Re: [Uta] "webby" STS and DANE/DNSSEC co-existence

Viktor Dukhovni <ietf-dane@dukhovni.org> Wed, 13 April 2016 19:14 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C68212D682 for <uta@ietfa.amsl.com>; Wed, 13 Apr 2016 12:14:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uzqDcIIu39gb for <uta@ietfa.amsl.com>; Wed, 13 Apr 2016 12:14:07 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [38.117.134.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EADE912D926 for <uta@ietf.org>; Wed, 13 Apr 2016 12:14:06 -0700 (PDT)
Received: by mournblade.imrryr.org (Postfix, from userid 1034) id 21A76284DEF; Wed, 13 Apr 2016 19:14:06 +0000 (UTC)
Date: Wed, 13 Apr 2016 19:14:06 +0000
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
To: uta@ietf.org
Message-ID: <20160413191405.GF26423@mournblade.imrryr.org>
References: <570C0CD2.9030401@cs.tcd.ie> <20160411212128.GA26423@mournblade.imrryr.org> <CANtKdUekXNkVvsfq0UjCiaaPVBgoVGfrfnYUrdoOf0EegXMuPg@mail.gmail.com> <20160413014304.GB26423@mournblade.imrryr.org> <CANtKdUf0kN5aOmX0-NsyQXz_+PRGfaXa37DFZoCX3FqdYh5CpA@mail.gmail.com> <5249C8ED-CACD-4765-909E-CB8EB218BF10@noware.co.uk> <CANtKdUctfEKuQAscMkt_A5wcA84Z4y3L4KvcsxVd2Qb0NRBtgw@mail.gmail.com> <96AFF4DD-A934-4C92-A72E-AF729CE053D7@noware.co.uk> <CANtKdUcvhE+xxXtrRFgS0gcEE=8qLyPea5BpdLkv2DYmt9BHww@mail.gmail.com> <A41EBA6F-D988-491B-A436-C7D3EE2018C1@noware.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <A41EBA6F-D988-491B-A436-C7D3EE2018C1@noware.co.uk>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <http://mailarchive.ietf.org/arch/msg/uta/ccWr8SacEl7V_ZxUiLSoBX-uoFc>
Subject: Re: [Uta] "webby" STS and DANE/DNSSEC co-existence
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: uta@ietf.org
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Apr 2016 19:14:08 -0000

On Wed, Apr 13, 2016 at 10:59:06AM +0100, Neil Cook wrote:

> However this does bring up a good point - if I want to support STS *and*
> DANE as a receiver, and have a homogeneous MX/MTA setup, i.e. not something
> like the above, I would have to support the common subset of both
> specifications, at least as far as MTA configuration is concerned, e.g.
> no self-signed certs. That is a consequence we haven�t discussed before.

STS is WebPKI.  If you want STS, you need a certificate from one
of the usual CAs.  With a self-signed certificate (some day just
a bare public key and no certificate at all) you can only use DANE.

Top 10 issuers of certs for DANE MX hosts:

     172 ; Issuer = CN=StartCom Class 1 Primary Intermediate Server CA,OU=Secure Digital Certificate Signing,O=StartCom Ltd.,C=IL
     166 ; Issuer = CN=COMODO RSA Domain Validation Secure Server CA,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB
     165 ; Issuer = CN=Let's Encrypt Authority X1,O=Let's Encrypt,C=US
      91 ; Issuer = CN=StartCom Class 2 Primary Intermediate Server CA,OU=Secure Digital Certificate Signing,O=StartCom Ltd.,C=IL
      90 ; Issuer = CN=Gandi Standard SSL CA 2,O=Gandi,L=Paris,ST=Paris,C=FR
      81 ; Issuer = CN=StartCom Class 1 DV Server CA,OU=StartCom Certification Authority,O=StartCom Ltd.,C=IL
      63 ; Issuer = CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US
      62 ; Issuer = CN=RapidSSL SHA256 CA - G3,O=GeoTrust Inc.,C=US
      38 ; Issuer = CN=WoSign CA Free SSL Certificate G2,O=WoSign CA Limited,C=CN
      33 ; Issuer = CN=CAcert Class 3 Root,OU=http://www.CAcert.org,O=CAcert Inc.

( Note some of the MX hosts support many hundreds of domains, the above counts
  the issuer just once for each issued certificate, not once per domain served. )

-- 
	Viktor.