Re: forgery-resilience recommendations section

JINMEI Tatuya / 神明達哉 <jinmei@isl.rdc.toshiba.co.jp> Wed, 22 August 2007 14:32 UTC

Return-path: <owner-namedroppers@ops.ietf.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1INrGE-0000nB-LO; Wed, 22 Aug 2007 10:32:42 -0400
Received: from psg.com ([147.28.0.62]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1INrGE-0004uI-8l; Wed, 22 Aug 2007 10:32:42 -0400
Received: from majordom by psg.com with local (Exim 4.67 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1INr7T-0003HI-QC for namedroppers-data@psg.com; Wed, 22 Aug 2007 14:23:39 +0000
X-Spam-Checker-Version: SpamAssassin 3.2.1 (2007-05-02) on psg.com
X-Spam-Level:
X-Spam-Status: No, score=-0.6 required=5.0 tests=AWL,BAYES_00,HEADER_SPAM, RDNS_NONE autolearn=no version=3.2.1
Received: from [66.92.146.160] (helo=ogud.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.67 (FreeBSD)) (envelope-from <namedroppers@mail.ogud.com>) id 1INr7Q-0003Gs-O1 for namedroppers@ops.ietf.org; Wed, 22 Aug 2007 14:23:38 +0000
Received: from mail.ogud.com (localhost [127.0.0.1]) by ogud.com (8.13.1/8.13.1) with ESMTP id l7MENOTq023237 for <namedroppers@ops.ietf.org>; Wed, 22 Aug 2007 10:23:24 -0400 (EDT) (envelope-from namedroppers@mail.ogud.com)
Received: (from namedroppers@localhost) by mail.ogud.com (8.13.1/8.13.1/Submit) id l7MENO8h023236 for namedroppers@ops.ietf.org; Wed, 22 Aug 2007 10:23:24 -0400 (EDT) (envelope-from namedroppers)
Received: from [202.249.10.124] (helo=shuttle.wide.toshiba.co.jp) by psg.com with esmtp (Exim 4.67 (FreeBSD)) (envelope-from <jinmei@isl.rdc.toshiba.co.jp>) id 1INM4x-00063t-TU for namedroppers@ops.ietf.org; Tue, 21 Aug 2007 05:15:01 +0000
Received: from jmb.local (unknown [IPv6:2001:200:1b1:1010:217:f2ff:fe26:34a0]) by shuttle.wide.toshiba.co.jp (Postfix) with ESMTP id EC7927301E; Tue, 21 Aug 2007 14:14:55 +0900 (JST)
Date: Tue, 21 Aug 2007 14:14:48 +0900
Message-ID: <m1veb9xyd3.wl%jinmei@isl.rdc.toshiba.co.jp>
From: JINMEI Tatuya / 神明達哉 <jinmei@isl.rdc.toshiba.co.jp>
To: Edward Lewis <Ed.Lewis@neustar.biz>
Cc: Mark Andrews <Mark_Andrews@isc.org>, Ólafur Guðmu ndsson /DNSEXT chair <ogud@ogud.com>, namedroppers@ops.ietf.org
Subject: Re: forgery-resilience recommendations section
In-Reply-To: <a06240800c2eaca90ea3d@[192.168.1.100]>
References: <200708170136.l7H1aoXq068041@drugs.dv.isc.org> <a06240800c2eaca90ea3d@[192.168.1.100]>
User-Agent: Wanderlust/2.14.0 (Africa) Emacs/22.0 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka")
Content-Type: text/plain; charset="US-ASCII"
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-id: DNSEXT discussion <namedroppers.ops.ietf.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52e1467c2184c31006318542db5614d5

[ Moderators note: Post was moderated, either because it was posted by
   a non-subscriber, or because it was over 20K.  
   With the massive amount of spam, it is easy to miss and therefore 
   delete relevant posts by non-subscribers. 
   Please fix your subscription addresses. ]

At Fri, 17 Aug 2007 00:06:24 -0400,
Edward Lewis <Ed.Lewis@neustar.biz> wrote:

> So, let me propose that we document that there is a need for more 
> bits of unpredictability based on the calculations already in the 
> draft.  An open question to me is to specify a number, I mean, others 
> will have a far better idea than I so I won't suggest a number and 
> will go along with any consensus.  As far as how the "extended 
> unpredictability" is implemented is probably left best to the code 
> writers with maybe some hints in the document - but let's avoid 
> ratholing on anything that isn't needed for interoperability.

I agree on this point.  It sounds too much to me for a protocol
specification to specify a countermeasure that is pretty
implementation-dependent, especially with an RFC2119 keyword,
such as this one:

   Implementations SHOULD be configurable to use one or multiple ports
   for queries.

					JINMEI, Tatuya
					Communication Platform Lab.
					Corporate R&D Center, Toshiba Corp.
					jinmei@isl.rdc.toshiba.co.jp


--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>