Re: [dd] DS pinning for secondaries

Philip Homburg <pch-dd@u-1.phicoh.com> Wed, 28 February 2024 15:30 UTC

Return-Path: <pch-b538D2F77@u-1.phicoh.com>
X-Original-To: dd@ietfa.amsl.com
Delivered-To: dd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 90694C14F5FC for <dd@ietfa.amsl.com>; Wed, 28 Feb 2024 07:30:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GFHfP6SqDksy for <dd@ietfa.amsl.com>; Wed, 28 Feb 2024 07:30:40 -0800 (PST)
Received: from stereo.hq.phicoh.net (stereo.hq.phicoh.net [IPv6:2a10:3781:2413:1:2a0:c9ff:fe9f:17a9]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2143FC14EB17 for <dd@ietf.org>; Wed, 28 Feb 2024 07:30:38 -0800 (PST)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (TLS version=TLSv1.2 cipher=ECDHE-RSA-CHACHA20-POLY1305) (Smail #158) id m1rfLtC-0000KxC; Wed, 28 Feb 2024 16:30:34 +0100
Message-Id: <m1rfLtC-0000KxC@stereo.hq.phicoh.net>
To: dd@ietf.org
Cc: Petr Špaček <pspacek@isc.org>
From: Philip Homburg <pch-dd@u-1.phicoh.com>
Sender: pch-b538D2F77@u-1.phicoh.com
References: <9ffd0747-054d-4f84-a7f9-43265974b07d@isc.org> <45b4a54d-8d85-caf0-e1df-74f61c81b1a6@nohats.ca> <4b17b7ec-ccc3-48d1-b4df-54bba4202e5d@isc.org>
In-reply-to: Your message of "Wed, 28 Feb 2024 09:54:29 +0100 ." <4b17b7ec-ccc3-48d1-b4df-54bba4202e5d@isc.org>
Date: Wed, 28 Feb 2024 16:30:33 +0100
Archived-At: <https://mailarchive.ietf.org/arch/msg/dd/ShXypP8IFr9XmwGIEkaDX595Gzo>
Subject: Re: [dd] DS pinning for secondaries
X-BeenThere: dd@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: DNS Delegation <dd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dd>, <mailto:dd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dd/>
List-Post: <mailto:dd@ietf.org>
List-Help: <mailto:dd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dd>, <mailto:dd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Feb 2024 15:30:41 -0000

> > Why not a regular DS at the parent to lock this? And only use DELEG
> > for NS/glue.
> 
> Makes sense to me - if we think through various compatibility
> scenarios with legacy vs. DELEG-aware clients.

If the DELEG in alias mode would get its own parameters, then one of the
parameters could be 'use DS at the parent'. That would allow validators to
just use the DS record without confusion.