On Fri, Jun 30, 2017 at 07:06:20PM -0500, /dev/rob0 wrote:
> [ LE certificate expired, DANE notification received ]
>
> > My temporary fix was to remove the TLSA records, sorry. I cannot
> > risk losing mail as my poor brain tries to digest all this. :)
>
> 14 months later I got back to this. :)
>
> > I'm going to consider my options here before I replace the TLSA
> > records. I am thinking I only want my LE cert on submission (so
> > that MUAs will be able to verify it) and to replace my port 25 cert
> > with one from my own private CA.
>
> And this is what I have done, initially on domain nodns4.us, but
> several other zones are signed and will be using TLSA records.
I see non-LE certs, but I don't presently see "2 1 1" records
associated with your private CA, just "3 1 1" records for the leaf
certificate (same for both MX hosts, which may be a single point
of failure if key rotation is done synchronously on both MX hosts):
nodns4.us. IN MX 10 mx3.nodns4.us.
_25._tcp.mx3.nodns4.us. IN TLSA 3 1 1
11bde0823d61d2795ee51ddd8af0201b3dfe0f78a1a6f98150ab02a4297640bc ; passed
Subject =
[email protected],CN=harrier.slackbuilds.org,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
Issuer = [email protected],CN=SlackBuilds.ORG
Signing CA,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
Inception = 2017-06-30T18:25:10Z
Expiration = 2020-10-07T18:25:10Z
Fingerprint =
7ebb8cc2057b842c7a4f460a9fc955c88ba796f7edded330be6aef13e1d97230
nodns4.us. IN MX 20 mx4.nodns4.us.
_25._tcp.mx4.nodns4.us. IN TLSA 3 1 1
11bde0823d61d2795ee51ddd8af0201b3dfe0f78a1a6f98150ab02a4297640bc ; passed
Subject =
[email protected],CN=harrier.slackbuilds.org,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
Issuer = [email protected],CN=SlackBuilds.ORG
Signing CA,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
Inception = 2017-06-30T18:25:10Z
Expiration = 2020-10-07T18:25:10Z
Fingerprint =
7ebb8cc2057b842c7a4f460a9fc955c88ba796f7edded330be6aef13e1d97230
> Thanks again for all your work on DANE and Postfix.
>
> Thanks also to P@rick and the sys4.de gang for the validation site.
>
> Question: I noticed my domain in a drop-down list there. Is the
> validation site maintaining a list of DANE-enabled and former DANE
> zones?
Yes, it does "completion" as you type. I argued against this
feature. Users can just cut/paste their own domains.
> IOW, should I drop a note to Victor when adding more zones,
> or is the validation site taking care of that?
I get domain data feeds from many sources, with the validation site
being one such source. So you're covered by the ongoing survey.
--
Viktor.