* chairs gave a short summary of document status * chris newman presentd DEEP - changes from 01 - now a wg draft - fold in coments from Russ - add reference from TLS BCP Open Issues - need to gather deployment data on 465/587 - John Levine: all support 587 and all big except hotmail support 465 with start_tls - Chris: then the draft should be changed to reflect this - Keith: there were other reasons why a separate port made sense - design tradeoff issues discussion - Legard Levinson (?) Was Dane considered? - Chris: few references to Dane in the current document.. some open issues - discussion about account setup and Dane - David Lamparter: Dane can't inform a client about the availability of TLS - only about certificates - Keith More: wo dnssec its just a different set of security holes - Pete Resnick: don't latch to non-validated certs - Chris: yes but latching gets addl security - Keith: - don't latch to unvalidated certs - Yaron: passive security is a misnomer - also a middlebox can provide a false certificate. Don't latch unless validate. - Orit (as individual) but don't latch. - Stephen: latch for a short period? - Keith: don't create systems that create support-issues - Consensus: don't latch invalid certificates - =JeffH pointed out a reference to HSTS - Update IMAP mandatory to implement ciphers to match bcp - SeanT: yes you should update - Alexei: yes update and update all 3 by changing the mandatory to implement ciphers with a reference to the TLS BCP - Stephen: you could point to the specific preferred ciphers from the BCP - Keith: reference a specific version of the BCP - Barry: that won't matter given how we do references - Orit: keep track of interop issues - Improve document clarity - Chris: open to suggestions for improving organization and readability - Discussion about the goals of document improvement and the (non-)BCP status of this specification - Volunteers to review: Sean Turner Dave Crocker - Open questions - Discussions on how clients can avoid latching on TLS 1.0 * Open Mic - Pete is stepping down as AD. IESG reorg means UTA will kept in APPS but with Stephen Farrell as Responsabl AD