[dnsext] Related to section 5.1 of dnssec-bis-updates (-14)

Edward Lewis <Ed.Lewis@neustar.biz> Thu, 13 October 2011 15:16 UTC

Return-Path: <Ed.Lewis@neustar.biz>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D403421F8ADC for <dnsext@ietfa.amsl.com>; Thu, 13 Oct 2011 08:16:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -105.948
X-Spam-Level:
X-Spam-Status: No, score=-105.948 tagged_above=-999 required=5 tests=[AWL=0.649, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O7YjyvB9XsA6 for <dnsext@ietfa.amsl.com>; Thu, 13 Oct 2011 08:16:25 -0700 (PDT)
Received: from stora.ogud.com (stora.ogud.com [66.92.146.20]) by ietfa.amsl.com (Postfix) with ESMTP id 0EEBF21F8AB8 for <dnsext@ietf.org>; Thu, 13 Oct 2011 08:16:16 -0700 (PDT)
Received: from ccur-lt61.cis.neustar.com (nyttbox.md.ogud.com [10.20.30.4]) by stora.ogud.com (8.14.4/8.14.4) with ESMTP id p9DFGEAI049857; Thu, 13 Oct 2011 11:16:15 -0400 (EDT) (envelope-from Ed.Lewis@neustar.biz)
Received: from [192.168.129.103] by ccur-lt61.cis.neustar.com (PGP Universal service); Thu, 13 Oct 2011 11:16:15 -0400
X-PGP-Universal: processed; by ccur-lt61.cis.neustar.com on Thu, 13 Oct 2011 11:16:15 -0400
Mime-Version: 1.0
Message-Id: <a06240801cabc9d0de24d@[192.168.129.103]>
In-Reply-To: <20111012144101.205a61dff9fc1684c258b274662bb912.3f5e55ecf1.wbe@email00.se cureserver.net>
References: <20111012144101.205a61dff9fc1684c258b274662bb912.3f5e55ecf1.wbe@email00.se cureserver.net>
Date: Thu, 13 Oct 2011 11:16:12 -0400
To: dnsext@ietf.org
From: Edward Lewis <Ed.Lewis@neustar.biz>
Content-Type: multipart/alternative; boundary="============_-893603521==_ma============"
X-Scanned-By: MIMEDefang 2.72 on 10.20.30.4
Cc: ed.lewis@neustar.biz
Subject: [dnsext] Related to section 5.1 of dnssec-bis-updates (-14)
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Oct 2011 15:16:25 -0000

In this section of the still-a-draft update to the DNSSEC definition 
of RFC 4033-4035 an issue has arisen that needs to be addressed.

# http://tools.ietf.org/html/draft-ietf-dnsext-dnssec-bis-updates-14
#
#5.1.  Errors in Canonical Form Type Code List
#
#   When canonicalizing DNS names, DNS names in the RDATA section of NSEC
#   and RRSIG resource records are not downcased.
#
#   [RFC4034] Section 6.2 item 3 has a list of resource record types for
#   which DNS names in the RDATA are downcased for purposes of DNSSEC
#   canonical form (for both ordering and signing).  That list
#   erroneously contains NSEC and RRSIG.  According to [RFC3755], DNS
#   names in the RDATA of NSEC and RRSIG should not be downcased.
#
#   The same section also erroneously lists HINFO, and twice at that.
#   Since HINFO records contain no domain names, they are not subject to
#   downcasing.

For the purposes of this email a "major implementation" refers to a 
widely distributed general purpose implementation of DNS.  It's 
become apparent that two major implementations of validators have 
differed on downcaseing the RRSIG.

We've been trying to determine why this problem hasn't surfaced in a 
real-world outage.  It seems that all major implementations of 
signers down case the RRSIG before signing.

Treat this as a suggestion.  Unexcuse RRSIG from the list of names 
that avoid downcasing.  (NSEC is not a problem.)  Any thoughts?
-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis             
NeuStar                    You can leave a voice message at +1-571-434-5468

Vote for the word of the day:
"Papa"razzi - father that constantly takes photos of the baby
Corpureaucracy - The institution of corporate "red tape"