Re: [dns-privacy] [Fwd: [EXT] New Version Notification for draft-vandijk-dprive-ds-dot-signal-and-pin-01.txt]

"Wessels, Duane" <dwessels@verisign.com> Tue, 14 July 2020 22:13 UTC

Return-Path: <dwessels@verisign.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2131E3A087B for <dns-privacy@ietfa.amsl.com>; Tue, 14 Jul 2020 15:13:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I-MhSbpvrm2h for <dns-privacy@ietfa.amsl.com>; Tue, 14 Jul 2020 15:13:56 -0700 (PDT)
Received: from mail6.verisign.com (mail6.verisign.com [69.58.187.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1F7703A0879 for <dns-privacy@ietf.org>; Tue, 14 Jul 2020 15:13:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=13727; q=dns/txt; s=VRSN; t=1594764836; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=0ANWFPZKVnb3ZikQ2AQW/oI1dQh4ApsqvorbfnSlA6Y=; b=PyvtrPJX//NwuK6mQ83X8BdiWMhT6Ni+UL8TXsdnxio/VqDA2NZi40MK EZL6v5bIU6kxHzzaGIN6vnFlRNpq6RovGaMzX1jw5HI8Q2kGnvs9hIzDe f4zVq4yzaGvRGKqmE35GmK6E/6eFHvyv3fjYzlk8N/0hLFQvm1mKcjwCF A5QMPEmoRjwdUzinIZ3fCJH2NO6PuQe4NxpDFkdSE/dQKuRrH9rnTrzuk k3Sjfp/40yljMcB/hyX1HI0EidzYvoowwlHAIlHEgbCyDWaMwaAP0nYl0 oKn3kXfmqU+7/CTTByRBICrTl0y2GRBpC8UVMirfoRC88NIt01NEDPOSM Q==;
IronPort-SDR: i3TgAXLEXjTjd7rbqlDlD1F//0P8rmfeb6DhOY3YYeUgiCIAUfHG0DR/wZ+AGdi+IPDB7BBTzz ahZlhm/dlBTrKLe+fmHsJFmcVK2fYKZawCJqQxQMh0i8m0xieKOFk+rEfAzNaKsEB4ZY+WwXKI mnVrMbjEmDiAtWhJ+ml5YMJJT4b2qouJFbJTAa1Yh+2L2B4HVYqLGs0Fqq+eR30W9Sdv8xfIdD lOc3WcWbwLfTIZsWMck5HMieOhC8ky0l5gT256iEEht0NyEbuZrNhxqCIIUUpS1SArFSbi9soa e18=
X-IronPort-AV: E=Sophos; i="5.75,353,1589256000"; d="p7s'?scan'208"; a="2170757"
IronPort-PHdr: 9a23:OIai9RM8Jk28IqprraMl6mtUPXoX/o7sNwtQ0KIMzox0K/zzosbcNUDSrc9gkEXOFd2Cra4d1ayN6uu4ByQp2tWoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6nK94iQPFRrhKAF7Ovr6GpLIj8Swyuu+54Dfbx9HiTagYL5+Nhu7oRjeusUKgIZpN7o8xAbOrnZUYepd2HlmJUiUnxby58ew+IBs/iFNsP8/9MBOTLv3cb0gQbNXEDopPWY15Nb2tRbYVguA+mEcUmQNnRVWBQXO8Qz3UY3wsiv+sep9xTWaMMjrRr06RTiu86FmQwLzhSwZKzA27n3Yis1ojKJavh2hoQB/w5XJa42RLfZyY7/Rcc8fSWdHQ81fVTFOApmkYoUPEeQPIPpYoYf+qVsArxSwAgisC//gxTJTiX/6wag63v4hEQ3awgAtGc8FvnTOrNXyMacfSe65w6nWwjXYdPNZxzP96JPQfhs8r/+MQKh/cczPxkUhCgjIiUifqIL7MDOOzeQCrWyb7/F7WOKxlWEnsQBxoiOuxscjjInFnJ4aylfB9Shgxos+ONK3RlJhb9G+DJtQqz+VN5FwQs46TWxlpDs3x7MJtJKmfSUHxpspywLRZvCZfYaG4h3uWfiRLzp3mX9rd7yyigiu/EWuy+DxV9e43UpWoiRFk9TBuXYA3AHd5MiAT/ty5Eah2TCX2g/P6+FEOlw7la3BJ5E9xb4wk4IfsUXdES/qlkX6lqiWdl8r+uSw5OTnY6nmpp+BN4BvkA3xLqMumsm5DO8lMQYOR3CW9fmg2LH54EH0QrtHgucrnqTZvp3WP8sWq6qhDwNIzoov8QuzAjW63NgCgHUKI1FIdAiag4XqPVzFPer2Au2lg1u2lTdm3/XGPrr8DZrTNnXDi7Lhfapl605b1Qoz0chT55JKBbEFJ/L+QlL8usDAABMkMwO62+npB9Rh2o8AQ26PHLOWMKTIsV+Q/O4gOfSDaJULuDbnMPgl4eTigmM+mV8YZaWp3J0XZ26kHvl+PkmVfWDgjsoDHGoEpAYyUeznhVOYXTNcY3u+R6c86Ss6CIKiA4fDXIetgLmZ0SimEJxZeHtGCkuSHnfsbIWJQOkMZzyIIs9giTwEVLehS4k72R6ysw/6zqJrLvDI9S0AqZLjyN916vXLlR4s6Tx7Ed6d33uTT25umGMEXSI53KF9oUx+0VqDya94gvJGGtxJ+vxJVBw6OYTAwOx9DtD4QhjBccuRSFa6XtWmBik8Qc83w98Vekp9A8+ijhHd3yWwH7AUl6eGBJ0q/aLA0Xj9PcF9y2zJ1Ppps15zesZTOHfumKd5vyTSBY2Bx12Ui6uwM7oV2mjB9WWA5XKJo0xCXAhrF67CWCZMSFHRqIGz2U7ZVLKqEvBvHhZIz8PIYv9GddDyllhCX9/9Nc7feGO+nSG7AhPeleDEV5bjZ2hIhHaVM0MDiQ1GuC/ebQU=
X-IPAS-Result: A2EyAACELQ5f/zGZrQpgGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQFAgUqDGSuBCAqVQ4Nzli2BaQQHAQEBAQEBAQEBAwQBGxQEAQEChEoCggklOBMCAwEBCwEBAQUBAQEBAQYDAQEBAoZEDII3KQFwgQMBAQEBAQEBAQEBAQEBAQEBAQEBFgJDVRIBAR0BAQEBAgFuCQIFCwIBCBEDAQIBIwsCMB0IAgQOBQ6DGAGCXBGpQzV0gTSKYhCBOAGBUoNmETaHDIFCPoERJxyCTT6CXAIDgR0+GAkegwuCLQSZM5pugQQDB4JdhDGCV4FLhnCKGhUJgnaBHogbkwWsR0+DUgIEAgQFAhWBaoF7cBUaISoBgj4JNRIXAg2OKhcUiE6FQnQCNQIGCAEBAwmPLoERAQE
Received: from BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) by BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1913.5; Tue, 14 Jul 2020 18:13:53 -0400
Received: from BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d]) by BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d%6]) with mapi id 15.01.1913.005; Tue, 14 Jul 2020 18:13:53 -0400
From: "Wessels, Duane" <dwessels@verisign.com>
To: Peter van Dijk <peter.van.dijk@powerdns.com>
CC: "dns-privacy@ietf.org" <dns-privacy@ietf.org>
Thread-Topic: [EXTERNAL] [dns-privacy] [Fwd: [EXT] New Version Notification for draft-vandijk-dprive-ds-dot-signal-and-pin-01.txt]
Thread-Index: AQHWWTlpH/XSr8rmuEChXkY6NJt7lqkH6LaA
Date: Tue, 14 Jul 2020 22:13:53 +0000
Message-ID: <E7A268F1-7DC8-46A7-8F39-4E205ED2B7AF@verisign.com>
References: <159463003055.14524.9899091401351118756@ietfa.amsl.com> <8be56d973ff1757fb6395b5b2abdf90fe73e02ec.camel@powerdns.com>
In-Reply-To: <8be56d973ff1757fb6395b5b2abdf90fe73e02ec.camel@powerdns.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3445.104.14)
x-originating-ip: [10.170.148.18]
Content-Type: multipart/signed; boundary="Apple-Mail=_FC172EB1-23CF-49E8-973D-83459721A451"; protocol="application/pkcs7-signature"; micalg="sha-256"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/AU6cOG9kamKndDBuEA-MaDU1szg>
Subject: Re: [dns-privacy] [Fwd: [EXT] New Version Notification for draft-vandijk-dprive-ds-dot-signal-and-pin-01.txt]
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2020 22:13:58 -0000

Hi Peter,

While I remain neutral as to whether or not ds-dot-signal-and-pin is a good idea overall, you can count me as one that thinks flags=257 is a bad idea.  I don't think anything in 403[345] say that flags can be interpreted differently depending on the algorithm or on the value of the Zone Signing column.  

The document uses the phrase "DNSKEY algorithm" very often but I think you really mean DNS Security Algorithm (or just algorithm).  For example, 

   more than one DS record with DNSKEY algorithm TBD

is better as just

   more than one DS record with algorithm TBD

DW



> On Jul 13, 2020, at 10:16 AM, Peter van Dijk <peter.van.dijk@powerdns.com> wrote:
> 
> Hello,
> 
> please find below revision -01 of our proposal for enabling DoT from
> resolver to authoritative.
> 
> New in this revision:
> 
> * a lot of clarifying text without changing the underlying protocol
> 
> * the DNSKEY flags field is now specified to be 257 instead of 0. We
> know that this goes against the explicit wishes of some of those who
> commented on -00, but we argue in the document that because our algo
> TBD will have 'Zone Signing=N' in the IANA DNSKEY algo registry, the
> flags do not mean 'ZONE' and 'SEP'. The value 257, meanwhile, is
> believed to go down with registries much easier.
> 
> * we added a 'Design considerations' section that explains how this
> protocol came to be, and why we did not go the TLSA route. You can
> click through to it directly via 
> https://secure-web.cisco.com/1547Nd7TUhQCx--6BXQ2V7Fe6OsN72FFOIoB6X79e4tCF2s3ZpnvtGzBeZ35b3VZublqmT2QWLNxBE-H4UuDLJnh3itcQpBUb6pvqqG91nLQIfZ6JfJk-0nXyuSFLvD9anUSvqQjNwa7usrKjP9E-9zoOj8_4YAfpeb5yetnz5zz6RafsBHm8OG4n_AdFMl89cKxMT7P4a9IwkKlAutHh5GjZM1CDogcPKO6FLJ6QgiE6IYhafhiHX3qtYL2Z_veABcJwEj5EI9_m4VdsUVb3gfMkZPh0RCerOSzBeJ00Eqk/https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin-01%23section-9
> 
> Furthermore, we have tried to do a review of this protocol against the
> requirements of the DPRIVE phase 2 document.  You can find this review
> (which might be updated outside of revisions of this draft or the phase
> 2 draft) via 
> https://secure-web.cisco.com/1A25tPS76irHgdA_csUZGhdQB7R1rIbrOg1TW6d07W694zX71PQw1tAqCq4W-Yy-5i2h9ujLnVA3gCvVmF1AQkb04kNBNapCJrd3AIAma9QbnSKK_h65nrwXbi62Ylrxwjlpuook_wYJpyVmdsE3gvLF0fupzhFzjV6ufEXcxtz5FLv5H7STGDYGhD6pmlkXs4s4Ne03z_NV7Y5lT1r-RooYejeWscUws5c7DkEBTF3L_pTOYu_NRH1SA1SAGABwE_uaOR1fq1Gj1BIsI4yBwQw/https%3A%2F%2Fgithub.com%2FPowerDNS%2Fparent-signals-dot%2Ftree%2Fmaster%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin%2Fyardsticks
> 
> We'll be presenting the draft at the IETF108 dprive session.
> 
> Kind regards,
> Manu, Robin & Peter
> 
> -------- Forwarded Message --------
> From: internet-drafts@ietf.org
> To: Robin Geuze <robing@transip.nl>, Peter van Dijk <
> peter.van.dijk@powerdns.com>, Emmanuel Bretelle <chantra@fb.com>
> Subject: [EXT] New Version Notification for draft-vandijk-dprive-ds-
> dot-signal-and-pin-01.txt
> Date: Mon, 13 Jul 2020 01:47:10 -0700
> 
> A new version of I-D, draft-vandijk-dprive-ds-dot-signal-and-pin-01.txt
> has been successfully submitted by Peter van Dijk and posted to the
> IETF repository.
> 
> Name:		draft-vandijk-dprive-ds-dot-signal-and-pin
> Revision:	01
> Title:		Signalling Authoritative DoT support in DS records, with key pinning
> Document date:	2020-07-13
> Group:		Individual Submission
> Pages:		14
> URL:            https://secure-web.cisco.com/1DsK2MVevadXT3GdniFfbtgOI396AfHCVKwwaV2-vAgI7z9Dd0q8NsHHtR5-Yvr8yKxH_PsQUrwCjagVNwgqtbfFNBSLwggZdZvleOtsjhVoeUmEteo8hKdrw77dn5UNKta2PuxqVGaZXwtZvs-4DQaP4xGc7jPUy3_Rl9Vtv_nHj5nYYy0pJo9XXQX5rtZ6xX1eZb29S5H51GbUukAdUD8vkiLEdfM49HeyTI1UBukpyYtaF3GsqY0KDHV7wEEhE_7DCsOfkqajfAZNXedeMR1XYjo04sw1CHYXBLmmkRBg/https%3A%2F%2Fwww.ietf.org%2Finternet-drafts%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin-01.txt
> Status:         https://secure-web.cisco.com/1lJ9HOKB3lcr0FYkKcTfMImWTawCKcgf31T_3MoPvTc9gMCdIA_ajbmqsJ4rIMbt424s-ph7cAAqmJvl7MVr3ebT547Uz7sP9gA7HUHq-Jx2RjBRUFvf_sL64ZKYdT15vGJxq7MpweDRIPtOdTKsKNv-7NgTI_zAHJaHlrnwE3rB6ex-YZqGLp-UKZEns5N_nBOxy5aA_nGhijjVJn4ekYBrw2ZJ2AYXki5uFYvUSkauqxifxZ84Bd__Ltjygp285gciA0joIcrkb8IFNsx7kzw/https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin%2F
> Htmlized:       https://secure-web.cisco.com/1cFirxV4x2U2WbrlVzODCuwJ9pifdlZzpYB3Xq4t0hBEgNekIlAEC-Qthjgvz5EUvGHxGpLRuuJ0NL0AmSAMwJnYwkyUtIROhvZOTM45Ze3dx738rFrs2e_k-8D7glvhyQAD7w2Mjr1A3F3l2fjbaOmBsljJ1LJytf57_udaJAPOpJmsI6Ip1FR1kSyJo4jGWKohWGdfySdd04FQyHE_RzAkfHiIej1GUpf0sGSG1N6W1AGS0JqaP3n_z9B-8bpjygQQkaOVIplt3dkiTwRMmifie6zY8oHApoQ6Zt6MnNUs/https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin-01
> Htmlized:       https://secure-web.cisco.com/1qb7nne1k8JWZ9GEh-uAWdl-u6Mhi6O8_8Pzl8QXe9Dzj2fke3Yp3Lu3zG4n-UuoqspLdcytKXzf4Oir91tyZjbWWaD-cZsFk3_rIp96C0u0ZHmuKvRpjk_-4bnUomgVl6Qdcq2SIHDRccnLkyPGFTetYLTLPWDtU006kgMiJew7_CgzsFQaZkG2JhrlctuexOkV9g16YgQt1-ZrC5Jyflx8kTXzTP265IEMzVMHLh_zQfudmDvNJs1EN3Vny1D04m6_Np0nUD5OdugJIIAXobQ/https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-vandijk-dprive-ds-dot-signal-and-pin
> Diff:           https://secure-web.cisco.com/1GFziADh6Ps303cC7no5h066e5QUtC3w3B9PhlbQogmsIsTEpjHoxBjjV5jI_xo-E7Ouq6_sRJQ3DFzxTfv2gu_gJhENy9HaMRJlTv4ZdjbRml8xqknYL8ikBI4v9cPljlio4g31kh0mowVjkt8OQL1SYALLNcfTUESDQJPW6sDn8xm6yLlq4lN2FZBRrBCWYdy6CfzELZj69Ct4DPKqc37F7qIY3ryJXputr1-Dxq-ZRW-FFbM5q5uNI53j2do3TkuIN-x1Drh_97kESsgmkj9v1JiEoETl1rZsdF_NkL18/https%3A%2F%2Fwww.ietf.org%2Frfcdiff%3Furl2%3Ddraft-vandijk-dprive-ds-dot-signal-and-pin-01
> 
> Abstract:
>   This document specifies a way to signal the usage of DoT, and the
>   pinned keys for that DoT usage, in authoritative servers.  This
>   signal lives on the parent side of delegations, in DS records.  To
>   ensure easy deployment, the signal is defined in terms of (C)DNSKEY.
> 
> 
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> The IETF Secretariat
> 
> 
> 
> 
> _______________________________________________
> dns-privacy mailing list
> dns-privacy@ietf.org
> https://secure-web.cisco.com/1elCUqFgvC0UgZ2a2VlikLcYh0tCisMp6IB7ahB5AEcXCueMnDkz3rd9BglCkM6x8gnDfs6wyU7CA3FvMFsH2Zx6VxDHYQTdLdov0FYXMKmVyBJbJa8_880H0UV7hUzEfPlk7tyOzvGdyvTD5NmPUXuoCS5kfdkP9JSVfROSk01NwBVn0YAtZTelH75b9bc3HzLhyW3weRLkX7gHuJk-0XBo1b1ZV0gzjjAyd8DA1-j4GfRtdbhABtGh16GSzG_m_gf3ocdjA8ncwIr9kB45GsQVQ_eS73Hss3wAI_M-Emgw/https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fdns-privacy
>