WEBVTT

1
00:00:01.760 --> 00:00:03.679
- Join us as we gather around the hedge,

2
00:00:03.679 --> 00:00:05.139
- where we dig into technology,

3
00:00:05.440 --> 00:00:08.160
- business, and culture with the finest minds in

4
00:00:08.160 --> 00:00:09.139
- computer networking.

5
00:00:21.054 --> 00:00:22.914
- Well, hello, Tom, and hello, Audrey.

6
00:00:23.375 --> 00:00:25.154
- Glad to see Audrey's doing well.

7
00:00:25.535 --> 00:00:28.289
- Yeah. Yeah. Audrey's good. I'm good too. I

8
00:00:28.370 --> 00:00:30.870
- I I missed Audrey earlier this morning. We

9
00:00:31.010 --> 00:00:33.010
- were gonna do a recording, and it fell

10
00:00:33.010 --> 00:00:34.390
- through for whatever reason.

11
00:00:34.850 --> 00:00:37.649
- Changes in time, changes in attitude, changes in

12
00:00:37.649 --> 00:00:38.149
- latitude.

13
00:00:39.729 --> 00:00:41.969
- Someone lost a flip flop, I think. I

14
00:00:41.969 --> 00:00:42.870
- I don't know.

15
00:00:43.664 --> 00:00:44.325
- Or something

16
00:00:45.184 --> 00:00:47.104
- or a pop top and ended up in

17
00:00:47.104 --> 00:00:49.125
- their flip. I don't know. Whatever it was.

18
00:00:49.424 --> 00:00:52.225
- So yeah. Alright. I do not have any

19
00:00:52.225 --> 00:00:55.184
- Jimmy Buffett on my turntable downstairs. That would

20
00:00:55.184 --> 00:00:57.024
- be too hard for me to do work

21
00:00:57.024 --> 00:00:57.524
- to.

22
00:00:58.250 --> 00:01:00.170
- Van Morrison, I can do, you know, and

23
00:01:00.170 --> 00:01:02.809
- Miles Davis, but the Jimmy Buffet's a little

24
00:01:02.809 --> 00:01:03.309
- bit

25
00:01:03.609 --> 00:01:06.009
- outside my ability to I do have Jimmy

26
00:01:06.009 --> 00:01:08.590
- Buffet, but it's upstairs. Anyway, alright.

27
00:01:09.369 --> 00:01:11.290
- So let's go over here to Henry. Henry

28
00:01:11.290 --> 00:01:14.284
- Virgil, where are you? And just, like, hello

29
00:01:14.284 --> 00:01:16.284
- and Yeah. So I'm in San Francisco right

30
00:01:16.284 --> 00:01:17.805
- now. I think last time I was on

31
00:01:17.805 --> 00:01:20.224
- the podcast, I was a researcher at Princeton.

32
00:01:20.524 --> 00:01:23.084
- I since left Princeton and became CEO of

33
00:01:23.084 --> 00:01:24.384
- a cybersecurity startup,

34
00:01:24.924 --> 00:01:27.185
- and then hence why I'm in San Francisco.

35
00:01:30.390 --> 00:01:31.609
- Oh, interesting.

36
00:01:32.469 --> 00:01:34.810
- Yeah. I'm not sure if that's, well, anyway,

37
00:01:35.350 --> 00:01:36.090
- I don't know.

38
00:01:38.469 --> 00:01:41.510
- Far different places, Princeton and San Francisco. Far,

39
00:01:41.510 --> 00:01:42.570
- far different places.

40
00:01:42.965 --> 00:01:44.244
- There used to be I don't know if

41
00:01:44.244 --> 00:01:45.284
- it's still there or not. There used to

42
00:01:45.284 --> 00:01:46.504
- be a Mexican place,

43
00:01:47.125 --> 00:01:48.024
- there in Princeton

44
00:01:48.564 --> 00:01:50.484
- that it was a bring your own bottle

45
00:01:50.484 --> 00:01:53.125
- place, whatever. And they have the absolute best

46
00:01:53.125 --> 00:01:55.329
- nachos on the face of the earth, Like,

47
00:01:55.329 --> 00:01:56.310
- fresh cooked,

48
00:01:56.770 --> 00:01:57.430
- you know,

49
00:01:58.130 --> 00:01:59.810
- like, they cut them and they cooked them

50
00:01:59.810 --> 00:02:01.409
- when you ordered them. They came out of

51
00:02:01.409 --> 00:02:03.969
- the oil hot, and, I mean, they were

52
00:02:03.969 --> 00:02:05.730
- so, so good. But it's been so many

53
00:02:05.730 --> 00:02:07.250
- years since I've been in Princeton that I

54
00:02:07.250 --> 00:02:09.250
- don't even know if that place is still

55
00:02:09.250 --> 00:02:12.414
- around. Alright. Shiloh, where are you other than

56
00:02:12.414 --> 00:02:13.155
- in the woods?

57
00:02:14.894 --> 00:02:16.655
- I am. I am quite literally in the

58
00:02:16.655 --> 00:02:17.474
- woods. I,

59
00:02:18.094 --> 00:02:20.495
- I actually moved from where Henry just moved

60
00:02:20.495 --> 00:02:21.634
- to, to Maryland,

61
00:02:22.094 --> 00:02:24.174
- and, I live in in a wooded part.

62
00:02:24.174 --> 00:02:24.674
- And

63
00:02:25.080 --> 00:02:27.580
- I, am at Fastly. And,

64
00:02:28.439 --> 00:02:30.840
- there, I was one of the founders of

65
00:02:30.840 --> 00:02:34.139
- the certification authority we run called Certainly and,

66
00:02:35.479 --> 00:02:36.699
- and do a lot of,

67
00:02:37.319 --> 00:02:37.819
- contributions

68
00:02:38.360 --> 00:02:40.379
- to Boulder for Let's Encrypt

69
00:02:41.375 --> 00:02:42.814
- operations and things. So,

70
00:02:43.135 --> 00:02:45.474
- this was very natural piece for,

71
00:02:46.014 --> 00:02:47.955
- for me to work on because it benefits,

72
00:02:48.254 --> 00:02:49.074
- a lot of people.

73
00:02:49.615 --> 00:02:52.335
- Cool. And, Michael, I see a shirt that

74
00:02:52.335 --> 00:02:54.360
- looks like a college shirt. Is that a

75
00:02:54.360 --> 00:02:56.439
- is that a That is correct. Georgia Tech

76
00:02:56.439 --> 00:02:57.659
- yellow jackets represent.

77
00:02:58.439 --> 00:03:00.360
- I am. My my father went to Georgia

78
00:03:00.360 --> 00:03:02.780
- Tech, so keep going. Excellent. Excellent.

79
00:03:03.560 --> 00:03:06.060
- Great taste. I am here in Atlanta, Georgia

80
00:03:06.439 --> 00:03:07.500
- as you might expect,

81
00:03:10.585 --> 00:03:11.224
- And I am,

82
00:03:12.105 --> 00:03:13.944
- well, my day job is with Amazon Trust

83
00:03:13.944 --> 00:03:16.344
- Services, which is Amazon's public,

84
00:03:16.665 --> 00:03:17.645
- certificate authority.

85
00:03:18.185 --> 00:03:18.685
- Okay.

86
00:03:19.944 --> 00:03:22.985
- That's cool. Good. Awesome. Alright. So we are

87
00:03:22.985 --> 00:03:24.284
- here to talk about

88
00:03:25.590 --> 00:03:27.590
- DNS persist, but let's not talk about that

89
00:03:27.590 --> 00:03:28.090
- first.

90
00:03:28.790 --> 00:03:31.110
- Let's just back into the problem and talk

91
00:03:31.110 --> 00:03:32.870
- about certificates. I don't know who wants to

92
00:03:32.870 --> 00:03:33.689
- address this.

93
00:03:34.230 --> 00:03:36.069
- I know Shiloh had started talking about this

94
00:03:36.069 --> 00:03:36.569
- before.

95
00:03:37.430 --> 00:03:40.104
- But, like, what is the problem with certificates?

96
00:03:40.104 --> 00:03:41.965
- Like, what are we doing with certificates,

97
00:03:42.584 --> 00:03:44.264
- and why are we seeing this happen? I

98
00:03:44.264 --> 00:03:47.405
- know you said before certificate lifetimes are shortening.

99
00:03:47.705 --> 00:03:49.224
- What's going on there? Like, what are we

100
00:03:49.305 --> 00:03:50.925
- what what are we facing here?

101
00:03:51.750 --> 00:03:54.550
- Well, there are threats for certificates that are

102
00:03:54.550 --> 00:03:55.830
- that are in use,

103
00:03:56.389 --> 00:03:57.930
- and they there's, cryptographic

104
00:03:58.629 --> 00:03:59.689
- threats and,

105
00:03:59.990 --> 00:04:00.490
- operational

106
00:04:00.949 --> 00:04:03.669
- key exposure threats and things. So tightening up

107
00:04:03.669 --> 00:04:04.169
- lifetimes

108
00:04:04.469 --> 00:04:06.969
- is a is a security posture improvement,

109
00:04:07.884 --> 00:04:09.025
- across across,

110
00:04:09.805 --> 00:04:10.864
- the industry. So,

111
00:04:11.644 --> 00:04:14.544
- in doing that, that pushes automation to be,

112
00:04:15.004 --> 00:04:17.644
- front and center in all all aspects of

113
00:04:17.644 --> 00:04:18.144
- keeping,

114
00:04:18.444 --> 00:04:21.250
- things online because everything uses TLS, and then

115
00:04:21.250 --> 00:04:23.089
- TLS uses x five zero nine and and

116
00:04:23.089 --> 00:04:23.750
- that this

117
00:04:24.129 --> 00:04:26.629
- is an integral part to the entire Internet

118
00:04:26.770 --> 00:04:27.270
- infrastructure.

119
00:04:28.050 --> 00:04:28.529
- So,

120
00:04:29.330 --> 00:04:31.970
- the the methods that came along with Acme,

121
00:04:31.970 --> 00:04:33.970
- which is the standardized way of doing of

122
00:04:33.970 --> 00:04:35.509
- doing certificate operations,

123
00:04:36.814 --> 00:04:38.435
- only allowed for for,

124
00:04:39.935 --> 00:04:40.435
- security

125
00:04:41.535 --> 00:04:43.855
- operations that were online and,

126
00:04:44.175 --> 00:04:46.835
- done at the time of the certificate issuance.

127
00:04:47.615 --> 00:04:49.715
- And that creates a lot of operational friction

128
00:04:49.899 --> 00:04:52.479
- and and for different parts of, the industry.

129
00:04:53.579 --> 00:04:55.279
- And so we presented,

130
00:04:55.899 --> 00:04:58.079
- an alternative, which is based on the DNS.

131
00:04:59.019 --> 00:05:01.919
- Okay. So when you shorten certificate lifetimes,

132
00:05:02.514 --> 00:05:05.154
- you're not only putting pressure on DNS, you're

133
00:05:05.154 --> 00:05:07.714
- actually putting pressure or not on DNS, on

134
00:05:07.714 --> 00:05:11.495
- the automation side. You're also actually putting pressure,

135
00:05:11.794 --> 00:05:14.194
- like, you have to be Internet connected at

136
00:05:14.194 --> 00:05:16.935
- all times to make that that automation work.

137
00:05:17.250 --> 00:05:18.230
- You also have,

138
00:05:19.490 --> 00:05:21.410
- the other it seems to me like there's

139
00:05:21.410 --> 00:05:23.910
- a trade off even on the security side

140
00:05:24.290 --> 00:05:26.150
- of having short lived certificates

141
00:05:26.930 --> 00:05:28.550
- in that things get desynchronized

142
00:05:30.210 --> 00:05:33.185
- and, you know, there are certain patterns that

143
00:05:33.185 --> 00:05:36.064
- can emerge from that. Is that a correct

144
00:05:36.064 --> 00:05:38.544
- assessment or is, like, am I, like, you

145
00:05:38.544 --> 00:05:41.925
- know is shorter certificate life always better or

146
00:05:42.144 --> 00:05:43.584
- is it there are So I think there's

147
00:05:43.584 --> 00:05:45.740
- a couple of trade offs across the ecosystem.

148
00:05:45.959 --> 00:05:46.680
- The first is the,

149
00:05:47.399 --> 00:05:49.000
- I think what Shiloh was talking about, the

150
00:05:49.000 --> 00:05:50.300
- renewal friction.

151
00:05:50.680 --> 00:05:52.600
- So the fact that now a lot of

152
00:05:52.600 --> 00:05:54.839
- orgs today still have, like, a person who

153
00:05:54.839 --> 00:05:55.819
- manages certificates,

154
00:05:56.360 --> 00:05:58.519
- that person makes a change in DNS and,

155
00:05:58.519 --> 00:05:58.935
- like, you know, once a year goes and

156
00:05:58.935 --> 00:05:59.064
- installs a bunch of certificates, and that type

157
00:05:59.064 --> 00:05:59.910
- of flow is just not gonna work with

158
00:06:01.855 --> 00:06:04.415
- bunch of certificates, and that type of flow

159
00:06:04.415 --> 00:06:06.194
- is just not gonna work with shorter lifespans.

160
00:06:06.334 --> 00:06:08.334
- And then the risk, that I think is

161
00:06:08.334 --> 00:06:10.814
- very relevant to this group is that you

162
00:06:10.814 --> 00:06:13.055
- might just take that, like, master DNS key

163
00:06:13.055 --> 00:06:14.759
- that that person used to be using and

164
00:06:14.839 --> 00:06:16.839
- spread it out to all of your servers.

165
00:06:16.839 --> 00:06:18.600
- So now they can make that DNS change

166
00:06:18.600 --> 00:06:20.060
- in an automated fashion.

167
00:06:20.439 --> 00:06:22.600
- But now you just put your, like, keys

168
00:06:22.600 --> 00:06:25.080
- to your kingdom, your DNS key on every

169
00:06:25.080 --> 00:06:26.759
- server. So I think there's sort of some

170
00:06:26.759 --> 00:06:28.574
- operational risk with shorter serves

171
00:06:29.055 --> 00:06:31.134
- about how people are gonna implement the automation,

172
00:06:31.134 --> 00:06:33.555
- and are they gonna risk doing something wrong?

173
00:06:34.014 --> 00:06:35.375
- And then I think, you know, we also

174
00:06:35.375 --> 00:06:37.795
- work a lot in the broader certificate ecosystem

175
00:06:38.335 --> 00:06:40.995
- on the CA side and the certificate transparency

176
00:06:41.215 --> 00:06:41.715
- side.

177
00:06:42.240 --> 00:06:43.439
- You know, a lot of these CAs are

178
00:06:43.439 --> 00:06:46.420
- doing several million certs a day. And

179
00:06:46.800 --> 00:06:48.259
- every time you cut lifespan,

180
00:06:48.639 --> 00:06:50.339
- that cert count a day

181
00:06:50.720 --> 00:06:52.879
- goes up. And then the need for a

182
00:06:52.879 --> 00:06:54.319
- CA to be on,

183
00:06:55.040 --> 00:06:56.955
- goes up. I think one of the interesting

184
00:06:56.955 --> 00:06:58.714
- conversations I had with the Let's Encrypt people,

185
00:06:58.714 --> 00:07:00.574
- they said if there's a seven day cert,

186
00:07:01.035 --> 00:07:02.634
- that means that, you know, people are gonna

187
00:07:02.634 --> 00:07:04.475
- renew after, like, four days of, like, three

188
00:07:04.475 --> 00:07:05.375
- days of runway.

189
00:07:05.915 --> 00:07:06.654
- And then

190
00:07:07.115 --> 00:07:09.355
- if Let's Encrypt were to somehow go out

191
00:07:09.355 --> 00:07:11.435
- for three days and their SRT team is,

192
00:07:11.435 --> 00:07:13.399
- like, five people that would have to get

193
00:07:13.399 --> 00:07:14.920
- on an airplane and fly to the data

194
00:07:14.920 --> 00:07:16.600
- center. They couldn't get there in, like, three

195
00:07:16.600 --> 00:07:19.000
- days, half the Internet would go down. So

196
00:07:19.000 --> 00:07:21.080
- you put more strain on sort of, you

197
00:07:21.080 --> 00:07:23.639
- know, CAs to be boys up. And then

198
00:07:23.639 --> 00:07:25.814
- also the certificate transparency infrastructure,

199
00:07:26.194 --> 00:07:28.355
- people talk about a lot now. They log

200
00:07:28.355 --> 00:07:30.274
- every cert that's signed, and then the signing

201
00:07:30.274 --> 00:07:31.714
- volume goes up. So there's a lot in

202
00:07:31.714 --> 00:07:34.214
- the ecosystem changing to support this,

203
00:07:34.675 --> 00:07:36.435
- but we're really looking at the sort of

204
00:07:36.435 --> 00:07:37.415
- operational friction.

205
00:07:40.569 --> 00:07:43.289
- Okay. That's kinda cool. And so yeah. So

206
00:07:43.289 --> 00:07:45.689
- there are also there are real human cost

207
00:07:45.689 --> 00:07:49.050
- to this, not just automation. Right? If your

208
00:07:49.050 --> 00:07:50.589
- if your cert goes faster,

209
00:07:50.970 --> 00:07:51.949
- then that becomes

210
00:07:52.329 --> 00:07:52.829
- essentially

211
00:07:53.610 --> 00:07:54.110
- a,

212
00:07:55.154 --> 00:07:57.714
- not really a an attack surface, but a

213
00:07:57.714 --> 00:07:58.774
- failure surface

214
00:07:59.314 --> 00:08:00.294
- in the network

215
00:08:00.754 --> 00:08:02.834
- that become or in the system, not necessarily

216
00:08:02.834 --> 00:08:04.915
- just the network, but in the system that

217
00:08:04.915 --> 00:08:06.995
- says, okay, well, if this goes this goes

218
00:08:06.995 --> 00:08:09.509
- out, oh my, now I have a problem

219
00:08:09.509 --> 00:08:10.709
- that I have to go solve. And like

220
00:08:10.709 --> 00:08:11.829
- you said, people may have to get on

221
00:08:11.829 --> 00:08:14.310
- an airplane and fly. Well, that, like, that

222
00:08:14.310 --> 00:08:15.129
- really stinks

223
00:08:15.509 --> 00:08:17.610
- because that's, you know, family and

224
00:08:18.550 --> 00:08:20.389
- I don't know, fuel and all the other

225
00:08:20.389 --> 00:08:22.310
- stuff that goes with that. That's that's really

226
00:08:22.310 --> 00:08:22.810
- painful.

227
00:08:23.294 --> 00:08:24.514
- Yeah. Alright.

228
00:08:24.894 --> 00:08:27.375
- So all of that said, anything else you

229
00:08:27.375 --> 00:08:29.535
- wanna bring up there, Tom, before we jump

230
00:08:29.535 --> 00:08:30.035
- into?

231
00:08:30.495 --> 00:08:31.935
- No. I have a couple of questions for

232
00:08:31.935 --> 00:08:34.754
- later on. Okay. Cool. Alright. So

233
00:08:36.620 --> 00:08:37.679
- all that said,

234
00:08:38.700 --> 00:08:41.340
- if we what the solution that you're talking

235
00:08:41.340 --> 00:08:42.940
- about let's talk about so that's kind of

236
00:08:42.940 --> 00:08:43.679
- the problem.

237
00:08:44.299 --> 00:08:47.259
- So how are you thinking about structurally, like,

238
00:08:47.259 --> 00:08:47.759
- architecturally?

239
00:08:48.620 --> 00:08:50.159
- How are you thinking about

240
00:08:51.085 --> 00:08:53.644
- solving this? You know, not without getting not

241
00:08:53.725 --> 00:08:55.985
- no technical details at this point. Just like,

242
00:08:56.284 --> 00:08:58.445
- what is the general pattern? What are you

243
00:08:58.445 --> 00:09:00.705
- trying to to do to solve this?

244
00:09:01.085 --> 00:09:03.245
- Well, I think because of, you know, some

245
00:09:03.559 --> 00:09:05.579
- so Henry did security analyses,

246
00:09:05.959 --> 00:09:08.919
- and Michael put, profiles in place at the

247
00:09:08.919 --> 00:09:11.879
- CAB forum that allowed for the idea that

248
00:09:11.879 --> 00:09:14.699
- you could replace this sort of online,

249
00:09:15.480 --> 00:09:15.980
- challenges

250
00:09:16.440 --> 00:09:17.820
- with a standing authorization

251
00:09:18.315 --> 00:09:19.215
- that says,

252
00:09:19.674 --> 00:09:20.575
- I authorize

253
00:09:21.274 --> 00:09:22.654
- this Acme account,

254
00:09:23.595 --> 00:09:26.154
- to always make changes on the to you

255
00:09:26.154 --> 00:09:28.414
- know, in certificates by issuing new certificates,

256
00:09:29.835 --> 00:09:32.815
- on this on this name, on this, FQDN.

257
00:09:35.220 --> 00:09:35.720
- Okay.

258
00:09:36.980 --> 00:09:39.379
- So anybody want to expand on that a

259
00:09:39.379 --> 00:09:41.540
- little? Go ahead. Sorry. Yeah. I think it's

260
00:09:41.540 --> 00:09:43.860
- it's true that the thing that certificates are

261
00:09:43.860 --> 00:09:46.100
- best at is expiring, so they're time bombs.

262
00:09:46.100 --> 00:09:46.754
- And so

263
00:09:48.195 --> 00:09:50.054
- this is not effectively a new problem.

264
00:09:50.595 --> 00:09:53.634
- For years, ever since Acme was started, there

265
00:09:53.634 --> 00:09:55.975
- was DNS based domain control verification,

266
00:09:56.914 --> 00:09:59.309
- and there were smart people that, meanwhile, that

267
00:09:59.389 --> 00:10:01.090
- have figured out ways to

268
00:10:01.470 --> 00:10:04.610
- work around the limitations and reduce the risk

269
00:10:04.669 --> 00:10:05.169
- of,

270
00:10:05.950 --> 00:10:06.450
- having

271
00:10:06.909 --> 00:10:09.309
- a outage related to a certificate expiring because

272
00:10:09.309 --> 00:10:11.809
- you were unable to renew the certificate

273
00:10:12.350 --> 00:10:12.850
- because

274
00:10:13.309 --> 00:10:14.049
- of reasons.

275
00:10:14.590 --> 00:10:16.824
- And a lot of those mechanisms,

276
00:10:19.125 --> 00:10:21.684
- essentially equated to something that the term Henry

277
00:10:21.684 --> 00:10:24.004
- used. So I'm leveraging it from him, which

278
00:10:24.004 --> 00:10:25.065
- is CNAME magic,

279
00:10:25.524 --> 00:10:26.904
- in which you would

280
00:10:27.924 --> 00:10:29.684
- do something similar in which you'd add a

281
00:10:29.684 --> 00:10:30.904
- CNAME that delegates

282
00:10:31.230 --> 00:10:32.049
- that domain

283
00:10:32.429 --> 00:10:35.230
- or that, basically, that renewal or that domain

284
00:10:35.230 --> 00:10:37.649
- control validation action to another entity.

285
00:10:38.110 --> 00:10:39.970
- Most of the time, it is a CDN

286
00:10:40.029 --> 00:10:43.009
- or some other infrastructure provider. Sometimes it's a

287
00:10:43.375 --> 00:10:46.355
- single entity within an organization or some enterprise

288
00:10:46.415 --> 00:10:47.075
- use cases.

289
00:10:47.535 --> 00:10:50.495
- But it's another way of reasoning about this

290
00:10:50.495 --> 00:10:53.075
- problem of how do I prevent these clients

291
00:10:53.134 --> 00:10:54.595
- individually having to

292
00:10:55.134 --> 00:10:57.055
- each being exposed to this risk of being

293
00:10:57.055 --> 00:10:58.355
- unable to renew successfully.

294
00:10:58.710 --> 00:11:01.690
- How do I centralize in that particular model,

295
00:11:01.750 --> 00:11:03.670
- solve it in one place, and do it

296
00:11:03.670 --> 00:11:04.970
- in a way that makes sense?

297
00:11:05.509 --> 00:11:06.009
- And

298
00:11:06.629 --> 00:11:08.950
- this builds upon that legacy about how do

299
00:11:08.950 --> 00:11:11.029
- we do that in a more straightforward and,

300
00:11:11.815 --> 00:11:14.774
- direct way and explicit way than what folks

301
00:11:14.774 --> 00:11:16.935
- were doing on their own. So are you

302
00:11:16.935 --> 00:11:18.715
- doing a c name on the CAA?

303
00:11:19.735 --> 00:11:20.875
- Is that basically

304
00:11:21.254 --> 00:11:23.095
- is is that I'm trying to understand in

305
00:11:23.095 --> 00:11:24.375
- my head, like, how this

306
00:11:25.160 --> 00:11:27.259
- If you wanna get into the mechanics, happy

307
00:11:27.399 --> 00:11:29.240
- to. Would love to. Well, well, I don't

308
00:11:29.240 --> 00:11:31.000
- know if if anybody else wants to describe

309
00:11:31.000 --> 00:11:31.899
- more of the,

310
00:11:32.360 --> 00:11:34.920
- more of the overall problem and solution before

311
00:11:34.920 --> 00:11:37.259
- we jump there, if Tom has questions. But,

312
00:11:37.524 --> 00:11:38.024
- yeah.

313
00:11:38.964 --> 00:11:41.065
- So, basically, you are delegating

314
00:11:42.084 --> 00:11:42.584
- certificate

315
00:11:43.605 --> 00:11:44.105
- renewal

316
00:11:45.284 --> 00:11:46.664
- to a third party.

317
00:11:47.284 --> 00:11:49.044
- Now is this for on this is for

318
00:11:49.044 --> 00:11:51.945
- ongoing operations or for in times of emergency?

319
00:11:52.559 --> 00:11:55.299
- Right? It's both players Or or is it?

320
00:11:55.519 --> 00:11:56.639
- I think This used

321
00:11:58.320 --> 00:11:59.519
- Yeah. I'm sorry. I think we have a

322
00:11:59.840 --> 00:12:00.580
- Go ahead.

323
00:12:01.519 --> 00:12:02.320
- Collision lag.

324
00:12:02.879 --> 00:12:04.399
- I was gonna say, just to be clear,

325
00:12:04.399 --> 00:12:06.559
- this is for peep this is largely what

326
00:12:06.559 --> 00:12:08.235
- people used to be doing. They would use

327
00:12:08.235 --> 00:12:11.214
- a c name to delegate certificate renewal

328
00:12:11.595 --> 00:12:13.754
- to a third party Oh, okay. On an

329
00:12:13.754 --> 00:12:16.394
- ongoing basis. And I will foreshadow a little

330
00:12:16.394 --> 00:12:17.995
- bit what we're trying to do. You know,

331
00:12:17.995 --> 00:12:19.855
- a c name is a particular vehicle

332
00:12:20.475 --> 00:12:21.134
- in DNS,

333
00:12:21.670 --> 00:12:24.149
- and this was not really the the number

334
00:12:24.149 --> 00:12:25.910
- one rule of the c name. And you

335
00:12:25.910 --> 00:12:27.990
- can also imagine once you delegate with that

336
00:12:27.990 --> 00:12:29.830
- c name, that third party has to run

337
00:12:29.830 --> 00:12:30.970
- this piece of infrastructure

338
00:12:31.350 --> 00:12:33.509
- that essentially is the target of that c

339
00:12:33.509 --> 00:12:36.070
- name and constantly changes a bunch of DNS

340
00:12:36.070 --> 00:12:37.985
- records just to get certificates.

341
00:12:39.884 --> 00:12:42.125
- So you move the failure point outside of

342
00:12:42.125 --> 00:12:44.605
- the primary zone to this secondary c name

343
00:12:44.605 --> 00:12:47.725
- delegated zone, but you still have this, like,

344
00:12:47.725 --> 00:12:50.365
- always up infrastructure that can go down, can

345
00:12:50.365 --> 00:12:51.825
- break, introduces complexity.

346
00:12:53.320 --> 00:12:53.820
- Yeah.

347
00:12:54.600 --> 00:12:55.580
- And and interestingly,

348
00:12:55.960 --> 00:12:58.519
- c names are imperfect even in this regard

349
00:12:58.519 --> 00:12:59.019
- because

350
00:12:59.639 --> 00:13:03.100
- c names are cached and flattened whenever possible

351
00:13:03.240 --> 00:13:04.139
- by recursive,

352
00:13:05.000 --> 00:13:05.500
- resolvers.

353
00:13:05.985 --> 00:13:08.705
- And so you you you flatten the c

354
00:13:08.705 --> 00:13:10.404
- name today at 10:00,

355
00:13:10.784 --> 00:13:13.524
- and then somebody changed the delegation or whatever.

356
00:13:13.825 --> 00:13:16.464
- And now you're basically out until that cache

357
00:13:16.464 --> 00:13:20.690
- runs out, and that recursive resolver says, oh,

358
00:13:20.750 --> 00:13:23.309
- my cache ran out. My TTL expired. I

359
00:13:23.309 --> 00:13:25.549
- need to go reflatten that c name. And

360
00:13:25.549 --> 00:13:27.950
- so that's gonna cause lots of angst and

361
00:13:27.950 --> 00:13:28.450
- problems

362
00:13:29.070 --> 00:13:32.210
- in that process. Just that just that TTL

363
00:13:32.750 --> 00:13:35.445
- and etcetera that goes into this. Yeah. So

364
00:13:35.445 --> 00:13:37.384
- that's I can see where that's an issue.

365
00:13:38.004 --> 00:13:41.125
- The, the problem with CNAME is that you

366
00:13:41.125 --> 00:13:43.065
- cannot have more than one.

367
00:13:43.365 --> 00:13:46.165
- And so that Okay. That's huge problem for

368
00:13:46.165 --> 00:13:48.105
- multi CDN, multi CA

369
00:13:49.045 --> 00:13:49.545
- customers.

370
00:13:50.210 --> 00:13:52.129
- Yeah. Right? And that's where you want to

371
00:13:52.129 --> 00:13:52.629
- authorize

372
00:13:53.090 --> 00:13:53.590
- to,

373
00:13:54.129 --> 00:13:56.230
- things to to do this on your behalf.

374
00:13:57.009 --> 00:13:58.230
- And yeah.

375
00:13:58.690 --> 00:14:00.370
- So I so I know d names are

376
00:14:00.370 --> 00:14:02.529
- new, and a lot of people don't like

377
00:14:02.529 --> 00:14:04.610
- them. Would d names solve part of that

378
00:14:04.610 --> 00:14:05.110
- problem?

379
00:14:05.985 --> 00:14:07.985
- Yes. Oh, oh, boy. I'm getting a lot

380
00:14:07.985 --> 00:14:08.485
- of

381
00:14:09.745 --> 00:14:11.745
- don't go there. I I don't think a

382
00:14:11.745 --> 00:14:13.424
- d name is fully the answer. I think

383
00:14:13.424 --> 00:14:15.184
- of the d name more as helping with

384
00:14:15.184 --> 00:14:17.825
- sort of sub labels, you know, below the

385
00:14:17.825 --> 00:14:18.565
- c name.

386
00:14:19.289 --> 00:14:20.970
- But I I think it's it's a good

387
00:14:20.970 --> 00:14:23.370
- point to transition into the solution, which is

388
00:14:23.370 --> 00:14:25.529
- just not to use not to use c

389
00:14:25.529 --> 00:14:27.370
- names anymore, at least not for this type

390
00:14:27.370 --> 00:14:29.789
- of online renewal stuff. Okay.

391
00:14:31.975 --> 00:14:34.054
- Okay. Yeah. That sounds good. So so yeah.

392
00:14:34.054 --> 00:14:35.914
- So if you're not using c names,

393
00:14:37.174 --> 00:14:40.534
- how what, like, system are you using? Are

394
00:14:40.534 --> 00:14:41.754
- you creating a new

395
00:14:42.294 --> 00:14:43.115
- record type?

396
00:14:44.519 --> 00:14:45.019
- EXT.

397
00:14:46.039 --> 00:14:46.539
- Okay.

398
00:14:48.519 --> 00:14:51.100
- We yeah. And we are, you know,

399
00:14:51.559 --> 00:14:54.360
- fundamentally, you're just trying to prove control of

400
00:14:54.360 --> 00:14:55.019
- a Danus

401
00:14:55.480 --> 00:14:55.980
- name

402
00:14:56.414 --> 00:14:58.815
- in in Acme, right, and in DCV for

403
00:14:58.815 --> 00:14:59.875
- DCV. And

404
00:15:00.254 --> 00:15:00.735
- you

405
00:15:01.375 --> 00:15:03.615
- in the previous model, you would look at

406
00:15:03.615 --> 00:15:04.115
- that,

407
00:15:04.894 --> 00:15:07.134
- DNS name as an a record and talk

408
00:15:07.134 --> 00:15:09.695
- to port 80 on the thing or or,

409
00:15:10.740 --> 00:15:13.220
- and and now or trail the or trace

410
00:15:13.220 --> 00:15:16.019
- the c name. Right? And, now what you

411
00:15:16.019 --> 00:15:18.039
- can do is you can have TXT records

412
00:15:18.419 --> 00:15:20.580
- at more of course, more than one at

413
00:15:20.580 --> 00:15:22.679
- that same exact, DNS

414
00:15:23.299 --> 00:15:24.759
- record that says that

415
00:15:25.115 --> 00:15:26.654
- this CA is authorized

416
00:15:27.195 --> 00:15:29.914
- and this account at that CA is authorized

417
00:15:29.914 --> 00:15:32.254
- or this other entity at that a subscriber

418
00:15:32.315 --> 00:15:34.654
- of some sort at that CA is authorized

419
00:15:34.875 --> 00:15:35.934
- to issue certificates

420
00:15:36.554 --> 00:15:38.554
- to this name, to this DNS name that

421
00:15:38.554 --> 00:15:41.029
- I'm part of. And, of course, you have

422
00:15:41.029 --> 00:15:43.269
- you have the the DNSSEC, and you have

423
00:15:43.269 --> 00:15:45.750
- things that are that are that are sealing

424
00:15:45.750 --> 00:15:48.570
- that, part of it. So that's your,

425
00:15:49.350 --> 00:15:51.509
- you you're proving now what you wanted to

426
00:15:51.509 --> 00:15:54.009
- prove, which is control of that domain name.

427
00:15:54.544 --> 00:15:55.444
- Okay. Interesting.

428
00:15:55.985 --> 00:15:58.304
- So I guess my I guess my when

429
00:15:58.304 --> 00:16:00.964
- whenever when whenever anyone says TXT,

430
00:16:01.345 --> 00:16:03.264
- my immediate response is gonna be the same

431
00:16:03.264 --> 00:16:05.365
- thing my response is with,

432
00:16:06.649 --> 00:16:09.370
- AFI SAFE's in BGP, which I wish we

433
00:16:09.370 --> 00:16:10.590
- would not use so many

434
00:16:10.970 --> 00:16:13.049
- of. Please, there are other ways of carrying

435
00:16:13.049 --> 00:16:16.250
- data in in BGP than AFI SAFE's. And

436
00:16:16.250 --> 00:16:18.889
- we just keep like, oh, it's an opaque

437
00:16:18.889 --> 00:16:21.230
- LSA. Let's just throw more stuff in there.

438
00:16:21.335 --> 00:16:24.134
- So I guess my my initial reaction is

439
00:16:24.134 --> 00:16:24.875
- always gonna

440
00:16:25.254 --> 00:16:27.414
- be why TXT? Why not a new record

441
00:16:27.414 --> 00:16:27.914
- type?

442
00:16:28.774 --> 00:16:31.995
- Are we perhaps causing confusion in the TXT

443
00:16:32.054 --> 00:16:32.554
- space

444
00:16:33.014 --> 00:16:34.870
- by doing this? And I'm not saying it's

445
00:16:34.870 --> 00:16:36.709
- invalid, I'm just saying those are like initial

446
00:16:36.709 --> 00:16:40.389
- reactions that always come to mind whenever anyone

447
00:16:40.389 --> 00:16:43.350
- starts using a TXT or an AFI SAFI

448
00:16:43.350 --> 00:16:45.429
- or whatever it is. An opaque LSA in

449
00:16:45.429 --> 00:16:46.169
- in OSPF.

450
00:16:46.950 --> 00:16:47.690
- Is there,

451
00:16:48.524 --> 00:16:49.964
- I mean, are those

452
00:16:50.764 --> 00:16:53.325
- other things were considered, but TXT ended up

453
00:16:53.325 --> 00:16:56.304
- being best? It was the easiest path forward.

454
00:16:57.084 --> 00:16:58.924
- I don't know. I'm just asking, like, how

455
00:16:58.924 --> 00:17:00.924
- does that how does that work? Largely on

456
00:17:00.924 --> 00:17:01.825
- following precedent.

457
00:17:02.370 --> 00:17:06.130
- So the primary way of do validating domain

458
00:17:06.130 --> 00:17:10.549
- control is a TXT record at _acmechallenge,

459
00:17:10.930 --> 00:17:13.589
- .dom yourdomain.com.

460
00:17:13.730 --> 00:17:15.805
- And then the IETF actually, you know, came

461
00:17:15.805 --> 00:17:17.644
- out to endorse this eventually. They have, like,

462
00:17:17.644 --> 00:17:18.545
- a best practices

463
00:17:19.164 --> 00:17:19.664
- recommendation,

464
00:17:20.365 --> 00:17:23.244
- like RFC on domain control validation, which says

465
00:17:23.244 --> 00:17:24.684
- the best way to do it is to

466
00:17:24.684 --> 00:17:25.184
- show

467
00:17:25.485 --> 00:17:27.265
- uploading of a TXT record

468
00:17:27.829 --> 00:17:30.890
- at, you know, that underscore prefix label. And

469
00:17:30.950 --> 00:17:32.789
- so we had you know, that's what the

470
00:17:32.789 --> 00:17:34.710
- ecosystem is used to, and that was what

471
00:17:34.710 --> 00:17:37.109
- used to be behind those c name records

472
00:17:37.109 --> 00:17:39.029
- we were talking about. So you used to

473
00:17:39.029 --> 00:17:41.450
- follow the c name to an ephemeral TXT

474
00:17:41.509 --> 00:17:42.009
- record.

475
00:17:42.484 --> 00:17:44.325
- And, you know, kind of keeping with the

476
00:17:44.325 --> 00:17:44.825
- consistency

477
00:17:45.285 --> 00:17:47.924
- just to let's use the same as similar

478
00:17:47.924 --> 00:17:50.005
- looking of a record as possible. Yeah. But

479
00:17:50.005 --> 00:17:51.605
- just put it where the c name used

480
00:17:51.605 --> 00:17:53.785
- to live and just make it a persistent

481
00:17:53.845 --> 00:17:55.890
- delegation to, like, say, hey. That can sign

482
00:17:55.890 --> 00:17:56.630
- my account

483
00:17:56.930 --> 00:17:57.910
- again and again.

484
00:18:00.930 --> 00:18:03.170
- Okay. And that makes sense because people have

485
00:18:03.170 --> 00:18:06.289
- already written code. People have already written runbooks.

486
00:18:06.289 --> 00:18:08.450
- They know how to do this. You're just

487
00:18:08.450 --> 00:18:10.710
- kind of changing what they're already doing

488
00:18:11.085 --> 00:18:14.304
- rather than inventing something absolutely totally new

489
00:18:14.765 --> 00:18:17.085
- in in the environment, which then makes sense.

490
00:18:17.085 --> 00:18:17.585
- Yeah.

491
00:18:17.884 --> 00:18:20.845
- Okay. So that's perfectly valid answer. I just

492
00:18:20.845 --> 00:18:23.005
- always ask. Right? Because I I do see

493
00:18:23.005 --> 00:18:24.544
- people do stuff and I'm like,

494
00:18:25.279 --> 00:18:27.519
- you know, yes. It's opaque. That doesn't mean

495
00:18:27.519 --> 00:18:29.200
- you can throw anything you want to at

496
00:18:29.200 --> 00:18:29.700
- it.

497
00:18:30.399 --> 00:18:30.899
- Yeah.

498
00:18:31.519 --> 00:18:33.619
- Which we do. We do a lot.

499
00:18:35.359 --> 00:18:37.039
- Even I think you raise a great point

500
00:18:37.039 --> 00:18:39.440
- about following precedent and about people already used

501
00:18:39.440 --> 00:18:41.315
- to this. Even the mechanisms on how you

502
00:18:41.315 --> 00:18:41.815
- identify

503
00:18:42.515 --> 00:18:45.414
- who which accounts or which entity is authorized,

504
00:18:45.555 --> 00:18:48.035
- how you identify the CA, they also follow

505
00:18:48.035 --> 00:18:49.715
- precedents. We're using a lot of the same

506
00:18:49.715 --> 00:18:50.215
- syntax

507
00:18:50.755 --> 00:18:51.815
- that the certificate

508
00:18:52.434 --> 00:18:53.335
- authority authorization,

509
00:18:53.715 --> 00:18:55.255
- CA records utilize

510
00:18:55.619 --> 00:18:56.279
- to specify,

511
00:18:57.859 --> 00:18:59.000
- the certificate authorities.

512
00:18:59.700 --> 00:19:01.960
- The account URI is following,

513
00:19:02.740 --> 00:19:04.660
- the ACME structure is allowed as well, and

514
00:19:04.660 --> 00:19:06.259
- we go into more details about how that

515
00:19:06.259 --> 00:19:08.220
- can be expressed, which is another interesting part

516
00:19:08.220 --> 00:19:09.000
- of the conversation.

517
00:19:09.539 --> 00:19:10.904
- But so a lot of

518
00:19:11.865 --> 00:19:14.205
- the origination of the this direction

519
00:19:14.664 --> 00:19:17.065
- is based on what is it that how

520
00:19:17.065 --> 00:19:19.545
- does domain control validation already work, and how

521
00:19:19.545 --> 00:19:21.865
- can we streamline it and improve it in

522
00:19:21.865 --> 00:19:23.945
- a way that has some nice properties but

523
00:19:23.945 --> 00:19:24.445
- doesn't

524
00:19:25.049 --> 00:19:27.450
- shock anybody about what is going on. Okay.

525
00:19:27.450 --> 00:19:29.150
- That that is indeed one of the considerations

526
00:19:29.210 --> 00:19:31.769
- that led us here. Okay. And and just

527
00:19:31.769 --> 00:19:33.870
- to be clear for people who are listening,

528
00:19:34.330 --> 00:19:35.150
- you're not

529
00:19:35.610 --> 00:19:36.110
- actually

530
00:19:36.490 --> 00:19:39.210
- extending the lifetime of a certificate. You're you're

531
00:19:39.210 --> 00:19:40.110
- actually saying

532
00:19:40.804 --> 00:19:43.785
- these short life certificates or shorter life certificates

533
00:19:44.325 --> 00:19:46.964
- are actually better in a security from a

534
00:19:46.964 --> 00:19:47.944
- security perspective.

535
00:19:48.325 --> 00:19:50.404
- We're just gonna find a way to make

536
00:19:50.404 --> 00:19:52.505
- it easier to automate and manage

537
00:19:53.125 --> 00:19:54.825
- those shorter lifetime certificates.

538
00:19:55.799 --> 00:19:57.579
- So yeah. Just okay. Good.

539
00:19:58.039 --> 00:20:00.619
- That is correct. And one of the interesting

540
00:20:00.679 --> 00:20:02.859
- parts of the way that public certificate,

541
00:20:03.960 --> 00:20:06.440
- the public e public e PKI works, excuse

542
00:20:06.440 --> 00:20:08.359
- me, is that there are actually two timelines

543
00:20:08.359 --> 00:20:09.339
- that are being managed

544
00:20:09.674 --> 00:20:11.755
- behind the scenes. There's the when you perform

545
00:20:11.755 --> 00:20:13.134
- a domain control validation,

546
00:20:13.994 --> 00:20:16.235
- that is a femoral action that get at

547
00:20:16.235 --> 00:20:18.315
- a point in time determination that says, at

548
00:20:18.315 --> 00:20:20.494
- this point, I validated that this

549
00:20:21.115 --> 00:20:23.115
- applicant is what we call the person requesting

550
00:20:23.115 --> 00:20:23.695
- a certificate,

551
00:20:24.190 --> 00:20:25.809
- has control over this domain,

552
00:20:26.350 --> 00:20:28.590
- and then you can issue a certificate based

553
00:20:28.590 --> 00:20:29.490
- off of that

554
00:20:29.869 --> 00:20:31.090
- assertion of control.

555
00:20:31.470 --> 00:20:34.830
- And so this decouples the ability to issue

556
00:20:34.830 --> 00:20:36.529
- certificates or renew certificates

557
00:20:37.285 --> 00:20:38.964
- from the ability to,

558
00:20:40.325 --> 00:20:42.005
- prove that you have control. Because now you

559
00:20:42.005 --> 00:20:43.785
- have a mechanism to have a persistent

560
00:20:44.724 --> 00:20:48.164
- means of asserting control, validating that the TXD

561
00:20:48.164 --> 00:20:49.684
- record that we're talking about is still in

562
00:20:49.684 --> 00:20:53.009
- place, And then your ability to renew certificates

563
00:20:53.009 --> 00:20:53.990
- based off of that

564
00:20:54.369 --> 00:20:54.869
- existing

565
00:20:55.170 --> 00:20:56.630
- domain validation record

566
00:20:57.009 --> 00:20:58.930
- is decoupled. So you can issue as many

567
00:20:58.930 --> 00:21:00.069
- certificates on whatever

568
00:21:00.369 --> 00:21:02.069
- short whatever lifetime you need

569
00:21:02.464 --> 00:21:04.384
- with only having to take action on the

570
00:21:04.384 --> 00:21:07.505
- certificate rather than having to rotate the renewal

571
00:21:07.505 --> 00:21:09.125
- knots, the DNS knots

572
00:21:09.664 --> 00:21:11.744
- at the same time. So what else what

573
00:21:11.744 --> 00:21:14.305
- else in the ecosystem has to change to

574
00:21:14.305 --> 00:21:16.224
- take advantage of this? You published a c

575
00:21:16.224 --> 00:21:17.789
- name or sorry, not a c name, a

576
00:21:17.789 --> 00:21:18.289
- TXT.

577
00:21:19.149 --> 00:21:21.710
- And and so what what other code changes,

578
00:21:21.710 --> 00:21:24.130
- what practices change to make this work?

579
00:21:26.429 --> 00:21:28.669
- Well, the the policy change in the cap

580
00:21:28.669 --> 00:21:30.984
- form is already in place. So what's,

581
00:21:31.424 --> 00:21:33.505
- what needs to happen is the implementation of

582
00:21:33.505 --> 00:21:34.164
- this, and,

583
00:21:35.424 --> 00:21:35.825
- that's,

584
00:21:36.304 --> 00:21:39.825
- going on this year now already with, Boulder,

585
00:21:39.825 --> 00:21:42.085
- which is for let's encrypts back end, and,

586
00:21:42.944 --> 00:21:44.964
- it's going on with, a

587
00:21:45.400 --> 00:21:47.559
- number of client implementations as well that are

588
00:21:47.559 --> 00:21:49.740
- used on, at least, on large scale,

589
00:21:50.279 --> 00:21:51.179
- hosting providers.

590
00:21:53.160 --> 00:21:55.640
- So so there's software changes, right, in reading

591
00:21:55.640 --> 00:21:57.480
- the record correctly? Because it used to be

592
00:21:57.480 --> 00:21:59.559
- a c name pointing at a text, and

593
00:21:59.559 --> 00:22:00.619
- now it's a text.

594
00:22:01.585 --> 00:22:02.565
- Alright. So now

595
00:22:02.865 --> 00:22:04.865
- I have that piece so that so you're

596
00:22:04.865 --> 00:22:07.984
- saying the things like bind or whatever other

597
00:22:07.984 --> 00:22:09.125
- tools that you use

598
00:22:09.585 --> 00:22:12.164
- are actually being built now to handle this.

599
00:22:12.544 --> 00:22:14.164
- So that if I'm an end user,

600
00:22:14.549 --> 00:22:16.970
- if I download the latest update or whatever,

601
00:22:17.509 --> 00:22:19.049
- those things are built in.

602
00:22:19.430 --> 00:22:20.170
- And I think

603
00:22:20.950 --> 00:22:22.630
- Well, bind wouldn't need to be updated, would

604
00:22:22.630 --> 00:22:24.789
- it? Yeah. Not bind, but whatever. That's nice.

605
00:22:24.789 --> 00:22:26.750
- Because it's t f c. It's t x

606
00:22:26.750 --> 00:22:27.850
- t r t. Exactly.

607
00:22:28.934 --> 00:22:29.174
- Yeah.

608
00:22:29.894 --> 00:22:32.934
- The the yeah. The, the providers, like Let's

609
00:22:32.934 --> 00:22:33.434
- Encrypt,

610
00:22:33.974 --> 00:22:36.615
- and certainly will be providing it, like, this

611
00:22:36.615 --> 00:22:39.015
- year. And then so as soon as clients

612
00:22:39.015 --> 00:22:41.335
- update, they can start taking advantage of this.

613
00:22:41.335 --> 00:22:41.835
- And

614
00:22:42.134 --> 00:22:42.634
- it,

615
00:22:43.549 --> 00:22:46.130
- it should just make their friction go down.

616
00:22:47.390 --> 00:22:49.089
- This will manifest as another

617
00:22:49.549 --> 00:22:51.250
- domain control validation method

618
00:22:51.549 --> 00:22:53.410
- that is an option for,

619
00:22:54.109 --> 00:22:56.634
- clients to select and servers to support. So

620
00:22:56.634 --> 00:22:58.875
- there has to be support for this method

621
00:22:58.875 --> 00:23:00.555
- on both sides, the client and the server

622
00:23:00.555 --> 00:23:01.055
- side.

623
00:23:02.315 --> 00:23:04.474
- And when you say client, are peep should

624
00:23:04.474 --> 00:23:06.795
- be people be thinking of web browsers, stuff

625
00:23:06.795 --> 00:23:08.955
- like that? Or should they be thinking what

626
00:23:09.299 --> 00:23:11.140
- yeah. What should they be thinking of? Yeah.

627
00:23:11.140 --> 00:23:13.460
- Acme clients. So more like Acme clients. They're

628
00:23:13.460 --> 00:23:15.940
- thinking about. Yeah. Yeah. I kind of assumed

629
00:23:15.940 --> 00:23:17.380
- that's what you meant, but I just wanna

630
00:23:17.380 --> 00:23:19.460
- make sure, you know, people listening to this

631
00:23:19.460 --> 00:23:21.380
- again are probably thinking Well, the client to

632
00:23:21.380 --> 00:23:22.039
- a certificate

633
00:23:22.900 --> 00:23:23.340
- authority

634
00:23:23.779 --> 00:23:26.044
- Right. Is the server to an end user.

635
00:23:26.265 --> 00:23:27.085
- Yeah. Yeah.

636
00:23:28.664 --> 00:23:31.704
- Right. Right. Yes. Okay. That makes sense. Right.

637
00:23:31.704 --> 00:23:33.464
- And so So cert bot is is a

638
00:23:33.464 --> 00:23:35.544
- pretty popular one from Let's Encrypt, and that's

639
00:23:35.544 --> 00:23:37.244
- that's getting updated in tandem.

640
00:23:38.025 --> 00:23:38.525
- Okay.

641
00:23:39.170 --> 00:23:39.670
- Awesome.

642
00:23:40.450 --> 00:23:42.789
- So we're gonna have these shorter list certificates.

643
00:23:43.009 --> 00:23:43.509
- Operationally,

644
00:23:44.289 --> 00:23:46.369
- if you run not if you run if

645
00:23:46.369 --> 00:23:47.349
- you run a CA

646
00:23:47.809 --> 00:23:50.529
- or if you have a certificate in your

647
00:23:50.529 --> 00:23:51.029
- organization,

648
00:23:51.775 --> 00:23:53.694
- you need to watch for this. Right? And

649
00:23:53.694 --> 00:23:55.535
- you need to make sure that is there

650
00:23:55.535 --> 00:23:56.595
- anything administratively

651
00:23:57.535 --> 00:23:58.275
- that say,

652
00:23:58.654 --> 00:23:59.315
- I am

653
00:23:59.615 --> 00:24:01.474
- big bank number 48

654
00:24:01.615 --> 00:24:04.355
- or whatever my company is, my organization is.

655
00:24:04.734 --> 00:24:06.355
- What do I need to do

656
00:24:07.099 --> 00:24:08.480
- in relation to this,

657
00:24:10.059 --> 00:24:11.759
- other than just update the software?

658
00:24:12.460 --> 00:24:14.700
- Is it primarily gonna be on my CA

659
00:24:14.700 --> 00:24:15.200
- side?

660
00:24:15.740 --> 00:24:17.820
- Like, if I'm I think there's definitely or

661
00:24:17.820 --> 00:24:20.220
- not. Several recommendations we would make for this,

662
00:24:20.220 --> 00:24:21.119
- you know, hypothetical

663
00:24:21.420 --> 00:24:22.035
- big bank.

664
00:24:22.755 --> 00:24:25.015
- The first is to try to eliminate

665
00:24:25.474 --> 00:24:27.974
- all manual certificate renewal processes

666
00:24:28.515 --> 00:24:30.835
- that will always cause increased friction. I know

667
00:24:30.835 --> 00:24:33.154
- many enterprises, as I said, are still doing

668
00:24:33.154 --> 00:24:35.269
- this manual process where they have, like, a

669
00:24:35.269 --> 00:24:37.429
- compliance person who gets the certs from the

670
00:24:37.429 --> 00:24:37.929
- CA

671
00:24:38.230 --> 00:24:39.529
- and puts them on the servers,

672
00:24:39.990 --> 00:24:41.910
- and it needs to go to be an

673
00:24:41.910 --> 00:24:44.230
- Acme client that can get certs from the

674
00:24:44.230 --> 00:24:45.690
- CA themselves automatically

675
00:24:46.309 --> 00:24:47.369
- and then deploy

676
00:24:47.825 --> 00:24:50.884
- automatically. What's really good and why we're recommending

677
00:24:50.944 --> 00:24:52.724
- people adopt this method today

678
00:24:53.105 --> 00:24:55.744
- is that the prior generation of Acme clients

679
00:24:55.744 --> 00:24:58.144
- needed to have some type of access to

680
00:24:58.144 --> 00:25:00.805
- either the HTTP directories on those servers

681
00:25:01.424 --> 00:25:03.880
- or to the DNS infrastructure. And what we're

682
00:25:03.880 --> 00:25:05.960
- saying is your Acme client doesn't need to

683
00:25:05.960 --> 00:25:07.079
- do any of that. But you can still

684
00:25:07.079 --> 00:25:09.799
- have that compliance person go in, write this

685
00:25:09.799 --> 00:25:12.059
- DNS record, put it in DNS,

686
00:25:12.599 --> 00:25:15.480
- and we've decoupled that. So one thing we're

687
00:25:15.480 --> 00:25:18.460
- doing is actually making it easier for enterprises

688
00:25:18.599 --> 00:25:20.325
- to lean into that adoption,

689
00:25:21.025 --> 00:25:22.945
- get the ACME plans out there, get the

690
00:25:22.945 --> 00:25:26.465
- automated certificate management, and still have, you know,

691
00:25:26.465 --> 00:25:29.045
- secure DNS zones that don't have any credentials

692
00:25:29.105 --> 00:25:31.585
- anywhere and just put these static records in

693
00:25:31.585 --> 00:25:33.744
- place to opt optimize them. So I think

694
00:25:33.744 --> 00:25:37.029
- for enterprise that are looking to adopt certificate

695
00:25:37.170 --> 00:25:37.670
- automation,

696
00:25:38.210 --> 00:25:40.609
- I would say that this DNS persist proposal

697
00:25:40.609 --> 00:25:41.509
- is the strongest,

698
00:25:42.049 --> 00:25:44.230
- most recommended way forward right now.

699
00:25:46.930 --> 00:25:47.430
- Okay.

700
00:25:49.144 --> 00:25:50.684
- And if I were

701
00:25:51.224 --> 00:25:53.384
- a provider, I'm gonna be pretty much in

702
00:25:53.384 --> 00:25:55.304
- the same position, like a transit or something

703
00:25:55.304 --> 00:25:57.884
- like that. Because I just I have customers

704
00:25:57.944 --> 00:25:59.404
- and I have CA servers

705
00:25:59.704 --> 00:26:01.544
- that I can use Acme client on to

706
00:26:01.544 --> 00:26:03.910
- do all the stuff there. And if I

707
00:26:03.910 --> 00:26:05.990
- were an IX, it's gonna be pretty much

708
00:26:05.990 --> 00:26:08.490
- the same. So really, the place this

709
00:26:08.789 --> 00:26:10.869
- it has the most impact is just in

710
00:26:10.869 --> 00:26:12.490
- building the TXT records

711
00:26:12.789 --> 00:26:13.289
- and

712
00:26:13.590 --> 00:26:16.330
- in for certificate authorities, like Let's Encrypt

713
00:26:17.265 --> 00:26:20.224
- to manage their end of the of the

714
00:26:20.224 --> 00:26:20.724
- situation.

715
00:26:21.105 --> 00:26:23.845
- Right? And software developers who are building

716
00:26:24.224 --> 00:26:24.964
- the tools.

717
00:26:25.585 --> 00:26:27.345
- Is that where you would say the most

718
00:26:27.345 --> 00:26:29.505
- impact is? Impact, you mean, like, input into

719
00:26:29.505 --> 00:26:32.085
- the ecosystem and the need to change software?

720
00:26:32.500 --> 00:26:34.579
- Yeah. Yeah. Right. Right. You actually have to

721
00:26:34.579 --> 00:26:37.460
- do something. Yes. Yeah. I these enterprises banks

722
00:26:37.460 --> 00:26:38.440
- don't have to.

723
00:26:40.900 --> 00:26:43.460
- Okay. Yeah. I'm just thinking through all the

724
00:26:43.460 --> 00:26:45.539
- different roles that people might have and, like,

725
00:26:45.539 --> 00:26:48.234
- you know, where would would the impact be

726
00:26:48.234 --> 00:26:49.914
- different for any of these? But it doesn't

727
00:26:49.914 --> 00:26:52.315
- seem like it would be. It's mostly gonna

728
00:26:52.315 --> 00:26:53.615
- be on certificate authorities.

729
00:26:54.634 --> 00:26:56.634
- Stuff like that is where that end of

730
00:26:56.634 --> 00:26:57.615
- it's gonna be.

731
00:26:57.994 --> 00:26:58.974
- I'm I'm curious.

732
00:26:59.355 --> 00:27:01.455
- Do any of y'all have a sense of

733
00:27:01.809 --> 00:27:04.869
- the distribution of methods of domain control authorization

734
00:27:05.410 --> 00:27:07.990
- that are used today? Is it, like, mostly

735
00:27:08.369 --> 00:27:10.470
- the c name method, or is it balanced,

736
00:27:10.529 --> 00:27:12.450
- or is it kind of all over the

737
00:27:12.450 --> 00:27:14.690
- place? Or maybe that's hard to get. You

738
00:27:14.690 --> 00:27:15.170
- probably would

739
00:27:15.914 --> 00:27:17.355
- I guess you'd have to get that from

740
00:27:17.355 --> 00:27:20.095
- the CA, but, like, any any sense there?

741
00:27:20.315 --> 00:27:22.154
- I have a so we've done research on

742
00:27:22.154 --> 00:27:24.154
- that back when I was at Princeton. We

743
00:27:24.154 --> 00:27:27.375
- collected Let's Encrypt blogs that included validation data

744
00:27:27.595 --> 00:27:29.115
- and then published summary statistics on what validation

745
00:27:29.115 --> 00:27:29.855
- looks like.

746
00:27:37.250 --> 00:27:38.930
- Let's encrypt boat, we were looking at, like,

747
00:27:38.930 --> 00:27:39.910
- 70%

748
00:27:40.369 --> 00:27:41.269
- people changing

749
00:27:41.970 --> 00:27:43.029
- dot well known

750
00:27:43.985 --> 00:27:47.105
- directories on their HTTP servers, and that's one

751
00:27:47.105 --> 00:27:48.164
- way to do verification.

752
00:27:48.865 --> 00:27:50.164
- And then 30%

753
00:27:50.545 --> 00:27:53.105
- with this type of DNS stuff, I don't

754
00:27:53.105 --> 00:27:55.585
- think we broke down the DNS to what

755
00:27:55.585 --> 00:27:57.390
- I call magic CNAME, which is where you

756
00:27:57.390 --> 00:27:59.630
- outsource it to someone else versus in zone,

757
00:27:59.630 --> 00:28:00.450
- like, changes.

758
00:28:00.830 --> 00:28:02.430
- I would suspect that a lot of the

759
00:28:02.430 --> 00:28:04.830
- DNS was being done through the the CNAME

760
00:28:04.830 --> 00:28:06.910
- stuff. But I should note that, like, when

761
00:28:06.910 --> 00:28:09.150
- you follow electric encrypt instructions, you kinda got,

762
00:28:09.150 --> 00:28:11.355
- like, this choice. It's normally, like, a little

763
00:28:11.355 --> 00:28:13.434
- cert bot that runs close to the server

764
00:28:13.434 --> 00:28:13.934
- dir.

765
00:28:14.474 --> 00:28:16.394
- If you go to other CAs, they have

766
00:28:16.394 --> 00:28:17.855
- much higher rates of

767
00:28:18.154 --> 00:28:20.715
- DNS validation. I don't you know, that logic

768
00:28:20.715 --> 00:28:22.555
- is, I think, less public, but I will

769
00:28:22.555 --> 00:28:24.654
- say it varies from CA to CA.

770
00:28:25.355 --> 00:28:27.009
- So but I I would definitely think north

771
00:28:27.009 --> 00:28:28.849
- of 30%. I think Let's Encrypt actually has

772
00:28:28.849 --> 00:28:29.509
- a low

773
00:28:30.130 --> 00:28:32.230
- percentage of people doing DNS

774
00:28:32.529 --> 00:28:35.509
- validation, and it's more popular enterprises too.

775
00:28:38.505 --> 00:28:40.605
- Yeah. Well, Let's Encrypt tends

776
00:28:41.065 --> 00:28:42.765
- to pull in the people who,

777
00:28:43.144 --> 00:28:45.644
- for whatever reason, are not paying

778
00:28:46.105 --> 00:28:46.605
- ACA

779
00:28:46.904 --> 00:28:48.125
- to do the work.

780
00:28:48.505 --> 00:28:50.345
- You know, it's more of an open source

781
00:28:50.345 --> 00:28:52.470
- kind of a community based.

782
00:28:52.769 --> 00:28:55.250
- And therefore, you're going to get the smaller

783
00:28:55.250 --> 00:28:58.470
- companies, the, you know, companies without somebody

784
00:28:59.089 --> 00:29:01.349
- on board that's going to do the work

785
00:29:01.650 --> 00:29:04.289
- that you're talking about full time. And so

786
00:29:04.289 --> 00:29:07.134
- therefore, they're probably just gonna follow, you know,

787
00:29:07.134 --> 00:29:08.355
- simplest path forward.

788
00:29:08.654 --> 00:29:10.335
- What's the easiest way for me to get

789
00:29:10.335 --> 00:29:11.555
- to where I wanna go?

790
00:29:11.934 --> 00:29:13.615
- Because I just want my website up in

791
00:29:13.615 --> 00:29:15.775
- the web. I just want it running, and

792
00:29:15.775 --> 00:29:17.535
- I don't want customers calling me because they

793
00:29:17.535 --> 00:29:18.914
- don't have a green lock

794
00:29:19.299 --> 00:29:21.000
- on their browser. Thank you.

795
00:29:21.859 --> 00:29:23.779
- That's what that's what a lot of people

796
00:29:23.779 --> 00:29:25.720
- want. It's, you know, keep fighting.

797
00:29:26.579 --> 00:29:28.820
- I think for the most part, people will

798
00:29:28.820 --> 00:29:31.140
- just need to update their software as it's

799
00:29:31.140 --> 00:29:32.200
- released, and

800
00:29:32.545 --> 00:29:35.125
- they will be able to keep going forward

801
00:29:35.345 --> 00:29:37.505
- the same way or they and they should

802
00:29:37.505 --> 00:29:38.005
- reevaluate

803
00:29:38.305 --> 00:29:40.785
- their their needs as far as access goes

804
00:29:40.785 --> 00:29:43.664
- and and maybe close down some channels to

805
00:29:43.664 --> 00:29:45.605
- create a more secure environment

806
00:29:45.904 --> 00:29:47.204
- that they had already.

807
00:29:48.329 --> 00:29:50.089
- Okay. So that's all sounds cool to me.

808
00:29:50.089 --> 00:29:51.710
- I mean, it all sounds very simple

809
00:29:52.009 --> 00:29:52.509
- and

810
00:29:53.130 --> 00:29:55.950
- very straightforward, and what you're doing makes sense.

811
00:29:56.250 --> 00:29:58.109
- Now do you have any challenges

812
00:29:58.490 --> 00:29:58.990
- in

813
00:29:59.529 --> 00:30:00.029
- deployment?

814
00:30:00.809 --> 00:30:02.730
- Like, do you see any place where you're

815
00:30:02.730 --> 00:30:03.049
- thinking

816
00:30:03.845 --> 00:30:05.365
- now I know. You know, it's kinda but,

817
00:30:05.365 --> 00:30:05.865
- anyway,

818
00:30:06.325 --> 00:30:07.845
- like, where we're gonna hit I p v

819
00:30:07.845 --> 00:30:09.945
- six moments where people are gonna be like,

820
00:30:10.085 --> 00:30:10.585
- no.

821
00:30:12.244 --> 00:30:14.424
- Or or do you think it's fairly straightforward

822
00:30:15.125 --> 00:30:17.285
- and, you know, it's just gonna roll out

823
00:30:17.285 --> 00:30:18.265
- and you'll see

824
00:30:18.589 --> 00:30:21.390
- an increasing deployment over time. I wouldn't call

825
00:30:21.390 --> 00:30:23.549
- it a challenge exactly, but I think, an

826
00:30:23.549 --> 00:30:26.109
- emerging area on the deployment front is just

827
00:30:26.109 --> 00:30:27.329
- the existence of

828
00:30:27.710 --> 00:30:29.089
- non Acme CAs

829
00:30:29.549 --> 00:30:31.825
- and Acme accounts that live under,

830
00:30:32.365 --> 00:30:34.684
- non Acme accounts. So maybe this is just

831
00:30:34.684 --> 00:30:35.484
- a a brief,

832
00:30:35.884 --> 00:30:37.505
- background on the CA industry.

833
00:30:37.964 --> 00:30:40.684
- But, you know, some CAs use the automated

834
00:30:40.684 --> 00:30:44.509
- certificate management environment protocol. It's a client to

835
00:30:44.509 --> 00:30:45.410
- CA protocol

836
00:30:45.789 --> 00:30:47.329
- that gets you your certs automatically.

837
00:30:47.869 --> 00:30:50.669
- Some CAs have other automation channels,

838
00:30:50.990 --> 00:30:52.910
- and then some CAs, you know, don't have

839
00:30:52.910 --> 00:30:57.095
- any automation options. But, essentially, Acme represents some

840
00:30:57.234 --> 00:30:58.454
- fraction of the ecosystem.

841
00:30:58.994 --> 00:31:00.914
- And one thing that we actually have CA

842
00:31:00.914 --> 00:31:03.174
- operators talk about is they might have

843
00:31:03.634 --> 00:31:05.954
- some Acme accounts that live under sort of

844
00:31:05.954 --> 00:31:08.855
- a more global umbrella of, like, an enterprise

845
00:31:08.994 --> 00:31:09.494
- account.

846
00:31:09.940 --> 00:31:11.940
- So one thing that I think we've put

847
00:31:11.940 --> 00:31:13.559
- into the draft more recently

848
00:31:14.180 --> 00:31:16.200
- is kind of the ability to do authorization

849
00:31:16.420 --> 00:31:18.660
- at the level of this enterprise account and

850
00:31:18.660 --> 00:31:21.320
- then have your Acme accounts, like, live underneath

851
00:31:21.380 --> 00:31:23.380
- it. So I'd say as we're kind of

852
00:31:23.380 --> 00:31:25.394
- interacting more with the broader space

853
00:31:26.275 --> 00:31:28.755
- of CAs and users, we're discovering more of

854
00:31:28.755 --> 00:31:30.615
- these use cases about, like,

855
00:31:31.315 --> 00:31:33.075
- where is Acme? Like, you know, the the

856
00:31:33.075 --> 00:31:35.714
- standard IETF model is, like, that is the

857
00:31:35.714 --> 00:31:39.049
- subscriber account, the Acme account. But increasingly, we

858
00:31:39.049 --> 00:31:41.950
- actually see, like, The subscriber has some type

859
00:31:42.329 --> 00:31:44.970
- of external billing relationship with the CA, and

860
00:31:44.970 --> 00:31:47.609
- Acme is just the protocol they run on

861
00:31:47.609 --> 00:31:49.289
- their server. So I'd say that's a neat

862
00:31:49.289 --> 00:31:50.750
- emerging use case, like,

863
00:31:51.130 --> 00:31:52.509
- Acme as a as a protocol

864
00:31:53.210 --> 00:31:55.765
- and less as, like, your primary account,

865
00:31:56.224 --> 00:31:57.845
- you know, relationship with the

866
00:31:58.144 --> 00:31:58.644
- CA.

867
00:32:01.505 --> 00:32:03.585
- Couldn't they use the same systems? They just

868
00:32:03.585 --> 00:32:05.585
- have to have them built into their into

869
00:32:05.585 --> 00:32:06.404
- their ecosystem

870
00:32:07.159 --> 00:32:09.000
- in the same way, I would think. Yeah.

871
00:32:09.000 --> 00:32:10.679
- They do. They use similar things, but

872
00:32:11.400 --> 00:32:14.200
- you have this identity that's so because we

873
00:32:14.200 --> 00:32:16.359
- authorize on that account identity, you have this

874
00:32:16.359 --> 00:32:18.059
- introduction of this other identity

875
00:32:18.679 --> 00:32:20.795
- okay. That's kind of the CA account. And

876
00:32:20.795 --> 00:32:22.875
- then you have to sort of create a

877
00:32:22.875 --> 00:32:24.875
- policy around what does that mean to have

878
00:32:24.875 --> 00:32:26.954
- a broader account and map that back to

879
00:32:26.954 --> 00:32:28.335
- individual Acme accounts.

880
00:32:30.954 --> 00:32:33.289
- Yeah. Alright. Yeah. That makes sense.

881
00:32:33.909 --> 00:32:35.829
- So what does it look like? Are you

882
00:32:35.829 --> 00:32:38.329
- seeing deployments? Are you seeing lots of deployment?

883
00:32:40.149 --> 00:32:42.470
- Are you, like, is it rolling out pretty

884
00:32:42.470 --> 00:32:44.470
- fast? Or is it slow? Or what what

885
00:32:44.470 --> 00:32:46.230
- do you think the future holds here? Where

886
00:32:46.309 --> 00:32:48.244
- where's the where's it looking?

887
00:32:49.105 --> 00:32:51.045
- I think on a lot of the major,

888
00:32:51.505 --> 00:32:55.265
- open source projects that are, in heavy use,

889
00:32:55.265 --> 00:32:58.224
- there there's all active work to to get

890
00:32:58.224 --> 00:33:00.164
- integration, and there's there's interest,

891
00:33:00.625 --> 00:33:02.404
- across the board because it solves

892
00:33:03.000 --> 00:33:05.180
- a lot of operational friction for people,

893
00:33:05.640 --> 00:33:06.140
- and,

894
00:33:06.920 --> 00:33:08.539
- they they would like to use it.

895
00:33:09.000 --> 00:33:09.500
- Okay.

896
00:33:10.039 --> 00:33:10.539
- Cool.

897
00:33:12.440 --> 00:33:13.240
- Okay. Any

898
00:33:13.799 --> 00:33:15.720
- is this a draft? Is this in draft

899
00:33:15.720 --> 00:33:17.420
- state? Is it a working group item?

900
00:33:17.835 --> 00:33:19.934
- Where is this in the IETF process?

901
00:33:22.154 --> 00:33:24.154
- We're between o one and o two of

902
00:33:24.154 --> 00:33:26.234
- the draft right now. Work draft. It's a

903
00:33:26.315 --> 00:33:28.794
- it's adopted at the We think it's ACME

904
00:33:28.794 --> 00:33:29.615
- working group.

905
00:33:32.049 --> 00:33:33.509
- Okay. So it's adopted.

906
00:33:33.890 --> 00:33:36.690
- It's just okay. Cool. I'm just always curious,

907
00:33:36.690 --> 00:33:38.690
- like, you know, what if you're at that

908
00:33:38.690 --> 00:33:41.650
- point, the likelihood of major changes coming down

909
00:33:41.650 --> 00:33:42.309
- the road

910
00:33:42.744 --> 00:33:45.784
- because somebody comes in sideways and says, oh,

911
00:33:45.784 --> 00:33:47.224
- no. You should have done it this way

912
00:33:47.224 --> 00:33:49.304
- or whatever. Some of the security people or

913
00:33:49.304 --> 00:33:52.105
- something. Right? Are much lower once you once

914
00:33:52.105 --> 00:33:54.184
- you're adopted into a working group draft and

915
00:33:54.184 --> 00:33:56.924
- you're kind of rolling along through the process.

916
00:33:57.809 --> 00:33:59.890
- The odds of massive changes are are much

917
00:33:59.890 --> 00:34:00.390
- lower.

918
00:34:01.089 --> 00:34:03.089
- Something, you know, people when they read drafts

919
00:34:03.089 --> 00:34:04.769
- in the ITF, they don't realize that if

920
00:34:04.769 --> 00:34:05.269
- it's

921
00:34:05.569 --> 00:34:08.289
- certain stages, things are more more likely to

922
00:34:08.289 --> 00:34:08.949
- be changed.

923
00:34:09.489 --> 00:34:11.489
- And then in other stages and so, you

924
00:34:11.489 --> 00:34:13.190
- know, it's a good thing to know that.

925
00:34:13.485 --> 00:34:15.985
- Alright. Cool. I don't really have any other

926
00:34:16.445 --> 00:34:18.684
- particular questions. It all sounds like a cool

927
00:34:18.684 --> 00:34:19.184
- technology,

928
00:34:19.724 --> 00:34:21.505
- cool cool solution to

929
00:34:21.805 --> 00:34:23.744
- a problem that is approaching.

930
00:34:24.605 --> 00:34:27.085
- And, you know, instead of people just typing

931
00:34:27.085 --> 00:34:27.585
- faster

932
00:34:28.530 --> 00:34:31.510
- and getting on airplanes to carry USB keys

933
00:34:31.809 --> 00:34:32.949
- around the servers,

934
00:34:34.690 --> 00:34:35.590
- you can actually

935
00:34:36.449 --> 00:34:39.030
- build a system where it can be rationally

936
00:34:39.170 --> 00:34:39.670
- automated.

937
00:34:40.144 --> 00:34:43.505
- So, yeah, that's always a good thing. Yeah.

938
00:34:43.505 --> 00:34:46.224
- Sneaker nets never never fun. So I don't

939
00:34:46.224 --> 00:34:46.704
- know.

940
00:34:47.105 --> 00:34:49.505
- Anything else anybody wants to say before we

941
00:34:49.505 --> 00:34:52.065
- wrap up as far as future, current, anything

942
00:34:52.065 --> 00:34:52.565
- else?

943
00:34:53.369 --> 00:34:54.750
- Henry, anything you

944
00:34:55.210 --> 00:34:56.010
- I'm really good. Just,

945
00:34:56.569 --> 00:34:58.650
- I think Shiloh is quite quite about the

946
00:34:58.650 --> 00:35:00.969
- deployment, but, you know, let's incur test stated

947
00:35:00.969 --> 00:35:02.670
- intent to support this. And

948
00:35:03.210 --> 00:35:06.029
- Shiloh here is from, certainly from Fastly,

949
00:35:06.494 --> 00:35:09.583
- So and, Leica Slaughters from Amazon. Like, we

950
00:35:09.583 --> 00:35:12.053
- do definitely see the major CAs at least

951
00:35:12.053 --> 00:35:14.523
- coming coming out with this. It's already coming

952
00:35:14.523 --> 00:35:16.994
- out in the ACME clients. So this is

953
00:35:16.994 --> 00:35:19.464
- gonna be a real option for enterprises to

954
00:35:19.464 --> 00:35:20.699
- reduce their certificate friction.

955
00:35:22.699 --> 00:35:25.760
- Alright. Awesome. Shiloh, anything from your end?

956
00:35:27.019 --> 00:35:29.099
- Yeah. All the major cloud providers, I think,

957
00:35:29.099 --> 00:35:30.480
- are interested, and,

958
00:35:31.179 --> 00:35:34.059
- it's it's just gonna make things better in

959
00:35:34.059 --> 00:35:34.719
- the TLS

960
00:35:35.255 --> 00:35:37.994
- ecosystem, which allows better security posture,

961
00:35:38.855 --> 00:35:39.355
- overall.

962
00:35:39.735 --> 00:35:42.775
- Okay. Anything else, Michael? You wanna cover? Yeah.

963
00:35:42.775 --> 00:35:45.755
- Change is coming, and we highly encourage automation.

964
00:35:45.815 --> 00:35:47.815
- We don't like seeing certs expire. This is

965
00:35:47.815 --> 00:35:50.135
- one mechanism, one additional tool in your tool

966
00:35:50.135 --> 00:35:50.909
- belt to prevent

967
00:35:51.389 --> 00:35:52.369
- cert related outages.

968
00:35:52.909 --> 00:35:55.549
- So we encourage you to use it. Okay.

969
00:35:55.549 --> 00:35:57.389
- Cool. Join us on the mailing list for

970
00:35:57.389 --> 00:35:59.389
- our ETF if you have comments or concerns

971
00:35:59.389 --> 00:35:59.789
- or

972
00:36:00.190 --> 00:36:02.269
- Okay. Be happy to take in collaborators as

973
00:36:02.269 --> 00:36:04.690
- well. Alright. Tom, any other questions?

974
00:36:05.505 --> 00:36:08.005
- No. No. It's been great. Alright. Cool. Alright.

975
00:36:08.144 --> 00:36:09.904
- Henry, where can people find you? Do you

976
00:36:09.904 --> 00:36:12.644
- have a blog, or are you on Yes.

977
00:36:12.784 --> 00:36:13.764
- Some kind of

978
00:36:14.065 --> 00:36:16.944
- social antisocial media? Yes. I was LinkedIn, but

979
00:36:16.944 --> 00:36:20.259
- I'm quite mad about updating that. I now

980
00:36:20.259 --> 00:36:23.139
- blog through our security company, Crosslayer Labs. So

981
00:36:23.139 --> 00:36:23.639
- Crosslayer

982
00:36:23.940 --> 00:36:26.179
- Labs, all1word,.com,

983
00:36:26.500 --> 00:36:27.400
- /blog,

984
00:36:27.539 --> 00:36:29.559
- and I have some articles there. Okay.

985
00:36:31.695 --> 00:36:34.655
- Awesome. Very good. And, Shiloh, any place you

986
00:36:34.655 --> 00:36:35.635
- you are publicly

987
00:36:36.575 --> 00:36:39.135
- out there saying things to people or just

988
00:36:39.135 --> 00:36:41.135
- living in a way? I think the closest

989
00:36:41.135 --> 00:36:42.994
- I get to social media is GitHub,

990
00:36:43.535 --> 00:36:44.994
- s hirick on there.

991
00:36:46.390 --> 00:36:47.449
- And I,

992
00:36:47.909 --> 00:36:49.989
- I do blog occasionally for as part of

993
00:36:49.989 --> 00:36:50.489
- Fastly.

994
00:36:51.510 --> 00:36:54.789
- Okay. So Okay. Cool. Michael, anything from you?

995
00:36:54.789 --> 00:36:55.289
- LinkedIn.

996
00:36:55.590 --> 00:36:56.489
- That's it. Okay.

997
00:36:58.085 --> 00:37:00.324
- He took your, he took your thing, Tom.

998
00:37:00.324 --> 00:37:01.944
- You can't say anything now.

999
00:37:05.525 --> 00:37:07.065
- That's alright. Less is more.

1000
00:37:07.844 --> 00:37:08.984
- Less is more.

1001
00:37:09.364 --> 00:37:10.664
- Alright. Go ahead, Tom.

1002
00:37:11.760 --> 00:37:12.260
- LinkedIn.

1003
00:37:12.880 --> 00:37:15.140
- See. It's it's like a thing. Alright.

1004
00:37:16.320 --> 00:37:17.920
- I'm Russ White. You can find me here

1005
00:37:17.920 --> 00:37:20.159
- at the hedge at rule eleven dot tech.

1006
00:37:20.159 --> 00:37:21.539
- I'm on LinkedIn occasionally,

1007
00:37:22.000 --> 00:37:24.719
- on exit routing geek occasionally, not very often,

1008
00:37:24.719 --> 00:37:26.824
- but sometimes I am. And

1009
00:37:27.605 --> 00:37:29.125
- we've we know we live in an attention

1010
00:37:29.125 --> 00:37:31.045
- driven economy. Thank you very much for listening

1011
00:37:31.045 --> 00:37:32.085
- all the way to the bitter end of

1012
00:37:32.085 --> 00:37:34.164
- this episode of The Hedge, and we will

1013
00:37:34.164 --> 00:37:35.304
- catch you next time.