On Fri, Jun 30, 2017 at 07:06:20PM -0500, /dev/rob0 wrote:

> [ LE certificate expired, DANE notification received ]
> 
> > My temporary fix was to remove the TLSA records, sorry.  I cannot 
> > risk losing mail as my poor brain tries to digest all this. :)
> 
> 14 months later I got back to this. :)
> 
> > I'm going to consider my options here before I replace the TLSA 
> > records.  I am thinking I only want my LE cert on submission (so 
> > that MUAs will be able to verify it) and to replace my port 25 cert 
> > with one from my own private CA.
> 
> And this is what I have done, initially on domain nodns4.us, but 
> several other zones are signed and will be using TLSA records.

I see non-LE certs, but I don't presently see "2 1 1" records
associated with your private CA, just "3 1 1" records for the leaf
certificate (same for both MX hosts, which may be a single point
of failure if key rotation is done synchronously on both MX hosts):

    nodns4.us. IN MX 10 mx3.nodns4.us.
    _25._tcp.mx3.nodns4.us. IN TLSA 3 1 1 
11bde0823d61d2795ee51ddd8af0201b3dfe0f78a1a6f98150ab02a4297640bc ; passed

      Subject = 
[email protected],CN=harrier.slackbuilds.org,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
      Issuer = [email protected],CN=SlackBuilds.ORG 
Signing CA,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
      Inception = 2017-06-30T18:25:10Z
      Expiration = 2020-10-07T18:25:10Z
      Fingerprint = 
7ebb8cc2057b842c7a4f460a9fc955c88ba796f7edded330be6aef13e1d97230

    nodns4.us. IN MX 20 mx4.nodns4.us.
    _25._tcp.mx4.nodns4.us. IN TLSA 3 1 1 
11bde0823d61d2795ee51ddd8af0201b3dfe0f78a1a6f98150ab02a4297640bc ; passed

      Subject = 
[email protected],CN=harrier.slackbuilds.org,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
      Issuer = [email protected],CN=SlackBuilds.ORG 
Signing CA,OU=Harrier,O=SlackBuilds.Org,L=Northport,ST=Alabama,C=US
      Inception = 2017-06-30T18:25:10Z
      Expiration = 2020-10-07T18:25:10Z
      Fingerprint = 
7ebb8cc2057b842c7a4f460a9fc955c88ba796f7edded330be6aef13e1d97230

> Thanks again for all your work on DANE and Postfix.
> 
> Thanks also to P@rick and the sys4.de gang for the validation site.
> 
> Question: I noticed my domain in a drop-down list there.  Is the 
> validation site maintaining a list of DANE-enabled and former DANE 
> zones?  

Yes, it does "completion" as you type.  I argued against this
feature.  Users can just cut/paste their own domains.

> IOW, should I drop a note to Victor when adding more zones, 
> or is the validation site taking care of that?

I get domain data feeds from many sources, with the validation site
being one such source.  So you're covered by the ongoing survey.

-- 
        Viktor.

Reply via email to