Re: [dnsext] publishing policy attributes in the DNS

Andrew Sullivan <ajs@anvilwalrusden.com> Mon, 01 October 2012 15:07 UTC

Return-Path: <ajs@anvilwalrusden.com>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 811761F0D3F for <dnsext@ietfa.amsl.com>; Mon, 1 Oct 2012 08:07:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.803
X-Spam-Level:
X-Spam-Status: No, score=-0.803 tagged_above=-999 required=5 tests=[AWL=0.037, BAYES_00=-2.599, HELO_MISMATCH_INFO=1.448, HOST_MISMATCH_NET=0.311]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9Lv1FD06h+JS for <dnsext@ietfa.amsl.com>; Mon, 1 Oct 2012 08:07:53 -0700 (PDT)
Received: from mx1.yitter.info (ow5p.x.rootbsd.net [208.79.81.114]) by ietfa.amsl.com (Postfix) with ESMTP id 0FE8B1F0D17 for <dnsext@ietf.org>; Mon, 1 Oct 2012 08:07:53 -0700 (PDT)
Received: from mx1.yitter.info (nat-04-mht.dyndns.com [216.146.45.243]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.yitter.info (Postfix) with ESMTPSA id E1C238A031 for <dnsext@ietf.org>; Mon, 1 Oct 2012 15:07:50 +0000 (UTC)
Date: Mon, 01 Oct 2012 11:07:58 -0400
From: Andrew Sullivan <ajs@anvilwalrusden.com>
To: dnsext@ietf.org
Message-ID: <20121001150758.GA11975@mx1.yitter.info>
References: <D3A1FA66-E7FF-4E5C-AC8C-FC0354FEE1D9@kirei.se> <82ADB7D5-4F2F-44F1-B465-66ABB3DDCB21@hopcount.ca>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <82ADB7D5-4F2F-44F1-B465-66ABB3DDCB21@hopcount.ca>
User-Agent: Mutt/1.5.21 (2010-09-15)
Subject: Re: [dnsext] publishing policy attributes in the DNS
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Oct 2012 15:07:53 -0000

Emphatically no hat.

On Mon, Oct 01, 2012 at 09:39:07AM -0400, Joe Abley wrote:
> No doubt there are others. It seems to me that we might consider standardising some kind of POLICY RRtype (or multiple RRTypes) that could be used to signal these kinds of things. Such RRSets would be informational and optional, and would not change existing query processing rules.
> 

For one proposal along these lines, see
http://tools.ietf.org/html/draft-sullivan-domain-origin-assert-01.

Best,

A

-- 
Andrew Sullivan
ajs@anvilwalrusden.com