Re: [DNSOP] [dns-operations] dnsop-any-notimp violates the DNS standards

Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp> Fri, 13 March 2015 16:03 UTC

Return-Path: <mohta@necom830.hpcl.titech.ac.jp>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0397B1A87A6 for <dnsop@ietfa.amsl.com>; Fri, 13 Mar 2015 09:03:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.498
X-Spam-Level: **
X-Spam-Status: No, score=2.498 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r03QPR3RfE6S for <dnsop@ietfa.amsl.com>; Fri, 13 Mar 2015 09:02:59 -0700 (PDT)
Received: from necom830.hpcl.titech.ac.jp (necom830.hpcl.titech.ac.jp [131.112.32.132]) by ietfa.amsl.com (Postfix) with SMTP id 157EF1A8AA6 for <dnsop@ietf.org>; Fri, 13 Mar 2015 09:02:52 -0700 (PDT)
Received: (qmail 18341 invoked from network); 13 Mar 2015 15:48:38 -0000
Received: from necom830.hpcl.titech.ac.jp (HELO ?127.0.0.1?) (131.112.32.132) by necom830.hpcl.titech.ac.jp with SMTP; 13 Mar 2015 15:48:38 -0000
Message-ID: <55030A28.8050707@necom830.hpcl.titech.ac.jp>
Date: Sat, 14 Mar 2015 01:02:48 +0900
From: Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: dnsop@ietf.org
References: <20150312125913.20188.qmail@cr.yp.to> <3D558422-D5DA-4434-BDED-E752BA353358@flame.org> <m27fulry37.wl%randy@psg.com>
In-Reply-To: <m27fulry37.wl%randy@psg.com>
Content-Type: text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/bt4yA7fxIwvaZGqPMWUIfxXEndY>
Subject: Re: [DNSOP] [dns-operations] dnsop-any-notimp violates the DNS standards
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Mar 2015 16:03:05 -0000

Randy Bush wrote:

>> What problem are we specifically trying to solve here again?
> 
> not break things that are working

Yup. Qmail or any software produced by djb adhering the existing
standards of the Internet.


Paul Vixie wrote:

> everything is broken, depending on whom you ask.

The worst broken thing in DNS is DNSSEC.

As a person who have been saying DNSSEC has been broken from the
beginning, after which, as certain amount of operational experiences,
it was revised several times along ways to fix some (but not all),
IMHO, broken parts, may I volunteer to fix not ANT but DNSSEC entirely?

Before replying me, remember that you have been saying, from the
beginning, that DNSSEC was OK if it were properly implemented.

I may temporally ignore fundamental operational impossibility of
DNSSEC and try to make it least harmful w.r.t. DDOS.

						Masataka Ohta