Re: [apps-discuss] Comments on draft-sullivan-domain-policy-authority

Andrew Sullivan <ajs@anvilwalrusden.com> Fri, 19 July 2013 19:45 UTC

Return-Path: <ajs@anvilwalrusden.com>
X-Original-To: apps-discuss@ietfa.amsl.com
Delivered-To: apps-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4104C11E8193 for <apps-discuss@ietfa.amsl.com>; Fri, 19 Jul 2013 12:45:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.79
X-Spam-Level:
X-Spam-Status: No, score=-0.79 tagged_above=-999 required=5 tests=[AWL=0.050, BAYES_00=-2.599, HELO_MISMATCH_INFO=1.448, HOST_MISMATCH_NET=0.311]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3PbY7rOnNTMH for <apps-discuss@ietfa.amsl.com>; Fri, 19 Jul 2013 12:45:26 -0700 (PDT)
Received: from mx1.yitter.info (ow5p.x.rootbsd.net [208.79.81.114]) by ietfa.amsl.com (Postfix) with ESMTP id 8345D11E8113 for <apps-discuss@ietf.org>; Fri, 19 Jul 2013 12:45:26 -0700 (PDT)
Received: from mx1.yitter.info (nat-07-mht.dyndns.com [216.146.45.246]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.yitter.info (Postfix) with ESMTPSA id 073348A031 for <apps-discuss@ietf.org>; Fri, 19 Jul 2013 19:45:24 +0000 (UTC)
Date: Fri, 19 Jul 2013 15:45:23 -0400
From: Andrew Sullivan <ajs@anvilwalrusden.com>
To: apps-discuss@ietf.org
Message-ID: <20130719194523.GG40049@mx1.yitter.info>
References: <CAL0qLwbu-vUjD2Wg2FnzUrnWeXzNV8Va-BBp6XgAWm-gQNGaQQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAL0qLwbu-vUjD2Wg2FnzUrnWeXzNV8Va-BBp6XgAWm-gQNGaQQ@mail.gmail.com>
User-Agent: Mutt/1.5.21 (2010-09-15)
Subject: Re: [apps-discuss] Comments on draft-sullivan-domain-policy-authority
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Jul 2013 19:45:36 -0000

Hi,

On Fri, Jul 19, 2013 at 11:48:29AM -0700, Murray S. Kucherawy wrote:

> One thing it doesn't mention is that it will require a SOPA record to be
> created at every extant node in the DNS tree for a domain that wishes to
> make use of it.  Unless I've misread something, the document does indicate
> that a node can indicate it is in the same policy realm as all of its
> descendants, but it also says this relationship needs to be confirmed to be
> believed.  That means all of the descendant nodes also have to have SOPA
> records pointing back to that parent node.  If I'm understanding that
> correctly, the document should probably call this out as a constraint as
> well.

In the inclusion case, yes.  

This is an unhappy consequence of my worry about certain security
implications of the relationship, but thinking about it after John
Levine made the same argument to me off-list I'm wondering whether we
just need to invent a new relation class that asserts "mail policy
apex", which can assert mail control over everything beneath it.  The
problem with this is the same security problem we have with just doing
inclusion without a corresponding inclusion record at the target.
However, as several people have argued, a parent has the ultimate
authority to redirect the name, so maybe the best way to handle this
is just contracts.

> APPSAWG/APPAREA agenda, if the authors of both drafts would be interested
> in talking to that audience about their ideas in Berlin.

I'm prepared to discuss this if others think it would be useful.

Best, 

A

-- 
Andrew Sullivan
ajs@anvilwalrusden.com