Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec-algo-signal-04.txt
Miek Gieben <miek@miek.nl> Fri, 09 March 2012 09:07 UTC
Return-Path: <miekg@atoom.net>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
with ESMTP id D21CB21F85AE for <dnsext@ietfa.amsl.com>;
Fri, 9 Mar 2012 01:07:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.073
X-Spam-Level:
X-Spam-Status: No, score=-2.073 tagged_above=-999 required=5 tests=[AWL=0.527,
BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FDBf9uX6ZcyU for
<dnsext@ietfa.amsl.com>; Fri, 9 Mar 2012 01:07:52 -0800 (PST)
Received: from elektron.atoom.net (cl-201.ede-01.nl.sixxs.net
[IPv6:2001:7b8:2ff:c8::2]) by ietfa.amsl.com (Postfix) with ESMTP id
4127E21F85F1 for <dnsext@ietf.org>; Fri, 9 Mar 2012 01:07:51 -0800 (PST)
Received: by elektron.atoom.net (Postfix, from userid 1000) id 93A3540004;
Fri, 9 Mar 2012 10:07:48 +0100 (CET)
Date: Fri, 9 Mar 2012 10:07:48 +0100
From: Miek Gieben <miek@miek.nl>
To: dnsext@ietf.org
Message-ID: <20120309090748.GA20102@miek.nl>
Mail-Followup-To: dnsext@ietf.org
References: <20120306162935.4172.91398.idtracker@ietfa.amsl.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="DocE+STaALJfprDB"
Content-Disposition: inline
In-Reply-To: <20120306162935.4172.91398.idtracker@ietfa.amsl.com>
User-Agent: Vim/Mutt/Linux
X-Home: http://www.miek.nl
Subject: Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec-algo-signal-04.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>,
<mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>,
<mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Mar 2012 09:07:52 -0000
[ Quoting <internet-drafts@ietf.org> at 08:29 on Mar 6 in "[dnsext] I-D Action:..." ] > > A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the DNS Extensions Working Group of the IETF. > > Title : Signaling Cryptographic Algorithm Understanding in DNSSEC > Author(s) : Steve Crocker > Scott Rose > Filename : draft-ietf-dnsext-dnssec-algo-signal-04.txt > Pages : 8 > Date : 2012-03-06 > > The DNS Security Extensions (DNSSEC) were developed to provide origin > authentication and integrity protection for DNS data by using digital > signatures. These digital signatures can be generated using > different algorithms. This draft sets out to specify a way for > validating end-system resolvers to signal to a server which > cryptographic algorithms and hash algorithms they support. I read a comment in the draft that this option list can get very long, which indeed is true. How about the following scheme: A resolver indicates the highest algorithm number it understands and thus *also* all *previous* algorithms. This way the whole option can be shortened to 4 bytes: 0: OPTION-CODE 1: DAU byte value 2: DHU byte value 3: N3U byte value And maybe this option can be renamed to Crypto Understood. A drawback is that a number of current specified features aren't available with this scheme. Regards, Miek Gieben
- [dnsext] I-D Action: draft-ietf-dnsext-dnssec-alg… internet-drafts
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Marc Lampo
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Warren Kumari
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Patrik Fältström
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Scott Rose
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Scott Rose
- [dnsext] FW: I-D Action: draft-ietf-dnsext-dnssec… Marc Lampo
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Mark Andrews
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] FW: I-D Action: draft-ietf-dnsext-dn… Scott Rose