAA0161BC8830E0@DM5PR14MB1289.namprd14.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=CBonnell@trustwave.com; 
x-originating-ip: [204.13.202.248]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR07MB3574; 6:egWGwQuCwPkObZFTFsey6BJBKK/u6ddM5lBVoZkmrj2d2kOywuey4P6ByUb3KRaYFJzRaAY1BTujLjr8vyJhFmXIpmBWrItIluvHEtVPrrm+lHTkDcyBuFAhBR1RQwNKV4DiciCOp+IJ/Sz2KzTtc56O0fPH+TbdBaIqHHzs6aBoT6a1yuw6mwXgBvF7Pnljnldutk9ZSOCta/YyxRa6YAhDbgy6MUCrhCOBakzLMnYT710QLAJygMzOwElUhAWhErD0EVv96eKdNAtEP5nCsAkXXGVlQJYmq5/u+SvzBoysmwil+L+3TAZGIixBH4ldF4xjCY/2PYIKHXE8XTA4z5tK9gGmlhoGa8lrVceJbL4=; 5:KCeTrVoP23QvkfWzfagwbtZnGkwsSsGu4U+SMXuHRaTbQceipke2YJs59q/ICFlPdfFASHPsc6u1M0JpQLjvPLi+R8rhsXPof62XTtFXRCstH0XpT3afrUMw7oU8NqCAizPVf1sPF3+BRs/iTlX1UfSzEZrGxOCGIBBqKBYHy4U=; 24:VwLhdG/jCB0FGtLOfBsZx/FmLKLzEiTP2lw9fNa+UgyFaVjDiWkeb5lyyCWzuLB+llddmY2XGwoV1y+tJIDUIkN62ZE4zEdb4nhfuhgGctw=; 7:uYeH7yvhSCXEjEvXgPUZZAarYPd9nMoBI2qxFQ0wpBUAKgLU+pv+wSCPNMAnjb92yeVgS2Qes1JKd/OM3pnlIE7nyiKNFFS9STbL4ZebsIc4AOLhXg55cFJJEaPvAfO9Pj4pscYHZsZiQkM5JLQsdqeqDjYeQXW99Z4mHcoik2Si54JamjSiiNIUFJECdHYeBeCONR5VMAvlb1w3F+u6l1dku79ld0wRFujyscldvh7q3oPwwlHXkiEiUCTEql4X
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 01db15e8-fc5e-471b-a6ff-08d547c3373f
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4627115)(201703031133081)(201702281549075)(2017052603307)(7153060); SRVR:CY4PR07MB3574; 
x-ms-traffictypediagnostic: CY4PR07MB3574:
x-microsoft-antispam-prvs: <CY4PR07MB35748EFDF012475B161F5463CF0C0@CY4PR07MB3574.namprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(232896897485771)(192374486261705)(171964332516350); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040470)(2401047)(8121501046)(5005006)(3002001)(93006095)(93001095)(10201501046)(3231023)(6041268)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123564045)(20161123562045)(20161123558120)(6072148)(201708071742011); SRVR:CY4PR07MB3574; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:CY4PR07MB3574; 
x-forefront-prvs: 0527DFA348
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(979002)(376002)(39380400002)(39860400002)(396003)(346002)(366004)(24454002)(13464003)(199004)(189003)(6246003)(80792005)(6436002)(99286004)(2906002)(229853002)(97736004)(2900100001)(77096006)(6486002)(66066001)(316002)(53936002)(110136005)(5660300001)(14454004)(81166006)(8676002)(8936002)(81156014)(93886005)(68736007)(2950100002)(25786009)(33656002)(76176011)(83716003)(53546011)(3660700001)(3846002)(105586002)(3280700002)(59450400001)(72206003)(478600001)(102836003)(6116002)(36756003)(561944003)(6506007)(2501003)(106356001)(82746002)(6306002)(6512007)(7736002)(966005)(305945005)(86362001)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR07MB3574; H:CY4PR07MB3575.namprd07.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: trustwave.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <8EBE74A6F5BC9F479BC294CE45966A33@namprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: trustwave.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 01db15e8-fc5e-471b-a6ff-08d547c3373f
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Dec 2017 16:03:31.2187 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cb1dab68-a067-4b6b-ae7e-c012e8c33f6a
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR07MB3574
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/KU4u-utnrGZDjq7Cu9Sg_RSh1c4>
Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 16:03:41 -0000

QWZ0ZXIgdGhpbmtpbmcgYWJvdXQgdGhpcyBmdXJ0aGVyLCBJ4oCZbSBpbiBmYXZvciBvZiB1c2lu
ZyBzZW1pY29sb25zIHRvIGRlbGltaXQgcGFyYW1ldGVycywgYXMgVGltIG1lbnRpb25lZCB0aGF0
IHdlIGxpa2VseSBuZWVkIHRvIGNvbnRpbnVlIHVzaW5nIHRoZSBzZW1pY29sb24gdG8gZGVsaW1p
dCB0aGUgaWRlbnRpZnlpbmcgZG9tYWluIG5hbWUgZnJvbSB0aGUgcGFyYW1ldGVyIGxpc3QgZHVl
IHRvIGl0cyBjdXJyZW50IHViaXF1aXR5LiBJdCB3b3VsZCBiZSBpbmNvbnNpc3RlbnQgdG8gdXNl
IGEgc2VtaWNvbG9uIHRvIGRlbGltaXQgdGhlIGlkZW50aWZ5aW5nIGRvbWFpbiBuYW1lIGZyb20g
dGhlIHBhcmFtZXRlciBsaXN0IGJ1dCBhbHNvIG1hbmRhdGUgdGhhdCBwYXJhbWV0ZXIgbmFtZS92
YWx1ZSBwYWlycyBiZSBkZWxpbWl0ZWQgdXNpbmcgd2hpdGVzcGFjZS4gVGhhdCBiZWluZyBzYWlk
LCBJIGxpa2UgdGhlIGlkZWEgdGhhdCBub24tc2lnbmlmaWNhbnQgd2hpdGVzcGFjZSBjYW4gYmUg
dXNlZCBpbiByZWNvcmRzIHRvIGltcHJvdmUgaHVtYW4gcmVhZGFiaWxpdHkuDQoNCkdpdmVuIHRo
YXQgUkZDIDUyMzQgcHJvaGliaXRzIHRoZSB1c2Ugb2YgaW1wbGljaXQg4oCcbGluZWFyIHdoaXRl
IHNwYWNl4oCdIGluIHNlY3Rpb24gMy4xIChodHRwOi8vd3d3LnJmY3JlYWRlci5jb20vI3JmYzUy
MzRfbGluZTIwNCksIFJGQyA2ODQ0IG11c3QgZXhwbGljaXRseSBzdGF0ZSBpbiB0aGUgcHJvZHVj
dGlvbiBydWxlcyB0aGF0IG5vbi1zaWduaWZpY2FudCB3aGl0ZXNwYWNlIGlzIHN1cHBvcnRlZC4g
V2l0aCB0aGF0IGluIG1pbmQsIEkgYmVsaWV2ZSB0aGF0IHRoZSBBQk5GIHByb2R1Y3Rpb24gcnVs
ZXMgaW4gUkZDIDY4NDQgc2VjdGlvbiA1LjEgKGh0dHA6Ly93d3cucmZjcmVhZGVyLmNvbS8jcmZj
Njg0NF9saW5lNDQ3KSBmb3Ig4oCcaXNzdWV2YWx1ZeKAnSBzaG91bGQgYmUgbW9kaWZpZWQgdG8g
c29tZXRoaW5nIHNpbWlsYXIgdG8gdGhpczoNCg0KaXNzdWV2YWx1ZSA9ICpXU1AgW2RvbWFpbl0g
KldTUCBbIjsiICpXU1AgW3BhcmFtZXRlcnNdICpXU1BdDQpwYXJhbWV0ZXJzID0gKHBhcmFtZXRl
ciAqV1NQIOKAnDvigJ0gKldTUCBwYXJhbWV0ZXJzKSAvIHBhcmFtZXRlcg0KcGFyYW1ldGVyID0g
dGFnICI9IiB2YWx1ZQ0KdGFnID0gMSooQUxQSEEgLyBESUdJVCkNCnZhbHVlID0gKigleDIxLTNB
IC8gJXgzQy03RSkNCg0KKFRoZSDigJxwYXJhbWV0ZXLigJ0gYW5kIOKAnHRhZ+KAnSBwcm9kdWN0
aW9uIHJ1bGVzIGFyZSB1bmNoYW5nZWQgYnV0IEkgbGlzdGVkIHRoZW0gaGVyZSB0byBsaXN0IHRo
ZSByZWxldmFudCBydWxlcyBpbiBvbmUgcGxhY2UuKQ0KDQpOb3RlIHRoYXQgSSByZW1vdmVkIHRo
ZSDigJxzcGFjZeKAnSBwcm9kdWN0aW9uIHJ1bGUsIGFzIFJGQyA1MjM0IHByb3ZpZGVzIHVzIHdp
dGggYSBuZWFybHkgaWRlbnRpY2FsIChkaWZmZXJpbmcgb25seSBpbiB0aGUgbnVtYmVyIG9mIGFs
bG93ZWQgcmVwZXRpdGlvbnMsIGJ1dCB0aGUgY2hhcmFjdGVyIGNsYXNzIGlzIHRoZSBzYW1lKSDi
gJxXU1DigJ0gcnVsZSBpbiBpdHMgY29yZSBtb2R1bGUgKGh0dHA6Ly93d3cucmZjcmVhZGVyLmNv
bS8jcmZjNTIzNF9saW5lNTIwKS4gQWxzbyBub3RlIHRoYXQgSSBtb2RpZmllZCB0aGUg4oCcdmFs
dWXigJ0gcnVsZSwgYXMgd2UgbmVlZCB0byBleGNsdWRlIHRoZSBzZW1pY29sb24gKEFTQ0lJIGNv
ZGUgMHgzQikgZnJvbSB0aGUgc2V0IG9mIGFsbG93ZWQgY2hhcmFjdGVycyBpbiBwYXJhbWV0ZXIg
dmFsdWVzLg0KDQpUaGFua3MsDQpDb3JleQ0KIA0KQ29yZXkgQm9ubmVsbA0KU2VuaW9yIFNvZnR3
YXJlIEVuZ2luZWVyDQoNClRydXN0d2F2ZSB8IFNNQVJUIFNFQ1VSSVRZIE9OIERFTUFORHd3dy50
cnVzdHdhdmUuY29tIDxodHRwOi8vd3d3LnRydXN0d2F2ZS5jb20vPg0KIA0KMjAxNyBCZXN0IE1h
bmFnZWQgU2VjdXJpdHkgU2VydmljZSBXaW5uZXIg4oCTIFNDIE1lZGlhDQoNCk9uIDEyLzE4LzE3
LCA5OjQxIEFNLCAiU3Bhc20gb24gYmVoYWxmIG9mIFRpbSBIb2xsZWJlZWsiIDxzcGFzbS1ib3Vu
Y2VzQGlldGYub3JnIG9uIGJlaGFsZiBvZiB0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbT4gd3Jv
dGU6DQoNCiAgICBBcyBwb2ludGVkIG91dCBvbiB0aGUgY2FiZl92YWxpZGF0aW9uIGxpc3QsIHRo
ZSBvcmlnaW5hbCB0ZXh0IGlzbid0IGp1c3QNCiAgICBhbWJpZ3VvdXMsIHRoZSBSRkMgY29udHJh
ZGljdHMgaXRzZWxmLiAgSSBkb24ndCBmZWVsIHRvbyBzdHJvbmdseSBlaXRoZXINCiAgICB3YXks
IGFzIGxvbmcgYXMgaXQgZ2V0cyByZXNvbHZlZCBzb29uLCBhcyBwcm9wZXJ0eSB0YWdzIGFyZSBh
Ym91dCB0byBiZWNvbWUNCiAgICBjb21tb25seSBkZXBsb3llZCAodGhlcmUgd2VyZSBzZXZlcmFs
IHByb3Bvc2VkIHVzZXMgZGlzY3Vzc2VkIGF0IHRoZSBUYWlwZWkNCiAgICBmYWNlLXRvLWZhY2Ug
bWVldGluZyBvZiB0aGUgQ0EvQnJvd3NlciBmb3J1bSkuDQogICAgDQogICAgSSBkbyBob3dldmVy
IGhhdmUgYSBzbGlnaHQgcHJlZmVyZW5jZSBmb3Igb25seSBoYXZpbmcgYSBzaW5nbGUgc2VwYXJh
dG9yDQogICAgKHdoaXRlc3BhY2UpLCBub3QgdHdvIGluIG9yZGVyIHRvIGF2b2lkIGNvbmZ1c2lv
biBhYm91dCB3aGF0IHRvIGRvIGFib3V0DQogICAgd2hpdGVzcGFjZSBhZnRlciBzZW1pY29sb25z
IGFuZCBhcm91bmQgPSBzaWducy4NCiAgICANCiAgICBUaGUgc2VtaWNvbG9uIGRvZXNuJ3QgcmVh
bGx5IHNlcnZlIGEgdXNlZnVsIHB1cnBvc2UsIHRob3VnaCB3ZSBkbyBoYXZlIHRvDQogICAga2Vl
cCBvbmUgc2luY2UgdGhlcmUgYXJlIGV4aXN0aW5nIENBQSByZWNvcmRzIG91dCB0aGVyZSB0aGF0
IHVzZSBpdC4gIEknZA0KICAgIGxpa2UgdGhlIGdyYW1tYXIgdG8gZXNzZW50aWFsbHkgYmU6DQog
ICAgDQogICAgICAgIGRvbWFpbiA7IFtuYW1lID0gdmFsdWVdKw0KICAgIA0KICAgIHdpdGggdGhl
IGNsYXJpZmljYXRpb24gdGhhdCB3aGl0ZXNwYWNlIGlzIGlnbm9yZWQuDQogICAgDQogICAgU28g
bXkgcGVyc29uYWwgcHJlZmVyZW5jZSBpcyB0aGUgZmlyc3Qgc3R5bGUgeW91IG1lbnRpb25lZCwg
aW4gbGluZSB3aXRoIHRoZQ0KICAgIHN1Ym1pdHRlZCBlcnJhdGE6DQogICAgDQogICAgICAgIGh0
dHA6Ly9zY2FubWFpbC50cnVzdHdhdmUuY29tLz9jPTQwNjImZD1nTk8zMnNGSGVsdUljTG02WGRt
ckFnN2p3NGx6SkZ1U2RnTVp6eXY5UFEmcz01JnU9aHR0cCUzYSUyZiUyZmV4YW1wbGUlMmVjb20g
SU4gQ0FBIDAgaXNzdWUgImh0dHA6Ly9zY2FubWFpbC50cnVzdHdhdmUuY29tLz9jPTQwNjImZD1n
Tk8zMnNGSGVsdUljTG02WGRtckFnN2p3NGx6SkZ1U2RsZE9uMzMtYWcmcz01JnU9aHR0cCUzYSUy
ZiUyZmV4YW1wbGUlMmVuZXQlM2IgZm9vPWJhciBiYXI9cXV4Ig0KICAgIA0KICAgIEl0J3MgdGhl
IHN0eWxlIEkgdXNlZCBpbiBteSBwcm9wb3NhbCBmb3IgaW5kdXN0cnkgc3RhbmRhcmQgcHJvcGVy
dHkgdGFnDQogICAgbmFtZXMgb24gY2FiZl92YWxpZGF0aW9uIGxhc3Qgd2Vlay4NCiAgICANCiAg
ICAtVGltDQogICAgDQogICAgPiAtLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KICAgID4gRnJv
bTogU3Bhc20gW21haWx0bzpzcGFzbS1ib3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSmFj
b2IgSG9mZm1hbi0NCiAgICA+IEFuZHJld3MNCiAgICA+IFNlbnQ6IEZyaWRheSwgRGVjZW1iZXIg
MTUsIDIwMTcgOTowNiBQTQ0KICAgID4gVG86IHNwYXNtQGlldGYub3JnDQogICAgPiBTdWJqZWN0
OiBSZTogW2xhbXBzXSBGd2Q6IFtwa2l4XSBbVGVjaG5pY2FsIEVycmF0YSBSZXBvcnRlZF0gUkZD
Njg0NA0KICAgICg1MjAwKQ0KICAgID4gDQogICAgPiBPbiAxMi8wOC8yMDE3IDEwOjE2IEFNLCBS
dXNzIEhvdXNsZXkgd3JvdGU6DQogICAgPiA+IGh0dHA6Ly9zY2FubWFpbC50cnVzdHdhdmUuY29t
Lz9jPTQwNjImZD1nTk8zMnNGSGVsdUljTG02WGRtckFnN2p3NGx6SkZ1U2RsSlB5U3F1YUEmcz01
JnU9aHR0cCUzYSUyZiUyZnd3dyUyZXJmYy1lZGl0b3IlMmVvcmclMmZlcnJhdGElMmZlaWQ1MjAw
DQogICAgPiANCiAgICA+IFRoZSBxdWVzdGlvbiBoZXJlIGlzIHdoZXRoZXIgQ0FBIHJlY29yZHMg
d2l0aCBwcm9wZXJ0eSB0YWdzIHNob3VsZCBsb29rDQogICAgPiBsaWtlOg0KICAgID4gDQogICAg
PiBodHRwOi8vc2Nhbm1haWwudHJ1c3R3YXZlLmNvbS8/Yz00MDYyJmQ9Z05PMzJzRkhlbHVJY0xt
NlhkbXJBZzdqdzRsekpGdVNkZ01aenl2OVBRJnM9NSZ1PWh0dHAlM2ElMmYlMmZleGFtcGxlJTJl
Y29tIElOIENBQSAwIGlzc3VlICJodHRwOi8vc2Nhbm1haWwudHJ1c3R3YXZlLmNvbS8/Yz00MDYy
JmQ9Z05PMzJzRkhlbHVJY0xtNlhkbXJBZzdqdzRsekpGdVNkbGRPbjMzLWFnJnM9NSZ1PWh0dHAl
M2ElMmYlMmZleGFtcGxlJTJlbmV0JTNiIGZvbz1iYXIgYmFyPXF1eCINCiAgICA+IA0KICAgID4g
b3I6DQogICAgPiANCiAgICA+IGh0dHA6Ly9zY2FubWFpbC50cnVzdHdhdmUuY29tLz9jPTQwNjIm
ZD1nTk8zMnNGSGVsdUljTG02WGRtckFnN2p3NGx6SkZ1U2RnTVp6eXY5UFEmcz01JnU9aHR0cCUz
YSUyZiUyZmV4YW1wbGUlMmVjb20gSU4gQ0FBIDAgaXNzdWUgImh0dHA6Ly9zY2FubWFpbC50cnVz
dHdhdmUuY29tLz9jPTQwNjImZD1nTk8zMnNGSGVsdUljTG02WGRtckFnN2p3NGx6SkZ1U2RsZE9u
MzMtYWcmcz01JnU9aHR0cCUzYSUyZiUyZmV4YW1wbGUlMmVuZXQlM2IgZm9vPWJhcjsgYmFyPXF1
eCINCiAgICA+IA0KICAgID4gKG5vdGUgdGhlIHNlY29uZCBzZW1pY29sb24pDQogICAgPiANCiAg
ICA+IEkgdGhpbmsgdGhlIG9yaWdpbmFsIHRleHQgaXMgYW1iaWd1b3VzIG9uIHRoZSBwb2ludCwg
YW5kIHNpbmNlIHByb3BlcnR5DQogICAgdGFncyBhcmUNCiAgICA+IG5vdCB5ZXQgd2lkZWx5IGRl
cGxveWVkIHRoaXMgaXMgYSBzb21ld2hhdCBmcmVlIGNob2ljZS4gSSB0aGluayB0aGUNCiAgICB2
ZXJzaW9uDQogICAgPiB3aGVyZSBwcm9wZXJ0eSB0YWdzIGFyZSBzZXBhcmF0ZWQgYnkgc2VtaWNv
bG9ucyBtYWtlcyBtb3JlIHNlbnNlIGFuZCBpcw0KICAgID4gbGVzcyBlcnJvciBwcm9uZS4gSXQg
YWxzbyBoYXBwZW5zIHRvIGJlIHdoYXQgSHVnbyBMYW5kYXUncyBkcmFmdCBmb3IgQ0FBDQogICAg
PiBSZWNvcmQgRXh0ZW5zaW9ucyB1c2VzOg0KICAgID4gaHR0cHM6Ly9zY2FubWFpbC50cnVzdHdh
dmUuY29tLz9jPTQwNjImZD1nTk8zMnNGSGVsdUljTG02WGRtckFnN2p3NGx6SkZ1U2RsRkl5bjZ1
T0Emcz01JnU9aHR0cHMlM2ElMmYlMmZ0b29scyUyZWlldGYlMmVvcmclMmZodG1sJTJmZHJhZnQt
aWV0Zi1hY21lLWNhYS0wMyUyM3BhZ2UtOQ0KICAgID4gDQogICAgPiBBbmQgd2hhdCB3YXMgYnJp
ZWZseSBpbXBsZW1lbnRlZCBpbiBMZXQncyBFbmNyeXB0J3MgQm91bGRlciAoc2luY2Ugcm9sbGVk
DQogICAgPiBiYWNrIGR1ZSB0byBhIGJ1Zyk6DQogICAgPiANCiAgICA+IGh0dHBzOi8vc2Nhbm1h
aWwudHJ1c3R3YXZlLmNvbS8/Yz00MDYyJmQ9Z05PMzJzRkhlbHVJY0xtNlhkbXJBZzdqdzRsekpG
dVNkZ1FVejN2OGJRJnM9NSZ1PWh0dHBzJTNhJTJmJTJmZ2l0aHViJTJlY29tJTJmbGV0c2VuY3J5
cHQlMmZib3VsZGVyJTJmcHVsbCUyZjMxNDUlMmZmaWxlcyUyM2RpZmYtDQogICAgPiAzZWZhYjUz
ZjJiY2M1NDNhYzJlNzcxZWM4ODJjNTdjMUwzMTANCiAgICA+IA0KICAgID4gU28gbXkgZmVlbGlu
ZyBpcyB3ZSBzaG91bGQgcmVqZWN0IHRoaXMgZXJyYXR1bSBhbmQgY2xhcmlmeSBpbiB0aGUgb3Ro
ZXINCiAgICA+IGRpcmVjdGlvbiwgcmVxdWlyaW5nIHNlbWljb2xvbnMgYmV0d2VlbiBwcm9wZXJ0
eSB0YWdzLiBUaG91Z2h0cz8NCiAgICA+IA0KICAgID4gX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX18NCiAgICA+IFNwYXNtIG1haWxpbmcgbGlzdA0KICAgID4g
U3Bhc21AaWV0Zi5vcmcNCiAgICA+IGh0dHBzOi8vc2Nhbm1haWwudHJ1c3R3YXZlLmNvbS8/Yz00
MDYyJmQ9Z05PMzJzRkhlbHVJY0xtNlhkbXJBZzdqdzRsekpGdVNkZ29mbnktcVB3JnM9NSZ1PWh0
dHBzJTNhJTJmJTJmd3d3JTJlaWV0ZiUyZW9yZyUyZm1haWxtYW4lMmZsaXN0aW5mbyUyZnNwYXNt
DQogICAgDQoNCg==


From nobody Wed Dec 20 09:28:23 2017
Return-Path: <tim.hollebeek@digicert.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA4491270A3 for <spasm@ietfa.amsl.com>; Wed, 20 Dec 2017 09:28:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level: 
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=digicert.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5fADly8qCIzY for <spasm@ietfa.amsl.com>; Wed, 20 Dec 2017 09:28:18 -0800 (PST)
Received: from mail1.bemta8.messagelabs.com (mail1.bemta8.messagelabs.com [216.82.243.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22CC01241F3 for <spasm@ietf.org>; Wed, 20 Dec 2017 09:28:18 -0800 (PST)
Received: from [216.82.242.46] (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256 bits)) by server-4.bemta-8.messagelabs.com id 03/04-09815-1BD9A3A5; Wed, 20 Dec 2017 17:28:17 +0000
X-Brightmail-Tracker: H4sIAAAAAAAAA1WSa0hTYRjH955ztp2GJ45T83EY1IHMDIdS2dI +1JdaVFTQh7DAzvTkRrvIzowFXZYolXbR0kxTl2YRpVnNQgspZ5YtoVohtq5aVGo3u2pEtLN3 3b793vf/f57/8748NKl+qtDQgtMh2K28mVOoqP4preeTW2rTM1MOt87XjY6eoXRV98cVurq+7 AWk/t3HV3J9Y+M4ofc92E2tJDPlJqvB5lwvN56uqyfyipqQc8eJUaULed2oGE2gKfY9AXUBXT FS0Wq2nICekhoCH64hqB0aV0ouBZsCfR03CImjWQd03i2hJI5il8KOojdyfL8M2nfeRpgXwfG ru5Q4YRoMdJ1VSMyw62Cvv5TCAY0E3Gn1hIQJ7EJ45DkWKkbsJPjmawqFkWwsBF64QwxsNAzc vaXAHANDz3/KMXPwsHkMYZ4MfncJkgKA9Sqh9OKRsEkLF8rehk3LwfO4l8KmFgTnvgyRxYgOH pKg7PsqPMQ6qP3kDYdthILqzjAvg+NPPoRru0jor7gUni4e+gf9YaFSAbt6/CFBzeZA+SncKY rVwOP7uxHmeHj9qENeihKr/3lpdbCeZN0IBi/0EtWhP4uEm1UvKGxKgorm4TDPhBP1IyTmDDj 8vVOBeSqUlwwoMc+Bke5RdBTRp1CiKNg3Cfbk1DStwW7KNTosvMmcnJqi01oEUeRzBTNvELXZ Nst5FFyz7TIZakOllxd7URxNcDFMgz49Uz3RYMvZbORFY5Y93yyIXhRP0xwwJ2uCWqRdyBWcG 0zm4K7+loGO4KKZQklmxDzeIppyseRDs+iajsAPgn5ZNeIi1ZTVZhU0scxWycpKVmO+9U+j33 vvR5M1UQySyWTqiDzBbjE5/teHUSyNuCjGJ3WJMFkdf/KGg6MQwVEq1syVRnHwfyWNC23zRPR lHJokzPi6Yk7LzP335K0tW5p9P4oi164o3HJwetlbW0PRWNbVHErFDbzceYW7rm4rzg+kD85u byhYrU6O0X5e6B+b9+xAoCtjSa+sMW0iU6g5GndpXpsnzzruN+gFLlO1516903il2/jeldBVu bWgUrUvrtyd1pTuWpTg5CjRyKcmkXaR/wWGQGgr8gMAAA==
X-Env-Sender: tim.hollebeek@digicert.com
X-Msg-Ref: server-8.tower-96.messagelabs.com!1513790895!103317867!1
X-Originating-IP: [216.32.180.178]
X-StarScan-Received: 
X-StarScan-Version: 9.4.45; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 14707 invoked from network); 20 Dec 2017 17:28:15 -0000
Received: from mail-bn3nam01lp0178.outbound.protection.outlook.com (HELO NAM01-BN3-obe.outbound.protection.outlook.com) (216.32.180.178) by server-8.tower-96.messagelabs.com with AES256-SHA256 encrypted SMTP; 20 Dec 2017 17:28:15 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digicert.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=zJ75FPbfglfMMxD0FpTQV/Q75g5WZQ81MQS+7W78rSM=; b=eAHg23DcOADt6IkGAFNw6QqTcjigml3o+F8Q17b/BZbCw/A6EQ05nRLf5Q03zN4WWJGHo0AdebUoxi9IgnDWWXmTBIGprBSkmysSCE8I71xNmoog/c5LFtFmm5ZNeb4DuxdAHXAehWgpJiBgWslsG8vJyhC4U5jBFgQybH9ta64=
Received: from DM5PR14MB1289.namprd14.prod.outlook.com (10.173.132.19) by DM5PR14MB1290.namprd14.prod.outlook.com (10.173.132.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.15; Wed, 20 Dec 2017 17:28:14 +0000
Received: from DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) by DM5PR14MB1289.namprd14.prod.outlook.com ([10.173.132.19]) with mapi id 15.20.0323.018; Wed, 20 Dec 2017 17:28:14 +0000
From: Tim Hollebeek <tim.hollebeek@digicert.com>
To: Corey Bonnell <CBonnell@trustwave.com>, Jacob Hoffman-Andrews <jsha@eff.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
Thread-Index: AQHTcFCyWaXtVbwstEuAXIDvoZy1oKNFZbiAgAPSpGCAAz8rgIAAF5QA
Date: Wed, 20 Dec 2017 17:28:14 +0000
Message-ID: <DM5PR14MB12890C21BF6E8271AB6397CB830C0@DM5PR14MB1289.namprd14.prod.outlook.com>
References: <20171208180055.ACB1EB81ACE@rfc-editor.org> <5AB43438-406D-482D-81DD-B9A30BE84459@vigilsec.com> <ad5b6045-84ba-32b3-7739-b2464fc40c2f@eff.org> <DM5PR14MB128950E8291574FAA0161BC8830E0@DM5PR14MB1289.namprd14.prod.outlook.com> <B94567AD-1DB4-4508-B629-F7F760237A15@trustwave.com>
In-Reply-To: <B94567AD-1DB4-4508-B629-F7F760237A15@trustwave.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [74.111.107.128]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR14MB1290; 6:+pN4lwWjFl2JXtJCTmvp3g7giKEr4TCuQeyZ2AFZrzSzcstvbRAkWwbuPpbQlNMBDU5NubbeFG3+4cDO/T2ec6NDLG9+Yy39iJc0+scicK9YB+6LGTWvJcl+rgcFRwfSQ/ak+bYWX4JRy/peA8DGFknpyi6PG9HR7yc1QY+bxNHb/dFHpwwuWv4P3zueBVFKFrm4eH5ddyyZ6C2fr3cOwPmI4wm3CmrEZMPkCo+yuTB1MdLRxXJ6+xfeqcKAtQk5953D/Rx3rnXqhMI0XtR82pzE/kaFh6jFbQSsmiXJ7+j0F0aKH4Me1lZbYL/Rp39zdm0mzkAsGVqWBsU0zWLsFFbsymmM9hGH/d8SYbgSZqk=; 5:/qOZqbPhlZZKAxpA38vf7qhl/A/hKs0nHNlRPUTKO4GYjLnCp9eh2XNmQWRUQtDJUVL/Pa5z0QRK8HHcz3xr7LChNiK2LXn6gA41EkSGco6ZPCx6rxg+4YND/Y8scwtX9nYIf0MgetX5dAdkmuDawRIJtn8VkDU+WvV+VgN1Gfc=; 24:GNOVImICqbRjmO8ebMY/SQE6Jk/VpVxejzMMdB+e5y7lbKEAr59qHd2MUkpD4u7ftRFnBSGvu+7jYaMt6ycD43pQ1Zk6sK5AQOD2HyE5H4E=; 7:XGy4XRH/GWVC4uH3if2q6+S9gyk5BlnbOryG+y8N6HscHK5xB1Y3ZEkddKrhRNMGjSdiCCDx2ciC9nqrDN5Jvi0hMT3Bma4XlEY6FlToNV/taj6bXAhI8d2Czg8d9L7eHM5kRwvbcNOsZVEUcWmePfEGiSgagNyAU42jMx2xzVI+dUYauCg278wq40XY3di3p+vvHxeaMdazjmBLocrr30lBgL+qTGtdJtJlSlDx//rXlKkEWgojLy0g6MNxXbAe
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: b6cf9772-b4ec-4ac3-f188-08d547cf0d1e
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603307)(7153060)(49563074); SRVR:DM5PR14MB1290; 
x-ms-traffictypediagnostic: DM5PR14MB1290:
x-microsoft-antispam-prvs: <DM5PR14MB129055A17B8CDCDAA0A8F0ED830C0@DM5PR14MB1290.namprd14.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705)(258766100185102);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040470)(2401047)(8121501046)(5005006)(3231023)(3002001)(93006095)(93001095)(10201501046)(6041268)(20161123560045)(20161123562045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(2016111802025)(20161123564045)(6043046)(6072148)(201708071742011); SRVR:DM5PR14MB1290; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:DM5PR14MB1290; 
x-forefront-prvs: 0527DFA348
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39380400002)(366004)(376002)(39860400002)(346002)(396003)(199004)(24454002)(189003)(13464003)(55016002)(575784001)(53936002)(3280700002)(5660300001)(2950100002)(97736004)(561944003)(305945005)(3846002)(8676002)(6246003)(25786009)(74316002)(93886005)(7736002)(33656002)(102836003)(81156014)(81166006)(86362001)(2900100001)(2501003)(6116002)(99936001)(66066001)(2906002)(3660700001)(68736007)(6306002)(106356001)(316002)(59450400001)(8936002)(14454004)(966005)(229853002)(7696005)(6436002)(99286004)(478600001)(110136005)(77096006)(6506007)(53546011)(105586002)(76176011)(9686003)(19400905002)(19627235001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR14MB1290; H:DM5PR14MB1289.namprd14.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: digicert.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=2.16.840.1.101.3.4.2.1; boundary="----=_NextPart_000_075E_01D3797D.39A78870"
MIME-Version: 1.0
X-OriginatorOrg: digicert.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b6cf9772-b4ec-4ac3-f188-08d547cf0d1e
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Dec 2017 17:28:14.5633 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf813fa1-bde5-4e75-9479-f6aaa8b1f284
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR14MB1290
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/yUzf_e7xpW6UFJ4ovXa1DPGMY6E>
Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 (5200)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 17:28:22 -0000

------=_NextPart_000_075E_01D3797D.39A78870
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

This looks good to me.  I could get behind this.

-Tim

> -----Original Message-----
> From: Corey Bonnell [mailto:CBonnell@trustwave.com]
> Sent: Wednesday, December 20, 2017 9:04 AM
> To: Tim Hollebeek <tim.hollebeek@digicert.com>; Jacob Hoffman-Andrews
> <jsha@eff.org>; spasm@ietf.org
> Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] RFC6844 =
(5200)
>=20
> After thinking about this further, I=E2=80=99m in favor of using =
semicolons to delimit
> parameters, as Tim mentioned that we likely need to continue using the
> semicolon to delimit the identifying domain name from the parameter =
list due
> to its current ubiquity. It would be inconsistent to use a semicolon =
to delimit
> the identifying domain name from the parameter list but also mandate =
that
> parameter name/value pairs be delimited using whitespace. That being =
said, I
> like the idea that non-significant whitespace can be used in records =
to
> improve human readability.
>=20
> Given that RFC 5234 prohibits the use of implicit =E2=80=9Clinear =
white space=E2=80=9D in
> section 3.1 (https://clicktime.symantec.com/a/1/223l-
> OOuL7oxSQZbmNPzrW-fzlB3ZyRehuXa1uhXQ_0=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fwww.rfcreader.c
> om%2F%23rfc5234_line204), RFC 6844 must explicitly state in the =
production
> rules that non-significant whitespace is supported. With that in mind, =
I believe
> that the ABNF production rules in RFC 6844 section 5.1
> (https://clicktime.symantec.com/a/1/QXA3DmFxWmhgnol1OsR_jPGPFCJRny
> 0xy6bKiW3sKgo=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fwww.rfcreader.c
> om%2F%23rfc6844_line447) for =E2=80=9Cissuevalue=E2=80=9D should be =
modified to
> something similar to this:
>=20
> issuevalue =3D *WSP [domain] *WSP [";" *WSP [parameters] *WSP]
> parameters =3D (parameter *WSP =E2=80=9C;=E2=80=9D *WSP parameters) / =
parameter
> parameter =3D tag "=3D" value
> tag =3D 1*(ALPHA / DIGIT)
> value =3D *(%x21-3A / %x3C-7E)
>=20
> (The =E2=80=9Cparameter=E2=80=9D and =E2=80=9Ctag=E2=80=9D production =
rules are unchanged but I listed them
> here to list the relevant rules in one place.)
>=20
> Note that I removed the =E2=80=9Cspace=E2=80=9D production rule, as =
RFC 5234 provides us
> with a nearly identical (differing only in the number of allowed =
repetitions, but
> the character class is the same) =E2=80=9CWSP=E2=80=9D rule in its =
core module
> (https://clicktime.symantec.com/a/1/-0fHBEr5CPqHK4BAN-1-SoYnA0YT-
> 6fhfpIyNPkPvE4=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fwww.rfcreader.c
> om%2F%23rfc5234_line520). Also note that I modified the =
=E2=80=9Cvalue=E2=80=9D rule, as we
> need to exclude the semicolon (ASCII code 0x3B) from the set of =
allowed
> characters in parameter values.
>=20
> Thanks,
> Corey
>=20
> Corey Bonnell
> Senior Software Engineer
>=20
> Trustwave | SMART SECURITY ON DEMANDwww.trustwave.com
> <https://clicktime.symantec.com/a/1/WBsY-
> EHcHWXZ8gHVn_TTn1EioTncr2wyhIBkPnoJz5U=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fwww.trustwave.c
> om%2F>
>=20
> 2017 Best Managed Security Service Winner =E2=80=93 SC Media
>=20
> On 12/18/17, 9:41 AM, "Spasm on behalf of Tim Hollebeek" <spasm-
> bounces@ietf.org on behalf of tim.hollebeek@digicert.com> wrote:
>=20
>     As pointed out on the cabf_validation list, the original text =
isn't just
>     ambiguous, the RFC contradicts itself.  I don't feel too strongly =
either
>     way, as long as it gets resolved soon, as property tags are about =
to become
>     commonly deployed (there were several proposed uses discussed at =
the
> Taipei
>     face-to-face meeting of the CA/Browser forum).
>=20
>     I do however have a slight preference for only having a single =
separator
>     (whitespace), not two in order to avoid confusion about what to do =
about
>     whitespace after semicolons and around =3D signs.
>=20
>     The semicolon doesn't really serve a useful purpose, though we do =
have to
>     keep one since there are existing CAA records out there that use =
it.  I'd
>     like the grammar to essentially be:
>=20
>         domain ; [name =3D value]+
>=20
>     with the clarification that whitespace is ignored.
>=20
>     So my personal preference is the first style you mentioned, in =
line with the
>     submitted errata:
>=20
>         https://clicktime.symantec.com/a/1/guXt-
> wbIajcv9dPXp03AETYKnnGzu7bRQAzwwoTu1BQ=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdg
> MZzyv9PQ%26s%3D5%26u%3Dhttp%3A%2F%2Fexample.com IN CAA 0 issue
> "https://clicktime.symantec.com/a/1/WSJJP7Kr5g1Ihc2JaYcIqr4LdXmpgvuwtx
> BN746PBxk=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdld
> On33-
> ag%26s%3D5%26u%3Dhttp%253a%252f%252fexample%252enet%253b
> foo=3Dbar bar=3Dqux"
>=20
>     It's the style I used in my proposal for industry standard =
property tag
>     names on cabf_validation last week.
>=20
>     -Tim
>=20
>     > -----Original Message-----
>     > From: Spasm [mailto:spasm-bounces@ietf.org] On Behalf Of Jacob
> Hoffman-
>     > Andrews
>     > Sent: Friday, December 15, 2017 9:06 PM
>     > To: spasm@ietf.org
>     > Subject: Re: [lamps] Fwd: [pkix] [Technical Errata Reported] =
RFC6844
>     (5200)
>     >
>     > On 12/08/2017 10:16 AM, Russ Housley wrote:
>     > > https://clicktime.symantec.com/a/1/P19HMr1W_-AM1Bgx1hv9xaT-
> Y052koOWPbFvWFXceKc=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdlJ
> PySquaA%26s%3D5%26u%3Dhttp%3A%2F%2Fwww.rfc-
> editor.org%2Ferrata%2Feid5200
>     >
>     > The question here is whether CAA records with property tags =
should look
>     > like:
>     >
>     > https://clicktime.symantec.com/a/1/guXt-
> wbIajcv9dPXp03AETYKnnGzu7bRQAzwwoTu1BQ=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdg
> MZzyv9PQ%26s%3D5%26u%3Dhttp%3A%2F%2Fexample.com IN CAA 0 issue
> "https://clicktime.symantec.com/a/1/WSJJP7Kr5g1Ihc2JaYcIqr4LdXmpgvuwtx
> BN746PBxk=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdld
> On33-
> ag%26s%3D5%26u%3Dhttp%253a%252f%252fexample%252enet%253b
> foo=3Dbar bar=3Dqux"
>     >
>     > or:
>     >
>     > https://clicktime.symantec.com/a/1/guXt-
> wbIajcv9dPXp03AETYKnnGzu7bRQAzwwoTu1BQ=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdg
> MZzyv9PQ%26s%3D5%26u%3Dhttp%3A%2F%2Fexample.com IN CAA 0 issue
> "https://clicktime.symantec.com/a/1/WSJJP7Kr5g1Ihc2JaYcIqr4LdXmpgvuwtx
> BN746PBxk=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttp%3A%2F%2Fscanmail.trustwa
> ve.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdld
> On33-
> ag%26s%3D5%26u%3Dhttp%253a%252f%252fexample%252enet%253b
> foo=3Dbar; bar=3Dqux"
>     >
>     > (note the second semicolon)
>     >
>     > I think the original text is ambiguous on the point, and since =
property
>     tags are
>     > not yet widely deployed this is a somewhat free choice. I think =
the
>     version
>     > where property tags are separated by semicolons makes more sense =
and
> is
>     > less error prone. It also happens to be what Hugo Landau's draft =
for CAA
>     > Record Extensions uses:
>     > https://clicktime.symantec.com/a/1/oeSHiU8l3ajgJiEMVtTF83-
> EFY63Rq8bkGOhkAfEU4w=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttps%3A%2F%2Fscanmail.trustw
> ave.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdl
> FIyn6uOA%26s%3D5%26u%3Dhttps%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdra
> ft-ietf-acme-caa-03%23page-9
>     >
>     > And what was briefly implemented in Let's Encrypt's Boulder =
(since rolled
>     > back due to a bug):
>     >
>     > https://clicktime.symantec.com/a/1/e4GMdQoD7tFbx08-
> UGuLKKtPdCFSB5rS2W-lBYmcerE=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttps%3A%2F%2Fscanmail.trustw
> ave.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdg
> QUz3v8bQ%26s%3D5%26u%3Dhttps%3A%2F%2Fgithub.com%2Fletsencrypt%
> 2Fboulder%2Fpull%2F3145%2Ffiles%23diff-
>     > 3efab53f2bcc543ac2e771ec882c57c1L310
>     >
>     > So my feeling is we should reject this erratum and clarify in =
the other
>     > direction, requiring semicolons between property tags. Thoughts?
>     >
>     > _______________________________________________
>     > Spasm mailing list
>     > Spasm@ietf.org
>     > https://clicktime.symantec.com/a/1/Op2fbuRdBuUkj-Y9VkPB3yT4ud-
> Nr0bBS0NRCEoC6mQ=3D?d=3DRZrpddyRRTQ154PRoAlI-
> Q9RbRRqmTet1Xm0uCdsU_76X79txFJWMGdDB2vayT_egarHUxCPBwWT5eHf
> BNnpKlx7W1mdGFJxIUnhYLisSSX6EqRMdSKRkKNx4wnVnB7zbllNvijPQiAP0aw
> sDHbVIPazzk2B2mld5wAzznIvkCABWKNmv4EtLSB2Azz831XxmyzQpAOPgdhU
> GamB8As9HkVGdCAEm0-
> YzoAiCxR7FclB5StDbL8Rhxz6EWTqb4AvPLqa_SpYOcFuWsXrevKnJKyzleaW6qb
> Vgl8UPOOx53m6f4Rl0caquHZPVvYzzuh59qwvG64WcemTGe_h9duJ0pbCj-
> UYAwwzKOTBdAqtmAxXqS9xB80aaCuRw8cEMCdeJXpEhXH0x9p045zQRtLwqq
> BgWx9UwSIkOYJT331aaaas4Q%3D%3D&u=3Dhttps%3A%2F%2Fscanmail.trustw
> ave.com%2F%3Fc%3D4062%26d%3DgNO32sFHeluIcLm6XdmrAg7jw4lzJFuSdg
> ofny-
> qPw%26s%3D5%26u%3Dhttps%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistin
> fo%2Fspasm
>=20


------=_NextPart_000_075E_01D3797D.39A78870
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCD0sw
ggO3MIICn6ADAgECAhAM5+DlF9hG/o/lYPwb8DA5MA0GCSqGSIb3DQEBBQUAMGUxCzAJBgNVBAYT
AlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAi
BgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0wNjExMTAwMDAwMDBaFw0zMTEx
MTAwMDAwMDBaMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsT
EHd3dy5kaWdpY2VydC5jb20xJDAiBgNVBAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAK0OFc7kQ4BcsYfzt2D5cRKlrtwmlIiq9M71
IDkoWGAM+IDaqRWVMmE8tbEohIqK3J8KDIMXeo+QrIrneVNcMYQq9g+YMjZ2zN7dPKii72r7IfJS
Yd+fINcf4rHZ/hhk0hJbX/lYGDW8R82hNvlrf9SwOD7BG8OMM9nYLxj+KA+zp4PWw25EwGE1lhb+
WZyLdm3X8aJLDSv/C3LanmDQjpA1xnhVhyChz+VtCshJfDGYM2wi6YfQMlqiuhOCEe05F52ZOnKh
5vqk2dUXMXWuhX0irj8BRob2KHnIsdrkVxfEfhwOsLSSplazvbKX7aqn8LfFqD+VFtD/oZbrCF8Y
d08CAwEAAaNjMGEwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEXr
oq/0ksuCMS1Ri6enIZ3zbcgPMB8GA1UdIwQYMBaAFEXroq/0ksuCMS1Ri6enIZ3zbcgPMA0GCSqG
SIb3DQEBBQUAA4IBAQCiDrzf4u3w43JzemSUv/dyZtgy5EJ1Yq6H6/LV2d5Ws5/MzhQouQ2XYFwS
TFjk0z2DSUVYlzVpGqhH6lbGeasS2GeBhN9/CTyU5rgmLCC9PbMoifdf/yLil4Qf6WXvh+DfwWdJ
s13rsgkq6ybteL59PyvztyY1bV+JAbZJW58BBZurPSXBzLZ/wvFvhsb6ZGjrgS2U60K3+owe3WLx
vlBnt2y98/Efaww2BxZ/N3ypW2168RJGYIPXJwS+S86XvsNnKmgR34DnDDNmvxMNFG7zfx9jEB76
jRslbWyPpbdhAbHSoyahEHGdreLD+cOZUbcrBwjOLuZQsqf6CkUvovDyMIIFOjCCBCKgAwIBAgIQ
Di7WjgxCjxTrYbReNHesEzANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM
RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2Vy
dCBTSEEyIEFzc3VyZWQgSUQgQ0EwHhcNMTcxMTI4MDAwMDAwWhcNMjIwMjI1MTIwMDAwWjBWMQsw
CQYDVQQGEwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTERMA8GA1UEChMIRGlnaUNl
cnQxFjAUBgNVBAMTDVRpbSBIb2xsZWJlZWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDKUTIS9F3d7CfkCjsf4my28pYoZJDkEAiXVqGP4jzbFkszUQNfW3PYpFUo1GnKQykl/tM0qnzw
05bfVLo1+ce0e9fyAwYfulr+HaAVCPqx+PZw9CDY6c0NYd7Fc7S0scONxKekNF4q1mUucfGuGapW
sEsyix0CuR0NMuJ4I+w8qMn9MzjzI7bvduG+uVLmZIi0p6D8+2R5BOQFy0tVeQ/aLfS91fG1DTYF
YkPF+a/6JlFxzywPzCth8KW2Po4w8JqQWtam/ADKrgMaOnEJs9csefTW/FWRDeGQk5t3rnyS19FP
QfpyPPau4ChB5xokfRcg3VEwqfOoIIexjUhZY5X9AgMBAAGjggHzMIIB7zAfBgNVHSMEGDAWgBTn
AiOAAE/Y17yUC9k/dDlJMjyKeTAdBgNVHQ4EFgQUjqBhf3GcBV6YGYSmp2iS4Wi/3N4wDAYDVR0T
AQH/BAIwADAlBgNVHREEHjAcgRp0aW0uaG9sbGViZWVrQGRpZ2ljZXJ0LmNvbTAOBgNVHQ8BAf8E
BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMEMGA1UdIAQ8MDowOAYKYIZIAYb9
bAQBAjAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMIGIBgNVHR8E
gYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJ
RENBLWcyLmNybDA9oDugOYY3aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFz
c3VyZWRJRENBLWcyLmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3Nw
LmRpZ2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0Rp
Z2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOCAQEAmOLw9+cVMHn8tJ0k
76baCfFZwkvfvxSAlCXo+Fcsv55/og0V065Rpb4HvVTi0e0qKCMbBxc71NWxhMvKJHt+sfSmVatX
mAOPNDRvtVvJBkcd0bvzMut/r3npQqs1wezHLtAq+MlQZDjgiJB+DkNblnnphzEQSp7q/4K9oMoP
KViRxBv+/kseA8GOfhHU6EVmeu9xQrBqexH1DPUrUSGpNGDyvtUaU+bBy8Kz2hQfOu6f/73wLqUx
e583C9y2Gqn1xCB77yPxXqRSLLRC6FbrToJbKiFYQJ4znZZyhPYJHL0SOpWyXfVKp4PEO54A/xr5
oVyPhEQhOtasoIRCLtHZrzCCBk4wggU2oAMCAQICEASueWBmZpAaucV/pmxb3M0wDQYJKoZIhvcN
AQELBQAwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgQXNzdXJlZCBJRCBSb290IENBMB4XDTEz
MTEwNTEyMDAwMFoXDTI4MTEwNTEyMDAwMFowZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lD
ZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hB
MiBBc3N1cmVkIElEIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3PgRIz9qte/A
J3kbLQWHohBDMd8O1BUbT3ekIs4+jHDwvgeO3ScqvAEdtiwKyt1pWB9B7WoFH9pjeFkeIiwr+Lp+
yTU7VvEffEJ+JbAjGcZFONc9RPkgfGCuHLBaGAS+jzv3qfCUmqYMY0m2QRdTQDK9T+ZQelAfJUXo
8Ymvzf9e/1Dz8BcR/73FifW9YrnY+45FBIVtmc3FSE39JqsCNkXqNtdfauIagkEK3OnZ9ZEXjsYh
rTg8E+Yef2ac1U3ZRtr2z1KnfTskw7TBUTXGm+vU737kewPhRL16CzfgT8uCig1xGOSm4IksG/Oy
czzBsJKeGH29q33FfQihLMKfcwIDAQABo4IC+DCCAvQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNV
HQ8BAf8EBAMCAYYwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp
Y2VydC5jb20wgYEGA1UdHwR6MHgwOqA4oDaGNGh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
Q2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwOqA4oDaGNGh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9E
aWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwME
MIIBswYDVR0gBIIBqjCCAaYwggGiBgpghkgBhv1sAAIEMIIBkjAoBggrBgEFBQcCARYcaHR0cHM6
Ly93d3cuZGlnaWNlcnQuY29tL0NQUzCCAWQGCCsGAQUFBwICMIIBVh6CAVIAQQBuAHkAIAB1AHMA
ZQAgAG8AZgAgAHQAaABpAHMAIABDAGUAcgB0AGkAZgBpAGMAYQB0AGUAIABjAG8AbgBzAHQAaQB0
AHUAdABlAHMAIABhAGMAYwBlAHAAdABhAG4AYwBlACAAbwBmACAAdABoAGUAIABEAGkAZwBpAEMA
ZQByAHQAIABDAFAALwBDAFAAUwAgAGEAbgBkACAAdABoAGUAIABSAGUAbAB5AGkAbgBnACAAUABh
AHIAdAB5ACAAQQBnAHIAZQBlAG0AZQBuAHQAIAB3AGgAaQBjAGgAIABsAGkAbQBpAHQAIABsAGkA
YQBiAGkAbABpAHQAeQAgAGEAbgBkACAAYQByAGUAIABpAG4AYwBvAHIAcABvAHIAYQB0AGUAZAAg
AGgAZQByAGUAaQBuACAAYgB5ACAAcgBlAGYAZQByAGUAbgBjAGUALjAdBgNVHQ4EFgQU5wIjgABP
2Ne8lAvZP3Q5STI8inkwHwYDVR0jBBgwFoAUReuir/SSy4IxLVGLp6chnfNtyA8wDQYJKoZIhvcN
AQELBQADggEBAE7UiSe5/R2Hd34PKAWQ8QovyTs+vZOckMav+pFRhzJUa+jKwXFRXJmOtfrgYhmZ
pgeafBMn2+UCooQS2RX2CkRXxDSPbXMfOtagAT3e44LkRWuy6yX9gF4dOZC+W0L2zpFg4/mgVgxI
EM4zaHvNk6vwastPWA+5e10bBIGepyLiV0kn7pKTCL5pCFMCOi5dyBn0UIBOAtmwXZG0k4f5lpaB
VUCOZu2C2LsoX+1MYe0GWCgZUxFEvEcgKbIEbNiJVJk7ddtneCweknjGVT1YEhEybr1DDE0023vG
QtvsvqubYUwGkuOO3yEqUFcEwGCiNdUknmY3CUnP1fhls+DibsIxggO/MIIDuwIBATB5MGUxCzAJ
BgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xJDAiBgNVBAMTG0RpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBDQQIQDi7WjgxCjxTrYbReNHes
EzANBglghkgBZQMEAgEFAKCCAhcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTcxMjIwMTcyODA2WjAvBgkqhkiG9w0BCQQxIgQgS/tA9uJ8BewRn3PBbf+Tln1j0rLE
p63ZeHKsliSUsn8wgYgGCSsGAQQBgjcQBDF7MHkwZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERp
Z2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQg
U0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOthtF40d6wTMIGKBgsqhkiG9w0BCRACCzF7oHkw
ZTELMAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2lj
ZXJ0LmNvbTEkMCIGA1UEAxMbRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIENBAhAOLtaODEKPFOth
tF40d6wTMIGTBgkqhkiG9w0BCQ8xgYUwgYIwCwYJYIZIAWUDBAEqMAsGCWCGSAFlAwQBFjAKBggq
hkiG9w0DBzALBglghkgBZQMEAQIwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAsGCWCG
SAFlAwQCATALBglghkgBZQMEAgMwCwYJYIZIAWUDBAICMAcGBSsOAwIaMA0GCSqGSIb3DQEBAQUA
BIIBAF6zhvkLRsiAyfIeKMluD6iNRH9vNRduW0eEDSnpmPTRGgFtwMy4uEKUcKM4y0F4cA2G2F+O
neYW3xeXahvRjot0+ecP6EVFby8QqCVKsaSgNRRlMS6q5ZtU9QauOvVd2j59W2eZ4FJb594qKWqL
slXMn4uXGt8ZRlPMbuoPjPLKLAHa4oc0F1AKIK9/T6RWF4xwZ3kauNQCOe65kL/43bCGM9nsg5Kd
DOX8Xfa2Ozzij7Y4LCqWwWlwzgLNOToy5rxqYi8KZ/isffj8PzanqeHdlRyCb1jbdRvEK0K1kupL
c3qgQ6Hj2IIPbqD2Mcd/GnNIzw3Cvt4TM8Gj7IgZfcoAAAAAAAA=

------=_NextPart_000_075E_01D3797D.39A78870--


From nobody Wed Dec 20 11:19:54 2017
Return-Path: <session-request@ietf.org>
X-Original-To: spasm@ietf.org
Delivered-To: spasm@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 053871241F5; Wed, 20 Dec 2017 11:19:53 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Meeting Session Request Tool <session-request@ietf.org>
To: <session-request@ietf.org>
Cc: spasm@ietf.org, lamps-chairs@ietf.org, ekr@rtfm.com, housley@vigilsec.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.68.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151379759299.2762.4055876088123491418.idtracker@ietfa.amsl.com>
Date: Wed, 20 Dec 2017 11:19:52 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/xu0oFL2GphhY7m224e-NVE4VozY>
Subject: [lamps] lamps - Update to a Meeting Session Request for IETF 101
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 19:19:53 -0000

An update to a meeting session request has just been submitted by Russ Housley, a Chair of the lamps working group.


---------------------------------------------------------
Working Group Name: Limited Additional Mechanisms for PKIX and SMIME
Area Name: Security Area
Session Requester: Russ Housley

Number of Sessions: 1
Length of Session(s):  1 Hour
Number of Attendees: 50
Conflicts to Avoid: 
 First Priority: rtcweb ace acme stir ipwave tls sipbrandy sidrops saag perc quic curdle suit lamps
 Second Priority: cfrg dprive ecrit oauth sacm mile modern radext
 Third Priority: mtgvenue iasa20


People who must be present:
  Russ Housley
  Eric Rescorla
  Sean Turner
  Jim Schaad

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Wed Dec 27 08:02:43 2017
Return-Path: <spencerdawkins.ietf@gmail.com>
X-Original-To: spasm@ietf.org
Delivered-To: spasm@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7796A126FB3; Wed, 27 Dec 2017 08:02:41 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Spencer Dawkins <spencerdawkins.ietf@gmail.com>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-lamps-eai-addresses@ietf.org, Russ Housley <housley@vigilsec.com>, lamps-chairs@ietf.org, housley@vigilsec.com, spasm@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.68.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151439056144.29897.5203263014335278965.idtracker@ietfa.amsl.com>
Date: Wed, 27 Dec 2017 08:02:41 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/f4OpkO9sa-jdPQW_j6U1UT19wq0>
Subject: [lamps] Spencer Dawkins' No Objection on draft-ietf-lamps-eai-addresses-15: (with COMMENT)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Dec 2017 16:02:41 -0000

Spencer Dawkins has entered the following ballot position for
draft-ietf-lamps-eai-addresses-15: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-lamps-eai-addresses/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I know that you guys have been doing this longer than I've even been thinking
about it, but I'm looking at

  Due to operational reasons to be described shortly and name
   constraint compatibility reasons described in Section 6,
   SmtpUTF8Mailbox subjectAltName MUST only be used when the local-part
   of the email address contains non-ASCII characters.  When the local-
   part is ASCII, rfc822Name subjectAltName MUST be used instead of
   SmtpUTF8Mailbox.  This is compatible with legacy software that
   supports only rfc822Name (and not SmtpUTF8Mailbox).  The appropriate
   usage of rfc822Name and SmtpUTF8Mailbox is summarized in Table 1
   below.

and, if I'm reading this correctly, the plan is

        IF you don't NEED to send non-ASCII characters
                use rfc822Name
                and all implementations know what that means
                and all implementations will work fine
        ELSE you DO have non-ASCII characters so
                use SmtpUTF8Mailbox
                and all the new implementations will work fine
                and all the old implementations will barf
                which is OK because they can't handle non-ASCII anyway

Am I getting that right? Assuming so, I looked at the "operational reasons to
be described shortly" and "name constraint compatibility reasons described in
Section 6", and didn't see anything that was was quite that blunt.

Assuming that you're sending SmtpUTF8Mailbox to an implementation that doesn't
support it, and you figure that out, is there a well-understood fallback that
could be either referenced or described in a sentence or two?

If the answer is "what an implementation does at that point is up to the
implementation, and different implementations may have different reasons to
respond differently", that could be a fine answer, of course.


