Re: [dane] DANE and IPsec

2015-07-03 Thread Paul Wouters
See my previously sent email. There is still a problem. I can explain more once I have a real keyboard Sent from my iPhone On Jul 2, 2015, at 17:29, Yoav Nir ynir.i...@gmail.com wrote: On Jul 2, 2015, at 10:40 PM, Viktor Dukhovni ietf-d...@dukhovni.org wrote: On Thu, Jul 02, 2015 at

Re: [dane] DANE and IPsec

2015-07-03 Thread Paul Wouters
Host to host IPsec is very rare. But that's what we are trying to change :) But regardless, let’s assume that the local address is 198.51.100.2. So the quintuple for the connection would be (UDP, 198.51.100.2:704, 192.0.2.5:53) I don't think you want a tunnel per netflow, and still

Re: [dane] DANE and IPsec

2015-07-03 Thread Paul Wouters
The reverse failed. It is only useful in private cloud deployments lacking other types of authentication for publishing pubkeys (ldap, Kerberos , etc) Sent from my iPhone On Jul 2, 2015, at 19:01, Yoav Nir ynir.i...@gmail.com wrote: On Jul 3, 2015, at 12:28 AM, Viktor Dukhovni

Re: [dane] Deferral of SMIME draft

2015-07-03 Thread Osterweil, Eric
Hey Warren, Some comments below: On Jul 3, 2015, at 12:00 PM, Warren Kumari war...@kumari.net wrote: Thanks to everyone who offered to help author, but that's not the issue - the current authors are interested, able, and involved. Rather the issues include a lack of clear agreement on

Re: [dane] Deferral of SMIME draft

2015-07-03 Thread Viktor Dukhovni
On Fri, Jul 03, 2015 at 11:19:08PM +, Viktor Dukhovni wrote: On Fri, Jul 03, 2015 at 12:00:43PM -0400, Warren Kumari wrote: I'll try chat more with my co-chair / the authors about betting an early allocation from IANA of a code-point. The code point MUST precede settling on the final

Re: [dane] Deferral of SMIME draft

2015-07-03 Thread Warren Kumari
Thanks to everyone who offered to help author, but that's not the issue - the current authors are interested, able, and involved. Rather the issues include a lack of clear agreement on the email address processing and difficulty in getting actual review and feedback on drafts. We have quite

Re: [dane] DANE and IPsec

2015-07-03 Thread Paul Wouters
On Fri, 3 Jul 2015, Yoav Nir wrote: Seems like a limitation of DNS security. DNSSEC can authenticate that “mallory claimed that mallory.example.com is at 8.8.8.8”, but DNSSEC does nothing to tell me whether the claim is true. Ordinarily you gain nothing by pointing your DNS name at a wrong

Re: [dane] Deferral of SMIME draft

2015-07-03 Thread Viktor Dukhovni
On Fri, Jul 03, 2015 at 12:00:43PM -0400, Warren Kumari wrote: I'll try chat more with my co-chair / the authors about betting an early allocation from IANA of a code-point. The code point MUST precede settling on the final RRDATA format. Has that been achieved? If none of the issues are