Re: [dnsext] Adopting draft: draft-hoffman-dnssec-ecdsa-04.txt

Francis Dupont <Francis.Dupont@fdupont.fr> Wed, 05 January 2011 22:30 UTC

Return-Path: <Francis.Dupont@fdupont.fr>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9D58B3A6D0B for <dnsext@core3.amsl.com>; Wed, 5 Jan 2011 14:30:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.205
X-Spam-Level:
X-Spam-Status: No, score=-3.205 tagged_above=-999 required=5 tests=[AWL=0.044, BAYES_00=-2.599, HELO_EQ_FR=0.35, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DGBFAq6asFPQ for <dnsext@core3.amsl.com>; Wed, 5 Jan 2011 14:30:12 -0800 (PST)
Received: from givry.fdupont.fr (givry.fdupont.fr [91.121.26.85]) by core3.amsl.com (Postfix) with ESMTP id 875E83A67D6 for <dnsext@ietf.org>; Wed, 5 Jan 2011 14:30:12 -0800 (PST)
Received: from givry.fdupont.fr (localhost [127.0.0.1]) by givry.fdupont.fr (8.14.3/8.14.3) with ESMTP id p05MWIZI043441; Wed, 5 Jan 2011 22:32:18 GMT (envelope-from dupont@givry.fdupont.fr)
Message-Id: <201101052232.p05MWIZI043441@givry.fdupont.fr>
From: Francis Dupont <Francis.Dupont@fdupont.fr>
To: Edward Lewis <Ed.Lewis@neustar.biz>
In-reply-to: Your message of Wed, 05 Jan 2011 10:38:33 EST. <a06240801c94a3ed54f9e@[10.31.200.116]>
Date: Wed, 05 Jan 2011 23:32:18 +0100
Sender: Francis.Dupont@fdupont.fr
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsext@ietf.org
Subject: Re: [dnsext] Adopting draft: draft-hoffman-dnssec-ecdsa-04.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Jan 2011 22:30:13 -0000

 In your previous mail you wrote:

     - a validator SHOULD prefer the DS record of the same hash algorithm 
   over other hash algorithms for a key.  Prefer means that it SHOULD be 
   the first tried and if it fails, the validator MAY declare failure 
   without examining the other applicable hash algorithms.

=> thanks to have opened the can of worms about the validator behavior
when there are more than more than one DS RR using different digest
algorithm. Today only the case SHA-1 vs. SHA-256 is clear.

Regards

Francis.Dupont@fdupont.fr