Re: [dnsext] OPENPGPKEY RRTYPE review - [IANA #773394]

Jay Daley <jay@nzrs.net.nz> Sun, 10 August 2014 08:41 UTC

Return-Path: <jay@nzrs.net.nz>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0ADD71A0697 for <dnsext@ietfa.amsl.com>; Sun, 10 Aug 2014 01:41:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.285
X-Spam-Level: **
X-Spam-Status: No, score=2.285 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FRT_BELOW2=2.154, RP_MATCHES_RCVD=-0.668, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LZwzJc9Ku6Pn for <dnsext@ietfa.amsl.com>; Sun, 10 Aug 2014 01:41:31 -0700 (PDT)
Received: from srsomail.nzrs.net.nz (srsomail.nzrs.net.nz [202.46.183.22]) by ietfa.amsl.com (Postfix) with ESMTP id AF2C41A020B for <dnsext@ietf.org>; Sun, 10 Aug 2014 01:41:30 -0700 (PDT)
Received: from localhost (localhost.localdomain [127.0.0.1]) by srsomail.nzrs.net.nz (Postfix) with ESMTP id B0D364BC44A; Sun, 10 Aug 2014 20:41:27 +1200 (NZST)
X-Virus-Scanned: Debian amavisd-new at srsomail.office.nzrs.net.nz
Received: from srsomail.nzrs.net.nz ([202.46.183.22]) by localhost (srsomail.office.nzrs.net.nz [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BA7w7h02mXTZ; Sun, 10 Aug 2014 20:41:17 +1200 (NZST)
Received: from [192.168.2.231] (118-93-227-250.dsl.dyn.ihug.co.nz [118.93.227.250]) (Authenticated sender: jay) by srsomail.nzrs.net.nz (Postfix) with ESMTPSA id 5E3624BC44F; Sun, 10 Aug 2014 20:41:17 +1200 (NZST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Jay Daley <jay@nzrs.net.nz>
In-Reply-To: <20140808145847.GA48049@registro.br>
Date: Sun, 10 Aug 2014 20:41:15 +1200
Content-Transfer-Encoding: quoted-printable
Message-Id: <65E1B57B-BCFB-4444-83C3-CFA69BB87BAC@nzrs.net.nz>
References: <20140723213403.GN94557@registro.br> <20140808145847.GA48049@registro.br>
To: Frederico A C Neves <fneves@registro.br>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsext/s1AXSYusl0iF0khD_nRJ975lBLg
Cc: Paul Wouters <pwouters@redhat.com>, dnsext@ietf.org
Subject: Re: [dnsext] OPENPGPKEY RRTYPE review - [IANA #773394]
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext/>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Aug 2014 08:41:33 -0000

It would be helpful if the draft was updated to reflect the discussion on the list.

Jay

On 9/08/2014, at 2:58 am, Frederico A C Neves <fneves@registro.br> wrote:

> Dear Colleages,
> 
> This message ends the review process for the OPENPGPKEY RRTYPE. Based
> on the provided documentation and the list traffic, this request meets
> both requirements of RFC6895 section 3.1.1 and none of section
> 3.1.2. Therefore should be accepted.
> 
> Best Regards,
> Frederico Neves
> 
> On Wed, Jul 23, 2014 at 06:34:03PM -0300, Frederico A C Neves wrote:
>> Dear Colleagues,
>> 
>> Bellow is a completed template requesting a new RRTYPE assignment
>> under the procedures of RFC6895.
>> 
>> This message starts a 2 weeks period for an expert review of the DNS
>> RRTYPE parameter allocation for OPENPGPKEY specified at:
>> 
>> http://tools.ietf.org/html/draft-ietf-dane-openpgpkey-00#section-2
>> 
>> If you have comments regarding this request please post them here
>> before Aug 6th 21:00 UTC.
>> 
>> Best Regards,
>> Frederico Neves
>> 
>> --begin 6895 template TLSA--
>> A. Submission Date: 23-07-2014
>> 
>> B.1 Submission Type:  [x] New RRTYPE  [ ] Modification to RRTYPE
>> B.2 Kind of RR:  [x] Data RR  [ ] Meta-RR
>> 
>> C. Contact Information for submitter (will be publicly posted):
>>    Name: Paul Wouters         Email Address: pwouters@redhat.com
>>    International telephone number: +1-647-896-3464
>>    Other contact handles: paul@nohats.ca
>> 
>> D. Motivation for the new RRTYPE application.
>> 
>>    Publishing RFC-4880 OpenPGP formatted keys in DNS with DNSSEC
>>    protection to faciliate automatic encryption of emails in
>>    defense against pervasive monitoring.
>> 
>> E. Description of the proposed RR type.
>> 
>>    http://tools.ietf.org/html/draft-ietf-dane-openpgpkey-00#section-2
>> 
>> F. What existing RRTYPE or RRTYPEs come closest to filling that need
>>    and why are they unsatisfactory?
>> 
>>    The CERT RRtype is the closest match. It unfortunately depends on
>>    subtyping, and its use in general is no longer recommended. It
>>    also has no human usable presentation format. Some usage types of
>>    CERT require external URI's which complicates the security model.
>>    This was discussed in the dane working group.
>> 
>> G. What mnemonic is requested for the new RRTYPE (optional)?
>> 
>>    OPENPGPKEY
>> 
>> H. Does the requested RRTYPE make use of any existing IANA registry
>>    or require the creation of a new IANA subregistry in DNS
>>    Parameters?  If so, please indicate which registry is to be used
>>    or created.  If a new subregistry is needed, specify the
>>    allocation policy for it and its initial contents.  Also include
>>    what the modification procedures will be.
>> 
>>    The RDATA part uses the key format specified in RFC-4880, which
>>    itself use https://www.iana.org/assignments/pgp-parameters/pgp-parameters.xhtm
>> 
>>    This RRcode just uses the formats specified in those registries
>>    for its RRdata part.
>> 
>> 
>> I. Does the proposal require/expect any changes in DNS
>>    servers/resolvers that prevent the new type from being processed
>>    as an unknown RRTYPE (see [RFC3597])?
>> 
>>    No.
>> 
>> J. Comments:
>> 
>>    Currently, three software implementations of draft-ietf-dane-openpgpkey
>>    are using a private number.
>> --end 6895 template TLSA--
>> 
>> _______________________________________________
>> dnsext mailing list
>> dnsext@ietf.org
>> https://www.ietf.org/mailman/listinfo/dnsext
> 
> _______________________________________________
> dnsext mailing list
> dnsext@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsext


-- 
Jay Daley
Chief Executive
.nz Registry Services (New Zealand Domain Name Registry Limited)
desk: +64 4 931 6977
mobile: +64 21 678840
linkedin: www.linkedin.com/in/jaydaley