Re: Interpreting DNSSEC was Re: [dnsext] flip-flopping secure and unsecure DNAME/CNAME

Edward Lewis <Ed.Lewis@neustar.biz> Mon, 13 October 2008 18:01 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 761463A68E3; Mon, 13 Oct 2008 11:01:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.567
X-Spam-Level:
X-Spam-Status: No, score=-0.567 tagged_above=-999 required=5 tests=[AWL=-0.072, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T7d8vlfQRp2p; Mon, 13 Oct 2008 11:01:47 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 510E53A6820; Mon, 13 Oct 2008 11:01:47 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KpReY-0008wR-Ij for namedroppers-data@psg.com; Mon, 13 Oct 2008 17:56:22 +0000
Received: from [66.92.146.20] (helo=stora.ogud.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <Ed.Lewis@neustar.biz>) id 1KpReH-0008uK-EL for namedroppers@ops.ietf.org; Mon, 13 Oct 2008 17:56:11 +0000
Received: from [10.31.201.38] (mail.md.ogud.com [10.20.30.6]) by stora.ogud.com (8.14.2/8.14.2) with ESMTP id m9DHthC7007588; Mon, 13 Oct 2008 13:55:43 -0400 (EDT) (envelope-from Ed.Lewis@neustar.biz)
Mime-Version: 1.0
Message-Id: <a06240805c5193b226886@[10.31.201.38]>
In-Reply-To: <STNTEXCH12OdHa24ABv00004495@stntexch12.cis.neustar.com>
References: <Your message of "Mon, 22 Sep 2008 15:12:44 -0400." <E1KhqqB-000CE1-QD@psg.com> <200809230016.m8N0GS9E069236@drugs.dv.isc.org> <E1Khwdp-000J3V-QJ@psg.com> <a06240804c4ffc42abc16@[10.122.105.108]> <E1KicTm-000ANO-PO@psg.com> <a06240800c50fd3decd5b@[192.168.1.101]> <48F2DE42.1060209@links.org> <E1KpLkt-000HQ3-Is@psg.com> <48F33C34.3010901@nlnetlabs.nl> <D3AA46B662F334B8639E08CF@Ximines.local> <48F35170.30900@links.org> <4B27E2458EBA97669B259355@Ximines.local> <a06240800c5190d86422c@[192.168.1.101]> <STNTEXCH12OdHa24ABv00004495@stntexch12.cis.neustar.com>
Date: Mon, 13 Oct 2008 13:55:27 -0400
To: Michael StJohns <mstjohns@comcast.net>
From: Edward Lewis <Ed.Lewis@neustar.biz>
Subject: Re: Interpreting DNSSEC was Re: [dnsext] flip-flopping secure and unsecure DNAME/CNAME
Cc: Edward Lewis <Ed.Lewis@neustar.biz>, Alex Bligh <alex@alex.org.uk>, Ben Laurie <ben@links.org>, Wouter Wijngaards <wouter@NLnetLabs.nl>, namedroppers@ops.ietf.org
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Scanned-By: MIMEDefang 2.64 on 10.20.30.4
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

At 12:38 -0400 10/13/08, Michael StJohns wrote:
>At 10:57 AM 10/13/2008, Edward Lewis wrote:
>>DNSSEC only says "this answer looks good" or "doesn't look good." 
>>Trying to figure out whether the answer's disposition is 
>>temporary/permanent, correct/incorrect, trustworthy/not takes more 
>>than just the DNS data and more than just the query at hand.
>
>
>DNSSEC says the answer looks good - SECURE
>or doesn't look good - BOGUS
>or DNSSEC told me I shouldn't care about DNSSEC past some point - UNSECURE
>or I have no information which would let me determine what DNSSEC 
>thinks about the data - UNKNOWN
>
>"Trustworthy" begs a definition here for what "looks good" means in 
>relationship to "trusting" DNS data.

This is the kind of debate that'll never end, judging from past 
incarnations of this thread.  To me, an answer that is under a trust 
anchor and below a null DS set is "looks good" as far as DNSSEC is 
concerned.  I.e., to me, UNSECURE == SECURE == UNKNOWN, when I 
consider the "bottom line" of the query-response.  I guess I have a 
Machiavellian (ends justify the means, i.e., all that matters are the 
ends) streak in me.
-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis                                                +1-571-434-5468
NeuStar

Never confuse activity with progress.  Activity pays more.

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>