Re: [dnsext] Clarifying the mandatory algorithm rules

Samuel Weiler <weiler@watson.org> Thu, 18 November 2010 15:05 UTC

Return-Path: <weiler@watson.org>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1DE843A6863 for <dnsext@core3.amsl.com>; Thu, 18 Nov 2010 07:05:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.469
X-Spam-Level:
X-Spam-Status: No, score=-2.469 tagged_above=-999 required=5 tests=[AWL=0.130, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kdZqGNSf9XV2 for <dnsext@core3.amsl.com>; Thu, 18 Nov 2010 07:05:25 -0800 (PST)
Received: from fledge.watson.org (fledge.watson.org [65.122.17.41]) by core3.amsl.com (Postfix) with ESMTP id E57303A686B for <dnsext@ietf.org>; Thu, 18 Nov 2010 07:05:21 -0800 (PST)
Received: from fledge.watson.org (localhost.watson.org [127.0.0.1]) by fledge.watson.org (8.14.4/8.14.4) with ESMTP id oAIF65Go011546; Thu, 18 Nov 2010 10:06:05 -0500 (EST) (envelope-from weiler@watson.org)
Received: from localhost (weiler@localhost) by fledge.watson.org (8.14.4/8.14.4/Submit) with ESMTP id oAIF64F4011542; Thu, 18 Nov 2010 10:06:04 -0500 (EST) (envelope-from weiler@watson.org)
X-Authentication-Warning: fledge.watson.org: weiler owned process doing -bs
Date: Thu, 18 Nov 2010 10:06:04 -0500
From: Samuel Weiler <weiler@watson.org>
To: Phillip Hallam-Baker <hallam@gmail.com>
In-Reply-To: <AANLkTikmD0rdt=pYDn+Z3u-F3cmiLTgxUO=0=nOTBy--@mail.gmail.com>
Message-ID: <alpine.BSF.2.00.1011180953550.2821@fledge.watson.org>
References: <alpine.BSF.2.00.1011180553250.83352@fledge.watson.org> <4CE50C01.4010104@nic.cz> <alpine.BSF.2.00.1011180630550.83352@fledge.watson.org> <4CE515ED.5010009@nlnetlabs.nl> <AANLkTikmD0rdt=pYDn+Z3u-F3cmiLTgxUO=0=nOTBy--@mail.gmail.com>
User-Agent: Alpine 2.00 (BSF 1167 2008-08-23)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format="flowed"; charset="US-ASCII"
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.3 (fledge.watson.org [127.0.0.1]); Thu, 18 Nov 2010 10:06:05 -0500 (EST)
Cc: dnsext@ietf.org
Subject: Re: [dnsext] Clarifying the mandatory algorithm rules
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Nov 2010 15:05:27 -0000

On Thu, 18 Nov 2010, Phillip Hallam-Baker wrote:

> I can't quite understand why we would make a change to require 
> acceptance of the unsigned zone in this case.

There is a difference of opinion about what's being "changed" here. 
I think my proposed clarification is NOT a change -- RFC4035 does not 
tell resolvers to do what Unbound is doing.  Wouter seems to disagree.

>From my perspective, it's Wouter (and you?) that wants to make a 
change, in the form of requiring resolvers to check something RFC4035 
doesn't require them to check.

Different perspectives.


The "check everything and fail if anything break" seems to differ in 
spirit from the guidance that's already in dnssec-bis-updates; see 
section 5.4 "Caution About Local Policy and Multiple RRSIGs". 
(Slightly different details, same flavor.)  That section has been in 
this doc since the -00 version, dated May 2005.

While there may be merit in the approach Wouter suggests, my 
inclination as doc editor is to avoid changes unless strictly 
necessary.

Since we seem to have different ideas about the current state of the 
world, perhaps we need some more voices in this.  Perhaps the BIND 
authors have an opinion.  :-)

-- Sam