[dd] DS-pinning and Alias mode limitation
Roy Arends <roy@dnss.ec> Sun, 11 February 2024 00:34 UTC
Return-Path: <roy@dnss.ec>
X-Original-To: dd@ietfa.amsl.com
Delivered-To: dd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A65DC14F5E6 for <dd@ietfa.amsl.com>; Sat, 10 Feb 2024 16:34:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=dnss.ec
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iwVgaAYrhSdR for <dd@ietfa.amsl.com>; Sat, 10 Feb 2024 16:33:59 -0800 (PST)
Received: from mail-ot1-x329.google.com (mail-ot1-x329.google.com [IPv6:2607:f8b0:4864:20::329]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D76BC14E515 for <dd@ietf.org>; Sat, 10 Feb 2024 16:33:57 -0800 (PST)
Received: by mail-ot1-x329.google.com with SMTP id 46e09a7af769-6e2b6461aeeso1270115a34.0 for <dd@ietf.org>; Sat, 10 Feb 2024 16:33:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dnss.ec; s=google; t=1707611637; x=1708216437; darn=ietf.org; h=to:message-id:subject:date:mime-version:content-transfer-encoding :from:from:to:cc:subject:date:message-id:reply-to; bh=Uf48d4vVTiJK3QO2PpvOFIUoc2QctfWztZZAYGEEAyQ=; b=NYDd3j3Md6HPnmPMf1wVY5nA1kwHHggbS/DIQZuDKzmja+/V2dgQV6LFoXUkMNothA tRLGLQodYkaolAMq8/0NGi2wvvndYYY/SmJn/tNCr3OHqxNtf+TIu4YOWT9IUnh0oszw HDSoFfvSMQKFw0wXUPy+4EbSlncudxTUyLIZI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707611637; x=1708216437; h=to:message-id:subject:date:mime-version:content-transfer-encoding :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=Uf48d4vVTiJK3QO2PpvOFIUoc2QctfWztZZAYGEEAyQ=; b=DyQ4qJ6hyLGoM3Clx6gwDxdJHZtBmENXgx8rRqhmHN9Wszgtq5adoMtnhwO4ZBG+kQ YwjSLlG/ST+VsJaXqCeEL8jBp55/JpKyElmzzv+Y3fVHiMexwbqo9eRtTWfqV3QPez8U jOtcKdI8HCTko+WhgLdyjcHxRSwWDLcXImiRv8C/HIIVa8W4sXjicN7tbqeCoPB1k2kU Egtls/Lq2Vr62/O3A72aTqjLM1AgnqnHGfdUtrsoi9WSkX/DfH6iFPclY390LImvuEGi qytR+dAGe25amvWE5j7WjA2DoXlv2CMkHSi/c6zeXY+qE/vQ7ge5jTJDdcxpZTIUKwJu 3Kxg==
X-Gm-Message-State: AOJu0YyCCotjN/BEBICBBMhwiT8DbHuDBrL4bvVX1pN3gd14tJN7HH8M MF/p8GbkdwsTq9S/K07IRmzw7YkDSS0m1VxcbxaoCceyPrwYWJIYoVk24SiZjgCsMCxiKD4+ENL ZsTw=
X-Google-Smtp-Source: AGHT+IF3t1IZpyLik+WToBALAUlbwZcow7kN5gd+IcJxlEFa9pz2DG4LORhoYsEgIkzHGAgpVqyL1A==
X-Received: by 2002:a05:6830:1bc9:b0:6d9:ec35:a234 with SMTP id v9-20020a0568301bc900b006d9ec35a234mr3157646ota.10.1707611636804; Sat, 10 Feb 2024 16:33:56 -0800 (PST)
X-Forwarded-Encrypted: i=1; AJvYcCWzp0d7pGp+jAYvxMLDXfzuETBFrl7FqqnuNtvjXdWtQ1OYJohWEJGbQg2oZWHrHFlHwl7VBls4o8RtgQ==
Received: from smtpclient.apple ([78.111.198.85]) by smtp.gmail.com with ESMTPSA id o72-20020a62cd4b000000b006ddcadb1e2csm2995705pfg.29.2024.02.10.16.33.55 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 10 Feb 2024 16:33:56 -0800 (PST)
From: Roy Arends <roy@dnss.ec>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.400.31\))
Date: Sun, 11 Feb 2024 00:33:43 +0000
Message-Id: <1DE0D512-7962-4943-B21D-196A441A3BC8@dnss.ec>
To: dd@ietf.org
X-Mailer: Apple Mail (2.3774.400.31)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dd/xaR2GBWr4fNlLFvH6WHSsFvBKY8>
Subject: [dd] DS-pinning and Alias mode limitation
X-BeenThere: dd@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: DNS Delegation <dd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dd>, <mailto:dd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dd/>
List-Post: <mailto:dd@ietf.org>
List-Help: <mailto:dd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dd>, <mailto:dd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 Feb 2024 00:34:05 -0000
I understand that DS pinning involves DS material that references a DNSKEY, uniquely tied to a {zone-name-server} pair.
It's important to note that the digest in a DS record is generated based on the DNSKEY owner name and DNSKEY RDATA.
DS pinning won't function properly in DELEG Alias Mode when the target serves multiple zones. For instance:
foo.example DELEG 0 generic.example.net
bar.example DELEG 0 generic.example.net
generic.example.net SVCB 1 …. ds=AABBCC ns=ns1example.net
In this scenario, there must either be a unique 1:1 pairing between the DELEG owner and target name (instead of N:1), or the requirement for the digest to contain the DNSKEY owner name must be eliminated for aliased pinned DS to work effectively.
Warmly,
Roy
- [dd] DS-pinning and Alias mode limitation Roy Arends
- Re: [dd] DS-pinning and Alias mode limitation Ben Schwartz
- Re: [dd] DS-pinning and Alias mode limitation Roy Arends
- Re: [dd] [Ext] DS-pinning and Alias mode limitati… Edward Lewis