<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><a name="_MailEndCompose">OK – thanks. So Peter’s suggested improvement is appropriate and I’ll edit the draft of Ballot 202 accordingly, leaving these other issues for resolution by Ballot 184, or whichever.<o:p></o:p></a></p><p class=MsoNormal><span style='mso-bookmark:_MailEndCompose'><o:p> </o:p></span></p><p class=MsoNormal style='margin-bottom:2.0pt'><span style='mso-bookmark:_MailEndCompose'><b><span style='font-family:"Arial",sans-serif;color:#0174C3'>Ben Wilson, JD, CISA, CISSP<o:p></o:p></span></b></span></p><p class=MsoNormal style='margin-bottom:2.0pt'><span style='mso-bookmark:_MailEndCompose'><span style='font-family:"Arial",sans-serif;color:#686869'>VP Compliance<o:p></o:p></span></span></p><p class=MsoNormal style='margin-bottom:2.0pt'><span style='mso-bookmark:_MailEndCompose'><span style='font-family:"Arial",sans-serif;color:#686869'>+1 801 701 9678<o:p></o:p></span></span></p><p class=MsoNormal><span style='mso-bookmark:_MailEndCompose'><img width=133 height=29 style='width:1.3875in;height:.3in' id="Picture_x0020_1" src="cid:image001.jpg@01D2DAD9.95FFE6A0"><o:p></o:p></span></p><p class=MsoNormal><span style='mso-bookmark:_MailEndCompose'><o:p> </o:p></span></p><span style='mso-bookmark:_MailEndCompose'></span><p class=MsoNormal><b>From:</b> Ryan Sleevi [mailto:sleevi@google.com] <br><b>Sent:</b> Thursday, June 1, 2017 1:14 PM<br><b>To:</b> CA/Browser Forum Public Discussion List <public@cabforum.org><br><b>Cc:</b> Peter Bowen <pzb@amzn.com>; Ben Wilson <ben.wilson@digicert.com><br><b>Subject:</b> Re: [cabfpub] Pre-Ballot: Underscore Characters in SANs<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>In order for otherName:srvNames to be permitted? Yeah. Peter had a draft ballot for that, and Jeremy continued that draft. Our (Google's) problem had been that it was coupled to this ballot, when they're really separate things.<o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>We (Google) are super-excited for SRVNames - it'll actually be a good step forward for the Web PKI - but think it should be disconnected from this correctness ballot - which is about loosening the requirements of RFC5280, like we did for nameConstraints, because CAs have not been widely adhering to the BRs and RFC5280 and we're going to retroactively grant indulgences :)<o:p></o:p></p></div></div><div><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>On Thu, Jun 1, 2017 at 3:11 PM, Ben Wilson via Public <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>> wrote:<o:p></o:p></p><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><a name="m_-8432308923838352779__MailEndCompose">So, in order for this to happen, another ballot would subsequently be required that specifies the contents and validation for service names, correct?</a><o:p></o:p></p><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><b>From:</b> Peter Bowen [mailto:<a href="mailto:pzb@amzn.com" target="_blank">pzb@amzn.com</a>] <br><b>Sent:</b> Thursday, June 1, 2017 12:54 PM<br><b>To:</b> Ben Wilson <<a href="mailto:ben.wilson@digicert.com" target="_blank">ben.wilson@digicert.com</a>><br><b>Cc:</b> CA/Browser Forum Public Discussion List <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>><br><b>Subject:</b> Re: [cabfpub] Pre-Ballot: Underscore Characters in SANs<o:p></o:p></p></div></div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p><div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>The _<i>jabber.</i>_<a href="http://tcp.gmail.com" target="_blank">tcp.gmail.com</a> form is a service name. This would be represented in certificates using the c where the content would be _<a href="http://jabber.gmail.com" target="_blank">jabber.gmail.com</a> (the protocol, such as _tcp isn’t included in the certificate). Anything starting with underscore isn’t a hostname and can’t go in a dNSName.<o:p></o:p></p></div><div><div><div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p></div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p><div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>On Jun 1, 2017, at 11:21 AM, Ben Wilson <<a href="mailto:ben.wilson@digicert.com" target="_blank">ben.wilson@digicert.com</a>> wrote:<o:p></o:p></p></div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p><div><div><p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:12.0pt'>Peter,<br><br>Respectfully, I don't think we should be so specific as to where an underscore can appear in a SAN. <br><br>For example, one post I found, <a href="https://stackoverflow.com/questions/2180465/can-domain-name-subdomains-have-an-underscore-in-it" target="_blank">https://stackoverflow.com/questions/2180465/can-domain-name-subdomains-have-an-underscore-in-it</a>, says "It is perfectly legal to have an underscore in a domain name. Let me quote the standard, RFC 2181, section 11, 'Name syntax': The DNS itself places only one restriction on the particular labels that can be used to identify resource records. That one restriction relates to the length of the label and the full name. [...] Implementations of the DNS protocols must not place any restrictions on the labels that can be used. In particular, DNS servers must not refuse to serve a zone because it contains labels that might not be acceptable to some DNS client programs. See also the original DNS specification, RFC 1034, section 3.5 'Preferred name syntax' but read it carefully. Domains with underscores are very common in the wild. Check _jabber._<a href="http://tcp.gmail.com" target="_blank">tcp.gmail.com</a> or _sip._<a href="http://udp.apnic.net" target="_blank">udp.apnic.net</a>." <br><br>As you can see, these names start with an underscore, despite the fact that section 3.5 of RFC 1034 says, "The labels must follow the rules for ARPANET host names. They must<br>start with a letter, end with a letter or digit, and have as interior characters only letters, digits, and hyphen. There are also some restrictions on the length." <br><br>My point is, if the position of the underscore works, then let it work, and if it doesn't work, let the subscriber and the CA figure that out and reissue something that works. We shouldn't be creating unnecessary proscriptions or format validation checks in this area.<br><br>Ben<br><br>-----Original Message-----<br>From: Peter Bowen [<a href="mailto:pzb@amzn.com" target="_blank">mailto:pzb@amzn.com</a>] <br>Sent: Friday, May 26, 2017 10:12 AM<br>To: CA/Browser Forum Public Discussion List <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>><br>Cc: Ben Wilson <<a href="mailto:ben.wilson@digicert.com" target="_blank">ben.wilson@digicert.com</a>><br>Subject: Re: [cabfpub] Pre-Ballot: Underscore Characters in SANs<br><br>Ben,<br><br>I would suggest a couple of changes:<br><br>1) Underscores should only be allowed where hyphens are allowed. Notable hyphens and underscores cannot start or end a label. I suggest `one or more underscore characters (“_”) may be present in the FQDN in positions permitted to contain a hyphen character`<br><br>2) I would suggest adding a definition of Wildcard Domain Name and then using it here. `Wildcard Domain Name: A Domain Name formed by prepending "*." to a FQDN`<br><br>Thanks,<br>Peter<br><br><o:p></o:p></p><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>On May 25, 2017, at 1:08 PM, Ben Wilson via Public <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>> wrote:<br><br>I’m looking for two endorsers for Ballot 202 – Underscore Characters <br>in SANS The current Baseline Requirements do not expressly allow underscore characters in Subject Alternative Names. This ballot seeks to clarify that one or more underscore characters (“_”) are allowed in FQDNs. It also cleans up some of the language in Section 7.1.4.2.1 of the Baseline Requirements.<br><br>The following motion has been proposed by Ben Wilson of DigiCert and endorsed by - and - to introduce new Final Maintenance Guidelines for the "Baseline Requirements Certificate Policy for the Issuance and Management of Publicly-Trusted Certificates" (Baseline Requirements). <br><br>--Motion Begins--<br><br>REPLACE Section 7.1.4.2.1 of the Baseline Requirements in its entirety with: <br><br>7.1.4.2.1 Subject Alternative Name Extension<br><br>Certificate Field: extensions:subjectAltName<br><br>Required/Optional: Required<br><br>Contents: This extension MUST contain at least one entry. Each entry MUST be either a dNSName or iPAddress name. <br><br>For entries of the type dNSName, the entry MUST containing the Fully-Qualified Domain Name that the CA has validated in accordance with section 3.2.2.4. The FQDN must comply with RFC 5280, Section 4.2.1.6, including that the name be in “preferred name syntax,” with the following exceptions: a single wildcard character (“*”) MAY be present as the left-most, most subordinate level, if the CA has validated the name consistent with Section 3.2.2.6; and one or more underscore characters (“_”) may be present in the FQDN, in deviation from the “preferred name syntax”. The entry MUST NOT contain an Internal Name. <br><br>For entries of the type iPAddress, the entry MUST contain an IP address that the CA has validated in accordance with Section 3.2.2.5. The entry MUST NOT contain a Reserved IP Address. <br><br>--Motion Ends--<br><br>Thanks,<br><br>Ben<br><br>From: Public [<a href="mailto:public-bounces@cabforum.org" target="_blank">mailto:public-bounces@cabforum.org</a>] On Behalf Of Ben <br>Wilson via Public<br>Sent: Thursday, April 20, 2017 12:09 PM<br>To: Ryan Sleevi <<a href="mailto:sleevi@google.com" target="_blank">sleevi@google.com</a>>; CA/Browser Forum Public <br>Discussion List <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>><br>Cc: Ben Wilson <<a href="mailto:ben.wilson@digicert.com" target="_blank">ben.wilson@digicert.com</a>><br>Subject: Re: [cabfpub] Pre-Ballot: Underscore Characters in SANs<br><br>Thanks. I’ll rework this with the language suggested and re-circulate.<br>Ben<br><br>From: Ryan Sleevi [<a href="mailto:sleevi@google.com" target="_blank">mailto:sleevi@google.com</a>]<br>Sent: Thursday, April 20, 2017 11:36 AM<br>To: CA/Browser Forum Public Discussion List <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>><br>Cc: Ben Wilson <<a href="mailto:ben.wilson@digicert.com" target="_blank">ben.wilson@digicert.com</a>><br>Subject: Re: [cabfpub] Pre-Ballot: Underscore Characters in SANs<br><br><br><br>On Thu, Apr 20, 2017 at 1:07 PM, Ben Wilson via Public <<a href="mailto:public@cabforum.org" target="_blank">public@cabforum.org</a>> wrote:<br>All,<br><br>I’m looking for two endorsers for a proposed amendment to section 7.1.4.2.1 of the Baseline Requirements--to be modified to allow the underscore character (“_”) in SANs and to remove the sunset language in that section related to internal names and reserved IP addresses. The revised section 7.1.4.2.1 would read as follows:<br><br><br>7.1.4.2.1. Subject Alternative Name Extension<br>Certificate Field: extensions:subjectAltName<br>Required/Optional: Required<br>Contents: This extension MUST contain at least one entry. Each entry MUST be either a dNSName containing the Fully-Qualified Domain Name or an iPAddress containing the IP address of a server. The CA MUST confirm that the Applicant controls the Fully-Qualified Domain Name or IP address or has been granted the right to use it by the Domain Name Registrant or IP address assignee, as appropriate.<br>Wildcard FQDNs and underscores in FQDNs (encoded as IA5 strings) are permitted. <br>CAs SHALL NOT issue a certificate with a subjectAlternativeName extension or Subject commonName field containing a Reserved IP Address or Internal Name. <br><br>Ben,<br><br>Some suggested edits that may help resolve any future ambiguities, capturing the discussions from the Raleigh F2F.<br><br>"""<br>7.1.4.2.1 Subject Alternative Name Extension Certificate Field: <br>extensions:subjectAltName<br>Required/Optional: Required<br>Contents: This extension MUST contain at least one entry. The entry MUST be either a dNSName or iPAddress name.<br><br>For entries of the type dNSName, the entry MUST contain the Fully-Qualified Domain Name that CA has validated the Applicant's control or ownership of. The Fully-Qualified Domain Name must comply with RFC 5280, Section 4.2.1.6, including that of requiring the name be in the "preferred name syntax," with the following exceptions: A single wildcard ('*') character may be present as the left-most, most subordinate label, if the CA has validated the name consistent with Section 3.2.2.6. One or more underscore ('_') characters may be present within the Fully-Qualified Domain Name, in deviation from the "preferred name syntax." The entry MUST NOT contain an Internal Name.<br><br>For entries of the type iPAddress, the entry MUST contain an IP address that the CA has validated the Applicant's control of. The entry MUST NOT contain a Reserved IP Address.<br>"""<br><br>Here's a bit of explanation for the edits and why I made them:<br>- Split the rules regarding dNSName and iPAddress into two separate <br>sections, to make it unambiguous the contents they can contain<br>- Clarify that wildcards and underscores are NOT permitted for the <br>type iPAddress<br>- Clarify that domain names MUST follow the rules of RFC 5280, particularly that of preferred name syntax. This includes the prohibition of the " " label or that of e-mail addresses in the domain form (both examples given in RFC 5280). It clarifies that the exceptions to this rule are limited to the presence of wildcard characters and underscores.<br> * There's one issue which I debated trying to tackle in this, which is that it's possible for an applicant to register the literal "*.<a href="http://domain.com" target="_blank">domain.com</a>" (e.g. the actual wildcard character). The current and proposed wording fail to address this in 3.2.2.6, even though the intent is clearly that in the case of a *, the CA MUST validate the Applicant's control of the Domain Namespace indicated by removing the '*' label.<br> * Happy to suggest wording if it's clear the concern here<br>- Reuse the language from 3.2.2.4 and 3.2.2.5, specifically the "Applicant's control or ownership of" a domain name and "control of" an IP address.<br> - The existing wording, "granted the right to use", is ambiguous, because no process is defined within the BRs as to how an Applicant can demonstrate such a grant, or how the CA can verify such a grant.<br> - I believe the intent is with respect to reusing the validation <br>methods of 3.2.2.4, but if CAs feel that this is an intentional <br>loophole to permit some activity that would otherwise be prohibited or <br>underspecified, I'm happy to see what we can figure out<br>- Lays out a framework for permitting additional name types in the future, as discussed. This section could be tightened up further to support that future growth, but I tried to keep it mostly minimal for now, so that we could incrementally improve.<br><br>Do let me know what you think of those edits, and whether they bring the necessary clarity of intent and execution.<br><br><Underscore Characters in <br>SANs.pdf>_______________________________________________<br>Public mailing list<br><a href="mailto:Public@cabforum.org" target="_blank">Public@cabforum.org</a><br><a href="https://cabforum.org/mailman/listinfo/public" target="_blank">https://cabforum.org/mailman/listinfo/public</a><o:p></o:p></p></blockquote><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p></div></div></blockquote></div><p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'> <o:p></o:p></p></div></div></div></div><p class=MsoNormal style='margin-bottom:12.0pt'><br>_______________________________________________<br>Public mailing list<br><a href="mailto:Public@cabforum.org">Public@cabforum.org</a><br><a href="https://cabforum.org/mailman/listinfo/public" target="_blank">https://cabforum.org/mailman/listinfo/public</a><o:p></o:p></p></blockquote></div><p class=MsoNormal><o:p> </o:p></p></div></div></body></html>