[DNSOP] Re: Working Group Last Call draft-ietf-dnsop-structured-dns-error

tirumal reddy <kondtir@gmail.com> Tue, 26 November 2024 13:46 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73F44C1DFD43; Tue, 26 Nov 2024 05:46:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ojim5X_07cCQ; Tue, 26 Nov 2024 05:46:17 -0800 (PST)
Received: from mail-ej1-x629.google.com (mail-ej1-x629.google.com [IPv6:2a00:1450:4864:20::629]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B846C18DB8E; Tue, 26 Nov 2024 05:46:17 -0800 (PST)
Received: by mail-ej1-x629.google.com with SMTP id a640c23a62f3a-aa539d2b4b2so485251866b.1; Tue, 26 Nov 2024 05:46:17 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1732628775; x=1733233575; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=MPwwjztHgevVt/FhMj/kODJx9nLp0rRjZTfetNV1W8Y=; b=gone01LXmf1gapD89kPshfN1Ipo9QQDKyPV7tg4OTAuJj6ptkvTAm0VvjwRk6Yd3od gvgAlSVi00gaqWCgxY0hxG6kWsj1VbCw+r+qWxighypYLJsb4BQ9qbWCz2TE1aTBx4tC SZHzS1UM1Ri0kXg2QTqPYYTj2Q79AOalVMtkKQOTt5Vh5seglu/9JW+FM/UVklt5XEeG z9gCEL9aTdk3/n2vTtVirxsj5KLyrrsBQGglahYwqf1HpxGArjI0spPbnU0xpVcpDQUU C7kQGo31DfCIQ8WE21Vi4CCk5LCpkySvAGbN84wWOvAS5RIXcE/Im0Dx/iMNMKLbUi5q P+bQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1732628775; x=1733233575; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=MPwwjztHgevVt/FhMj/kODJx9nLp0rRjZTfetNV1W8Y=; b=b8Vxogog5ShnlKoemQqgkMcs4sQAs+j2fBCT3cu8BRGXHD+jejUB1T8cl3/j8PdLvF JPL6p8kRY2hKtSou8HHmFD21UO6ydL849cILb2onIoFWE/3sB7JLC5ExdKS1GZGf+Ojz EkAKIY7INXnngiVH0nfsoJRmp9pPbWLVDw0MP6lRJOMdXF88hnTQ4XqzML8tIh0EORVw UJK6B5YpMasmZEtc3i3Yi2gs9n2TEFASkem50/rtSeNibZ+CpM1R4OmFKqBlP6vx9R/F J+/Jr4pn6w8yYQye+OHHdgD6wZEWOmjKUFLvsm3I13oMoWhyJcxbkxcCRgmPQQj8XgHo 29Qg==
X-Forwarded-Encrypted: i=1; AJvYcCUSiayDCoZVAOJBlfgvu1MIpUuGS8Kc9uvpj+dVFifdQQEICeGHaHU/DtR1qMLTxMrZn9XMX4A=@ietf.org, AJvYcCVJBsOyOAVkmz5EfUUQC3Rq2canbaD8tNLBFjbuGrJMS7BAevdEoXbsMI8Adjc388yV36GovQTbArXvR4I=@ietf.org
X-Gm-Message-State: AOJu0YzQ5cObbiGBKXnaScKZqGAsw+CCWsrQtSuaedA1d7W+0eBL7rEh myIIx9B5z89mAqXILkCpFgCjIeMTywp27z59/P6aCGxpQFMUaYOBGZ0y/Fe1LXBhbHrSJ16pEY4 Yn47tp3dY/rg5lmv9erUcdhA794bJQhuysjA=
X-Gm-Gg: ASbGnct0rPWPahTCCF+o5VxXGZS26PTShctoO4H4RWvQQowukyC7L617uR1XQMea55D zESzBy9c1GYoASwkgzGkj0CV29seEnZSJ
X-Google-Smtp-Source: AGHT+IFLNiWurtnexuwK+JapWQtQacsuBWvmtGNkq7KQQUvDe1t3nfWsQTeF7Led9F5+xxEIEYL+C94qnFJ1OaNKr0o=
X-Received: by 2002:a17:907:9725:b0:a9e:85f8:2a49 with SMTP id a640c23a62f3a-aa56489115fmr350140966b.8.1732628775032; Tue, 26 Nov 2024 05:46:15 -0800 (PST)
MIME-Version: 1.0
References: <5725b858-a35d-41fa-a5a8-5a61e0ce3a7a@NLnetLabs.nl> <CADZyTkkoN5Mw4EKKFNnwV_DHOTvVLmfifWRjSJLCwSqqb4PMMw@mail.gmail.com>
In-Reply-To: <CADZyTkkoN5Mw4EKKFNnwV_DHOTvVLmfifWRjSJLCwSqqb4PMMw@mail.gmail.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Tue, 26 Nov 2024 19:15:38 +0530
Message-ID: <CAFpG3gdLaM2-DDROe9-sMCiH4KHNfn4BHbPoxFTGB4xNCHGAvA@mail.gmail.com>
To: Daniel Migault <mglt.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000a9df930627d11299"
Message-ID-Hash: 26ZF7NAILUE7HCVXV4LZ3UTX4RGIAJSS
X-Message-ID-Hash: 26ZF7NAILUE7HCVXV4LZ3UTX4RGIAJSS
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Benno Overeinder <benno@nlnetlabs.nl>, DNSOP Working Group <dnsop@ietf.org>, DNSOP Chairs <dnsop-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Working Group Last Call draft-ietf-dnsop-structured-dns-error
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/-elhsYdBfTud2cAH9Krnqkp0i10>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

 Thank you, Daniel, for the review. We have updated the draft to address
your comments. Please see inline responses for the comments we did not
address.

On Tue, 12 Nov 2024 at 17:00, Daniel Migault <mglt.ietf@gmail.com> wrote:

> I believe the document is ready, please find some comments.
>
> 3.  DNS Filtering Techniques and Their Limitations
>
> 1 and 2 do not work with DNSSEC is my primary concern and probably this needs to be mentioned.
>
>
Thanks, updated.


>
> 3 and 4. in my opinion could be merged.
>
>
We prefer not to merge 3 and 4.


>
> section 4.
>
> I am wondering if there is a recommendation to use only text versus other (Unicode Characters) or not and if there is a common reasonable size.
>
>
Regarding the use of text versus Unicode characters, the draft does not
currently mandate or restrict the use of Unicode characters. I don't think
size is an issue as the DNS messages are encrypted using DoT/DoH/DoQ.


>
> Maybe EDE can be expanded when first used - unless I am missing this has been done.
>
> section 5.2
>
> "Servers may decide to return small..." this might be a bit more normative language and it would be good to have a recommended value.
>
>
Updated text in Section 5.2 for better clarity, please see
https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/blob/main/draft-ietf-dnsop-structured-dns-error.md


>
>
> section 5.3
>
> The response MUST be received over an encrypted DNS channel.  If
>       not, the requestor MUST discard data in the EXTRA-TEXT field.
>
> I would like the proposal to make it possible to respond with a signed JOSE - bound to ANSWER, INFO-CODE.
>
>
I don't get the comment, please elaborate.


>
> I agree with relaxing the iANA registry for suberrors.
>
>
Please see my response
https://mailarchive.ietf.org/arch/msg/dnsop/z-bj0uue3uhhWAUGgtN3qSzW1w4/ on
the reason behind the strict registration policy for the IANA registry.


>
> I agree with the language tag as well.
>
>
Addressed.

Cheers,
-Tiru


>
>
> On Sat, Oct 26, 2024 at 11:11 PM Benno Overeinder <benno@nlnetlabs.nl>
> wrote:
>
>> Dear all,
>>
>> The draft-ietf-dnsop-structured-dns-error has seen several revisions and
>> there has been considerable discussion on the mailing list and in the
>> WG.  At IETF 116, Gianpaolo Scalone (Vodafone) and Ralf Weber (Akamai)
>> presented a proof of concept of this specification.
>>
>> The authors and the WG chairs believe the draft is ready for a Working
>> Group Last Call.
>>
>>
>> This initiates the Working Group Last Call (WGLC) for
>> draft-ietf-dnsop-structured-dns-error, "Structured Error Data for
>> Filtered DNS."
>>
>> The draft can be reviewed here:
>> https://datatracker.ietf.org/doc/draft-ietf-dnsop-structured-dns-error/
>>
>> Intended Status: Proposed Standard
>> Document Shepherd: Benno
>>
>> Please take the time to review this draft and share any relevant
>> comments.  For the WGLC to be effective, we need both positive support
>> and constructive feedback; a simple lack of objection isn’t enough.
>>
>> If you believe this draft is ready for publication as an RFC, please
>> state your support.  Conversely, if you feel the document isn’t ready
>> for publication, please provide your concerns and reasoning.
>>
>> This starts a two-week Working Group Last Call process, concluding on
>> November 9, 2024.
>>
>> Thank you,
>>
>> Suzanne
>> Tim
>> Benno
>>
>> _______________________________________________
>> DNSOP mailing list -- dnsop@ietf.org
>> To unsubscribe send an email to dnsop-leave@ietf.org
>>
>
>
> --
> Daniel Migault
> Ericsson
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org
>