Re: [dane] Brian Haberman's No Objection on draft-ietf-dane-srv-13: (with COMMENT)

Peter Saint-Andre - &yet <peter@andyet.net> Mon, 20 April 2015 16:07 UTC

Return-Path: <peter@andyet.net>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D5FCF1B2F50 for <dane@ietfa.amsl.com>; Mon, 20 Apr 2015 09:07:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A1AlMTDtyzVS for <dane@ietfa.amsl.com>; Mon, 20 Apr 2015 09:07:45 -0700 (PDT)
Received: from mail-ig0-f170.google.com (mail-ig0-f170.google.com [209.85.213.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1EBA1B2F51 for <dane@ietf.org>; Mon, 20 Apr 2015 09:07:45 -0700 (PDT)
Received: by igblo3 with SMTP id lo3so63235611igb.1 for <dane@ietf.org>; Mon, 20 Apr 2015 09:07:44 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type :content-transfer-encoding; bh=YshwVPLHFeZ1+pN4GzLFawjJxV6GjD0Dw+yegdi2mQs=; b=GAyUWJTpj4ZARnDBQeisFRf03fdzh69p5S0m8V8+R9joABAvcQBedILB52ZLbk4yYl x85krTddkbt0OepRzpY7EE6aLbwYEl4mZ4fyXaIYtkdaG6a3uftQxw0BNB1j+gmyg4n8 qSodAPsEWpkuiOiEI4WvEyH0Wfoe5/Ud9Ah4W50RbA0s62axyECAr0qMhQl5FmtlyPCp TQTbWK39tOzJeYyfdj7K92p+XxlhnYm6qmQQB2Vx5rGFl+IpI7ivjC9bmDkDRPxlc8rv Uv2dIgSkCgk2w96QlRPcPQCxIWlmY8JiNUFr7m44EUj+NfVDI/Hh77ZUfCP3kutMPVL/ ol0g==
X-Gm-Message-State: ALoCoQnqqOfR170kpZ+OF9sRZV6tmQKSQKzFOXAZC3/BlzMvpDloGrO5yaaeOz9nTEgZ2vSOB7gu
X-Received: by 10.42.38.208 with SMTP id d16mr19548837ice.45.1429546064450; Mon, 20 Apr 2015 09:07:44 -0700 (PDT)
Received: from aither.local (c-73-34-202-214.hsd1.co.comcast.net. [73.34.202.214]) by mx.google.com with ESMTPSA id o80sm11646781ioi.3.2015.04.20.09.07.43 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 20 Apr 2015 09:07:43 -0700 (PDT)
Message-ID: <5535244D.8040909@andyet.net>
Date: Mon, 20 Apr 2015 10:07:41 -0600
From: Peter Saint-Andre - &yet <peter@andyet.net>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: dane@ietf.org
References: <20150420145051.12174.16885.idtracker@ietfa.amsl.com> <20150420153616.GE25758@mournblade.imrryr.org> <5535202E.1030804@innovationslab.net> <20150420155825.GH25758@mournblade.imrryr.org>
In-Reply-To: <20150420155825.GH25758@mournblade.imrryr.org>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/8BtiGH3UDzeCcV1AaXN1itQkMaI>
Cc: iesg@ietf.org
Subject: Re: [dane] Brian Haberman's No Objection on draft-ietf-dane-srv-13: (with COMMENT)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Apr 2015 16:07:47 -0000

On 4/20/15 9:58 AM, Viktor Dukhovni wrote:
> On Mon, Apr 20, 2015 at 11:50:06AM -0400, Brian Haberman wrote:
>
>>> Some clients only have IPv4 connectivity, and will only make A
>>> queries.  Other clients only have IPv6 connectivity and will only
>>> make AAAA queries, some will perform both.
>>
>> Agreed on the actions of the client based on availability of v4 and v6
>> service.  The wording in the first two bullets could be made clearer.
>> Would this substitution capture the intent?
>>
>> OLD:
>>     o  If either the A or AAAA RRSets are "secure", the client ...
>>
>>     o  If both RRsets are "insecure", the client ...
>>
>> NEW:
>>     o  If a returned RRSet is "secure", the client ...
>>
>>     o  If no returned RRsets are "secure", the client ...
>
> I think so, with luck the authors and others will also agree.

That seems fine to me.

And I'm not sure how we got that section pointer wrong in §3.1, will fix.

Peter

-- 
Peter Saint-Andre
https://andyet.com/