Re: [Add] draft-ietf-add-resolver-info-09

Ben Schwartz <bemasc@meta.com> Wed, 06 March 2024 16:44 UTC

Return-Path: <prvs=87959743c9=bemasc@meta.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1F8EC14F5F6 for <add@ietfa.amsl.com>; Wed, 6 Mar 2024 08:44:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=meta.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2B2iZkoudyOE for <add@ietfa.amsl.com>; Wed, 6 Mar 2024 08:44:47 -0800 (PST)
Received: from mx0a-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A03DCC14F5F5 for <add@ietf.org>; Wed, 6 Mar 2024 08:44:47 -0800 (PST)
Received: from pps.filterd (m0001303.ppops.net [127.0.0.1]) by m0001303.ppops.net (8.17.1.19/8.17.1.19) with ESMTP id 426FrT0p006551; Wed, 6 Mar 2024 08:44:45 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=s2048-2021-q4; bh=fjQLlwEiSQCp+A/OpKUn7bjCZMGb0rWD8VJpFjBGkqI=; b=U8K8mVwx8doJGjpSIsuHErFBgZMWrLR1+bUA6e06vJ+vEBB7rmFrV/mzK6cXIEIg2baK BiGdxtwAP9oJW6f15CBPU9pJ/2oYzlo248/9VdewDPFLxD/BFCS9TAB6jL+MSkfSRp6l zXyrLzBhof1xCQoJZKSuljXE7ztoyPUXmnx0LMrAgZsNobAUMEQKOPNXLzvUvVuz6Ujg w4r/RgoTKWvh5Rx4nO1Pz/C6p1nHdCsBZ2FYYIYn4ihadoAPLMW+aB9bV/jJgr5jPfGc LxgWUYn1cwjNXLycstLApO/GZMTJ82ZT38amG9ryhjk0i/GpeZfn3ratw8EXHvalZmaO ew==
Received: from nam12-dm6-obe.outbound.protection.outlook.com (mail-dm6nam12lp2169.outbound.protection.outlook.com [104.47.59.169]) by m0001303.ppops.net (PPS) with ESMTPS id 3wpuh7rbwg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 06 Mar 2024 08:44:45 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cOV7RdHEURvBT8fpcnPg8dwej70XiuZKa+FkZcaysy7eJeWhnwdYi6fCHtxJgtcPzYnBitjIqEhCi7ZHevUu62LU2aNJdhzTr4uZBJdTmLxRVB5PBB9c/Y5ax1hyXL/fmVAF2BQdghGRhu3Gr2gora+wts+TtLWT87H/BXxxlNw7uJSpt28ZEY/fjODqE/JZbqT7U20L+gUXSRJJwPvFHsjKHqPwoVTAO/evCQWBhSPsuy4+G9OW9XZy9iH5+6Pw+7eVE83a0FxdUy74zu9sJx2WB1IRvQ0qjg27geFIDjsyVQO+yrbXMlBmQ1jIPczF56zmzqnoFnfzhIoVDmngVg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kyY0dePRJBQfr91C05IJbidiMKiy1Tib79nIfSTyUJ4=; b=SuYa+Gnurhz7BQZq46CJnotMqFIjnyBQkPJ+CWYgyeudP/VNbt3+ur52xLX7Yr/g1LfeCObZ/gfdk1GK/f1I5M2bssIXjjzvic/gu8g5r0jx1BOuo7Zcg0tE5LTaB4KvlD4DD5TiouTEcB+Mw35m5qs8ZEjYHMcIiY83/XQ5QNYM3eJEMmmt00PJx7jA9Cwigt/acvgrChCpYitb0kJcFEVZuI3IXvY6yCAX/eOPu26ldHaPc0ME1Ov18T8RzX6Sg3mTCWgHOeziZd6Y4Pi+W5SNjBWPxh+ufnErOq3RcdPh0v0eIxwQxcLA2GGAF2ovX3SLeWL83uhodE6gU1K5TA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=meta.com; dmarc=pass action=none header.from=meta.com; dkim=pass header.d=meta.com; arc=none
Received: from SA1PR15MB4370.namprd15.prod.outlook.com (2603:10b6:806:191::8) by BLAPR15MB3859.namprd15.prod.outlook.com (2603:10b6:208:275::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7362.24; Wed, 6 Mar 2024 16:44:43 +0000
Received: from SA1PR15MB4370.namprd15.prod.outlook.com ([fe80::50:3dc9:3ace:9a3a]) by SA1PR15MB4370.namprd15.prod.outlook.com ([fe80::50:3dc9:3ace:9a3a%5]) with mapi id 15.20.7362.019; Wed, 6 Mar 2024 16:44:43 +0000
From: Ben Schwartz <bemasc@meta.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, Mark Andrews <marka@isc.org>
CC: tirumal reddy <kondtir@gmail.com>, "add@ietf.org" <add@ietf.org>
Thread-Topic: [Add] draft-ietf-add-resolver-info-09
Thread-Index: AQHaX6ZqtEjuUSvbvE2KC+5fRqzto7ETVWqAgABRx4CAAFlBAIAAccMAgBU/DAOAABA4gIAABNsAgAAkqYCAARZvAIAACT9S
Date: Wed, 06 Mar 2024 16:44:43 +0000
Message-ID: <SA1PR15MB43706C1080EC336BA65B3E03B3212@SA1PR15MB4370.namprd15.prod.outlook.com>
References: <SA1PR15MB4370C02BF2458CFD28D06265B3222@SA1PR15MB4370.namprd15.prod.outlook.com> <077D27F8-03C1-4ECC-97BE-579ABF22563F@isc.org> <0F58ECB8-29EC-4592-98A8-6019356C72B6@meta.com> <E845DAED-6428-4EA1-855C-861411F56A2D@isc.org> <DU2PR02MB10160CA2E3C2EF77CC4FC1F6388212@DU2PR02MB10160.eurprd02.prod.outlook.com>
In-Reply-To: <DU2PR02MB10160CA2E3C2EF77CC4FC1F6388212@DU2PR02MB10160.eurprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=fa344451-623b-4973-926d-58903daf702b; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-03-06T16:05:12Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=0; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA1PR15MB4370:EE_|BLAPR15MB3859:EE_
x-ms-office365-filtering-correlation-id: 7207e147-430d-4512-5004-08dc3dfcb96e
x-fb-source: Internal
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: glGU6ou8dvXK8s640GZfb27yzMnjFCTavlp92g5OCYaL2AM3CiahnksnIdsJHYWD2fiUVsFlemXbcA3iR29TcNIxMYksrZl25psT7rUHuAj3AW+Ui3iJWkxTSi/6DW5aGsb5TEze9j7fo/CbAwCBSV3i3VojJtjNS84wmAgIWioWiAdsuGu6981Nwg8xB1AAkeQGldWPfdodvxiGWkU/VT46gfoymKge8UQJB/b8kM2lUJFRPtO6WThZNGcV/8qh9bT0MzpFTlZN41GsrxWLwZH0CuzOdi86fRLYHbYaUikWrUZWjx5F5nmqd2CYurFyISfVNZ1wTuFoN7zHNoUhsNbA21f4CdVxEWobiyM6vHkFphntq5NMaClQt8ZY+trsXTSSfabMlK90zKgoxdbLxW2bhu2jEnHkjONadC1fgEbCSHfaMYHqhSA/nO4PLFKDV/AqCLCDbp46u0pV3Wx2lS+3JP4ornlCJzVjnza1Q8lgMc73tMhdJISks+LGvWvNYG+Pcd7nEieQkHgPUIzQxYnFkuO1X/vCrkLXWSvrUvRTEOEs6NFJi1f71mddaJKOV+qFGUdCvUcbk/pL7JrkwDciwEDWQo/bpkg3yl+gjL+9/npgXQn0wn9cFZBJZCgfrDAA6CUwFeJ0OgNGTOEI8Qy0C7SQ6t6P6FVD5YZacko=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR15MB4370.namprd15.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: BlKrOaVEV0tcJ2xvOSqfi0740rEn0DcS727uDRSNR1eJo8JDW3pMvdgbE7QZ+annHwd8NKJXWF5I5nKEXvI8pFUiPHIM9qthStgaIA/L5rFJ+7uE9tQvAXuJFG2Z9doLLoF239hqIwFz5s7n8zf38MVgd41OMr7xNjOj17UPtgCAukwyCOZoALZuLMRGeTlyVT10nqAaiBSsW+Bp0z3crPNNUyE4v3mRNZm2t5FMJi2lRWrSSqJkwW7eVB8DbQaJRVhwXIlpZsOlKr5xHDj+OcMWK8s3rNkToW+JfIaomQr8RF9XPOxwRmRAHqBNn14eeQMsCO70BAEMU5hkbTsEc7a5l7zzeXpyNYJNw1RpAVW4KdzthydmKmsdHdOjisn3Urj+pSWok4gf0VJkdi7dH3/2g6NKBSzZsluCiSDXU9myFVWlT7hJCtiPs0wTcrz9TmUZfjI/C1f9Njg7svN07XnzpNSZ5uP4xUamySSezJe3rfq3VXNYylyX8bkoOitGSLQjC0YkCu+vnt9TMsgKPOT3CXeJwvtsOYKnNOEERCne74YZaXthJF0yP4BFD7watMzBA2OeSYEzrxR/H4bRkxbNIYpS3RzCDd0vR8bcbgX4tbCbjadKjhurAZ6j9Wwq3zaQHFeOGgRHuVO93A8nJzp1UzxR8WetJJrnnV6v9kPmzD1xjxAJ4vQbteyDQfxaRVGtEr1642Ezp0e5fbOAix1QTEezuTpCaeRwIbxb6F0lnAz09Bq56aD1YKtYv544fMfKraLn+LB4J47El+WSU5vFAIcW22ndA9L1s9RJpmlGHS0I6m5fbq8lSamAQcN8Gqygw/oHG2kjXAdwYe86IKBcu88Du3dE5PK0t0V1ukVh8DfC7x2qKPnVBTB6lqiPBlAsYp3v15c5pCJKqAdpLrX8HtPZ5oBt0XoE9TPLOUFlDr7HGm0Wepkkzo15tOvNtmeF4mtdbJ5UuTv+qDXtwRSRgn3VTzBotWRMdjom5zs0qnV6a7zyKq3MtAg6OWxFp6dQRJhpI6f6vHGbsbUcsohsilFnleTstTLAhoDjKATv4xfyNGvayetc5xISmuDqkrGHGq2+Ds9Z17+C1TOs66/8lXs45TYGQGXCTXoc7RMrVIlHUqllrD9gG/9kJ1EYHV8tB80CR/fqwz3lOVrPkSX/XhvaslpmfsfGEqkY/sV42qeDXt2UveJLbBU42qB+tKG9kQEi7cNxtcc+p2hwxI45wRCGQWH659TmrVXrlyMQTEju95N3yTJxV2leOPO5aPS/McauNuAKc+K7b3PKkenS2xPSfA1rTl2A/RTD3bYOzDaMmpeGbVXJ0Lf4ziYhMVR2MekqTa9yMpqaxOCpfsvGUPqOOzY0jeK27lOsvbmMQ+n8FmfBuOrCTkhFdnK9yHLQmXAuwvMnXGhRiScHCfzNt4WAhosg6DHTnmAWUWJym+ST5zTdcwFJpDtrBmXaGOFkh9nHFkTPXvFPmNOnUXML/y3E5+El0ewvDmCQYOvKfa35eZs2HVuY3i4JWYIFK2OwV1bNxIJUtwM/9kketjfeOc6gMfjurpYGJu5TS3OG7YoPKY00pPJHvrub5V8/Y/m6IwibGTIS7k/sRj1LSg==
Content-Type: multipart/alternative; boundary="_000_SA1PR15MB43706C1080EC336BA65B3E03B3212SA1PR15MB4370namp_"
X-OriginatorOrg: meta.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR15MB4370.namprd15.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7207e147-430d-4512-5004-08dc3dfcb96e
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Mar 2024 16:44:43.1680 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 8ae927fe-1255-47a7-a2af-5f3a069daaa2
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: AVamk18j3g07NxZN5C4MhygHWCThVtKA9PuQGv5KpFN1CzjYlfxfYUj6EKUy1ySW
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLAPR15MB3859
X-Proofpoint-ORIG-GUID: Xg6A7Yk8HWsz1Xb1Y4TEkUa-IulgsAsM
X-Proofpoint-GUID: Xg6A7Yk8HWsz1Xb1Y4TEkUa-IulgsAsM
X-Proofpoint-UnRewURL: 8 URL's were un-rewritten
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-03-06_10,2024-03-05_01,2023-05-22_02
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/5vXEweEosBWTEzjaAAqSHbtv0r8>
Subject: Re: [Add] draft-ietf-add-resolver-info-09
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Mar 2024 16:44:51 -0000

I think the instruction to issue the request with RD=0 was helpful, even though it was not sufficient and may not be necessary.  It seems illogical for the client to say "recursion desired" when a recursively resolved answer would be rejected.

--Ben
________________________________
From: mohamed.boucadair@orange.com <mohamed.boucadair@orange.com>
Sent: Wednesday, March 6, 2024 11:07 AM
To: Mark Andrews <marka@isc.org>; Ben Schwartz <bemasc@meta.com>
Cc: tirumal reddy <kondtir@gmail.com>; add@ietf.org <add@ietf.org>
Subject: RE: [Add] draft-ietf-add-resolver-info-09

!-------------------------------------------------------------------|
  This Message Is From an External Sender

|-------------------------------------------------------------------!

Hi Mark, Ben,

Please let us know if the changes at [1] fix this issue.

Thank you

Cheers,
Tiru & Med

[1] https://author-tools.ietf.org/api/iddiff?doc_1=draft-ietf-add-resolver-info&url_2=https://boucadair.github.io/add-resolver-information/draft-ietf-add-resolver-info.txt

> -----Message d'origine-----
> De : Add <add-bounces@ietf.org> De la part de Mark Andrews
> Envoyé : mercredi 6 mars 2024 00:31
> À : Ben Schwartz <bemasc@meta.com>
> Cc : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>;
> tirumal reddy <kondtir@gmail.com>; add@ietf.org
> Objet : Re: [Add] draft-ietf-add-resolver-info-09
>
>
>
> > On 6 Mar 2024, at 08:19, Ben Schwartz <bemasc@meta.com> wrote:
> >
> >
> >> On Mar 5, 2024, at 4:02 PM, Mark Andrews <marka@isc.org> wrote:
> >
> >> Stop using +short and look at all of the response including whether
> aa is set or not in the flags.
> >
> > It is not set.  My complaint is that draft-ietf-add-resolver-info-11
> doesn’t mention the AA bit at all.  It needs to instruct the client to
> inspect this bit, and reject the response if AA=0.
>
> Yep.
>
> > draft-11 still contains text about the record appearing in the
> Authority section, which could be equivalent to this, but that text is
> in a different section and its normative effect on the client is
> unclear.  I don’t object to that text, but I don’t think it’s
> sufficient as written, and I don’t think it’s necessary if the client
> is required to enforce AA=1.
>
> That whole paragraph should be removed.
>
> > —Ben
> >
> >>
> >> --
> >> Mark Andrews
> >>
> >>> On 6 Mar 2024, at 07:09, Ben Schwartz <bemasc@meta.com> wrote:
> >>>
> >>>  Mark's suggestion is correct, but I don't think draft-11 captures
> >>> it correctly.  The draft-11 text only says
> >>>
> >>>    The DNS client MUST set the Recursion
> >>>    Desired (RD) bit of the query to 0 to ensure that the response
> is provided by the resolver.
> >>>    If the resolver does not support RESINFO, it will return an
> authoritative name error.
> >>>
> >>> This is factually incorrect, as can be observed by sending an RD=0
> query to an ordinary recursive resolver:
> >>>
> >>> % dig +short +norecurse
> >>>
> https://eur03.safelinks.protection.outlook.com/?url=http://www
> >>>
> .google.com%2F&data=05%7C02%7Cmohamed.boucadair%40orange.com%7C886ca
> >>>
> c3b3900432f540308dc3d6c5562%7C90c7a20af34b40bfbc48b9253b6f5d20%7C0%7
> >>>
> C0%7C638452782716903830%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAi
> >>>
> LCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=ml
> >>> L4GilpuruZ0Bz%2FR3YEY07eNE%2FRXs1%2B4EHa6eAIOL8%3D&reserved=0
> >>> @1.1.1.1
> >>> 142.251.167.104
> >>> 142.251.167.147
> >>> 142.251.167.99
> >>> 142.251.167.106
> >>> 142.251.167.103
> >>> 142.251.167.105
> >>>
> >>> Mark's suggestion is that the client verify that the response has
> AA=1.  That check ensures that the result was not populated insecurely
> over the network, but the draft doesn't mention it.
> >>>
> >>> --Ben
____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.