
From holz@net.in.tum.de  Wed Aug  1 08:00:30 2012
Return-Path: <holz@net.in.tum.de>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D525E11E80FD for <therightkey@ietfa.amsl.com>; Wed,  1 Aug 2012 08:00:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.249
X-Spam-Level: 
X-Spam-Status: No, score=-2.249 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3YamEcroewFn for <therightkey@ietfa.amsl.com>; Wed,  1 Aug 2012 08:00:30 -0700 (PDT)
Received: from smtp.serverkommune.de (serverkommune.de [176.9.61.43]) by ietfa.amsl.com (Postfix) with ESMTP id D648D21F8ACF for <therightkey@ietf.org>; Wed,  1 Aug 2012 08:00:24 -0700 (PDT)
Received: by smtp.serverkommune.de (Postfix, from userid 5001) id 1EC58809E9; Wed,  1 Aug 2012 17:00:23 +0200 (CEST)
Received: from [131.159.20.131] (ex6.serverkommune.de [176.9.61.43]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.serverkommune.de (Postfix) with ESMTPSA id 6D10380993 for <therightkey@ietf.org>; Wed,  1 Aug 2012 17:00:22 +0200 (CEST)
Message-ID: <50194486.9010902@net.in.tum.de>
Date: Wed, 01 Aug 2012 17:00:22 +0200
From: Ralph Holz <holz@net.in.tum.de>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20120714 Thunderbird/14.0
MIME-Version: 1.0
To: therightkey@ietf.org
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com>
In-Reply-To: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com>
X-Enigmail-Version: 1.4.3
OpenPGP: id=69B003EF
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Virus-Scanned: clamav-milter 0.97.3 at ex6
X-Virus-Status: Clean
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Aug 2012 15:00:31 -0000

Hi,

On 08/01/2012 12:12 AM, Ben Laurie wrote:
> Many CAs were dismayed by the time it took to issue a "log proof". It
> was also quite a bad name.
> 
> So, in v2 we reduce issuance time to (effectively) zero.
> 
> As always, comments please.

Maybe I'm missing something, or I don't understand your footnote 1
correctly.

But: you state that you create a SCH over the end-host cert and the need
for also hashing and signing the intermediate certs arises because you
want to avoid a CA having the same cert re-issued with a different
intermediate CA (that has the original intermediate CA's private key).

Are you assuming then that, if a CA tried this, the DN in the issuer
field of the end-host cert would be set to the same value again? E.g.,
empty or some standard value and the only SKID/AKID used in
verification? Otherwise, if you insert an intermediate CA that has a
different DN (and maybe key identifier), you'd get a different DER/PEM
and a different hash already.

Or maybe I'm confused. :)

Ralph

-- 
Ralph Holz
Network Architectures and Services
Technische Universität München
http://www.net.in.tum.de/de/mitarbeiter/holz/
PGP: A805 D19C E23E 6BBB E0C4  86DC 520E 0C83 69B0 03EF

From benl@google.com  Wed Aug  1 08:38:42 2012
Return-Path: <benl@google.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C47321F8A7F for <therightkey@ietfa.amsl.com>; Wed,  1 Aug 2012 08:38:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level: 
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aMB7HE4717Kw for <therightkey@ietfa.amsl.com>; Wed,  1 Aug 2012 08:38:41 -0700 (PDT)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 2F20621F8A7E for <therightkey@ietf.org>; Wed,  1 Aug 2012 08:38:40 -0700 (PDT)
Received: by obbwc20 with SMTP id wc20so14143465obb.31 for <therightkey@ietf.org>; Wed, 01 Aug 2012 08:38:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record; bh=nU512OULMMnXCAFhsMr3b8wBQIhsJ7WmF4h+IjPmBMo=; b=noi2SK2pv8SqIBq7uQr4yzmLYRjohStXjTY/tW0Rkd95pKFm8/za8xbjdqdkeXrna+ 4Guz2BSip7mAnRwb7dFQsedFF9qlYrBObbHRFIAg6F6UhKRScehTDZJ7URqxfD26eovo U2NAdbGKzOX+TbC4yNFwf2lXWFWavKITpAsv8BvPgpjMSigBoyxj3VA7qVwKZx4Y2V+f FxLDpb0pRhLY4KM4k5pnJW0ZzeFiJHrHn746fMuaIvImbbn2ShYKY5eIqAOb8YLWNonW 0SxDLmYbhy/pg9As6rQO3MGi9NP5B7vUjxozHUn1rxq6gAKlwXZnDa9MuHOe66Mse8FJ K3Mg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record :x-gm-message-state; bh=nU512OULMMnXCAFhsMr3b8wBQIhsJ7WmF4h+IjPmBMo=; b=WtiNHhHm6duAw6Olr7TJ0ayqOtAm5Z9FarWxQDYjJ4A9ywKfu7QUTWw2TpTx3aadej uBo0qyeeOpHD+wRiGj9zxbGwmQ0PdPkQsD8/7rbU9VCGiUaJsyoYUcZ2YcDyZrctRMGE tPGJtbF5F3H99gvc9BxFnrBcVOTdunv59mcTzR+mFadeQzItKP11KQLYIWvhV2go6ScQ NJCUnrzEpvyMw6GR3i6zX3ov4Wjm7WmokP4VGtoLPAqZpAV0zRb4/WKunvwlHCNMS6Kr BLQ4hGp/OXdKRSeG5D1wGgmREeqHhi1iUnFkRG1MgnZxXbbPJJ3g6T9UzGVmdS0SE4Ox CKJw==
Received: by 10.182.162.101 with SMTP id xz5mr29623089obb.47.1343835520461; Wed, 01 Aug 2012 08:38:40 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.182.162.101 with SMTP id xz5mr29623079obb.47.1343835520295; Wed, 01 Aug 2012 08:38:40 -0700 (PDT)
Received: by 10.60.171.199 with HTTP; Wed, 1 Aug 2012 08:38:40 -0700 (PDT)
In-Reply-To: <50194486.9010902@net.in.tum.de>
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com> <50194486.9010902@net.in.tum.de>
Date: Wed, 1 Aug 2012 16:38:40 +0100
Message-ID: <CABrd9SQBqRtAo1bNgAXs=bGwUTk1imJu=DPrqttZp3O0hb20EQ@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: Ralph Holz <holz@net.in.tum.de>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQlAAsbYyHqoCvHwEeLdu+cOcVefeWwGch3hID380dHbdAq6lRsFScINeJJEfhPin0WMmRuxHe71FKur47AWOiWyd1/bg4Iooxr2zFJ9lQJrUlH6OHoD9sFZt0T9lSsyvhOcgXtHR2DAR9tID/KP66L0I2FwYpGF68rFYxmUb1piJcP9nN4oNp269fPZo++4PPXlATxf
Cc: therightkey@ietf.org
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Aug 2012 15:38:42 -0000

On 1 August 2012 16:00, Ralph Holz <holz@net.in.tum.de> wrote:
> Hi,
>
> On 08/01/2012 12:12 AM, Ben Laurie wrote:
>> Many CAs were dismayed by the time it took to issue a "log proof". It
>> was also quite a bad name.
>>
>> So, in v2 we reduce issuance time to (effectively) zero.
>>
>> As always, comments please.
>
> Maybe I'm missing something, or I don't understand your footnote 1
> correctly.
>
> But: you state that you create a SCH over the end-host cert and the need
> for also hashing and signing the intermediate certs arises because you
> want to avoid a CA having the same cert re-issued with a different
> intermediate CA (that has the original intermediate CA's private key).
>
> Are you assuming then that, if a CA tried this, the DN in the issuer
> field of the end-host cert would be set to the same value again?

Of course.

> E.g.,
> empty or some standard value and the only SKID/AKID used in
> verification? Otherwise, if you insert an intermediate CA that has a
> different DN (and maybe key identifier), you'd get a different DER/PEM
> and a different hash already.
>
> Or maybe I'm confused. :)
>
> Ralph
>
> --
> Ralph Holz
> Network Architectures and Services
> Technische Universit=E4t M=FCnchen
> http://www.net.in.tum.de/de/mitarbeiter/holz/
> PGP: A805 D19C E23E 6BBB E0C4  86DC 520E 0C83 69B0 03EF
> _______________________________________________
> therightkey mailing list
> therightkey@ietf.org
> https://www.ietf.org/mailman/listinfo/therightkey

From holz@net.in.tum.de  Thu Aug  2 01:48:40 2012
Return-Path: <holz@net.in.tum.de>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42F1E21F8E52 for <therightkey@ietfa.amsl.com>; Thu,  2 Aug 2012 01:48:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.249
X-Spam-Level: 
X-Spam-Status: No, score=-2.249 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 490cy9b8wziA for <therightkey@ietfa.amsl.com>; Thu,  2 Aug 2012 01:48:39 -0700 (PDT)
Received: from smtp.serverkommune.de (serverkommune.de [176.9.61.43]) by ietfa.amsl.com (Postfix) with ESMTP id 4233121F8D2E for <therightkey@ietf.org>; Thu,  2 Aug 2012 01:48:38 -0700 (PDT)
Received: by smtp.serverkommune.de (Postfix, from userid 5001) id 4F0E580983; Thu,  2 Aug 2012 10:48:37 +0200 (CEST)
Received: from [131.159.20.131] (ex6.serverkommune.de [176.9.61.43]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.serverkommune.de (Postfix) with ESMTPSA id 842C08096C for <therightkey@ietf.org>; Thu,  2 Aug 2012 10:48:35 +0200 (CEST)
Message-ID: <501A3ED0.4050205@net.in.tum.de>
Date: Thu, 02 Aug 2012 10:48:16 +0200
From: Ralph Holz <holz@net.in.tum.de>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20120714 Thunderbird/14.0
MIME-Version: 1.0
To: therightkey@ietf.org
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com> <50194486.9010902@net.in.tum.de> <CABrd9SQBqRtAo1bNgAXs=bGwUTk1imJu=DPrqttZp3O0hb20EQ@mail.gmail.com>
In-Reply-To: <CABrd9SQBqRtAo1bNgAXs=bGwUTk1imJu=DPrqttZp3O0hb20EQ@mail.gmail.com>
X-Enigmail-Version: 1.4.3
OpenPGP: id=69B003EF
Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig2748E1A923E2DDB367B31D17"
X-Virus-Scanned: clamav-milter 0.97.3 at ex6
X-Virus-Status: Clean
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Aug 2012 08:48:40 -0000

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig2748E1A923E2DDB367B31D17
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi,

>> But: you state that you create a SCH over the end-host cert and the ne=
ed
>> for also hashing and signing the intermediate certs arises because you=

>> want to avoid a CA having the same cert re-issued with a different
>> intermediate CA (that has the original intermediate CA's private key).=

>>
>> Are you assuming then that, if a CA tried this, the DN in the issuer
>> field of the end-host cert would be set to the same value again?
>=20
> Of course.

OK, I think I understand. So that would (very likely) be a legitimate
change, i.e. CA changes notbefore/notafter but re-issues cert in same
way. With AKID the same, the end-host cert would not need to be
re-issued, but you still want the proof of exactly that one
certification with that one intermediate cert.

Ralph--
Ralph Holz
Network Architectures and Services
Technische Universit=E4t M=FCnchen
http://www.net.in.tum.de/de/mitarbeiter/holz/
PGP: A805 D19C E23E 6BBB E0C4  86DC 520E 0C83 69B0 03EF


--------------enig2748E1A923E2DDB367B31D17
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJQGj7fAAoJEFIODINpsAPv24IH/RstPiTio6GPW99zULbQbLun
VzaCW0yqD4T5tm53GRQ4FZde31FxcgoHP1qjGNAauhcTck0NNy5eehR0cgV6SMYE
rexqLstQta4RxHMQ3gaD5IL4ywe3HPrvx9xnnnokUCpcXJPCsan+7iv2EbeMWfOx
XQ1judFGwzviyqznfklD2fZ2O0TN0wCWitEeuapDhNXx/sQiOYuyJtQJ44TRBfPu
FQ0EKMdN7lZJeHnYZpM/lhkFiq2uBs1xOBuBdzpUyBXhWsjxvetBd4mAhaJHsxQI
o5VWUGr/t/PxPGAtBIsd8StWI7vFjHynUjwtqTiDtTr6hgFGLclRoUV8rcgxBno=
=zwUt
-----END PGP SIGNATURE-----

--------------enig2748E1A923E2DDB367B31D17--

From benl@google.com  Thu Aug  2 12:54:05 2012
Return-Path: <benl@google.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3FC411E81AF for <therightkey@ietfa.amsl.com>; Thu,  2 Aug 2012 12:54:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level: 
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ieOhdn5XEEVh for <therightkey@ietfa.amsl.com>; Thu,  2 Aug 2012 12:54:05 -0700 (PDT)
Received: from mail-gg0-f172.google.com (mail-gg0-f172.google.com [209.85.161.172]) by ietfa.amsl.com (Postfix) with ESMTP id 17B5911E8186 for <therightkey@ietf.org>; Thu,  2 Aug 2012 12:54:04 -0700 (PDT)
Received: by ggnc4 with SMTP id c4so9892288ggn.31 for <therightkey@ietf.org>; Thu, 02 Aug 2012 12:54:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record; bh=r87aJH1dRkaACreT5xtMtxVICd1eIjGTt0I3DreRh0w=; b=Wzs695vSnSVeiDCKNd1humlDePufDSA7+PWUZqYdNZHvXPpLHFZ+cEr48QPESnsbTc /EM/+JIHBSXskydfs4EV652G4CSIPdqIO/3SwS7UTiSIiS+EJcMphYfOAfteFuddC7GG 5Io4ukcNP/brlbNAZTgeLjt1JN+37IryexiCTO7qmUmN/KqouybiydhGxptgIfXErYSa aXQaIjiSN9KRviyJtLPTTxLJ3/ra0SXGKfYLpT9y4Wnuv+F8iZDzN0CgbdiVi3PLFgax ruBu/b36ofJ6eXB5bPXIw3awovt40QdKsew+mDM86Kf0KZtNb83Z40UmwDSTiFbmiwLe WolA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record :x-gm-message-state; bh=r87aJH1dRkaACreT5xtMtxVICd1eIjGTt0I3DreRh0w=; b=mh9WWTno5WkPMf/4+TaMRhObEfKfWixdtUG7LBNK7eson+qO+a5uQq9hNRvJAAsPHR 2C+0J8V7DqrEwdiqC7OQb1YwJ8VXpwSeF2PzVD5Wsh80Z8N1BriME8XlyyN5yPhKhtYG 0PF1JUr3gJvugADNWL/WwfCkmPWOLOQGvpPZ25PpFp31ZNiO8sRtis4wV7uu7wWcPzVM FrdyQBlXDm/dPHMTlvZ0ROba1TSKSLDYcEX/tthuSWseNwiGkMqJ9Zd/F3ZzU3Hl3Yft ua6Pp5nS03sNhxVq1y8GhrHo5VtJmgkmqDqGFTZT5JY+gG1ce5WapmxohZQBGnZUVnuQ ukag==
Received: by 10.60.8.165 with SMTP id s5mr40162923oea.62.1343937244452; Thu, 02 Aug 2012 12:54:04 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.60.8.165 with SMTP id s5mr40162899oea.62.1343937244247; Thu, 02 Aug 2012 12:54:04 -0700 (PDT)
Received: by 10.60.171.199 with HTTP; Thu, 2 Aug 2012 12:54:04 -0700 (PDT)
In-Reply-To: <501A3ED0.4050205@net.in.tum.de>
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com> <50194486.9010902@net.in.tum.de> <CABrd9SQBqRtAo1bNgAXs=bGwUTk1imJu=DPrqttZp3O0hb20EQ@mail.gmail.com> <501A3ED0.4050205@net.in.tum.de>
Date: Thu, 2 Aug 2012 20:54:04 +0100
Message-ID: <CABrd9SSKuj7dShXzTeoNDahecurx6DE20fjGsYOUv9v_mQQobA@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: Ralph Holz <holz@net.in.tum.de>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQkjJW1UBbDgIWvNrmjg6sm3dvPmeKRuocm8Dt/7s3U0kaWbzw8zIX13Cu7Qar6BJGkX3TlPtDlW+doFz/RBdaFVTFak2WU7bz1OpwVUFI468tVuvwyCPK6QeAjMVqfBRiT3mw7fCCw6l0SvbG24u3MpOy2MLSbee5jIyfdd93sVWlaspWf5racuGCPsl3c/jqJBGU9r
Cc: therightkey@ietf.org
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Aug 2012 19:54:05 -0000

On 2 August 2012 09:48, Ralph Holz <holz@net.in.tum.de> wrote:
> Hi,
>
>>> But: you state that you create a SCH over the end-host cert and the nee=
d
>>> for also hashing and signing the intermediate certs arises because you
>>> want to avoid a CA having the same cert re-issued with a different
>>> intermediate CA (that has the original intermediate CA's private key).
>>>
>>> Are you assuming then that, if a CA tried this, the DN in the issuer
>>> field of the end-host cert would be set to the same value again?
>>
>> Of course.
>
> OK, I think I understand. So that would (very likely) be a legitimate
> change, i.e. CA changes notbefore/notafter but re-issues cert in same
> way.

This change would require a new entry anyway.

> With AKID the same, the end-host cert would not need to be
> re-issued, but you still want the proof of exactly that one
> certification with that one intermediate cert.
>
> Ralph--
> Ralph Holz
> Network Architectures and Services
> Technische Universit=E4t M=FCnchen
> http://www.net.in.tum.de/de/mitarbeiter/holz/
> PGP: A805 D19C E23E 6BBB E0C4  86DC 520E 0C83 69B0 03EF
>
>
> _______________________________________________
> therightkey mailing list
> therightkey@ietf.org
> https://www.ietf.org/mailman/listinfo/therightkey
>

From James.H.Manger@team.telstra.com  Mon Aug 20 18:59:57 2012
Return-Path: <James.H.Manger@team.telstra.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59CAB21F84A6 for <therightkey@ietfa.amsl.com>; Mon, 20 Aug 2012 18:59:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.942
X-Spam-Level: 
X-Spam-Status: No, score=-0.942 tagged_above=-999 required=5 tests=[AWL=-0.410, BAYES_00=-2.599, HELO_EQ_AU=0.377, HOST_EQ_AU=0.327, NUMERIC_HTTP_ADDR=0.001, RELAY_IS_203=0.994, URI_HEX=0.368]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XD6P6VhkK6yy for <therightkey@ietfa.amsl.com>; Mon, 20 Aug 2012 18:59:56 -0700 (PDT)
Received: from ipxbvo.tcif.telstra.com.au (ipxbvo.tcif.telstra.com.au [203.35.135.204]) by ietfa.amsl.com (Postfix) with ESMTP id ACFAA21F84A5 for <therightkey@ietf.org>; Mon, 20 Aug 2012 18:59:54 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="4.77,800,1336312800"; d="scan'208";a="87533967"
Received: from unknown (HELO ipcavi.tcif.telstra.com.au) ([10.97.217.200]) by ipobvi.tcif.telstra.com.au with ESMTP; 21 Aug 2012 11:59:51 +1000
X-IronPort-AV: E=McAfee;i="5400,1158,6809"; a="109538861"
Received: from wsmsg3756.srv.dir.telstra.com ([172.49.40.84]) by ipcavi.tcif.telstra.com.au with ESMTP; 21 Aug 2012 11:59:50 +1000
Received: from WSMSG3153V.srv.dir.telstra.com ([172.49.40.159]) by wsmsg3756.srv.dir.telstra.com ([172.49.40.84]) with mapi; Tue, 21 Aug 2012 11:59:49 +1000
From: "Manger, James H" <James.H.Manger@team.telstra.com>
To: Ben Laurie <benl@google.com>, "therightkey@ietf.org" <therightkey@ietf.org>
Date: Tue, 21 Aug 2012 11:59:48 +1000
Thread-Topic: [therightkey] Certificate Transparency Version 2
Thread-Index: Ac1vaaTpBk+9P7kbQZK6cdd310Qi3gPzr1bQ
Message-ID: <255B9BB34FB7D647A506DC292726F6E114FAAE7F55@WSMSG3153V.srv.dir.telstra.com>
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com>
In-Reply-To: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com>
Accept-Language: en-US, en-AU
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US, en-AU
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Aug 2012 01:59:57 -0000

SXMgdGhlIEROUyBzY2hlbWUgaW4gQ2VydGlmaWNhdGUgVHJhbnNwYXJlbmN5IHYyIDxodHRwOi8v
d3d3LmxpbmtzLm9yZy8/cD0xMjU5PiBzY2FsYWJsZT8NCg0KSXQgbWVudGlvbnMgVFhUIHJlY29y
ZHMgc3VjaCBhczoNCg0KICA8c2lnbmVkLWNlcnQtaGFzaD4uaGFzaC5leGFtcGxlLm5ldA0KICA8
Y2VydC1pbmRleD4uPGxldmVsPi48dHJlZS1zaXplPi50cmVlLmV4YW1wbGUubmV0DQoNClN0aWNr
aW5nIHdpdGggdGhlIHNhbXBsZSBzaXplIGluIHRoZSBzcGVjIG9mIDEuMyBtaWxsaW9uIGNlcnRp
ZmljYXRlcywgbWVhbnMgdGhlcmUgd291bGQgYmUgMS4zIG1pbGxpb24gRE5TIGVudHJpZXMgaW1t
ZWRpYXRlbHkgYmVsb3cgLmhhc2guZXhhbXBsZS5uZXQgYW5kIHRoZSBzYW1lIG51bWJlciBpbW1l
ZGlhdGVseSBiZWxvdyAuMC4xMzAwMDAwLnRyZWUuZXhhbXBsZS5uZXQuDQoNClRoYXQgaXMgbXVj
aCBzbWFsbGVyIHRoYW4gdGhlIDEwMCBtaWxsaW9uIGVudHJpZXMgaW1tZWRpYXRlbHkgYmVsb3cg
LmNvbSBzbyBpdCBpcyBwb3NzaWJsZSwgdGhvdWdoIGl0IG1pZ2h0IHJlcXVpcmUgbW9yZSBoZXJv
aWNzIHRoYW4gc2hvdWxkIGJlIG5lY2Vzc2FyeS4NCg0KDQo8dHJlZS1zaXplPiBpcyAxMzAwMDAw
IGluIHRoZSBleGFtcGxlLiBJIGFzc3VtZSB0aGlzIGluY3JlbWVudHMgZm9yIGV2ZXJ5IGNlcnRp
ZmljYXRlIGxvZ2dlZC4gVGhpcyBzZWVtcyB0byBpbXBsaWVzIHlvdSBuZWVkIGEgd2hvbGUgbmV3
IEROUyB0cmVlIC4xMzAwMDAxLnRyZWUuZXhhbXBsZS5uZXQgKHdpdGggfjguNWUxMSA8Y2VydC1p
bmRleD4uPGxldmVsPiBzdWItZW50cmllcykgd2hlbiB0aGUgbmV4dCBjZXJ0aWZpY2F0ZSBpcyBp
c3N1ZWQhIEkgZ3Vlc3MgeW91IGNhbiBzeW50aGV0aWNhbGx5IGNyZWF0ZSB0aGVtIG9uLWRlbWFu
ZCwgYnV0IHRoYXQgZG9lcyBzZWVtIHRvIGRlc3Ryb3kgY2FjaGluZyBldGMuDQoNCkEgRE5TIHNj
aGVtZSB0aGF0IGRvZXNuJ3QgdXNlIDx0cmVlLXNpemU+IGFzIGEgRE5TIGxhYmVsICh0aGUgdHJl
ZSBzaXplIGlzIHN0aWxsIGtub3duIGZyb20gdGhlIFNpZ25lZCBUcmVlIEhlYWQpLCBhbmQgb25s
eSBwdWJsaXNoZXMgdGhlIHN0YWJsZSBwYXJ0cyBvZiB0aGUgTWVya2xlIHRyZWUgKHdpdGggc3Rh
YmxlIG5hbWVzKSBzaG91bGQgYmUgcG9zc2libGUuDQoNCi0tDQpKYW1lcyBNYW5nZXINCg0KPiAt
LS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KPiBGcm9tOiB0aGVyaWdodGtleS1ib3VuY2VzQGll
dGYub3JnIFttYWlsdG86dGhlcmlnaHRrZXktDQo+IGJvdW5jZXNAaWV0Zi5vcmddIE9uIEJlaGFs
ZiBPZiBCZW4gTGF1cmllDQo+IFNlbnQ6IFdlZG5lc2RheSwgMSBBdWd1c3QgMjAxMiA4OjEzIEFN
DQo+IFRvOiB0aGVyaWdodGtleUBpZXRmLm9yZw0KPiBTdWJqZWN0OiBbdGhlcmlnaHRrZXldIENl
cnRpZmljYXRlIFRyYW5zcGFyZW5jeSBWZXJzaW9uIDINCj4gDQo+IE1hbnkgQ0FzIHdlcmUgZGlz
bWF5ZWQgYnkgdGhlIHRpbWUgaXQgdG9vayB0byBpc3N1ZSBhICJsb2cgcHJvb2YiLiBJdA0KPiB3
YXMgYWxzbyBxdWl0ZSBhIGJhZCBuYW1lLg0KPiANCj4gU28sIGluIHYyIHdlIHJlZHVjZSBpc3N1
YW5jZSB0aW1lIHRvIChlZmZlY3RpdmVseSkgemVyby4NCj4gDQo+IEFzIGFsd2F5cywgY29tbWVu
dHMgcGxlYXNlLg0K

From benl@google.com  Tue Aug 21 03:49:25 2012
Return-Path: <benl@google.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0511621F8755 for <therightkey@ietfa.amsl.com>; Tue, 21 Aug 2012 03:49:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level: 
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pb5lWd0Ej5xA for <therightkey@ietfa.amsl.com>; Tue, 21 Aug 2012 03:49:24 -0700 (PDT)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 903D721F8713 for <therightkey@ietf.org>; Tue, 21 Aug 2012 03:49:24 -0700 (PDT)
Received: by obbwc20 with SMTP id wc20so12803394obb.31 for <therightkey@ietf.org>; Tue, 21 Aug 2012 03:49:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:x-system-of-record; bh=gpb2XVG6X12ZhVd9FnR0GR6MrbrAlf2ndLroZgEzO28=; b=oM3S1wmdNw037+Jw3dVZ3Rjg2WlhNh0PaLZK9gXDsqPIhqarBe8Atz3sFUTTfE/lJy EBIpWGdJ4BIoMtIMaREut0o/pMNXaJlqzSlTi4nyVtPrOeZN3dNLkYuZ4SpYP+/jjh4J 3ClicLwbv1lJN1Ls2Zpr75rOmFTb8MnTPvzO6RL3yZMt6LZ4KwRo2DEa6Xa5hfg/qNZE UUj81ow7z54FCuDAlyMcVixDn2D0jxq4kRIgZ05w2EsCvc+duEfbBYQgBNyAhmBeTMYY K2wchSgKMY8uPC6TsmpS7uCAjfbz8P07lm8FuV38xp9hizDqF3XvlRNrvR8ilEUpA+mV rlPg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:x-system-of-record:x-gm-message-state; bh=gpb2XVG6X12ZhVd9FnR0GR6MrbrAlf2ndLroZgEzO28=; b=npIo0l+BFHgVGWaPBbQhI8mABbNCSjaMOtJ3IXPc/rCLA8u6XtpxxlNXa9B97R5dI9 mS38itnM+fTP0onMi16UlVRPOpvBVRPEB87gdUBe13HV1Ys1q1tEvIT8QtxbBIYp38fB WUobF/EBpF66nucbGsb5tLTyczPdC8AQOcWGGxp7QCTt7hh72Yr97qN2AhZHtPaomd7e 2vsE6zmARjpmclKGI703pdsm30yYrL50VgyChtxqeqeEe9y60e1MQBw59k2lZk/UcD9f Hw42p4dQ3bkiRIZq9XX3bUt4p/90YlQnzuRDr1eXkVIvjHwVXc6dPsj+UGDjJhQ5M+Y7 MRYg==
Received: by 10.182.89.102 with SMTP id bn6mr12872849obb.7.1345546163642; Tue, 21 Aug 2012 03:49:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.182.89.102 with SMTP id bn6mr12872413obb.7.1345546147296; Tue, 21 Aug 2012 03:49:07 -0700 (PDT)
Received: by 10.60.9.164 with HTTP; Tue, 21 Aug 2012 03:49:07 -0700 (PDT)
In-Reply-To: <255B9BB34FB7D647A506DC292726F6E114FAAE7F55@WSMSG3153V.srv.dir.telstra.com>
References: <CABrd9SRjRqmTao4zz35P0oV05a+k9DcJjpKwX1YdBjSPkZoS7w@mail.gmail.com> <255B9BB34FB7D647A506DC292726F6E114FAAE7F55@WSMSG3153V.srv.dir.telstra.com>
Date: Tue, 21 Aug 2012 11:49:07 +0100
Message-ID: <CABrd9STQXFzBaBkUtBXRkOxWVSkU1_EaG1mr6epr8ooOUxHGUQ@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: "Manger, James H" <James.H.Manger@team.telstra.com>
Content-Type: text/plain; charset=ISO-8859-1
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQmiM09Z2cM2HRTJfls+dYZVmhSAXRF3lMlPdF2aRMMfjmdqrqX0UB97QJX2l/Fhi/bcMCnCTKTOEqH1qByxgxTN5kSlBR77MP8hpegMNgfPdp6Pl/hyapQqFV9QaSXvDENxvBcNphS2ew/DfEqE02j21n3FBHpZkMttR7LwQXTZ/x38SIgDwK4yLJfuxZGdaiOvnvW3
Cc: "therightkey@ietf.org" <therightkey@ietf.org>
Subject: Re: [therightkey] Certificate Transparency Version 2
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Aug 2012 10:49:25 -0000

On 21 August 2012 02:59, Manger, James H
<James.H.Manger@team.telstra.com> wrote:
> A DNS scheme that doesn't use <tree-size> as a DNS label (the tree size is still known from the Signed Tree Head), and only publishes the stable parts of the Merkle tree (with stable names) should be possible.

I agree that this ought to be possible - good idea.
