[DNSOP] Re: Orie Steele's No Objection on draft-ietf-dnsop-rfc8624-bis-09: (with COMMENT)

Wes Hardaker <wjhns1@hardakers.net> Tue, 20 May 2025 22:01 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E5C542AE5E5A; Tue, 20 May 2025 15:01:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bTyanGPGejuR; Tue, 20 May 2025 15:01:35 -0700 (PDT)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 88C1C2AE5E3D; Tue, 20 May 2025 15:01:35 -0700 (PDT)
Received: from localhost (unknown [10.0.0.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.hardakers.net (Postfix) with ESMTPSA id 7CF9D2412A; Tue, 20 May 2025 15:01:34 -0700 (PDT)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 7CF9D2412A
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1747778494; bh=8I3YkZdIqa3GDpC1Tgeoh8zlahnDrXOMLXDnJCqzxOA=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=jX/7Dw7TFqpRTJ8MHa7OJhdQfEyPCELMLSU8aJRBxp9GvzBMrgxXF1r+3tS7RfBh+ tDfe89zoIBvcWZdb9YIS8JI1U2kz1lhX4KJpdHm8cEvZzYbpoINkaUFJTInVG2oJrL jMDbUSMh4iv7TETJq4IuD2Tf+yw6oLMVGO7DS+bU=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Orie Steele via Datatracker <noreply@ietf.org>
In-Reply-To: <174768631165.485945.17542801112153835514@dt-datatracker-59b84fc74f-84jsl> (Orie Steele via Datatracker's message of "Mon, 19 May 2025 13:25:11 -0700")
References: <174768631165.485945.17542801112153835514@dt-datatracker-59b84fc74f-84jsl>
Date: Tue, 20 May 2025 15:01:34 -0700
Message-ID: <yblo6vndjr5.fsf@wd.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Message-ID-Hash: RVKGQNFHNN4C36OMSLZW4WLZWZPKF44R
X-Message-ID-Hash: RVKGQNFHNN4C36OMSLZW4WLZWZPKF44R
X-MailFrom: wjhns1@hardakers.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, Orie Steele <orie@or13.io>, draft-ietf-dnsop-rfc8624-bis@ietf.org, dnsop-chairs@ietf.org, dnsop@ietf.org, tjw.ietf@gmail.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Orie Steele's No Objection on draft-ietf-dnsop-rfc8624-bis-09: (with COMMENT)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/-lnGfBi5nUYW9Muu0i07Yi5c_Gc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Orie Steele via Datatracker <noreply@ietf.org> writes:

> ### Guidance to DEs for divergence?
> 
> ```
> 268        and "use".  We note that the values for "Implement for" and "Use for"
> 269        may diverge in the future
> ```
> 
> The divergence that is expected here is probably that there will be more
> implementation than use, right?
>
> Some additional guidance to DEs might be helpful here.

That would be the most logical.

added "as implementations generally precede deployments."


> ## Nits
> 
> ### KSK expand on first use.
> 
> ```
> 391        Upgrading algorithm at the same time as rolling the new KSK key will
> ```

Done, thanks
-- 
Wes Hardaker                                     
USC/ISI