Re: [dbound] New version of draft-deccio-dbound-organizational-domain-policy

Casey Deccio <casey@deccio.net> Mon, 04 April 2016 17:57 UTC

Return-Path: <casey@deccio.net>
X-Original-To: dbound@ietfa.amsl.com
Delivered-To: dbound@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1DF8E12D162 for <dbound@ietfa.amsl.com>; Mon, 4 Apr 2016 10:57:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=deccio.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V9gmb8V6nlrA for <dbound@ietfa.amsl.com>; Mon, 4 Apr 2016 10:57:04 -0700 (PDT)
Received: from mail-lf0-x236.google.com (mail-lf0-x236.google.com [IPv6:2a00:1450:4010:c07::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CD9CB12D1AA for <dbound@ietf.org>; Mon, 4 Apr 2016 10:57:03 -0700 (PDT)
Received: by mail-lf0-x236.google.com with SMTP id p188so155456129lfd.0 for <dbound@ietf.org>; Mon, 04 Apr 2016 10:57:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=deccio.net; s=google; h=mime-version:in-reply-to:references:date:message-id:subject:from:to; bh=HiwoByUYePRPIXxf0AS7yzSB+31ldwdaHoJ4ezUjgrs=; b=Om7ktTS9utp+K/Tmn9JocgwXZc9NqwgIAL/Uw/HfbtjyzcttIr3cUv32vHouV1AAJX j8vPW4tArlz3eylNoNye/Ns+QAbIvKLXoEL5jb2zvedf8v/E5UIJGD2NTzDWDnVVISEs YkwaRnNuAE83hfqiUQYonYtQrOm3htPN7BJWE=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to; bh=HiwoByUYePRPIXxf0AS7yzSB+31ldwdaHoJ4ezUjgrs=; b=Ifm9TX4MiPfFljxMJh0mkNAK4pAINyYgyaGuv9Hdsex70WfgKJYTVo3vYhMq7l1HI1 Lke1PAFg/0xAy/dgZM8twfmIzCg4MekgKUW0wM4msG5NoT/i3ffMu9V8jobYoRvMFErL +NRUwvUzWyIE1Lyhfp3P03U31hm4Pt3nAhkCRrcEc9r8cMA0XwMpVFoxQckwKXsOZGwj vuKLMruNxtW2KmFM4szru/SfGDJhKTLcv7xlhbRm8vC5VGIHafEYquaHMLQiQXKlR2Dv uZURlH2DuGwjtBr0JSz8st/RYIptjEbIwROt3C/EIxM/eNAFjb2W+XYzDb0douvzIqL4 zW/w==
X-Gm-Message-State: AD7BkJLcylJOVImwt1aD+8Fgg/EYBSnRkN/gBYM0swJtQ9elgBPZN0cWpc1tS8IGikm2ryPKEJ1ElpTvgR7J+w==
MIME-Version: 1.0
X-Received: by 10.194.205.138 with SMTP id lg10mr19519727wjc.153.1459792621855; Mon, 04 Apr 2016 10:57:01 -0700 (PDT)
Received: by 10.194.138.169 with HTTP; Mon, 4 Apr 2016 10:57:01 -0700 (PDT)
In-Reply-To: <CAEKtLiTwQadBMvvX1PS_Rr6kYafPQn8wHCb94Uek-SdVRptKrQ@mail.gmail.com>
References: <CAEKtLiTwQadBMvvX1PS_Rr6kYafPQn8wHCb94Uek-SdVRptKrQ@mail.gmail.com>
Date: Mon, 04 Apr 2016 13:57:01 -0400
Message-ID: <CAEKtLiQLytavJtZeLoBWbLoEPMptFLwcWw-Y0dRjWGY2NOc1AQ@mail.gmail.com>
From: Casey Deccio <casey@deccio.net>
To: "dbound@ietf.org" <dbound@ietf.org>
Content-Type: multipart/alternative; boundary="047d7bb70a1eac067d052fac7468"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dbound/uQUSxegrdcHDX3XP0ckk4FR0udM>
Subject: Re: [dbound] New version of draft-deccio-dbound-organizational-domain-policy
X-BeenThere: dbound@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: DNS tree bounds <dbound.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dbound>, <mailto:dbound-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dbound/>
List-Post: <mailto:dbound@ietf.org>
List-Help: <mailto:dbound-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dbound>, <mailto:dbound-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Apr 2016 17:57:06 -0000

On Mon, Apr 4, 2016 at 8:39 AM, Casey Deccio <casey@deccio.net> wrote:

>
> Key Differences:
> ----
> Note that the biggest change between version 01 and 02 is the elimination
> of the "_odup" TLD.  Instead, policies are published from the TLD and below.
>

One other difference that I neglected to mention is the addition of the
"+fetch" directive.  This directive makes it possible to advertise that a
set of policy statements for a given organizational domain may be
downloaded for local reference.  This also enables creation of a PSL from
ODUP statements in the DNS.  This is demonstrated in the odup2psl.py
script, which is included in:

https://github.com/verisign/odup

Note that another script, psl2odup.py, is used to do just the opposite:
generate ODUP from PSL.

Regards,
Casey