Re: [Acme] FW: [ietf-wg-acme/acme] Add a meta flag to indicate when GET requests for certificates are allowed (#462)

2018-10-10 Thread Tim Hollebeek
I suspect that the guessable account numbers is something the LE folks will eventually regret for one reason or another. It’s poor security design to make something public and/or guessable if it doesn’t need to be. -Tim From: Acme On Behalf Of Richard Barnes Sent: Tuesday, October 9,

Re: [Acme] FW: [ietf-wg-acme/acme] Add a meta flag to indicate when GET requests for certificates are allowed (#462)

2018-10-10 Thread Jacob Hoffman-Andrews
Updated to include Orders and Authorizations in the example as you requested. https://github.com/ietf-wg-acme/acme/pull/463/files On 10/09/2018 04:49 PM, Jacob Hoffman-Andrews wrote: I'll revise this to include examples from the other URLs. One of my goals is to switch away from the "counting

Re: [Acme] FW: [ietf-wg-acme/acme] Add a meta flag to indicate when GET requests for certificates are allowed (#462)

2018-10-10 Thread Jacob Hoffman-Andrews
Pushed some more changes. On 10/10/2018 02:06 PM, Jacob Hoffman-Andrews wrote: Updated to include Orders and Authorizations in the example as you requested. https://github.com/ietf-wg-acme/acme/pull/463/files On 10/09/2018 04:49 PM, Jacob Hoffman-Andrews wrote: I'll revise this to include ex

Re: [Acme] FW: [ietf-wg-acme/acme] Add a meta flag to indicate when GET requests for certificates are allowed (#462)

2018-10-10 Thread Richard Barnes
Chairs: It looks like there's consensus among the author team to close out this discussoin by merging #459, #460, and #463. Is that all right with you? On Wed, Oct 10, 2018 at 5:23 PM Jacob Hoffman-Andrews wrote: > Pushed some more changes. > > On 10/10/2018 02:06 PM, Jacob Hoffman-Andrews wrot

Re: [Acme] lack of nonce for external account binding (was Re: Benjamin Kaduk's Discuss on draft-ietf-acme-acme-14:) (with DISCUSS and COMMENT)

2018-10-10 Thread Richard Barnes
On Wed, Oct 3, 2018 at 11:54 AM Benjamin Kaduk wrote: > On Sat, Sep 15, 2018 at 08:51:55PM -0500, Benjamin Kaduk wrote: > > On Fri, Sep 14, 2018 at 03:59:07PM -0400, Daniel McCarney wrote: > > > > My co-author Daniel McCarney is working on the COMMENT comments. > > > > > > > IMPORTANT: I don't th

Re: [Acme] lack of nonce for external account binding (was Re: Benjamin Kaduk's Discuss on draft-ietf-acme-acme-14:) (with DISCUSS and COMMENT)

2018-10-10 Thread Benjamin Kaduk
On Wed, Oct 10, 2018 at 06:42:33PM -0400, Richard Barnes wrote: > On Wed, Oct 3, 2018 at 11:54 AM Benjamin Kaduk wrote: > > > On Sat, Sep 15, 2018 at 08:51:55PM -0500, Benjamin Kaduk wrote: > > > On Fri, Sep 14, 2018 at 03:59:07PM -0400, Daniel McCarney wrote: > > > > > My co-author Daniel McCarn

Re: [Acme] lack of nonce for external account binding (was Re: Benjamin Kaduk's Discuss on draft-ietf-acme-acme-14:) (with DISCUSS and COMMENT)

2018-10-10 Thread Richard Barnes
On Wed, Oct 10, 2018 at 6:47 PM Benjamin Kaduk wrote: > On Wed, Oct 10, 2018 at 06:42:33PM -0400, Richard Barnes wrote: > > On Wed, Oct 3, 2018 at 11:54 AM Benjamin Kaduk wrote: > > > > > On Sat, Sep 15, 2018 at 08:51:55PM -0500, Benjamin Kaduk wrote: > > > > On Fri, Sep 14, 2018 at 03:59:07PM -