[dnsext] [Errata Rejected] RFC4035 (7972)

RFC Errata System <rfc-editor@rfc-editor.org> Fri, 07 June 2024 20:58 UTC

Return-Path: <wwwrun@rfcpa.rfc-editor.org>
X-Original-To: dnsext@ietf.org
Delivered-To: dnsext@ietfa.amsl.com
Received: from rfcpa.rfc-editor.org (unknown [167.172.21.234]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D979C151527; Fri, 7 Jun 2024 13:58:08 -0700 (PDT)
Received: by rfcpa.rfc-editor.org (Postfix, from userid 461) id 06774204E22; Fri, 7 Jun 2024 13:58:08 -0700 (PDT)
To: nate@natechoe.dev, roy.arends@telin.nl, sra@isc.org, mlarson@verisign.com, massey@cs.colostate.edu, scott.rose@nist.gov
From: RFC Errata System <rfc-editor@rfc-editor.org>
Content-Type: text/plain; charset="UTF-8"
Message-Id: <20240607205808.06774204E22@rfcpa.rfc-editor.org>
X-MailFrom: wwwrun@rfcpa.rfc-editor.org
X-Mailman-Rule-Hits: max-recipients
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsext.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-size; news-moderation; no-subject; digests; suspicious-header
Message-ID-Hash: VJYLZOZ4QYQLJXAMOAGTTQE6QYJIF2PN
X-Message-ID-Hash: VJYLZOZ4QYQLJXAMOAGTTQE6QYJIF2PN
X-Mailman-Approved-At: Sat, 08 Jun 2024 19:37:34 -0700
CC: evyncke@cisco.com, iesg@ietf.org, dnsext@ietf.org, rfc-editor@rfc-editor.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [dnsext] [Errata Rejected] RFC4035 (7972)
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsext/wBtyUSlsHWZ8BEYNhFPjhPhd--A>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsext>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Owner: <mailto:dnsext-owner@ietf.org>
List-Post: <mailto:dnsext@ietf.org>
List-Subscribe: <mailto:dnsext-join@ietf.org>
List-Unsubscribe: <mailto:dnsext-leave@ietf.org>
Date: Fri, 07 Jun 2024 20:58:09 -0000
X-Original-Date: Fri, 7 Jun 2024 13:58:08 -0700 (PDT)

The following errata report has been rejected for RFC4035,
"Protocol Modifications for the DNS Security Extensions".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid7972

--------------------------------------
Status: Rejected
Type: Technical

Reported by: Nate Choe <nate@natechoe.dev>
Date Reported: 2024-06-06
Rejected by: Eric Vyncke (IESG)

Section: 4.2

Original Text
-------------
   Security-aware resolvers MAY query for missing security RRs in an
   attempt to perform validation; implementations that choose to do so
   must be aware that the answers received may not be sufficient to
   validate the original response.  For example, a zone update may have
   changed (or deleted) the desired information between the original and
   follow-up queries.

Corrected Text
--------------
   Security-aware resolvers MAY query for missing security RRs in an
   attempt to perform validation; implementations that choose to do so
   MUST be aware that the answers received may not be sufficient to
   validate the original response.  For example, a zone update may have
   changed (or deleted) the desired information between the original and
   follow-up queries.

Notes
-----
"MUST" is a key word according to RFC 2119/BCP 14 and should be capitalized.
 --VERIFIER NOTES-- 
 As it appears to the original authors, remaining members of dnsext mailing list, and myself as INT AD, the "must" here is not normative and should be kept in lowercase.

See also:
https://mailarchive.ietf.org/arch/msg/dnsext/1PZ58ajXFj_RodKgHzus6d6UB-U/

--------------------------------------
RFC4035 (draft-ietf-dnsext-dnssec-protocol-09)
--------------------------------------
Title               : Protocol Modifications for the DNS Security Extensions
Publication Date    : March 2005
Author(s)           : R. Arends, R. Austein, M. Larson, D. Massey, S. Rose
Category            : PROPOSED STANDARD
Source              : DNS Extensions
Stream              : IETF
Verifying Party     : IESG