Re: [dane] Start of WGLC for draft-ietf-dane-registry-acronym

Viktor Dukhovni <viktor1dane@dukhovni.org> Thu, 03 October 2013 21:11 UTC

Return-Path: <viktor1dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55EBA21F8EDF for <dane@ietfa.amsl.com>; Thu, 3 Oct 2013 14:11:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FCqgVfPvl74k for <dane@ietfa.amsl.com>; Thu, 3 Oct 2013 14:10:43 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [208.77.212.107]) by ietfa.amsl.com (Postfix) with ESMTP id B828621E8092 for <dane@ietf.org>; Thu, 3 Oct 2013 13:58:29 -0700 (PDT)
Received: by mournblade.imrryr.org (Postfix, from userid 1034) id 0A65F2AB0D1; Thu, 3 Oct 2013 20:58:29 +0000 (UTC)
Date: Thu, 03 Oct 2013 20:58:29 +0000
From: Viktor Dukhovni <viktor1dane@dukhovni.org>
To: dane@ietf.org
Message-ID: <20131003205829.GP483@mournblade.imrryr.org>
References: <20130919201216.14866.61161.idtracker@ietfa.amsl.com> <EACEEB05-2023-4F76-A6FE-A9B2FDC0AA59@kumari.net> <0lpprmumeb.fsf@wjh.hardakers.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <0lpprmumeb.fsf@wjh.hardakers.net>
User-Agent: Mutt/1.5.21 (2010-09-15)
Subject: Re: [dane] Start of WGLC for draft-ietf-dane-registry-acronym
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: dane@ietf.org
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Oct 2013 21:11:02 -0000

On Thu, Oct 03, 2013 at 01:31:24PM -0700, Wes Hardaker wrote:

> 5) security considerations
> 
>    There is definitely something to consider if someone publishes both
>    name records along with number records, and the client only parses
>    number records.  What happens with this:
> 
>    _666._tcp.first.example.   TLSA 3       1    1        {blob}
>    _666._tcp.first.example.   TLSA DANE-TA SPKI SHA2-256 {blob}
> 
>    Something needs to be said for that case; what would an existing
>    implementation do?  drop both? take one?  Either way, it should be
>    discussed/mentioned.

I'm confused I thought these were just user friendly names...  The
wire format of the DNS TLSA record is surely unchanged.  In which
case it is impossible to publish the second form, it is just an
input format in documentation (and perhaps source form zone files
in supporting DNS servers), but not a wire format.

-- 
	Viktor.