I have another question about the PRIVATE option. While planning the 
implementation of CT with our teams, we first thought that we would use the 
precertificate option as the default for all customers. Our hope was that most 
customers wouldn't even need to be aware of CT; they would get some extra data 
in their cert and there would be no change to deployment (I believe that was 
the hope of the CT designers too).

However, the PRIVATE subdomain masking option made us rethink that. If a 
customer wants to keep their fqdn private, they need to make that choice up 
front, before we've issued the cert to them. If they don't choose PRIVATE up 
front, their cert will get logged, and switching to PRIVATE after that would be 
pointless because their fqdn would be public. But that means forcing the 
customer to stop in the middle of the enrollment process, read up on CT, and 
make an informed decision. We're finding it's difficult to get most people to 
understand why they would choose SHA-2 instead of SHA-1, and educating them on 
CT and its options is expected to be far more difficult.

So we're considering making PRIVATE the default option, or perhaps the only 
option. It's arguably better for customers because it preserves a measure of 
privacy and postpones the time when they have to understand all the details of 
CT. It may be a little more challenging for a domain owner monitoring the logs, 
because they'll only see the precerts with serial numbers and no fqdns, but 
that's not much of a challenge. It makes our implementation simpler and 
therefore easier to test and deploy.

Any feedback on this idea?

-Rick


_______________________________________________
Trans mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/trans

Reply via email to