
From nobody Mon May  2 01:19:35 2016
Return-Path: <sca@andreasschulze.de>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 19E5612D131 for <dane@ietfa.amsl.com>; Mon,  2 May 2016 01:19:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level: 
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andreasschulze.de
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HDoCU1TWdeka for <dane@ietfa.amsl.com>; Mon,  2 May 2016 01:19:31 -0700 (PDT)
Received: from mail.somaf.de (mail.somaf.de [IPv6:2001:a60:f0b4:e503:2cdb:beff:feaa:880b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96E5F12B068 for <dane@ietf.org>; Mon,  2 May 2016 01:19:30 -0700 (PDT)
Received: from andreasschulze.de (andreasschulze.de [IPv6:2001:a60:f0b4:e503:d86e:8dce:a73e:2fec]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) (Authenticated sender: sca@andreasschulze.de) by mail.somaf.de (Postfix) with ESMTPSA id 3qyxzf3ZmgzDhX for <dane@ietf.org>; Mon,  2 May 2016 10:19:25 +0200 (CEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.somaf.de 3qyxzf3ZmgzDhX
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=andreasschulze.de; s=ybz; t=1462177166; bh=iWVdSma1WB3HMrCj2W8lHiOpedperMIf/BCGhiAkRkM=; h=Date:From:To:Subject; b=oeuS4w+NMMaxyPW05S5wZ+HYUAXYAVieQsQtv92/yKgylXy664aZfELs8f4Hn3AV6 GWoY17bpInALqlGHswEmxTQogGi9+AVAhnFypl/JBvvpOMlyH6Eq0stKE1LIQeGNGA IT73ibduAmhyShlsSXy4dbx5x/9N32B6T0ALsGvr7lWNeCSLIBtR6qqYxlIq4GlURM xV2a+QfUaGjrSNm6hQhbU5VO/mjYlsfTL/U/7t9co9+l5TnOyIhqscKKVjk49JM8AA ZG9j/t7L3XFNzy4INN9+4cvvDatioXv5+9gRuJILgRXPYhifw0TJkdEqkdOdzpcnuz gOxnRvLGGUeWA==
Received: from prx12.datevnet.de (prx12.datevnet.de [2a00:e50:f155:b:cb23:e1af:6ea7:7392]) by andreasschulze.de (Horde Framework) with HTTPS; Mon, 02 May 2016 10:19:25 +0200
Date: Mon, 02 May 2016 10:19:24 +0200
Message-ID: <20160502101924.Horde.UgYyIR_kiIoy4MwIa4J96qa@andreasschulze.de>
From: "A. Schulze" <sca@andreasschulze.de>
To: dane@ietf.org
User-Agent: Horde Application Framework 5
Content-Type: text/plain; charset=utf-8; format=flowed; DelSp=Yes
MIME-Version: 1.0
Content-Disposition: inline
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/Sr0AioWOpigfDOC_X8-GPLbZtdY>
Subject: Re: [dane] [Uta] NEWSFLASH: DANE TLSA records published for web.de!
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 May 2016 08:19:34 -0000

Am 22.04.2016 um 17:36 schrieb Viktor Dukhovni:
> So overall, the deployment picture picture is pretty good.  I've
> not heard of any significant issues from posteo.de, they I believe
> have enabled DANE outbound some time ago.

We - datev.de - use DANE on our outbound systems also since a year or so
10...20 destination domains of trouble we hit so far.

mostly their DNSSEC was broken. We "downgrade" the destination to  
normal encryption
and point postmaster@domain to https://dnsviz.net + https://dnscheck.iis.se

and yes: DANE works, messages stay in the queue. they don't get delivered :-)

Andreas



From nobody Mon May  2 16:28:35 2016
Return-Path: <internet-drafts@ietf.org>
X-Original-To: dane@ietf.org
Delivered-To: dane@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B3AC12D68F; Mon,  2 May 2016 16:28:33 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.19.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20160502232833.15728.68997.idtracker@ietfa.amsl.com>
Date: Mon, 02 May 2016 16:28:33 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/rQNmtSZEEBDALrVCTNcwgvXUk1w>
Cc: dane@ietf.org
Subject: [dane] I-D Action: draft-ietf-dane-openpgpkey-12.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 May 2016 23:28:33 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the DNS-based Authentication of Named Entities of the IETF.

        Title           : Using DANE to Associate OpenPGP public keys with email addresses
        Author          : Paul Wouters
	Filename        : draft-ietf-dane-openpgpkey-12.txt
	Pages           : 22
	Date            : 2016-05-02

Abstract:
   OpenPGP is a message format for email (and file) encryption that
   lacks a standardized lookup mechanism to securely obtain OpenPGP
   public keys.  DNS-Based Authentication of Named Entities ("DANE") is
   a method for publishing public keys in DNS.  This document specifies
   a DANE method for publishing and locating OpenPGP public keys in DNS
   for a specific email address using a new OPENPGPKEY DNS Resource
   Record.  Security is provided via Secure DNS, however the OPENPGPKEY
   record is not a replacement for verification of authenticity via the
   "Web Of Trust" or manual verification.  The OPENPGPKEY record can be
   used to encrypt an email that would otherwise have to be sent
   unencrypted.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-dane-openpgpkey/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-dane-openpgpkey-12

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-dane-openpgpkey-12


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Mon May  2 16:44:53 2016
Return-Path: <paul@nohats.ca>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 35A0112D698 for <dane@ietfa.amsl.com>; Mon,  2 May 2016 16:44:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level: 
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_ADSP_ALL=0.8, RP_MATCHES_RCVD=-0.996] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fW82SoFGgUab for <dane@ietfa.amsl.com>; Mon,  2 May 2016 16:44:49 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AD65412B02A for <dane@ietf.org>; Mon,  2 May 2016 16:44:49 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 3qzLWM3MC5z45c; Tue,  3 May 2016 01:44:47 +0200 (CEST)
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id X49xUPfQn2tM; Tue,  3 May 2016 01:44:45 +0200 (CEST)
Received: from bofh.nohats.ca (206-248-139-105.dsl.teksavvy.com [206.248.139.105]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Tue,  3 May 2016 01:44:44 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 265B26EC41C; Mon,  2 May 2016 19:44:44 -0400 (EDT)
DKIM-Filter: OpenDKIM Filter v2.10.3 bofh.nohats.ca 265B26EC41C
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 1895C4391CD8; Mon,  2 May 2016 19:44:44 -0400 (EDT)
Date: Mon, 2 May 2016 19:44:44 -0400 (EDT)
From: Paul Wouters <paul@nohats.ca>
To: dane WG list <dane@ietf.org>
In-Reply-To: <20160502232833.15728.68997.idtracker@ietfa.amsl.com>
Message-ID: <alpine.LRH.2.20.1605021942570.9128@bofh7.nohats.ca>
References: <20160502232833.15728.68997.idtracker@ietfa.amsl.com>
User-Agent: Alpine 2.20 (LRH 67 2015-01-07)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/jaxBzb0axPDN2eSJUfwlS7aE_sA>
Cc: Alexey Melnikov <aamelnikov@fastmail.fm>
Subject: Re: [dane] I-D Action: draft-ietf-dane-openpgpkey-12.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 May 2016 23:44:52 -0000

On Mon, 2 May 2016, internet-drafts@ietf.org wrote:

> 	Filename        : draft-ietf-dane-openpgpkey-12.txt

> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-dane-openpgpkey-12

I had forgotten to add text provided by Alexey Melnikov during the IESG
review.

Paul


From nobody Tue May  3 00:48:04 2016
Return-Path: <aamelnikov@fastmail.fm>
X-Original-To: dane@ietf.org
Delivered-To: dane@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B58B12D1BC; Tue,  3 May 2016 00:48:01 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "Alexey Melnikov" <aamelnikov@fastmail.fm>
To: "The IESG" <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.19.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20160503074801.7526.45722.idtracker@ietfa.amsl.com>
Date: Tue, 03 May 2016 00:48:01 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/Vh-CiJYLyWlL2QyQbOrVlcfyYAI>
Cc: draft-ietf-dane-openpgpkey@ietf.org, dane-chairs@ietf.org, dane@ietf.org
Subject: [dane] Alexey Melnikov's Yes on draft-ietf-dane-openpgpkey-12: (with COMMENT)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 May 2016 07:48:01 -0000

Alexey Melnikov has entered the following ballot position for
draft-ietf-dane-openpgpkey-12: Yes

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dane-openpgpkey/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

NOTE to editors: Thank you for addressing my earlier comments in -09, -10
and -12.

Despite many objections to publishing this specification I believe we
should run the experiment. I will vote "Yes" once DISCUSS-points are
addressed. I would rather see this experiment being done and fail (or
better - succeed), than to block publication of this document because it
is not perfect.

Some (edited) comments from Ned Freed that I (mostly) agree with:

1) In Section 3:

When describing unquoting and unescaping, I think it would be useful to
give an example, for example all of the following are equivalent and must
result in the same hashed value:

(1) first.last@example.com
(2) first . last @example.com
(3) "first.last"@example.com
(4) "\f\i\r\s\t.last"@example.com

2)

5.1.  Obtaining an OpenPGP key for a specific email address

   If no OpenPGP public keys are known for an email address, an
   OPENPGPKEY DNS lookup MAY be performed to seek the OpenPGP public key
   that corresponds to that email address.  This public key can then be
   used to verify a received signed message or can be used to send out
   an encrypted email message.  An application whose attempt fails to
   retrieve a DNSSEC verified OPENPGPKEY RR from the DNS should remember
   that failure for some time to avoid sending out a DNS request for
   each email message the application is sending out; such DNS requests
   constitute a privacy leak

Should the document give a specific recommendation about "remember for
some time"? Is it tied to TTL for the corresponding RR?
If you can provide some additional text explaining what is reasonable (or
not) here, that would improve the specification.



From nobody Tue May  3 01:24:04 2016
Return-Path: <fschmaus@gmail.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9FAB912D61E for <dane@ietfa.amsl.com>; Tue,  3 May 2016 01:24:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.42
X-Spam-Level: 
X-Spam-Status: No, score=-2.42 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.199, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l7cBYOc5zzQ4 for <dane@ietfa.amsl.com>; Tue,  3 May 2016 01:24:01 -0700 (PDT)
Received: from mail-wm0-f46.google.com (mail-wm0-f46.google.com [74.125.82.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 15A4F12D61B for <dane@ietf.org>; Tue,  3 May 2016 01:24:01 -0700 (PDT)
Received: by mail-wm0-f46.google.com with SMTP id g17so24693383wme.1 for <dane@ietf.org>; Tue, 03 May 2016 01:24:00 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to; bh=YafXo04q7IgLvLj4KGW0hjb+9n9RYXfjZcjwkcFR+eo=; b=KBGx/VOfn5cWr9IiyHoZLQhYgNJZD6RSge+2XWEtbk7Q7OgAfgU8lOubHBuOamRM0q NJZCig+pDZDdRxmoPgcxAUocPVp8cqkHQNhhecT7z6F7BhLhnwOjnuNt1YlwX9SL1tN0 xPDTgd/6eAlclZI0YOjfGIlqlxIF1Pqznc1nAgpyQxRIiIZAEoicJpbjCEzi3iKGhHih /cN0WW7xFFXEuZs/kM/5btNIPIzaKmEUeq8vKpPyJ0eoTKinDfUYjh/nCmdreBGdaPRN B7aQmFmvIIxbTL3Ae+YtXg2XUGI/m5JZYz4gMAnT9ULGgTZbdjFGC2q7sE15gVQ4Eru8 weDA==
X-Gm-Message-State: AOPr4FVZ5BYYD4WeGI6EPei07h0CjepjQ2QawzQRP84Ir4QGqojvOH18V+E0KZWq7D0/BA==
X-Received: by 10.194.163.229 with SMTP id yl5mr1424275wjb.6.1462263839463; Tue, 03 May 2016 01:23:59 -0700 (PDT)
Received: from [131.188.34.88] (flowbook2.informatik.uni-erlangen.de. [131.188.34.88]) by smtp.googlemail.com with ESMTPSA id jr8sm2484956wjb.15.2016.05.03.01.23.58 for <dane@ietf.org> (version=TLSv1/SSLv3 cipher=OTHER); Tue, 03 May 2016 01:23:58 -0700 (PDT)
To: dane@ietf.org
References: <20160502232833.15728.68997.idtracker@ietfa.amsl.com> <alpine.LRH.2.20.1605021942570.9128@bofh7.nohats.ca>
From: Florian Schmaus <flo@geekplace.eu>
Message-ID: <5728601D.9070608@geekplace.eu>
Date: Tue, 3 May 2016 10:23:57 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.7.0
MIME-Version: 1.0
In-Reply-To: <alpine.LRH.2.20.1605021942570.9128@bofh7.nohats.ca>
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="eGgSsE37HCLl1S7c4FiQoHEevPI6SxWrC"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/cYXExTF54NBg9kY2zIQnyLv4BcU>
Subject: Re: [dane] I-D Action: draft-ietf-dane-openpgpkey-12.txt
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 May 2016 08:24:03 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--eGgSsE37HCLl1S7c4FiQoHEevPI6SxWrC
Content-Type: multipart/mixed; boundary="wSMN9AhFg8L1Ahwe0qNNsvjST0EV6CXsg"
From: Florian Schmaus <flo@geekplace.eu>
To: dane@ietf.org
Message-ID: <5728601D.9070608@geekplace.eu>
Subject: Re: [dane] I-D Action: draft-ietf-dane-openpgpkey-12.txt
References: <20160502232833.15728.68997.idtracker@ietfa.amsl.com>
 <alpine.LRH.2.20.1605021942570.9128@bofh7.nohats.ca>
In-Reply-To: <alpine.LRH.2.20.1605021942570.9128@bofh7.nohats.ca>

--wSMN9AhFg8L1Ahwe0qNNsvjST0EV6CXsg
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

On 03.05.2016 01:44, Paul Wouters wrote:
> On Mon, 2 May 2016, internet-drafts@ietf.org wrote:
>=20
>>     Filename        : draft-ietf-dane-openpgpkey-12.txt
>=20
>> A diff from the previous version is available at:
>> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-dane-openpgpkey-12

Nit: s/privay/privacy/ (on page 10).

- Florian



--wSMN9AhFg8L1Ahwe0qNNsvjST0EV6CXsg--

--eGgSsE37HCLl1S7c4FiQoHEevPI6SxWrC
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQF8BAEBCgBmBQJXKGAdXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQxMzU3QjAxODY1QjI1MDNDMTg0NTNEMjA4
Q0FDMkE5Njc4NTQ4RTM1AAoJEIysKpZ4VI41vnAIAI68MW/4i0+XhItHMIZGJTq8
427bTbBFAwXjrLo4NJL5suXzU67bC07C9GQHj9RnXRelPGTnZMdmzzNV2twEaWGH
32fJBlkzl6PtgUUPNNq7MLJWMNiVeZWUtIZoZ2F5fZinlYvt/r8ZNHUQEJw1ctRm
Z2CGYtEh9UKdo6zzB2z3/mSJzQu1OGWXkSOiE7y8BiVZjxihLWSFprMiVI5QUxIO
JJiinQ3v2p6bCFdO+80mOv0QHM8ESrtSBeBn6O55NTqhxJpwb84TBxn4kJzOuKqN
oANBJQ81c6SMbk3lPWKm1PVBJh1HwCBwCsOALSTAML87w5DzEoX4Iof/+Te0eGg=
=CHEF
-----END PGP SIGNATURE-----

--eGgSsE37HCLl1S7c4FiQoHEevPI6SxWrC--


From nobody Mon May  9 10:34:31 2016
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: dane@ietf.org
Delivered-To: dane@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 1645312D589; Mon,  9 May 2016 10:34:30 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.20.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20160509173430.18418.66069.idtracker@ietfa.amsl.com>
Date: Mon, 09 May 2016 10:34:30 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/ma9KgKrhOZKetlsUL_UDrRnrjow>
Cc: dane-chairs@ietf.org, dane@ietf.org, The IESG <iesg@ietf.org>, draft-ietf-dane-openpgpkey@ietf.org, rfc-editor@rfc-editor.org
Subject: [dane] Document Action: 'Using DANE to Associate OpenPGP public keys with email addresses' to Experimental RFC (draft-ietf-dane-openpgpkey-12.txt)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.17
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 May 2016 17:34:30 -0000

The IESG has approved the following document:
- 'Using DANE to Associate OpenPGP public keys with email addresses'
  (draft-ietf-dane-openpgpkey-12.txt) as Experimental RFC

This document is the product of the DNS-based Authentication of Named
Entities Working Group.

The IESG contact persons are Stephen Farrell and Kathleen Moriarty.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-dane-openpgpkey/





Technical Summary:

This document proposes a method to publish and "locate" OPENPGP keys
inside the DNS. The goal of this approach is to make it easier to find
OPENPGP keys for email addresses.  The document defines a "method" to
convert email-addres into a special normal form. that is limited but
is expected to cover many cases. The OPENPGP DNS record specified has 
been allocated by an Expert Review.  

The method of mapping email addresses into the normal form has gone
through number of revisions based on feedback from WG participants and
email community. No one claims this is a perfect solution but good
solution for the particular problem space, where the sender to an
email has a "good" idea what an email address of the receipient
is. This protocol can be described as oppertunistic OPENPGP key
discovery. This is not a replacement service for PKGP servers but a
compliment. 

Working Group Summary:

The main issues that the WG has discused are 
a) is it a good idea to publish email addresses in DNSSEC signed zone? 
b) is the role of the nomalization from strictly a normalization or an
obfuscation as well? 
The consensus of the WG is that as the publicaion is by the zone owner
it is an opt-in policy, there is no requriement for adoption thus the
issue need to be addressed in the light of each organizations
polices, i.e this is not a protocol issue. 

The second issue there is a strong consenus that the purpose of the
normal for is only to map email addresses into a DNS label that is
valid in all implementations. 
The working group consensus is strong about advancing this document. 

We had two IETF last calls on this one. There were some good points
raised in those and changes resulted. There are however some email
folks who remain unhappy with this experiment so the IETF consensus
for this is rough. The responsible AD judges that we do however have
rough consensus for this experiment. (And will similarly have rough
consensus for some other experiments in this space.) I think though
that it'd be especially good here if the ART ADs give this one a
particularly close look in case I've erred in considering their objections.
(I of course don't think I did, but hey, I've been wrong before:-)
 
Document Quality:

Early version of this  document went through DNS expert review before
the DNS RR type was allocated. The editor has been real good at
working with people to address textual and techical issues. 
There are number of implemenations of this protocol and some
deoployment where organizations have placed over 1500 keys online. 

More review from email community is welcome but until the email
community proposes a better form of normalization rules for email
addresses this is the best we can do. 

Personnel:

Who is the Document Shepherd? Who is the Responsible Area Director?
Document Sheperd is Olafur Gudmundsson 
Responsible AD is : Stephen Farrell, 

