Re: [dane] WGLC: DANE-SRV (Abstract and introduction feedback)

"Michael J. Sheldon" <msheldon@godaddy.com> Tue, 02 December 2014 22:33 UTC

Return-Path: <msheldon@godaddy.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 285031A1AF2 for <dane@ietfa.amsl.com>; Tue, 2 Dec 2014 14:33:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tm9-tvB0i5hs for <dane@ietfa.amsl.com>; Tue, 2 Dec 2014 14:33:24 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0758.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::758]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1CF7A1A1ADC for <dane@ietf.org>; Tue, 2 Dec 2014 14:33:24 -0800 (PST)
Received: from CY1PR0201MB0826.namprd02.prod.outlook.com (25.160.141.27) by CY1PR0201MB0826.namprd02.prod.outlook.com (25.160.141.27) with Microsoft SMTP Server (TLS) id 15.1.26.15; Tue, 2 Dec 2014 22:33:00 +0000
Received: from CY1PR0201MB0826.namprd02.prod.outlook.com ([25.160.141.27]) by CY1PR0201MB0826.namprd02.prod.outlook.com ([25.160.141.27]) with mapi id 15.01.0026.003; Tue, 2 Dec 2014 22:33:00 +0000
From: "Michael J. Sheldon" <msheldon@godaddy.com>
To: "dane@ietf.org" <dane@ietf.org>
Thread-Topic: [dane] WGLC: DANE-SRV (Abstract and introduction feedback)
Thread-Index: AQHQDRcir8VKa4YA+Ey10TpiT5Xhfpx84n60
Date: Tue, 02 Dec 2014 22:33:00 +0000
Message-ID: <1417559579751.81339@godaddy.com>
References: <20141201013357.GF285@mournblade.imrryr.org> <547BC8F9.1070605@andyet.net>,<20141201033009.GI285@mournblade.imrryr.org>
In-Reply-To: <20141201033009.GI285@mournblade.imrryr.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [72.223.77.6]
x-microsoft-antispam: BCL:0;PCL:0;RULEID:;SRVR:CY1PR0201MB0826;
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:; SRVR:CY1PR0201MB0826;
x-forefront-prvs: 0413C9F1ED
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(189002)(199003)(24454002)(51704005)(2351001)(107886001)(107046002)(68736005)(120916001)(21056001)(50986999)(54356999)(76176999)(4396001)(99396003)(105586002)(106116001)(40100003)(97736003)(20776003)(2501002)(66066001)(106356001)(64706001)(122556002)(450100001)(36756003)(77156002)(31966008)(62966003)(117636001)(101416001)(46102003)(2656002)(99286002)(87936001)(95666004)(19580395003)(92726001)(92566001)(110136001)(86362001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY1PR0201MB0826; H:CY1PR0201MB0826.namprd02.prod.outlook.com; FPR:; SPF:None; MLV:sfv; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: godaddy.com
Archived-At: http://mailarchive.ietf.org/arch/msg/dane/878HQcodyJrUbV3Huc-ctAAStwc
Subject: Re: [dane] WGLC: DANE-SRV (Abstract and introduction feedback)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Dec 2014 22:33:26 -0000

>On Sun, Nov 30, 2014 at 06:48:41PM -0700, Peter Saint-Andre - &yet wrote:
>General comment:
>
>    The draft frequently talks about "hostnames", where what is
>    really meant is a transport endpoint (port, transport protocol,
>    host).  With PKIX-EE or DANE-EE certificate usages, TLSA records
>    are more precise than the Web PKI and can associate different,
>    non-interchangeable key material with distinct services on a
>    single host.  So in many places I will be suggesting replacing
>    statements about "hostnames" with statements about "transport
>    endpoints".

>From a DNS point of view, this may be more confusing. DNS does not distinguish between different types of record owners. If you put it in there, it just became a domain name, which most people will refer to as a host name if it is not at the apex.

I will agree that from a DANE point of view, it is a transport endpoint. But from a pure DNS point of view, it is domain/host name, regardless of intent.

Not saying it's not a good distinction, it is, but I would tread lightly where you are talking about the actual TLSA record owner name.

Michael Sheldon
Dev-DNS Services
GoDaddy.com