comments on ds-13

Paul Vixie <paul@vix.com> Tue, 11 March 2003 18:04 UTC

Received: from psg.com (mailnull@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA29889 for <dnsext-archive@lists.ietf.org>; Tue, 11 Mar 2003 13:04:32 -0500 (EST)
Received: from lserv by psg.com with local (Exim 3.36 #1) id 18so0p-000HLQ-00 for namedroppers-data@psg.com; Tue, 11 Mar 2003 09:58:03 -0800
Received: from [2001:4f8:3:bb:2e0:81ff:fe23:7b5a] (helo=as.vix.com) by psg.com with esmtp (Exim 3.36 #1) id 18so0l-000HKk-00 for namedroppers@ops.ietf.org; Tue, 11 Mar 2003 09:57:59 -0800
Received: from as.vix.com (localhost [127.0.0.1]) by as.vix.com (Postfix) with ESMTP id C0D55379E40 for <namedroppers@ops.ietf.org>; Tue, 11 Mar 2003 17:57:46 +0000 (GMT)
From: Paul Vixie <paul@vix.com>
To: namedroppers@ops.ietf.org
Subject: comments on ds-13
X-Mailer: MH-E 7.2; nmh 1.0.4; GNU Emacs 21.2.1
Date: Tue, 11 Mar 2003 17:57:46 +0000
Message-Id: <20030311175746.C0D55379E40@as.vix.com>
X-Spam-Status: No, hits=0.0 required=5.0 tests=QUOTED_EMAIL_TEXT,SPAM_PHRASE_00_01 version=2.43
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk

olafur, you wrote (in draft-ietf-dnsext-delegation-signer-13.txt),

>> DS RRsets MUST NOT appear at non-delegation points or at a zone's apex.

why not?  i think you can say they are irrelevant elsewhere, but i don't
think there's a way to show that they are in any way harmful elsewhere.

as a simple document quality issue, there is no way to enforce this
requirement and no reliable way to even know when it has been violated.
so at best it would be a SHOULD not a MUST.

however, even as a SHOULD, it overreaches.  the proper attitude of a
document toward its protocol is to specify things which, if left
unspecified, will lead to loss of interoperability or functionality.
there is no such argument to be made for restricting the placement of
DS RRs (or for restricting the use of KEYs for that matter.)

paul

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>