Re: [Gnso-rds-pdp-3] [EXTERNAL] Re: finishing report
I made only one major change - removing the link to the EWG definition, which I think we all agree is flawed, and I felt was redundant now. The only other change I made was turning website into web site. Thank you all for your efforts. David
On 12 Nov 2017, at 10:15 am, Feher, Kal <Kalman.Feher@team.neustar> wrote:
Sorry for my delayed response, I've been traveling to IETF.
I think the document is complete. I don't have any further changes.
Kal Feher
From: "Deacon, Alex" <Alex_Deacon@mpaa.org <mailto:Alex_Deacon@mpaa.org>> Date: Saturday, 11 November 2017 at 06:15 To: Kal Feher <kalman.feher@team.neustar <mailto:kalman.feher@team.neustar>>, "gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>>, David Cake <dave@davecake.net <mailto:dave@davecake.net>> Subject: Re: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report
Thanks Kal.
Apologies for the typo’s and auto-correct issues – I was in a rush to send it out.
Anyway - Here is one more update on top of yours with a few more mods to the purpose up front. It now states.
Purpose: Information collected by a certificate authority to enable contact between the registrant, or a technical or administrative representative of the registrant, to assist in verifying that the identity of the certificate applicant is the same as the entity that controls the domain name.
Alex
From: "Feher, Kal" <Kalman.Feher@team.neustar <mailto:Kalman.Feher@team.neustar>> Date: Thursday, November 9, 2017 at 5:52 PM To: "Deacon, Alex" <Alex_Deacon@mpaa.org <mailto:Alex_Deacon@mpaa.org>>, "gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>>, David Cake <dave@davecake.net <mailto:dave@davecake.net>> Subject: Re: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report
Please note that none of my emails to the subgroup mailing list have been received for some reason.
I've made some minor edits to the purpose. I fixed up a recurring typo for "identity". I replaced domain ownership with "control". That is the term used by CAs and the baseline guidelines. Ownership is not determined in this method. Bearing in mind that certificate requests could be delegated to hosting operators. With that minor and slightly pedantic change, I think the purpose is fine. If we wanted to be really pedantic then it would be "authorised control" as it appears in the certificate guideline glossary.
I disagree with adding the organisation field in the data elements. They are not required by Certificate Authorities and the guidelines are quite clear on this. This includes guidelines for basic certs (the domain control part of the baseline guide), organisation validated certs (domain control plus org validation from baseline guidelines) and extended validation certs (domain control from baseline plus the EV guidelines). As I stated in the f2f, the only thing the CAB forums use the RDS for is to contact the registrant/admin/tech contact to prove authorised control. RDS is not used to prove organisation identity. If a CA chose to do this, they'd actually be less secure and increase risks of fraudulent certificate validation.
Kal Feher Neustar Inc. Level 8, 10 Queens Road, Melbourne, Australia VIC 3004 Office +61 3 9866 3710 / kal.feher@team.neustar <mailto:kal.feher@team.neustar> / www.neustar.biz <https://urldefense.proofpoint.com/v2/url?u=https-3A__na01.safelinks.protecti...>
Follow Neustar: <image001.png> Facebook <https://urldefense.proofpoint.com/v2/url?u=https-3A__na01.safelinks.protecti...> <image002.png> LinkedIn <https://urldefense.proofpoint.com/v2/url?u=https-3A__na01.safelinks.protecti...> <image003.png> Twitter <https://urldefense.proofpoint.com/v2/url?u=https-3A__na01.safelinks.protecti...> The information contained in this e-mail message is intended only for the use of the recipient(s) named above and may contain confidential and/or privileged information. If you are not the intended recipient you have received this e-mail message in error and any review, dissemination, distribution, or copying of this message is strictly prohibited. If you have received this communication in error, please notify us immediately and delete the original message.
From: <gnso-rds-pdp-3-bounces@icann.org <mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of "Deacon, Alex" <Alex_Deacon@mpaa.org <mailto:Alex_Deacon@mpaa.org>> Date: Friday, 10 November 2017 at 07:03 To: "gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>> Subject: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report
Here is my “Post Abu Dhabi” update. I added a “purpose in one sentence” up top and then beefed up the data elements section to bring it in line with what other groups have done.
Thanks! Alex
From: <gnso-rds-pdp-3-bounces@icann.org <mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of "Deacon, Alex" <Alex_Deacon@mpaa.org <mailto:Alex_Deacon@mpaa.org>> Date: Tuesday, November 7, 2017 at 10:47 AM To: David Cake <dave@davecake.net <mailto:dave@davecake.net>>, "gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>> Cc: thomascovenant <dinasolveig@thomascovenant.org <mailto:dinasolveig@thomascovenant.org>> Subject: Re: [Gnso-rds-pdp-3] finishing report
I’ll take a shot at an update and send a revision on Thursday for review.
Aelx
From: <gnso-rds-pdp-3-bounces@icann.org <mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of David Cake <dave@davecake.net <mailto:dave@davecake.net>> Date: Tuesday, November 7, 2017 at 10:08 AM To: "gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org <mailto:gnso-rds-pdp-3@icann.org>> Cc: thomascovenant <dinasolveig@thomascovenant.org <mailto:dinasolveig@thomascovenant.org>> Subject: [Gnso-rds-pdp-3] finishing report
The DT3 report is due to be completed this friday. I have not scheduled a meeting, as previous discussion suggested there were only minor changes needed and it could be performed via email.
I have attached the report as presented - please suggest revisions and updates that you feel would make the report clearer.
David
_______________________________________________ Gnso-rds-pdp-3 mailing list Gnso-rds-pdp-3@icann.org <mailto:Gnso-rds-pdp-3@icann.org> https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmm.icann.or... <https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__na01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fmm.icann.org-252Fmailman-252Flistinfo-252Fgnso-2Drds-2Dpdp-2D3-26data-3D02-257C01-257Calex-5Fdeacon-2540mpaa.org-257Cc162c9a94fb1413d756008d5260a522f-257C17e50b56d5dd439b962acc7ecd9ab7fe-257C0-257C0-257C636456749375312535-26sdata-3D1HRS86K6bOumi0reYgBgaA7GP0MeZtgrc19ZsoR-252Fcg0-253D-26reserved-3D0%26d%3DDwMGaQ%26c%3DMOptNlVtIETeDALC_lULrw%26r%3D_-v0M-gLiqWrtaHtP66hjSPyu3ePgw9YIihGxxybjqU%26m%3DrzRr4g6MtzUJqXK5H44KX8aoreIW-_sbPBpQ8h1sLlk%26s%3DUOfx0sikJuNhn7yMlU4AfbKNIyvJrnogq6LTPVOon2c%26e%3D&data=02%7C01%7CAlex_Deacon%40mpaa.org%7C1b17b2e05018492403a208d527dd93fd%7C17e50b56d5dd439b962acc7ecd9ab7fe%7C0%7C0%7C636458755788365470&sdata=D0CgTxx9ST9FlDlDEc8ziqA%2F1F9%2Fob%2B0kntud0y1tNo%3D&reserved=0><image001.png><image002.png><image003.png>
Can you send your update? I didn’t see it attached. Thanks Alex From: David Cake <dave@davecake.net> Date: Sunday, November 12, 2017 at 9:02 PM To: "Feher, Kal" <Kalman.Feher@team.neustar> Cc: "Deacon, Alex" <Alex_Deacon@mpaa.org>, "gnso-rds-pdp-3@icann.org" <gnso-rds-pdp-3@icann.org> Subject: Re: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report I made only one major change - removing the link to the EWG definition, which I think we all agree is flawed, and I felt was redundant now. The only other change I made was turning website into web site. Thank you all for your efforts. David On 12 Nov 2017, at 10:15 am, Feher, Kal <Kalman.Feher@team.neustar<mailto:Kalman.Feher@team.neustar>> wrote: Sorry for my delayed response, I've been traveling to IETF. I think the document is complete. I don't have any further changes. Kal Feher From: "Deacon, Alex" <Alex_Deacon@mpaa.org<mailto:Alex_Deacon@mpaa.org>> Date: Saturday, 11 November 2017 at 06:15 To: Kal Feher <kalman.feher@team.neustar<mailto:kalman.feher@team.neustar>>, "gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>>, David Cake <dave@davecake.net<mailto:dave@davecake.net>> Subject: Re: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report Thanks Kal. Apologies for the typo’s and auto-correct issues – I was in a rush to send it out. Anyway - Here is one more update on top of yours with a few more mods to the purpose up front. It now states. Purpose: Information collected by a certificate authority to enable contact between the registrant, or a technical or administrative representative of the registrant, to assist in verifying that the identity of the certificate applicant is the same as the entity that controls the domain name. Alex From: "Feher, Kal" <Kalman.Feher@team.neustar<mailto:Kalman.Feher@team.neustar>> Date: Thursday, November 9, 2017 at 5:52 PM To: "Deacon, Alex" <Alex_Deacon@mpaa.org<mailto:Alex_Deacon@mpaa.org>>, "gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>>, David Cake <dave@davecake.net<mailto:dave@davecake.net>> Subject: Re: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report Please note that none of my emails to the subgroup mailing list have been received for some reason. I've made some minor edits to the purpose. I fixed up a recurring typo for "identity". I replaced domain ownership with "control". That is the term used by CAs and the baseline guidelines. Ownership is not determined in this method. Bearing in mind that certificate requests could be delegated to hosting operators. With that minor and slightly pedantic change, I think the purpose is fine. If we wanted to be really pedantic then it would be "authorised control" as it appears in the certificate guideline glossary. I disagree with adding the organisation field in the data elements. They are not required by Certificate Authorities and the guidelines are quite clear on this. This includes guidelines for basic certs (the domain control part of the baseline guide), organisation validated certs (domain control plus org validation from baseline guidelines) and extended validation certs (domain control from baseline plus the EV guidelines). As I stated in the f2f, the only thing the CAB forums use the RDS for is to contact the registrant/admin/tech contact to prove authorised control. RDS is not used to prove organisation identity. If a CA chose to do this, they'd actually be less secure and increase risks of fraudulent certificate validation. Kal Feher Neustar Inc. Level 8, 10 Queens Road, Melbourne, Australia VIC 3004 Office +61 3 9866 3710 / kal.feher@team.neustar<mailto:kal.feher@team.neustar> / www.neustar.biz<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense....> Follow Neustar: <image001.png> Facebook<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense....> <image002.png> LinkedIn<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense....> <image003.png> Twitter<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense....> ________________________________ The information contained in this e-mail message is intended only for the use of the recipient(s) named above and may contain confidential and/or privileged information. If you are not the intended recipient you have received this e-mail message in error and any review, dissemination, distribution, or copying of this message is strictly prohibited. If you have received this communication in error, please notify us immediately and delete the original message. From: <gnso-rds-pdp-3-bounces@icann.org<mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of "Deacon, Alex" <Alex_Deacon@mpaa.org<mailto:Alex_Deacon@mpaa.org>> Date: Friday, 10 November 2017 at 07:03 To: "gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>> Subject: [EXTERNAL] Re: [Gnso-rds-pdp-3] finishing report Here is my “Post Abu Dhabi” update. I added a “purpose in one sentence” up top and then beefed up the data elements section to bring it in line with what other groups have done. Thanks! Alex From: <gnso-rds-pdp-3-bounces@icann.org<mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of "Deacon, Alex" <Alex_Deacon@mpaa.org<mailto:Alex_Deacon@mpaa.org>> Date: Tuesday, November 7, 2017 at 10:47 AM To: David Cake <dave@davecake.net<mailto:dave@davecake.net>>, "gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>> Cc: thomascovenant <dinasolveig@thomascovenant.org<mailto:dinasolveig@thomascovenant.org>> Subject: Re: [Gnso-rds-pdp-3] finishing report I’ll take a shot at an update and send a revision on Thursday for review. Aelx From: <gnso-rds-pdp-3-bounces@icann.org<mailto:gnso-rds-pdp-3-bounces@icann.org>> on behalf of David Cake <dave@davecake.net<mailto:dave@davecake.net>> Date: Tuesday, November 7, 2017 at 10:08 AM To: "gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>" <gnso-rds-pdp-3@icann.org<mailto:gnso-rds-pdp-3@icann.org>> Cc: thomascovenant <dinasolveig@thomascovenant.org<mailto:dinasolveig@thomascovenant.org>> Subject: [Gnso-rds-pdp-3] finishing report The DT3 report is due to be completed this friday. I have not scheduled a meeting, as previous discussion suggested there were only minor changes needed and it could be performed via email. I have attached the report as presented - please suggest revisions and updates that you feel would make the report clearer. David _______________________________________________ Gnso-rds-pdp-3 mailing list Gnso-rds-pdp-3@icann.org<mailto:Gnso-rds-pdp-3@icann.org> https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmm.icann.org%2Fmailman%2Flistinfo%2Fgnso-rds-pdp-3&data=02%7C01%7Calex_deacon%40mpaa.org%7Cc162c9a94fb1413d756008d5260a522f%7C17e50b56d5dd439b962acc7ecd9ab7fe%7C0%7C0%7C636456749375312535&sdata=1HRS86K6bOumi0reYgBgaA7GP0MeZtgrc19ZsoR%2Fcg0%3D&reserved=0<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__na01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fmm.icann.org-252Fmailman-252Flistinfo-252Fgnso-2Drds-2Dpdp-2D3-26data-3D02-257C01-257Calex-5Fdeacon-2540mpaa.org-257Cc162c9a94fb1413d756008d5260a522f-257C17e50b56d5dd439b962acc7ecd9ab7fe-257C0-257C0-257C636456749375312535-26sdata-3D1HRS86K6bOumi0reYgBgaA7GP0MeZtgrc19ZsoR-252Fcg0-253D-26reserved-3D0%26d%3DDwMGaQ%26c%3DMOptNlVtIETeDALC_lULrw%26r%3D_-v0M-gLiqWrtaHtP66hjSPyu3ePgw9YIihGxxybjqU%26m%3DrzRr4g6MtzUJqXK5H44KX8aoreIW-_sbPBpQ8h1sLlk%26s%3DUOfx0sikJuNhn7yMlU4AfbKNIyvJrnogq6LTPVOon2c%26e%3D&data=02%7C01%7CAlex_Deacon%40mpaa.org%7C1b17b2e05018492403a208d527dd93fd%7C17e50b56d5dd439b962acc7ecd9ab7fe%7C0%7C0%7C636458755788365470&sdata=D0CgTxx9ST9FlDlDEc8ziqA%2F1F9%2Fob%2B0kntud0y1tNo%3D&reserved=0> <image001.png><image002.png><image003.png>
participants (2)
-
David Cake -
Deacon, Alex