
From nobody Wed Aug 16 12:25:30 2017
Return-Path: <melinda.shore@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 049331323AA for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 12:25:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ODhIUu7guJFU for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 12:25:26 -0700 (PDT)
Received: from mail-pg0-x235.google.com (mail-pg0-x235.google.com [IPv6:2607:f8b0:400e:c05::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 23ADF13235A for <trans@ietf.org>; Wed, 16 Aug 2017 12:25:26 -0700 (PDT)
Received: by mail-pg0-x235.google.com with SMTP id u5so27229771pgn.0 for <trans@ietf.org>; Wed, 16 Aug 2017 12:25:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=to:from:subject:message-id:date:user-agent:mime-version; bh=DmnFb52wZQmANJa1ZuyazkXt53BGPtWHqjwrJAWS/wI=; b=Rg/hvRORqslqiEEIFG90zHyS4PWTZh6qXMPdfuAGYAJVTlmlf6D1uq0tbAn0zW8UXO f0b91HOSIJHKQrwsyWeTVgaM2oEnxJSCGOi/eVcfckmAT2PXe9RcPQ81JpHsKMn2fr8h 1d6Aa+M+Z+HSkhtwa9PQYPrwL3mp8y84HcDCkBAJ6g/tSuUNX8QUqiv7t6e3xASZieDF cEQevWBVnw53B51JJnrRYGxYn6SEaUpFJIHFsvmKQ/eVJKw5GuxxxeT4gyxEQhkQgkPD frc3WmiAYiCZLbYIdhYm19OJJX3W0gAGmDBAKiRkdvlf6lLGhLbrEsLC/GcV4ZaoHzbe 76Ug==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:message-id:date:user-agent :mime-version; bh=DmnFb52wZQmANJa1ZuyazkXt53BGPtWHqjwrJAWS/wI=; b=qOnx8IdeSoFYAcJavD+J8Q9cvhy4O07jlCLJA6miGA3RATL3iW169tfbmfRq+MomHp oYR0TRMwQh5mk+oW8OGZPaa8nH7HBoaKpxieKzEn8op6IIPVT4HzgpO5vihWHax+f/xy jcB8AMpDuKrAKBwTcPDFOIYVseUpkBEebBiHhUFc47WpT37Hic2aOplY5YaNhyrQRHi4 UblJeV2r/z8ZzLAfi26llyIaAWVYCEMbElufBuhnbafVuPtWrPPvz6HwNNsEyebgAfvN zcj2L8+2VxUH5dXgdFJ+3/Qhtn2UJIOamyrusz0cFY+cecS1C8+9QBtPZ0olB137SCHD dQwA==
X-Gm-Message-State: AHYfb5g+KsUOheTv0mxDSktP8ALkcqhxBLyRfxEdF8NOPo5QIA/md41a 0ksB15lVEoKc22iUNDM=
X-Received: by 10.84.236.5 with SMTP id q5mr2942788plk.233.1502911525307; Wed, 16 Aug 2017 12:25:25 -0700 (PDT)
Received: from aspen.local (209-193-10-192-radius.dynamic.acsalaska.net. [209.193.10.192]) by smtp.gmail.com with ESMTPSA id t14sm2965652pgr.94.2017.08.16.12.25.23 for <trans@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Aug 2017 12:25:24 -0700 (PDT)
To: "trans@ietf.org" <trans@ietf.org>
From: Melinda Shore <melinda.shore@gmail.com>
Message-ID: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
Date: Wed, 16 Aug 2017 11:25:20 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="TSewdCrjTSx6bnWp5KaEca24S2s4Mm26h"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/6oPntxCFmK7LpFNt50BSyW2BmRY>
Subject: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 19:25:28 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--TSewdCrjTSx6bnWp5KaEca24S2s4Mm26h
Content-Type: multipart/mixed; boundary="wsT1gkDWMobStax03fq3n1p6Ja4rKUqbL";
 protected-headers="v1"
From: Melinda Shore <melinda.shore@gmail.com>
To: "trans@ietf.org" <trans@ietf.org>
Message-ID: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
Subject: Future work

--wsT1gkDWMobStax03fq3n1p6Ja4rKUqbL
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi, all:

With our major deliverable now pushed out towards IETF
last call, it's time to start considering whether or not
there's additional work to do, or if we're done.  As
we've talked about before, we know that there's at least
some interest in:

=2E a client behavior document
=2E logging DNSSEC records
=2E logging binaries

Plus, I'm somewhat concerned about lack of gossip implementation
and deployment, and it's worth considering whether that's because
of lack of interest or because people running logs don't think
that what's in the gossip spec is suitable for their needs.

So, we're looking for feedback on future work, and particularly
on whether or not there are people working on drafts relevant to
this working group, or people with plans to work on drafts.

Melinda


--wsT1gkDWMobStax03fq3n1p6Ja4rKUqbL--

--TSewdCrjTSx6bnWp5KaEca24S2s4Mm26h
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJZlJwhAAoJELiGRpM6HoEu1QoP/31DGROhPciPl7WS3aw/v1Hw
AT6+45LuKp7YaCWIiHOGjQ1e4MK/QaACxqM0AecmwqkWAsgcioKKIzf1rBwTEHAe
lAS6Y63TtcFvbIHgxTQ7onEvEJbftuYR+eTeoruzTJHYwEtWQTnxDmOwX4s4qG8X
c/OwiYoJ1PGuKtLwWXSa+rqp6c1Jh8bb8tz0Ta61gGlG8tN11vmXiyVRDOZNX3PH
meyjkZva47jtZ7PpWr7LMreVyfX4FGEc1YPVVF5a3L1UhkhtsqaEyxJ6Xjm8lDRE
3QO4DCL92kiOcxFz2K9OgEzTzEIbWmT1e4R/IaFUDonAeCAekHLhm82sWMkjDalJ
WNnD6tpDwovd6bHBFpEqbdIV4PmninuLZb++XKWr27dTpr59WXRE/BjTXEXYu4KB
tVC5Mj4WiMwJvo9a/MQ09mRXu8c//wIjiU6Xy0NsGxkhzMnPEE37n12SEE7IYg0S
7rToHANin+cgDQtBUSGGZhDSEBmdwst6pFvzO9HCjRjsZSFaJmbMNFkK4XjSmujX
T7ghXfdoZa+vIuP+TWz/yVGfseY4LSKLlUi/qy9Z9qPZ3hXD9aTUeO6K9/KFGK0s
vGIdUJtDNcnBga+RE7SE+GkDEsPc8c+2fzAfBGzcvB/lHBP8+HP1t7B2uYj/2Ff+
QPkg+EXqAJR7oh5kcPym
=QoYM
-----END PGP SIGNATURE-----

--TSewdCrjTSx6bnWp5KaEca24S2s4Mm26h--


From nobody Wed Aug 16 13:09:26 2017
Return-Path: <agwa@andrewayer.name>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 732AE132630 for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 13:09:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewayer.name
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qfYqXAAZaFet for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 13:09:23 -0700 (PDT)
Received: from alcazar.beanwood.com (alcazar.beanwood.com [IPv6:2600:3c00:e000:6c::1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1E6EE132027 for <trans@ietf.org>; Wed, 16 Aug 2017 13:09:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=andrewayer.name; s=beanwood20160511; t=1502914162; bh=tZJEbdIL6mqRnekKFXLcuxohw4pmyMciMsTZsC4kwgc=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=kXymlHNRJXjPCvQtfb6u7YJzbyLjBY42Ql+QfJUpNqOzrnMBV8vUbn7tXxnY9a7Uz jDeKEJTaie3+T5ziCyWTIX0TqIuLoowhrHuUu4yDOoTzgE2pxBt64wjL5GUTlEEw5V yf6E+NgRqS/klVxkoUrnDKwSBnIWD6zRrWmX2kZ1HUZ/hALrIjrHz0j8UuS+M1X3Cl fNz/WQ9VLOzmxWqtg+Ndjdy3SDJxkOFC5ivZYHaRtJCcDaRKZGK4FY38bcxMZsZW/q VeDQVrWqhxjQMy0v4hBvICj/dCsB03jVp2HuWG13VQ869XNHXDlaUTOivolx8+yqH+ dHL07opxvu1Tw==
Date: Wed, 16 Aug 2017 13:09:21 -0700
From: Andrew Ayer <agwa@andrewayer.name>
To: Melinda Shore <melinda.shore@gmail.com>
Cc: "trans@ietf.org" <trans@ietf.org>
Message-Id: <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name>
In-Reply-To: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/FUWu3uEFXjn5DGGmsEUTvKfonCU>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 20:09:24 -0000

On Wed, 16 Aug 2017 11:25:20 -0800
Melinda Shore <melinda.shore@gmail.com> wrote:

> Hi, all:
> 
> With our major deliverable now pushed out towards IETF
> last call, it's time to start considering whether or not
> there's additional work to do, or if we're done.  As
> we've talked about before, we know that there's at least
> some interest in:
> 
> . a client behavior document
> . logging DNSSEC records
> . logging binaries

I've also seen interest expressed on the mailing list for:

* A monitor API
* A strict version of CT

> Plus, I'm somewhat concerned about lack of gossip implementation
> and deployment, and it's worth considering whether that's because
> of lack of interest or because people running logs don't think
> that what's in the gossip spec is suitable for their needs.

Note that logs don't participate in gossip, so your question is one
for TLS clients and monitors/auditors.

The biggest problem is that the gossip spec only works with CTv2,
and there are no CTv2 logs in existence, let alone implementations.

Nevertheless, there's a fairly obvious and minor modification to make
STH pollination work with CTv1, and I know of 7 different
monitor/auditor implementations which are using this variation of the
spec to exchange STHs from publicly-trusted CTv1 logs.

That said, I know of no implementations of SCT feedback, nor of any plans
by TLS clients to implement any part of gossip.

Regards,
Andrew


From nobody Wed Aug 16 14:25:52 2017
Return-Path: <tom@ritter.vg>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FE3D13271D for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 14:25:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ritter.vg
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uHsyOsPBVvza for <trans@ietfa.amsl.com>; Wed, 16 Aug 2017 14:25:43 -0700 (PDT)
Received: from mail-qk0-x22c.google.com (mail-qk0-x22c.google.com [IPv6:2607:f8b0:400d:c09::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6C820132356 for <trans@ietf.org>; Wed, 16 Aug 2017 14:25:43 -0700 (PDT)
Received: by mail-qk0-x22c.google.com with SMTP id z18so27407543qka.4 for <trans@ietf.org>; Wed, 16 Aug 2017 14:25:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ritter.vg; s=vg; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=9af/S9fLdFDnac5yxmbGCWKp27OPABWe2+FqHJhUU1w=; b=JwF7XPxnX8eduDwzPhynhuz6YxUbnAy90T9xhrpuHHbf86QWQtAud7dKFVj/3eLLtj oyF6nHAPWE903pYvSIOBQaY2hDdMbjhIrKyoWUR4XTZFc/o3sNrge0B4p20V8eyNLzE+ a4AyiFYzbc0q22w0QmU0UuS0IAPv+XQlQNAmg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=9af/S9fLdFDnac5yxmbGCWKp27OPABWe2+FqHJhUU1w=; b=FgjZOzWjMxcyoBwKHqFF84EiK74KeEZqA6vE1QGkmzur1U2k1x6MSZyjPsjmbPER62 SFtLAe+8ik5FW4zF+W/SYGougA/RZ50jWr4NE1B172bs+ToQbzFxoIYezflUXzPsw8On zh2oVYjaILzBvm5MQOewZp2CPzCuITSRxzJJR+PTRfryoJCkKri6l9cCDu/dUygZNJ2o C+cjk8sxCkJf1xXMqinrGAB3puQ2NHoHFPzZsMpovwRA0mqH5Q5fJ8HJOCTh9irYx1NE C1RXI1v2TlcAzFIVQRpVqI1S3fnqMXXiqBHP5rVg6PrL+iVxwEmvu8Le7ELWyRs+AD1v bjaw==
X-Gm-Message-State: AHYfb5iwkZalHceZ/7Rktb/yixqNzwdOQ/HcdqK7n4e5aoyFEsXb6hIU tV4nQGUOJlkExFHzJkx2r8eegO50cQUo
X-Received: by 10.55.27.222 with SMTP id m91mr4308331qkh.298.1502918742470; Wed, 16 Aug 2017 14:25:42 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.30.67 with HTTP; Wed, 16 Aug 2017 14:25:21 -0700 (PDT)
In-Reply-To: <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com> <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name>
From: Tom Ritter <tom@ritter.vg>
Date: Wed, 16 Aug 2017 16:25:21 -0500
Message-ID: <CA+cU71nMGU9ibu0J_CoNFtOcihhLzts0gNp8RBY6V0Ck64Ymww@mail.gmail.com>
To: Andrew Ayer <agwa@andrewayer.name>
Cc: Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/aBVFuszJfGMc18N7GQYWQOQD9mw>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 21:25:45 -0000

On 16 August 2017 at 15:09, Andrew Ayer <agwa@andrewayer.name> wrote:
> That said, I know of no implementations of SCT feedback, nor of any plans
> by TLS clients to implement any part of gossip.

Well, there's Google's thing, which I talked about here:
https://www.ietf.org/mail-archive/web/trans/current/msg02626.html

There was Richard Barnes interest in changing the ways logs operate
(maybe that's what Andrew means by Strict CT?).

I am interested in several of these things, but I do not think I am a
good candidate to be an author.

-tom


From nobody Thu Aug 17 02:33:02 2017
Return-Path: <benl@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A2C313266F for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 02:33:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level: 
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EbtagrqaCjsb for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 02:32:58 -0700 (PDT)
Received: from mail-vk0-x22d.google.com (mail-vk0-x22d.google.com [IPv6:2607:f8b0:400c:c05::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6219C13247A for <trans@ietf.org>; Thu, 17 Aug 2017 02:32:58 -0700 (PDT)
Received: by mail-vk0-x22d.google.com with SMTP id d124so20512052vkf.2 for <trans@ietf.org>; Thu, 17 Aug 2017 02:32:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=D5hX9VJpWuwKPfAv6HNtYYnppN+16EsJvmBkMTTXrgE=; b=TRVZBvfxyvv8410nB/gUq7QRvF2m8+QGGQAv3CkOJzB+iloYFweSt4/sYBOLxapyXL xAGi0HE+mG5O6lOwmrmRW2lcOErjdoYU2m0V7aTC0xAjnOnhHknTUusLIr9o05bF4Ypw myBjBAv0aq6WCqP4HCERA3s8vCQby/bjxJ0SL/qA3cGIBdSpZGxCfUPUrrwTlw089Zl8 iR+boO8YYO4/YAN2I/FbWZEgTKWAgq/ljdCsRJGxSsmYrLmvBjipZPL5UC48sacqVKRK YoFUmbJGMPhU8hMUTRAoXzh9ICp8gq0cHAZQk1CFMwV1LR2oo/fEN/6jrd9+tY+126Hx LwvA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=D5hX9VJpWuwKPfAv6HNtYYnppN+16EsJvmBkMTTXrgE=; b=j1hgDhWnjnfUjWXtFYnZ3r71qu9QDnnRUmKuT5wnvlEEZeF2RKEKsCAt6+7Vn4X4XF qZV4TKmlkWIxS+LvIbpBcB13sAwfyEg52+fnUN1BzxnIDdHjnDHAj2ugDjXilnQ0ZmBx o2eDVlfSBIBNl4vvgMFbXrTkmuKcZs5pRdjiuyS6r3OgmzGwOpHtIurVRBrERwuYPzn4 i0ApIfYuJyNfk0U2r1ZkgWHILbI4yY2ErJmROJM36ixoJ1YMaTfhWku34wR63AGQ6m5a mXlxXfqAjOwdk7N0aYxKOdOyTLyNy0l2causoxBZ7BcPLojZQ4gli8U2MppOFPzC7KON hB1g==
X-Gm-Message-State: AHYfb5gqmwqWRcUGpueX2oz1yfEDshztzjxEWxCiIBQEkMy8LNDzROKX WQxFazyVNlLkT0WK5xtcjA3TKyLiJwuz
X-Received: by 10.31.89.195 with SMTP id n186mr2946468vkb.5.1502962377217; Thu, 17 Aug 2017 02:32:57 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.31.164.140 with HTTP; Thu, 17 Aug 2017 02:32:56 -0700 (PDT)
In-Reply-To: <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com> <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name>
From: Ben Laurie <benl@google.com>
Date: Thu, 17 Aug 2017 10:32:56 +0100
Message-ID: <CABrd9SQYWYSxd4hUyRrqCpqJ20sHOUdULpQ0q+qkqCFa_sEVsw@mail.gmail.com>
To: Andrew Ayer <agwa@andrewayer.name>
Cc: Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
Content-Type: multipart/alternative; boundary="001a114e1ff29b64570556efb2ce"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/tmD1eIzA_D0hMDcAfHMoQFOIACs>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 09:33:00 -0000

--001a114e1ff29b64570556efb2ce
Content-Type: text/plain; charset="UTF-8"

On 16 August 2017 at 21:09, Andrew Ayer <agwa@andrewayer.name> wrote:

> On Wed, 16 Aug 2017 11:25:20 -0800
> Melinda Shore <melinda.shore@gmail.com> wrote:
>
> > Hi, all:
> >
> > With our major deliverable now pushed out towards IETF
> > last call, it's time to start considering whether or not
> > there's additional work to do, or if we're done.  As
> > we've talked about before, we know that there's at least
> > some interest in:
> >
> > . a client behavior document
> > . logging DNSSEC records
> > . logging binaries
>
> I've also seen interest expressed on the mailing list for:
>
> * A monitor API
>

Since we now know how to build verifiable monitors, perhaps that is part of
an API?


> * A strict version of CT
>

What do you mean by this?


>
> > Plus, I'm somewhat concerned about lack of gossip implementation
> > and deployment, and it's worth considering whether that's because
> > of lack of interest or because people running logs don't think
> > that what's in the gossip spec is suitable for their needs.
>
> Note that logs don't participate in gossip, so your question is one
> for TLS clients and monitors/auditors.
>
> The biggest problem is that the gossip spec only works with CTv2,
> and there are no CTv2 logs in existence, let alone implementations.
>
> Nevertheless, there's a fairly obvious and minor modification to make
> STH pollination work with CTv1, and I know of 7 different
> monitor/auditor implementations which are using this variation of the
> spec to exchange STHs from publicly-trusted CTv1 logs.
>
> That said, I know of no implementations of SCT feedback, nor of any plans
> by TLS clients to implement any part of gossip.
>

IMO "gossipless gossip", i.e. cross-logging of STHs is the way to go.


>
> Regards,
> Andrew
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>

--001a114e1ff29b64570556efb2ce
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On 16 August 2017 at 21:09, Andrew Ayer <span dir=3D"ltr">&lt;<a href=
=3D"mailto:agwa@andrewayer.name" target=3D"_blank">agwa@andrewayer.name</a>=
&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0=
 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=3D"">On We=
d, 16 Aug 2017 11:25:20 -0800<br>
Melinda Shore &lt;<a href=3D"mailto:melinda.shore@gmail.com">melinda.shore@=
gmail.com</a>&gt; wrote:<br>
<br>
&gt; Hi, all:<br>
&gt;<br>
&gt; With our major deliverable now pushed out towards IETF<br>
&gt; last call, it&#39;s time to start considering whether or not<br>
&gt; there&#39;s additional work to do, or if we&#39;re done.=C2=A0 As<br>
&gt; we&#39;ve talked about before, we know that there&#39;s at least<br>
&gt; some interest in:<br>
&gt;<br>
&gt; . a client behavior document<br>
&gt; . logging DNSSEC records<br>
&gt; . logging binaries<br>
<br>
</span>I&#39;ve also seen interest expressed on the mailing list for:<br>
<br>
* A monitor API<br></blockquote><div><br></div><div>Since we now know how t=
o build verifiable monitors, perhaps that is part of an API?</div><div>=C2=
=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;borde=
r-left:1px #ccc solid;padding-left:1ex">
* A strict version of CT<br></blockquote><div><br></div><div>What do you me=
an by this?</div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<span class=3D""><br>
&gt; Plus, I&#39;m somewhat concerned about lack of gossip implementation<b=
r>
&gt; and deployment, and it&#39;s worth considering whether that&#39;s beca=
use<br>
&gt; of lack of interest or because people running logs don&#39;t think<br>
&gt; that what&#39;s in the gossip spec is suitable for their needs.<br>
<br>
</span>Note that logs don&#39;t participate in gossip, so your question is =
one<br>
for TLS clients and monitors/auditors.<br>
<br>
The biggest problem is that the gossip spec only works with CTv2,<br>
and there are no CTv2 logs in existence, let alone implementations.<br>
<br>
Nevertheless, there&#39;s a fairly obvious and minor modification to make<b=
r>
STH pollination work with CTv1, and I know of 7 different<br>
monitor/auditor implementations which are using this variation of the<br>
spec to exchange STHs from publicly-trusted CTv1 logs.<br>
<br>
That said, I know of no implementations of SCT feedback, nor of any plans<b=
r>
by TLS clients to implement any part of gossip.<br></blockquote><div><br></=
div><div>IMO &quot;gossipless gossip&quot;, i.e. cross-logging of STHs is t=
he way to go.</div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Regards,<br>
Andrew<br>
<br>
______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/trans</a><br>
</blockquote></div><br></div></div>

--001a114e1ff29b64570556efb2ce--


From nobody Thu Aug 17 03:35:32 2017
Return-Path: <alcutter@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF658132063 for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 03:35:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RAzqsYRQPMdE for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 03:35:28 -0700 (PDT)
Received: from mail-pg0-x233.google.com (mail-pg0-x233.google.com [IPv6:2607:f8b0:400e:c05::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D054D132064 for <trans@ietf.org>; Thu, 17 Aug 2017 03:35:27 -0700 (PDT)
Received: by mail-pg0-x233.google.com with SMTP id v189so40222610pgd.2 for <trans@ietf.org>; Thu, 17 Aug 2017 03:35:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=GIUCYektItpcGHk4Jtf+BPPKVRENgnbbWr19jCHMcfA=; b=vo98FUz0zZwJD4RFy+0K/jXe6Fd4g+Skj7SgJrtUVgp6Ay5Dz0GbEFZXdia3DBs3ZY kHbUF9mqlbJCFiIYoNEi8bZ5B1hWEdwXl1RDcfyinos1wwzc+f47agsiYBcry2VxEMLc sciP5rijbawDZF9I50LSC2qe6VZgOYwLVpeSthEckdBfJ+aV8BYwm5IlLQ0S3AKBX+yv +wvmVzdHi6SQ8KYbZ/MoRwZWqWxbGRX9HSBYh750ybWsEmnkAEVRDAr91tZtc6NAbkuH CZQxGmTJbPuSBfkj7Wn5EoaI1MLn9FkdHITVZzaEUMUoGDWxeIyIVwqKr/zffpUXXDKG q7wA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=GIUCYektItpcGHk4Jtf+BPPKVRENgnbbWr19jCHMcfA=; b=MG2FvZYYEqgst5RSftbKT91cJ34gzWGAPXOuDRV009v+Hm3BtwgP0YBcLjY5R/jNrP QAQTsB2Tiegtqyq3ALh2EFSQ+QrVSY86e9Ob7q29J16D9koPGrvUqW3fNMxfMCqddkAO C00AIhPZ+vQyfI61MnRPw+AdFtk0h5C615sjke1ahanx58iLS87pgs89REBkLBlu3nv1 UW4xme8dJqKrei9GmriWwojcgfcdxGWi1+wFyIWfBzSrFn/qcs6mNpi4bpm996+x1rE0 hhlmh9bajJ3T5G0POM1MncpDUhENv9V/4jDuAkT5MQ+AbVNCVGwg0rqLCok71iJycpmI 6OnA==
X-Gm-Message-State: AHYfb5jQCNXnL8wwbyu462G7B+5EjAo2/DZB7sKna2WCWGTXzcKZGSp+ JCNIuMjZyihku/K9aAJjw3BUDpwZcuZS
X-Received: by 10.84.215.207 with SMTP id g15mr1349743plj.22.1502966127095; Thu, 17 Aug 2017 03:35:27 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.191.1 with HTTP; Thu, 17 Aug 2017 03:35:26 -0700 (PDT)
In-Reply-To: <CABrd9SQYWYSxd4hUyRrqCpqJ20sHOUdULpQ0q+qkqCFa_sEVsw@mail.gmail.com>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com> <20170816130921.01d50cfec40efb33ab4f0618@andrewayer.name> <CABrd9SQYWYSxd4hUyRrqCpqJ20sHOUdULpQ0q+qkqCFa_sEVsw@mail.gmail.com>
From: Al Cutter <al@google.com>
Date: Thu, 17 Aug 2017 11:35:26 +0100
Message-ID: <CACM=_OczZOWigG6Ovmh+vaE089O2k4ewSAZsiTaSRfHbjYQnAA@mail.gmail.com>
To: Ben Laurie <benl@google.com>
Cc: Andrew Ayer <agwa@andrewayer.name>, Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
Content-Type: multipart/alternative; boundary="f403045c575c1dd18c0556f09289"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/iWwZckInM3MG25LNAblPcMJEgvY>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 10:35:31 -0000

--f403045c575c1dd18c0556f09289
Content-Type: text/plain; charset="UTF-8"

On Thu, Aug 17, 2017 at 10:32 AM, Ben Laurie <benl@google.com> wrote:

>
>
> On 16 August 2017 at 21:09, Andrew Ayer <agwa@andrewayer.name> wrote:
>
>> On Wed, 16 Aug 2017 11:25:20 -0800
>> Melinda Shore <melinda.shore@gmail.com> wrote:
>>
>> > Hi, all:
>> >
>> > With our major deliverable now pushed out towards IETF
>> > last call, it's time to start considering whether or not
>> > there's additional work to do, or if we're done.  As
>> > we've talked about before, we know that there's at least
>> > some interest in:
>> >
>> > . a client behavior document
>> > . logging DNSSEC records
>> > . logging binaries
>>
>> I've also seen interest expressed on the mailing list for:
>>
>> * A monitor API
>>
>
> Since we now know how to build verifiable monitors, perhaps that is part
> of an API?
>

>
>> * A strict version of CT
>>
>
> What do you mean by this?
>
>
>>
>> > Plus, I'm somewhat concerned about lack of gossip implementation
>> > and deployment, and it's worth considering whether that's because
>> > of lack of interest or because people running logs don't think
>> > that what's in the gossip spec is suitable for their needs.
>>
>> Note that logs don't participate in gossip, so your question is one
>> for TLS clients and monitors/auditors.
>>
>> The biggest problem is that the gossip spec only works with CTv2,
>> and there are no CTv2 logs in existence, let alone implementations.
>>
>> Nevertheless, there's a fairly obvious and minor modification to make
>> STH pollination work with CTv1, and I know of 7 different
>> monitor/auditor implementations which are using this variation of the
>> spec to exchange STHs from publicly-trusted CTv1 logs.
>>
>> That said, I know of no implementations of SCT feedback, nor of any plans
>> by TLS clients to implement any part of gossip.
>>
>
> IMO "gossipless gossip", i.e. cross-logging of STHs is the way to go.
>

I agree, but you knew that already :)

To the broader, original, question - I do think there's plenty more work to
do, but I'd prefer to see any document work happening in parallel with
experimentation and implementations (and again I admit I'm not familiar
with IETF process, so feel free to tell me that's now how it's supposed to
work).
With that in mind, my team intends to start some experimental work on the
verifiable monitor and gossip topics soon (probably Q4 time-frame), once
we've dealt with getting Trillian based CT Logs into service, and related
existing-ecosystem work; and if there's interest we'd welcome discussion
and collaboration either here or over on the CT list.

Cheers,
Al.


>
>>
>> Regards,
>> Andrew
>>
>> _______________________________________________
>> Trans mailing list
>> Trans@ietf.org
>> https://www.ietf.org/mailman/listinfo/trans
>>
>
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>
>

--f403045c575c1dd18c0556f09289
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Thu, Aug 17, 2017 at 10:32 AM, Ben Laurie <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:benl@google.com" target=3D"_blank">benl@google.com</a>&gt;</s=
pan> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex=
;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><br><div cla=
ss=3D"gmail_extra"><br><div class=3D"gmail_quote"><span class=3D"">On 16 Au=
gust 2017 at 21:09, Andrew Ayer <span dir=3D"ltr">&lt;<a href=3D"mailto:agw=
a@andrewayer.name" target=3D"_blank">agwa@andrewayer.name</a>&gt;</span> wr=
ote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border=
-left:1px #ccc solid;padding-left:1ex"><span>On Wed, 16 Aug 2017 11:25:20 -=
0800<br>
Melinda Shore &lt;<a href=3D"mailto:melinda.shore@gmail.com" target=3D"_bla=
nk">melinda.shore@gmail.com</a>&gt; wrote:<br>
<br>
&gt; Hi, all:<br>
&gt;<br>
&gt; With our major deliverable now pushed out towards IETF<br>
&gt; last call, it&#39;s time to start considering whether or not<br>
&gt; there&#39;s additional work to do, or if we&#39;re done.=C2=A0 As<br>
&gt; we&#39;ve talked about before, we know that there&#39;s at least<br>
&gt; some interest in:<br>
&gt;<br>
&gt; . a client behavior document<br>
&gt; . logging DNSSEC records<br>
&gt; . logging binaries<br>
<br>
</span>I&#39;ve also seen interest expressed on the mailing list for:<br>
<br>
* A monitor API<br></blockquote><div><br></div></span><div>Since we now kno=
w how to build verifiable monitors, perhaps that is part of an API?=C2=A0</=
div></div></div></div></blockquote><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=
=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote"><span class=
=3D""><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* A strict version of CT<br></blockquote><div><br></div></span><div>What do=
 you mean by this?</div><span class=3D""><div>=C2=A0</div><blockquote class=
=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padd=
ing-left:1ex">
<span><br>
&gt; Plus, I&#39;m somewhat concerned about lack of gossip implementation<b=
r>
&gt; and deployment, and it&#39;s worth considering whether that&#39;s beca=
use<br>
&gt; of lack of interest or because people running logs don&#39;t think<br>
&gt; that what&#39;s in the gossip spec is suitable for their needs.<br>
<br>
</span>Note that logs don&#39;t participate in gossip, so your question is =
one<br>
for TLS clients and monitors/auditors.<br>
<br>
The biggest problem is that the gossip spec only works with CTv2,<br>
and there are no CTv2 logs in existence, let alone implementations.<br>
<br>
Nevertheless, there&#39;s a fairly obvious and minor modification to make<b=
r>
STH pollination work with CTv1, and I know of 7 different<br>
monitor/auditor implementations which are using this variation of the<br>
spec to exchange STHs from publicly-trusted CTv1 logs.<br>
<br>
That said, I know of no implementations of SCT feedback, nor of any plans<b=
r>
by TLS clients to implement any part of gossip.<br></blockquote><div><br></=
div></span><div>IMO &quot;gossipless gossip&quot;, i.e. cross-logging of ST=
Hs is the way to go.</div></div></div></div></blockquote><div><br></div><di=
v>I agree, but you knew that already :)</div><div><br></div><div>To the bro=
ader, original, question - I do think there&#39;s plenty more work to do, b=
ut I&#39;d prefer to see any document work happening in parallel with exper=
imentation and implementations (and again I admit I&#39;m not familiar with=
 IETF process, so feel free to tell me that&#39;s now how it&#39;s supposed=
 to work).</div><div>With that in mind, my team intends to start some exper=
imental work on the verifiable monitor and gossip topics soon (probably Q4 =
time-frame), once we&#39;ve dealt with getting Trillian based CT Logs into =
service, and related existing-ecosystem work; and if there&#39;s interest w=
e&#39;d welcome discussion and collaboration either here or over on the CT =
list.</div><div><br></div><div>Cheers,</div><div>Al.</div><div><br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_extra"><d=
iv class=3D"gmail_quote"><span class=3D""><div>=C2=A0</div><blockquote clas=
s=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;pad=
ding-left:1ex">
<br>
Regards,<br>
Andrew<br>
<br>
______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org" target=3D"_blank">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/trans</a><br>
</blockquote></span></div><br></div></div>
<br>______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/trans</a><br>
<br></blockquote></div><br></div></div>

--f403045c575c1dd18c0556f09289--


From nobody Thu Aug 17 03:45:21 2017
Return-Path: <rob.stradling@comodo.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61ACD126B7E for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 03:45:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.189
X-Spam-Level: 
X-Spam-Status: No, score=-4.189 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xt4bxk8jG2QF for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 03:45:14 -0700 (PDT)
Received: from mmextmx2.mcr.colo.comodoca.net (mmextmx2.mcr.colo.comodoca.net [IPv6:2a02:1788:402:c00::c0a8:9cd6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 917F0124E15 for <trans@ietf.org>; Thu, 17 Aug 2017 03:45:13 -0700 (PDT)
Received: (qmail 9919 invoked by uid 1004); 17 Aug 2017 10:45:11 -0000
Received: from rmdccgwarp1.reyn.mcr.dc.comodo.net (HELO maileu.comodo.net) (10.1.72.82) by mmextmx2.mcr.colo.comodoca.net (qpsmtpd/0.84) with ESMTP; Thu, 17 Aug 2017 11:45:11 +0100
Received: from [192.168.0.58] ([192.168.0.58]) by maileu.comodo.net (IceWarp 11.4.6.0 DEB8 x64) with ASMTP (SSL) id 201708171145115756; Thu, 17 Aug 2017 11:45:11 +0100
To: Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
From: Rob Stradling <rob.stradling@comodo.com>
Message-ID: <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
Date: Thu, 17 Aug 2017 11:45:11 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.0
MIME-Version: 1.0
In-Reply-To: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/tB8YhAapz_6RN9MJVMKlRCR9HK0>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 10:45:19 -0000

On 16/08/17 20:25, Melinda Shore wrote:
<snip>
> So, we're looking for feedback on future work, and particularly
> on whether or not there are people working on drafts relevant to
> this working group, or people with plans to work on drafts.

Hi Melinda.

I've started work on a draft entitled Private Key Compromise 
Transparency (PKCT).  The idea is to enable anyone who finds a 
compromised private key to submit a "proof of compromise" to one or more 
public log(s).  It'll build on top of 6962-bis, defining a new 
VersionedTransType value, etc.

Providers of certificate revocation services (CAs and browser vendors) 
will be able to monitor these PKCT logs and take appropriate action. 
Since the "proofs of compromise" will be programmatically verifiable, it 
will become possible to automate existing, error-prone, manual processes 
(e.g., see [1]).


[1] 
https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html

-- 
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online


From nobody Thu Aug 17 04:21:40 2017
Return-Path: <benl@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B40BE1204DA for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 04:21:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uZoJJsKQP1CR for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 04:21:37 -0700 (PDT)
Received: from mail-ua0-x236.google.com (mail-ua0-x236.google.com [IPv6:2607:f8b0:400c:c08::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 61CDB126B6D for <trans@ietf.org>; Thu, 17 Aug 2017 04:21:37 -0700 (PDT)
Received: by mail-ua0-x236.google.com with SMTP id q25so23544005uah.1 for <trans@ietf.org>; Thu, 17 Aug 2017 04:21:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=GyEz0+Fxbu+4Q9AcE/x1aKGz2RQtRxnIVSTwWOokKtI=; b=l94jvLvajsFQWnG99qmP22iUIHYMdMGRZsD4QDdGJUjEwoPSwDtRJld4+WCV2rltJL w6kYHuCgaRKfoIE1Uh9DwAAraw0ret8FbyJmuZ+8099V6ow+28/pkwAobIgrW9z5qEzg yYXQVKspLT12kLB2wgDa8kZAaHRXYLugOSUKdDuwol0aR36y1eBRpNxg5FnYi63gQ1dt dO2buAKbDN3Bbm5wnIo1t6KFFIizvTYKMT95JRwI7gnXvOsIhCXOo2IDz6hB1C19DlE9 jZiRXNTWFoliyf6uA4pfOL8F2kN4viMjeZpTWnviNtkcyAJoVFiKyKQTfKMjRfISM3BZ 6y/w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=GyEz0+Fxbu+4Q9AcE/x1aKGz2RQtRxnIVSTwWOokKtI=; b=axRVOKQuL1AD2npZ2Qx9NNxAoX0XJvT2i4GAonyNa4y80aRHPKLBtODNn7bOaIONTk 1/lxvyYSzSBaWFnOzjDtI3bUHzGidLzACPzud6nF4jimEuRf91NgrzqNDVZssWKYYstX BUOwAhIhL1sv9qICnMPqa4e4HAbO3TJyJ5zU2SetNTytx83MQlUBQ0QQYDvW3aaaWTmv hHmFlckAIxbVrNihATiTYadlsnX52+C4Ic23LcIPeDnODHn2ZJ+5OSCT6wfojXAuY06A KnaFlr7k7QlyL7kkhACVQUdji7sMLcjZddZceIMottAA7zDgl17rIdwF5hOP5F6towFG mgoQ==
X-Gm-Message-State: AHYfb5gxuyfZZ0EH9Xq7ffW2XPm8m5cSaVdQ9NRZ3i9LYU56f8Kw6JB6 UznQIxsl+AfCAh04M7ieHc2jqMBbPEtG
X-Received: by 10.159.57.237 with SMTP id p45mr2946534uag.198.1502968896263; Thu, 17 Aug 2017 04:21:36 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.31.164.140 with HTTP; Thu, 17 Aug 2017 04:21:35 -0700 (PDT)
In-Reply-To: <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com> <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
From: Ben Laurie <benl@google.com>
Date: Thu, 17 Aug 2017 12:21:35 +0100
Message-ID: <CABrd9SQt5zoqMEnDkanPKQo6AJFPQJx0ygt+41dUFsprBjgjbA@mail.gmail.com>
To: Rob Stradling <rob.stradling@comodo.com>
Cc: Melinda Shore <melinda.shore@gmail.com>, "trans@ietf.org" <trans@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c0e9d5a2c24540556f13709"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/WLFmIyaH4BJo77ZJDinKJcylOcg>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 11:21:40 -0000

--94eb2c0e9d5a2c24540556f13709
Content-Type: text/plain; charset="UTF-8"

On 17 August 2017 at 11:45, Rob Stradling <rob.stradling@comodo.com> wrote:

> On 16/08/17 20:25, Melinda Shore wrote:
> <snip>
>
>> So, we're looking for feedback on future work, and particularly
>> on whether or not there are people working on drafts relevant to
>> this working group, or people with plans to work on drafts.
>>
>
> Hi Melinda.
>
> I've started work on a draft entitled Private Key Compromise Transparency
> (PKCT).  The idea is to enable anyone who finds a compromised private key
> to submit a "proof of compromise" to one or more public log(s).  It'll
> build on top of 6962-bis, defining a new VersionedTransType value, etc.
>
> Providers of certificate revocation services (CAs and browser vendors)
> will be able to monitor these PKCT logs and take appropriate action. Since
> the "proofs of compromise" will be programmatically verifiable, it will
> become possible to automate existing, error-prone, manual processes (e.g.,
> see [1]).
>

Nice idea.


>
>
> [1] https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-
> with-a-Fake-Private-Key.html
>
> --
> Rob Stradling
> Senior Research & Development Scientist
> COMODO - Creating Trust Online
>
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>

--94eb2c0e9d5a2c24540556f13709
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On 17 August 2017 at 11:45, Rob Stradling <span dir=3D"ltr">&lt;<a href=
=3D"mailto:rob.stradling@comodo.com" target=3D"_blank">rob.stradling@comodo=
.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"ma=
rgin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 16/08/17 20=
:25, Melinda Shore wrote:<br>
&lt;snip&gt;<span class=3D""><br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
So, we&#39;re looking for feedback on future work, and particularly<br>
on whether or not there are people working on drafts relevant to<br>
this working group, or people with plans to work on drafts.<br>
</blockquote>
<br></span>
Hi Melinda.<br>
<br>
I&#39;ve started work on a draft entitled Private Key Compromise Transparen=
cy (PKCT).=C2=A0 The idea is to enable anyone who finds a compromised priva=
te key to submit a &quot;proof of compromise&quot; to one or more public lo=
g(s).=C2=A0 It&#39;ll build on top of 6962-bis, defining a new VersionedTra=
nsType value, etc.<br>
<br>
Providers of certificate revocation services (CAs and browser vendors) will=
 be able to monitor these PKCT logs and take appropriate action. Since the =
&quot;proofs of compromise&quot; will be programmatically verifiable, it wi=
ll become possible to automate existing, error-prone, manual processes (e.g=
., see [1]).<br></blockquote><div><br></div><div>Nice idea.</div><div>=C2=
=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;borde=
r-left:1px #ccc solid;padding-left:1ex">
<br>
<br>
[1] <a href=3D"https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-w=
ith-a-Fake-Private-Key.html" rel=3D"noreferrer" target=3D"_blank">https://b=
log.hboeck.de/archive<wbr>s/888-How-I-tricked-Symantec-<wbr>with-a-Fake-Pri=
vate-Key.html</a><span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
-- <br>
Rob Stradling<br>
Senior Research &amp; Development Scientist<br>
COMODO - Creating Trust Online</font></span><div class=3D"HOEnZb"><div clas=
s=3D"h5"><br>
<br>
______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org" target=3D"_blank">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/trans</a><br>
</div></div></blockquote></div><br></div></div>

--94eb2c0e9d5a2c24540556f13709--


From nobody Thu Aug 17 12:44:58 2017
Return-Path: <melinda.shore@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ADD39132667 for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 12:44:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8hrD-laFW4xh for <trans@ietfa.amsl.com>; Thu, 17 Aug 2017 12:44:51 -0700 (PDT)
Received: from mail-pg0-x22f.google.com (mail-pg0-x22f.google.com [IPv6:2607:f8b0:400e:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A90F132673 for <trans@ietf.org>; Thu, 17 Aug 2017 12:44:39 -0700 (PDT)
Received: by mail-pg0-x22f.google.com with SMTP id t80so21657559pgb.5 for <trans@ietf.org>; Thu, 17 Aug 2017 12:44:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to; bh=36avqAXoet8iM6ttF9duniDtr2apLSQOesEbFG5iExw=; b=lXXk3LtB1o1stq44pb4IeKyRpy76COj+YjmG3LxXbsn+5KCQBljrcZCreZUPCzUwsJ L7qcw/koB0cWF1pAXIkR4UMnE8j5joOHA7sn0pg7tjQiaKWeuO27dT6fZ1Ig7I7P5p5t YsMes/NJydNsPZP7Z0t0sCZASY2/Jl9x7XrX3Qc21BW23I/osEqqGkgfh9bCSWut7D9C HY+HsDdsX5MpSgPSFMr5BRJMGKNwsINjw97D0aQVcBFl/BMn1NwClC+Xe8YKxMt/5Y95 FIKFpAUaOdQCMcJGmqLMWGGRCoSei/ZpuZF3VLROYA6Hk4/fQlxr+kcEvvC99HW56qOg d+CA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to; bh=36avqAXoet8iM6ttF9duniDtr2apLSQOesEbFG5iExw=; b=F3819BM2Ex8PEYVfLjq8ZGl1Fgh/2LpIH/w7SrLcPgSAJ1GbanpYGZtF/5xZNr4esb +cJoSDpsSHht9IY6NRNtpFwCjfqUeeJkLfEwrLH38NoHXNuCsYSDBjlk46cSSpdJ5EK7 jlrmSQCyfcCC+nC1RkWN018WI/0Xyfb3eypm1I17XHB3NMTfKAbuX8hrMIBinG8/QBhU 5yJENkF/c/QDgArhIogaqqLD+mpVSrTs2u0RGDvXijhUpDV7M4mc/+Jk6NzYB4JHHR6y cSavzpWXBNByucfN5/ReFIQduJPkLvD5Gk5n8bTXah/8rEnNhDiDaX6CV5vThlLLrLmr tCPw==
X-Gm-Message-State: AHYfb5hxbzq7EsGEZSpl4a9cT9Oaj3av5d+bn/16+jd+ft+8auS7eEWH Jg7R4R4+Pnlsjju0e9M=
X-Received: by 10.84.232.200 with SMTP id x8mr202317plm.363.1502999078345; Thu, 17 Aug 2017 12:44:38 -0700 (PDT)
Received: from aspen.local (209-193-10-192-radius.dynamic.acsalaska.net. [209.193.10.192]) by smtp.gmail.com with ESMTPSA id r87sm8254468pfb.112.2017.08.17.12.44.36 for <trans@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 17 Aug 2017 12:44:36 -0700 (PDT)
To: "trans@ietf.org" <trans@ietf.org>
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com> <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
From: Melinda Shore <melinda.shore@gmail.com>
Message-ID: <ed2582f7-d559-5bf6-416c-c89fb128a945@gmail.com>
Date: Thu, 17 Aug 2017 11:44:33 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="6xVWfupAww7tLvOlK7QhCcWaISdcqAIL5"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/WfRdJLCXj6KhsmVd44qONQb0Sto>
Subject: Re: [Trans] Future work
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 19:44:56 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--6xVWfupAww7tLvOlK7QhCcWaISdcqAIL5
Content-Type: multipart/mixed; boundary="M9h1EnGNtAPvEGAm4eSc9dD1uXbEGLEpj";
 protected-headers="v1"
From: Melinda Shore <melinda.shore@gmail.com>
To: "trans@ietf.org" <trans@ietf.org>
Message-ID: <ed2582f7-d559-5bf6-416c-c89fb128a945@gmail.com>
Subject: Re: [Trans] Future work
References: <2a482e03-7ac9-d5e3-9d69-7694daf1265b@gmail.com>
 <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>
In-Reply-To: <c8c8b879-cfb3-a3b7-b2ee-f6555ee445d1@comodo.com>

--M9h1EnGNtAPvEGAm4eSc9dD1uXbEGLEpj
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi, all:

It sounds as if there's some interesting work going on, and work
that's relevant to this working group.  Work in the IETF proceeds
through the draft editing/revision process, so it would be excellent
to see some drafts starting to be posted on these topics.  Definitely
feel free to put out requests for collaboration and review!

Thanks,

Melinda


--M9h1EnGNtAPvEGAm4eSc9dD1uXbEGLEpj--

--6xVWfupAww7tLvOlK7QhCcWaISdcqAIL5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJZlfIiAAoJELiGRpM6HoEul2UP/0o7LwqdoitU/eqz0mqumAZh
z2G35UOBBdGZKHGxksS56aXSTe2WfJ1hCPEevpZpe2Wo+shRlcCZiq2ZpZ+Qdkuh
SxWbX3UQPSDnANLg0U9bNjHKWk5ncI97HWuUFpr+kZujEhE/lv8b8be+1Hjy9CUt
ctJNTitoq4rmEyMEd1TuLEv8T2f45alJ7MKlQxEGOyffT5IFEsf5CyruGYb0pfWH
Q+zUiL1GrEXm/MLO3mD4ka5WqY306NW+kb6KmFRMJEsi4/+dXGB4AKVsd4JQIp+z
xhg21dC4RLp9yvuRNUtir5QSFst6Z6TwQ6L+Lx1dlqYxrICJxkpw29WUxdS0aWVc
KmTvR1liYPiZN7NR3hrV2R67PFcaStAcVWdb/iWsBaTbsJZJ8MVuwoOj5iwWfxkl
RF6IZKrxoI6zCgpSZtdmxGrHqEh+XOpfuRnRYZAMx9gV2r8SrIuO8rFs7zg+rMN5
Fem1sglKT7/FRqkZfqDruGhhs7+9MX7juaQOPIoImf4yiH7zarFS7rS7VFC9Tgzn
4oq7buqj1CcssDW7VqFcXde51J1GskDoa3Rby19575y/CtjjezgokehjDFKCL2n1
+zJBYxRdLrDd3/lzNwesfPvbWWIXwmkt+1jEuQZOGGn9y03nAh4ralGrNdszZ/8j
NAT/jl475BvZiW43WHI9
=rwm3
-----END PGP SIGNATURE-----

--6xVWfupAww7tLvOlK7QhCcWaISdcqAIL5--


From nobody Thu Aug 17 12:46:14 2017
Return-Path: <session-request@ietf.org>
X-Original-To: trans@ietf.org
Delivered-To: trans@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id F074213266B; Thu, 17 Aug 2017 12:46:11 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Meeting Session Request Tool <session-request@ietf.org>
To: <session-request@ietf.org>
Cc: melinda.shore@nomountain.net, trans-chairs@ietf.org, trans@ietf.org, ekr@rtfm.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.58.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <150299917198.12265.17776480296683109244.idtracker@ietfa.amsl.com>
Date: Thu, 17 Aug 2017 12:46:11 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/LdqSx6rCU7Ejfm10hlfspdOZgYM>
Subject: [Trans] trans - New Meeting Session Request for IETF 100
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Aug 2017 19:46:12 -0000

A new meeting session request has just been submitted by Melinda Shore, a Chair of the trans working group.


---------------------------------------------------------
Working Group Name: Public Notary Transparency
Area Name: Security Area
Session Requester: Melinda Shore

Number of Sessions: 1
Length of Session(s):  1.5 Hours
Number of Attendees: 50
Conflicts to Avoid: 
 First Priority: ipsecme tls dnsop
 Second Priority: curdle



People who must be present:
  Eric Rescorla
  Melinda Shore
  Paul Wouters

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Fri Aug 18 13:15:53 2017
Return-Path: <tom@ritter.vg>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44B5F132223 for <trans@ietfa.amsl.com>; Fri, 18 Aug 2017 13:15:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ritter.vg
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9vKhxaSagwyd for <trans@ietfa.amsl.com>; Fri, 18 Aug 2017 13:15:50 -0700 (PDT)
Received: from mail-qt0-x22b.google.com (mail-qt0-x22b.google.com [IPv6:2607:f8b0:400d:c0d::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8ECED13218F for <trans@ietf.org>; Fri, 18 Aug 2017 13:15:50 -0700 (PDT)
Received: by mail-qt0-x22b.google.com with SMTP id a18so59607140qta.0 for <trans@ietf.org>; Fri, 18 Aug 2017 13:15:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ritter.vg; s=vg; h=mime-version:from:date:message-id:subject:to; bh=q6J6/IHADf5ZMWSoKLOgXhAdW+oFFcJhM/mymQxZKQo=; b=zbVHtUUFAadgkVFOOpD6qobRNJxVcUxJiuEcy6G72CD0saLRU8ubQ4aZ/WHmCMRzrM Jq6k+K29ewbgK3P7V+Lcqzlra0YQJG8kk8EHob/kfCErb06PlrJzHD7vHOQ37RipTspJ lztL5lwH6q05+cM7WLcrpDWJOP5/c5sh+LqNE=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=q6J6/IHADf5ZMWSoKLOgXhAdW+oFFcJhM/mymQxZKQo=; b=htNfBRcBpKxLxEPVvPQilmt6BLaOfJLGcIR5y7I9ImAgc7sWR5MIncvH5iVhbvEPUJ JQnRm2ixFsd0ms+5yEryCkqhwOcSsCX3xa2lKDYAyDPMO6EFSPasIBJafavIFlnqA0up F9dv5IbN0OZZ5gHZVBbxOcKkH20myU0JA6r9HV5+JkhURE0SkmPlurC7nh9oiVIhgLNj zrYheP9NOmEYpKo4mw2ycWbCV9ZvAtFp4jljONLXpede0l1kp++roTn1WGhS+j+TK8zp GnNJ7H0rBtdQWQmOAT+b7N1d01IZ8l2URuTMA8JqYVh6uGKtF20miMuCRJjYCf5YNj/E NJNA==
X-Gm-Message-State: AHYfb5iUSXOxe3Q2OUCIXvA5iqmXC5QOnnU1QmXwjL+i5COr4CkD+lTt xwFvezB9mPEQdth5eYimxxl/zAh32Yy8+E4=
X-Received: by 10.200.9.108 with SMTP id z41mr1643961qth.234.1503087349423; Fri, 18 Aug 2017 13:15:49 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.30.67 with HTTP; Fri, 18 Aug 2017 13:15:28 -0700 (PDT)
From: Tom Ritter <tom@ritter.vg>
Date: Fri, 18 Aug 2017 15:15:28 -0500
Message-ID: <CA+cU71mvAWRvde4Nga55OLD+3mET_7sbc-RsPmE02E2-UNpBsg@mail.gmail.com>
To: "trans@ietf.org" <trans@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/qwkWiaxlK4ILcwmRmLDxiwnghvY>
Subject: [Trans] Can logs return SCTs that correspond to Precerts in response to add-chain?
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Aug 2017 20:15:52 -0000

Ran into a question I didn't know the answer to, hopefully easy.

If a client submits a chain of valid certificates to a log (via
add-chain), but the leaf certificate was already added to the log as a
precert - is the log allowed to return the SCT associated with the
precert rather than the certificate?

-tom


From nobody Mon Aug 21 03:35:32 2017
Return-Path: <rob.stradling@comodo.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94AE81329BE for <trans@ietfa.amsl.com>; Mon, 21 Aug 2017 03:35:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.19
X-Spam-Level: 
X-Spam-Status: No, score=-4.19 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qAgw1rgSh2gI for <trans@ietfa.amsl.com>; Mon, 21 Aug 2017 03:35:26 -0700 (PDT)
Received: from mmextmx1.mcr.colo.comodoca.net (mmextmx1.mcr.colo.comodoca.net [IPv6:2a02:1788:402:c00::c0a8:9cd5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C78421329B3 for <trans@ietf.org>; Mon, 21 Aug 2017 03:35:25 -0700 (PDT)
Received: (qmail 25345 invoked by uid 1004); 21 Aug 2017 10:35:23 -0000
Received: from rmdccgwarp1.reyn.mcr.dc.comodo.net (HELO maileu.comodo.net) (10.1.72.82) by mmextmx1.mcr.colo.comodoca.net (qpsmtpd/0.84) with ESMTP; Mon, 21 Aug 2017 11:35:23 +0100
Received: from [192.168.0.58] ([192.168.0.58]) by maileu.comodo.net (IceWarp 11.4.6.0 DEB8 x64) with ASMTP (SSL) id 201708211135202551; Mon, 21 Aug 2017 11:35:20 +0100
To: Tom Ritter <tom@ritter.vg>, "trans@ietf.org" <trans@ietf.org>
References: <CA+cU71mvAWRvde4Nga55OLD+3mET_7sbc-RsPmE02E2-UNpBsg@mail.gmail.com>
From: Rob Stradling <rob.stradling@comodo.com>
Message-ID: <b5c69969-6113-2c0a-5bd1-f5261437e995@comodo.com>
Date: Mon, 21 Aug 2017 11:35:20 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.0
MIME-Version: 1.0
In-Reply-To: <CA+cU71mvAWRvde4Nga55OLD+3mET_7sbc-RsPmE02E2-UNpBsg@mail.gmail.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/kIhKsL0zhbGx0_AZgTJ9MKfpvRw>
Subject: Re: [Trans] Can logs return SCTs that correspond to Precerts in response to add-chain?
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Aug 2017 10:35:30 -0000

On 18/08/17 21:15, Tom Ritter wrote:
> Ran into a question I didn't know the answer to, hopefully easy.
> 
> If a client submits a chain of valid certificates to a log (via
> add-chain), but the leaf certificate was already added to the log as a
> precert - is the log allowed to return the SCT associated with the
> precert rather than the certificate?

Hi Tom.  The specification of the submit-entry endpoint [1] says:

   'Outputs:
       sct:  A base64 encoded "TransItem" of type "x509_sct_v2" or
          "precert_sct_v2", signed by this log, that corresponds to the
          "submission".'

Arguably a precert SCT does "correspond to" a certificate.  However, 
earlier in the document [2] it says:

   '...Note that if a certificate was previously logged as a
    precertificate, then the precertificate's SCT of type
    "precert_sct_v2" would not be appropriate; instead, a fresh
    SCT of type "x509_sct_v2" should be generated.'


[1] https://tools.ietf.org/html/draft-ietf-trans-rfc6962-bis-26#section-5.1

[2] https://tools.ietf.org/html/draft-ietf-trans-rfc6962-bis-26#section-4

-- 
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online

