Re: [Acme] .well-known for dns challenges

2019-07-19 Thread Benjamin Kaduk
I don't have much to add, but... On Tue, Jul 16, 2019 at 05:44:39PM +0100, Stephen Farrell wrote: > > Hiya, > > On 15/07/2019 17:00, Ted Hardie wrote: > > Howdy, > > > > A reply in-line. > > > > On Sun, Jul 14, 2019 at 2:07 PM Stephen Farrell > > wrote: > > > >> > > So, if I were personally

Re: [Acme] .well-known for dns challenges

2019-07-16 Thread Stephen Farrell
Hiya, On 15/07/2019 17:00, Ted Hardie wrote: > Howdy, > > A reply in-line. > > On Sun, Jul 14, 2019 at 2:07 PM Stephen Farrell > wrote: > >> > So, if I were personally configuring a similar system, I would avoid > ..well-known, because it makes the information available to anyone who polls >

Re: [Acme] .well-known for dns challenges

2019-07-16 Thread Stephen Farrell
Hiya, On 15/07/2019 18:30, Jacob Hoffman-Andrews wrote: > This seems like a clever idea! As Ted said, .well-known probably isn't > the right directory for it. If you put something in .well-known, that > suggests you plan to standardize it and register it with IANA. Sure, I'm not scared of

Re: [Acme] .well-known for dns challenges

2019-07-15 Thread Jacob Hoffman-Andrews
This seems like a clever idea! As Ted said, .well-known probably isn't the right directory for it. If you put something in .well-known, that suggests you plan to standardize it and register it with IANA. I'll also note that you may have a bootstrapping problem: Assuming that you verify

Re: [Acme] .well-known for dns challenges

2019-07-15 Thread Ted Hardie
Howdy, A reply in-line. On Sun, Jul 14, 2019 at 2:07 PM Stephen Farrell wrote: > > Hiya, > > I've a couple of questions as to 1) whether there are > any security issues with a thing I've done, (described > below) and 2) if it'd be worthwhile documenting something > like this. > > I've been

[Acme] .well-known for dns challenges

2019-07-14 Thread Stephen Farrell
Hiya, I've a couple of questions as to 1) whether there are any security issues with a thing I've done, (described below) and 2) if it'd be worthwhile documenting something like this. I've been working on encrypted SNI and as part of that have built a test server. It seems sensible that some