Re: [DNSOP] I-D Action: draft-wessels-dns-zone-digest-06.txt

"Wessels, Duane" <dwessels@verisign.com> Mon, 25 March 2019 21:15 UTC

Return-Path: <dwessels@verisign.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCDF61200B6 for <dnsop@ietfa.amsl.com>; Mon, 25 Mar 2019 14:15:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level:
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id juftYV4crUU8 for <dnsop@ietfa.amsl.com>; Mon, 25 Mar 2019 14:15:03 -0700 (PDT)
Received: from mail1.verisign.com (mail1.verisign.com [72.13.63.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E31DE120090 for <dnsop@ietf.org>; Mon, 25 Mar 2019 14:15:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=5455; q=dns/txt; s=VRSN; t=1553548503; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=HtnnIpnVBgs2lXfZAJokcMK04ifmResbyAC1/IsubJY=; b=iOuxFI/4a9AqohbFLnEu9e9zg98gwUQxaQsJgkSU2zAdeJtAiyJKYb68 KnU5nRQrB3fJeY39kC9HcYDI5mW7mcn+dUauqK3/JYQ1TyXkdGkCuxe6B 422ar8Ube/w/nn1ZNJ+fNYUcvJiThmvF/f5qAryS95MpF/fSOAuzSlpJ9 P898cFK2e2ywQWEPWryzhjAUvV8dO0n+a74O40T11mPQLB7BtqXIKkGMl Vw7SuJRzNG5sImaLsLjFP2SDSul+pJOvXx6JgNQmfGFAgcq7yHLSVx+is UhdPvDjWDOk8JVxxiaqhqJdTjvA6qiz3TWrbCjPxE9GpZ4PSsIo62wynK A==;
X-IronPort-AV: E=Sophos; i="5.60,270,1549929600"; d="p7s'?scan'208"; a="9867900"
IronPort-PHdr: 9a23:Nq2K+hJVUYS4tHtfF9mcpTZWNBhigK39O0sv0rFitYgfLPvxwZ3uMQTl6Ol3ixeRBMOHsqoC1Lqd6vy8EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQpFiCehbb9oLhi7rgrdutQZjIZtN6081gbHrnxUdupM2GhmP0iTnxHy5sex+J5s7SFdsO8/+sBDTKv3Yb02QaRXAzo6PW814tbrtQTYQguU+nQcSGQWnQFWDAXD8Rr3Q43+sir+tup6xSmaIcj7Rq06VDi+86tmTgLjhTwZPDAl7m7Yls1wjLpaoB2/oRx/35XUa5yROPZnY6/RYc8WSW9HU81MVSJOH5m8YpMPAeQfIOhYs4fzqVgArRS8BAmjGOzgxyRHhnPq2K03yfgtHR3Y0AEmAtkAsG7UrNLwNKoKX+y6zLfHzS7Yb/xI3Tf985DEeQ0vr/GRR71wd9TexUcyHA7Ck1qRp5LqPyiO1usTt2ib9PFtVfyxhG49qgFxuTmvxsgqioXTmo0VzVXE+Dx/zY0oJtO4UFZ2bcO4HJdKqi2XNYV7Ttk/T2xotis20LILtJqjcCQX1Jgr3QPTZv6bf4SS/x7uW+WcLS1liH9mYL6/iQi9/Eu8xuD5U8S7ylVHoy5endTJuH0ByQHc58mCR/Rm+kqs2DSC2gXd5+xKI007iKzWIIM7zLEqjJocq0HDEzfzmEXxkaCZaF0p+vOt6+T7erXmoYKcN5NshgH+LKsunsu/DPwlPwYSR2aX5OSz2qXs80L4XLlGkOc6krfFv5DdP8QbvrS1DBVI3Yo59Ra/FSym0NICkXYbK1JFfQqLj4nvO17QPPD1Feqzj0i2nDt2xf3LMKftDojNI3XNirvscrJw51ZZyAUpzNBf45xUCqsGIPL2QkL+qdLZAQEiMwyv3ennDM5925gAWW2RGK+ZMbjSsV6H5uIpOeWDeIgVuDPlJ/g/+/HulWM5mUMafaSx2psXbHS4HvV9LkSYf3Xsg8sBHX0WsQo5VObqkkGNUSZPZ3auWKIx/jQ7B5i6DYffXY2inLuB3CGmHp1Qe29GEE2MEXLye4qYXPcMbTqYItV9nTwcSbihV4gh2Amzuw/80LpnKfLU9zYZtZ39yNh16ffflRYo9Tx7XIyh1DSqS2V11l0BQT8x3qk39Ut5zlarw6V5n7pTEooAyelOV1JwCpPH1OF+EJS6dh/IeNrDAAKqXdi9Gjw1VfovzsUPeEdyHZOpiRWVjHniOKMci7HeXM98yanbxXWkYp8lk3s=
X-IPAS-Result: A2EPAACARJlc/zGZrQpkGgEBAQEBAgEBAQEHAgEBAQGBVAIBAQEBCwGEIgqZKiWDXZZYCgQBhGwChTU3Bg0BAQMBAQEIAQMCAQECgRGCOikBgmcBAQEBAgF5BQsCAQgYLgIwJQIEDgUOgxQBgW2wGYVGhFoPgS8BgUiKAIFBPoE4DBOCTD6Hf4ImA6Q2YAMGAoRfgg+MYpN+nkYCBAIEBQIVgWOBeXAVZQGCQZBLco8MgR8BAQ
Received: from BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) by BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1713.5; Mon, 25 Mar 2019 17:15:01 -0400
Received: from BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d]) by BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d%5]) with mapi id 15.01.1713.004; Mon, 25 Mar 2019 17:15:01 -0400
From: "Wessels, Duane" <dwessels@verisign.com>
To: Olli Vanhoja <olli@zeit.co>
CC: Matthew Pounsett <matt@conundrum.com>, "dnsop@ietf.org" <dnsop@ietf.org>
Thread-Topic: Re: [EXTERNAL] [DNSOP] I-D Action: draft-wessels-dns-zone-digest-06.txt
Thread-Index: AQHU40/OX2yFWUG8oEWCjrMLhz7nMA==
Date: Mon, 25 Mar 2019 21:15:01 +0000
Message-ID: <0E8CD2BB-C8C6-4387-8FAD-DAC84B381557@verisign.com>
References: <155009468256.9559.12509906855495134896@ietfa.amsl.com> <923006F8-EB5A-4098-81A2-782BC90BF220@verisign.com> <CAAiTEH_GmvNVgAZzwG+oaQrtNd_b=kpDSRz7ErbmTjuXrzziWg@mail.gmail.com> <CABrJZ5FBYpFrjpm-a+B9FF8rbVNXwy=V-MP0TPS8fG87OJeteg@mail.gmail.com>
In-Reply-To: <CABrJZ5FBYpFrjpm-a+B9FF8rbVNXwy=V-MP0TPS8fG87OJeteg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: multipart/signed; boundary="Apple-Mail=_D0C18CF5-9205-4F9D-B1FC-BA3A800AF70E"; protocol="application/pkcs7-signature"; micalg="sha1"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/-QkuQd7Lt695-IBL3XFtD5KjTs8>
Subject: Re: [DNSOP] I-D Action: draft-wessels-dns-zone-digest-06.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Mar 2019 21:15:05 -0000


> On Mar 25, 2019, at 3:47 PM, Olli Vanhoja <olli@zeit.co> wrote:
> 
>> Section 3.2. discussion:  Unless there's a potential benefit to non-apex ZONEMD records that I'm not seeing, I think it makes sense to forbid them.  Was there a particular thing that could be enabled by that, which prompted the suggestion?
> 
> I agree with this. I believe it would create unnecessary complexity.
> For example, which records would such a digest cover? Would the apex
> record cover also the records covered by this subdigest?

Matt / Olli,

I'm not aware of anything that could be enabled by non-apex ZONEMD records. My preference would be to forbid non-apex ZONEMD records.

I guess my concern was just that it means implementors need to check for this and treat the RR type somewhat specially, as they do for SOA and maybe a couple other RR types.

DW