Re: [TLS] draft-shore-tls-dnssec-chain-extension

2015-10-28 Thread Sean Turner
Melinda, As chair, I really appreciate you holding off. spt > On Oct 29, 2015, at 11:27, Melinda Shore wrote: > > Hi, all: > > We haven't been pushing on this because we recognize that getting > TLS 1.3 published is top priority, but we've got a new version > posted (https://tools.ietf.org/ht

Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Melinda Shore
On 7/19/15 11:49 AM, Viktor Dukhovni wrote: > My reading of the draft is that it is primary aimed at making DANE > practical for HTTPS, where last-mile considerations on the client > end are a significant part of the adoption barrier. > > For HTTP, MX and SRV records are out of scope. Clients th

Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Viktor Dukhovni
On Sun, Jul 19, 2015 at 08:18:18PM +0200, Daniel Kahn Gillmor wrote: > On Wed 2015-07-01 05:58:20 +0200, Viktor Dukhovni wrote: > > Instead, there would need to be in various cases: > > > > * A validated chain of CNAMEs (possibly synthesized via validated > > DNAME RRs) leading from the

Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Daniel Kahn Gillmor
Thanks for this draft, i'm definitely interested in seeing it push forward. On Wed 2015-07-01 05:58:20 +0200, Viktor Dukhovni wrote: > Instead, there would need to be in various cases: > > * A validated chain of CNAMEs (possibly synthesized via validated > DNAME RRs) leading from the cli