New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Clarify server status options #320
Conversation
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
|
Thanks Rich for sending this. Unfortunately, I don’t believe it is accurate or reflecting implementation experience to suggest the TLS 1.3 mechanism is preferred. The design of CT, and the ample implementation experience of both CAs and site operators, firmly supports embedded proofs as the preferred mechanism. This reduces server-side complexity and overhead for the general case (e.g. every TLS server having to manage the state of every UAs set of accepted Logs and required policies and appropriately ensure the necessary SCTs are sent). It remains a quite nice option for CDNs who are staffed to ensure such things, just as they do with certificate and certificate chains, but I think it’s rather the opposite: the TLS and OCSP mechanisms are less preferred because they have high operational complexity, ongoing maintenance costs (since the SCTs must continue to comply with policy, as opposed to issuance-date policies that embedded SCTs have), and create a more fragile, less agile ecosystem. |
Address feedback from Rob and Ryan.
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
|
Push commit to address comments from @robstradling and @sleevi |
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
|
I pushed a commit that fixes the three typo's @robstradling found. |
Take Ryan's rewording improvement. Co-authored-by: sleevi <ryan.sleevi@gmail.com>
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
Ryan's clarity improvements. Co-authored-by: sleevi <ryan.sleevi@gmail.com>
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
1 similar comment
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
|
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). Once you've signed (or fixed any issues), please reply here with What to do if you already signed the CLAIndividual signers
Corporate signers
|
Three ways for a server to send CT data. Clarify when and how each is used.