Re: [TLS] dnssec_chain entry in IANA registry seems to be missing CT

2022-02-23 Thread Eric Rescorla
On Wed, Feb 23, 2022 at 6:25 AM Salz, Rich wrote: > >It is probably "best" (for some definition of "best") to publish an > RFC > that Updates: 9102 and has the revised directive to IANA. > > I hope that is excessive. > > >Probably an errata report should be filed against RFC 9102 rega

Re: [TLS] dnssec_chain entry in IANA registry seems to be missing CT

2022-02-23 Thread Salz, Rich
>It is probably "best" (for some definition of "best") to publish an RFC that Updates: 9102 and has the revised directive to IANA. I hope that is excessive. >Probably an errata report should be filed against RFC 9102 regardless. IANA might be able to use the errata report without

Re: [TLS] dnssec_chain entry in IANA registry seems to be missing CT

2022-02-22 Thread Shumon Huque
On Tue, Feb 22, 2022 at 8:39 PM Benjamin Kaduk wrote: > On Tue, Feb 22, 2022 at 08:27:02PM -0500, Shumon Huque wrote: > > On Wed, Feb 16, 2022 at 4:29 AM Ilari Liusvaara < > ilariliusva...@welho.com> > > wrote: > > > > > I noticed that the "dnssec_chain" extension in the IANA registry lists > > >

Re: [TLS] dnssec_chain entry in IANA registry seems to be missing CT

2022-02-22 Thread Benjamin Kaduk
On Tue, Feb 22, 2022 at 08:27:02PM -0500, Shumon Huque wrote: > On Wed, Feb 16, 2022 at 4:29 AM Ilari Liusvaara > wrote: > > > I noticed that the "dnssec_chain" extension in the IANA registry lists > > only "CH" in the "TLS 1.3" column. However, the extension sends its > > response in the certifi

Re: [TLS] dnssec_chain entry in IANA registry seems to be missing CT

2022-02-22 Thread Shumon Huque
On Wed, Feb 16, 2022 at 4:29 AM Ilari Liusvaara wrote: > I noticed that the "dnssec_chain" extension in the IANA registry lists > only "CH" in the "TLS 1.3" column. However, the extension sends its > response in the certificate message (section 2.2), so I think that > column should read "CH, CT".