[DNSOP]Re: [IANA #1362913] expert review for draft-ietf-dnsop-dnssec-bootstrapping (dns-parameters)
Daniel Salzman <daniel.salzman@nic.cz> Tue, 07 May 2024 07:44 UTC
Return-Path: <daniel.salzman@nic.cz>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 26154C14F685 for <dnsop@ietfa.amsl.com>; Tue, 7 May 2024 00:44:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.096
X-Spam-Level:
X-Spam-Status: No, score=-7.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nic.cz
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZsH5BPal18hA for <dnsop@ietfa.amsl.com>; Tue, 7 May 2024 00:44:36 -0700 (PDT)
Received: from mail.nic.cz (mail.nic.cz [217.31.204.67]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32466C14F6B6 for <dnsop@ietf.org>; Tue, 7 May 2024 00:44:35 -0700 (PDT)
Received: from [IPV6:2001:1488:fffe:6:e8d1:1049:6c13:6dde] (unknown [IPv6:2001:1488:fffe:6:e8d1:1049:6c13:6dde]) by mail.nic.cz (Postfix) with ESMTPSA id 8C86A1C1381; Tue, 7 May 2024 09:44:31 +0200 (CEST)
Authentication-Results: mail.nic.cz; auth=pass smtp.auth=daniel.salzman@nic.cz smtp.mailfrom=daniel.salzman@nic.cz
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=nic.cz; s=default; t=1715067872; bh=32BTVO9pvcc44U5O3CudOUI6jyvLRqIMG7gE4302WHI=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From:Reply-To: Subject:To:Cc; b=jIYh5oNFMcYuwpwwpZlRuO4/ldUT+zCxEiXFlrU/3ZvQ7t2fDwiAc8ZoPS96aUQ6C 2xRC+9Lc+Jc9bLXYKAvQ54fM9mpYhQGZ/I73FbPXLqIXJHdCDVA/zLCsEwtf9NlgsZ YWakL52NeQ7Z4gALn/JAxl/kEKe5Cx4DlNudP2vY=
Message-ID: <a7471f3f-db56-48a5-92d4-49859eadb2f6@nic.cz>
Date: Tue, 07 May 2024 09:44:30 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Peter Thomassen <peter@desec.io>, drafts-expert-review-comment@iana.org
References: <RT-Ticket-1362913@icann.org> <rt-5.0.3-225992-1713566832-1739.1362913-9-0@icann.org> <647558F8-2FEF-4418-AE1C-3BDC3B22A89B@nohats.ca> <1cb4663f-9502-47db-a099-ce5147bb733e@desec.io> <94ea3a71-6c1c-10af-a71f-7cee34e8d0d4@nohats.ca> <F21226BA-266A-4BF8-AD17-0D908B10AC54@nist.gov> <rt-5.0.3-189191-1713786135-470.1362913-9-0@icann.org> <rt-5.0.3-1375868-1714672753-112.1362913-9-0@icann.org> <b09163e9-be13-4b94-b4c9-759ca7a2965f@desec.io>
Content-Language: en-GB
From: Daniel Salzman <daniel.salzman@nic.cz>
Autocrypt: addr=daniel.salzman@nic.cz; keydata= xsFNBFljlBcBEACuCSBlN1vTS9eEDqowZcLAAF8NytcTlRjXTLWMQtjU+fXkz9Vz10n9TIFj 9Kcec0p0+8F+SowybecwhmYoUzhKI7S9M1ziUmaIhFs2KvZ1GzigE/W5L448P/7pugh875e1 tIrkrbbcIp6+SxaLbgvXlFl630ILZl/gbYOa/Wk21sLu4RjQY39oHb0WTiwPnKhdMdwlnxm6 HeWkHzlvI9N8tlDc6oVnUfqVI8gUyExLnEYjDpZforTVgHRq6RNyfTRZkh8zRsXSTnJlk/bV EDW5i/VgIQugzkgpuTGWlCstryi/MRheNxU1YEUenT69okb96QStfr1J00n8L4VAs8V5IuFU cSc8UqSpB+LgERRTMRFo9IrEXAW/gEKlEVR+501BvJ0/Qggxbgz4PEnKNaxXmAnykJzot2VD KTzrr26a9LnrT0GWom9rg89Ih876PA53vUXBB+FWP9QOFDcOfz3nMjCrLbMzhTsAzrNFXxch zLq+66CLqsQQytDVFpLI+X++sKRTOHkq6vV1bAPjlljrannLnn1y/DvkOOkiHOdYyjmR7Dfk vxgcWh/3Gx4J9gipxZITOr7LamEYgHfElY/UWCtc1Vjt8Xvgt4dofDpvSwY9YzgRWxJKC5ew YdqTCI+zxL1f0fjkeiRYNi959UMMjgdcY7Zpi8oPPQmlyBw15QARAQABzSZEYW5pZWwgU2Fs em1hbiA8ZGFuaWVsLnNhbHptYW5AbmljLmN6PsLBlAQTAQoAPgIbAwULCQgHAwUVCgkICwUW AgMBAAIeAQIXgBYhBHQvpOlYKbbF6sa4VxC7evb+u9arBQJhp0QqBQkRkKUTAAoJEBC7evb+ u9ardC8P/3MOFkzXxU2B40C9YHLH+VU5omunG9yIBGBYRuBhhtgfHAfYkYxmOvRcXPknNeR/ 43tjH3YPlXsbBf3R4aD59MDIw0zhMB+TWyHML1P+p6PhxNRXCK6eaKRXW9d+/uaeMke46h6q tjVq3nPiBaKtfLIwqE2mD95uClxDt/4PGwuA0kWKFT7DV4gUwqcZqWtIGHrY0gglayT6F1Vo +x71cyGOKCiBDezv9LLuEANX62fA+/+zrGPWMFX4FA10lnBiww5cQQUG81NurnuvObYLJPdE p8b2GnlJ0MNAebLHP3qEetliXW/aHqofyiuzwSADvkjLaqwR58lJIRudIGgDKkCh/ZD2UCBT DVLBm5C/+Yui5sJWqLT0e5U5vLIosXHODIVEy9jC8mkMqYuG8CeqLiJeGolBNEzlolzWh2yc JoZQ7hGm97mNP2MQazgITbN4C7m8Y7WdJ5V1yKw8n6jyOLeEVS1b+0g2R9PKDC8taVH4o7xg zx5M5d4jybR23ic9vo17WzWL+Km7iF5LtcPKO88HX+bmSmZYiCcLrBDIPVrtt4OHriwjJte8 nOmZfRenUmI92oLuAflgWrR7OdnklT6PrAEO2X7nkjoP4iBRjYFXisZeNdLGGfz2BEoPyfFV QaFZjWWwbDRS2oYqIfr4aQ/akvaTszPfhbgsAq/AS2+czsFNBFljlBcBEADpGfFgbzb9f4Dj 2yuAdH3IjGUepKroiE2f6IlDmWlWl94Ei04bg0O7gCrlfjWkAnc0rGwI9XraARqV38LuAmtM jmtqD/zsZgUWjpBGvAaxZUY5Eaz0bWkEXtlnCE8nAPcx5qAZk19ZnNHFd58vU/eauk7d61IQ TAQ0e0KoQw/rH8keHdIqicoCUvjF+PcXnhoqPi6khyPEYEAkfy7rps3UaZiOy0HPNsPhNY1P B8qCnXlfGOtOBtOEXLsIGg6BxoCmJhM8TsPmcHX4DKEaOc7dmU2DLVkgdUMWTocRqRqooz1C WQmdmwHb5xOpeVXR62YVCx50KDaxSJ6vSGEisQ460ZBtjU/7S+/5VGho3KbeuK2X7vREbxaC sc0sxEdUZ4tGreA4We353/eHuZ4Aps5Fb9ljfRSnC2G2VliByIXOgMkJbwF7WLVfi2iJRoyQ WHv2N3thO9nzv4/gOWUL0w2yirlxj9scE1li1d/vLpepWpijYhsVRHdVcq3NI3l5iblikU9z POaDVs2CXeLpYFw4XgQ8QkRWNn67Wvn0299UtDxdWH9CYugbvHygVy+FZy0zLXtV2bipmOlI D4HWxChx6F2tr7FP49ZXSRytimyrCRh4VFCckaoi6lYeei2oY4E0DJBYhyMrornLQJ6Kglmk 03k57leWgxexiaBexH6BNQARAQABwsF8BBgBCgAmAhsMFiEEdC+k6VgptsXqxrhXELt69v67 1qsFAmGnRF0FCRGQpUYACgkQELt69v671qtpnxAAjNYg3w6FpPLJ4bjnU4Z67v7nGdia4/uN MaUW4/hDrhW3lYBznh2EgsLLalEiYyX/Qx+OrdY452pJBWJqgmkcWSCPLzP0wVf+FmosLnug OY2cjxf9sb8CkYxAPtSh4Afit5x/uOa2pHItR4N3bA4SxJEgK3JzMf+bjdRy3iRKFc/a6LW+ oA/yn1S190iaDI1ZX3UnflKPFKIW+n5gC42f6OycOJUHNgkCWT+t03WHoT5wN+n8ZhpcONXE vLxuKm4Q3mJxkYwfbS2SJWy89Dkn74A5Kt4jzfQTrYgkEpT2TBBr2JJtbG1yfEmY4RUEY3aA n7ZYB3a4D1kIIlp9NeJV7nshzF3Y/nNGqsOfRsCYjKXTg0qdUCe2FAb5vqES65oqFOSPZO+G ZeQfzgFwC8oLzbI0FzXOvPF8sj9Y9kmuHYhWFdZWFbXdh3p5SapSTynSFDlmF0v0Pp9AlJfG R2Jq4wmi/UKeNH/74060REFKT7uFtNv3bWr9usxleAn3vW7fVvSxGh5/JttuMdJaM1VI/oQ2 fjh5B9LToJSZzug3XxsaEeaWaErhrP2Ll5DgeVQTkr1/jPvJBFMzpd8inMOtY58V9pi9iRwL oJtHzGdv4s6WrAofMpXChYYtKt55KGo99rNASNHdXnZd0WbJUiuW2PslHGK1bb2So7T0ARqV H2U=
In-Reply-To: <b09163e9-be13-4b94-b4c9-759ca7a2965f@desec.io>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------p0gSnfFBUdIMgWlidoRvA0Nf"
X-Virus-Scanned: clamav-milter 0.103.10 at mail
X-Virus-Status: Clean
X-Rspamd-Server: mail
X-Rspamd-Pre-Result: action=no action; module=multimap; Matched map: WHITELISTED_IP
X-Rspamd-Queue-Id: 8C86A1C1381
X-Spamd-Bar: /
X-Spamd-Result: default: False [-0.20 / 20.00]; MIME_GOOD(-0.20)[multipart/signed,multipart/mixed,text/plain]; FROM_HAS_DN(0.00)[]; ASN(0.00)[asn:25192, ipnet:2001:1488::/32, country:CZ]; WHITELISTED_IP(0.00)[2001:1488:fffe:6:e8d1:1049:6c13:6dde]; MIME_TRACE(0.00)[0:+,1:+,2:+,3:~]; ARC_NA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; FUZZY_BLOCKED(0.00)[rspamd.com]; HAS_ATTACHMENT(0.00)[]
X-Rspamd-Action: no action
Message-ID-Hash: LXOGDRCVDORSTMACKQMT7FFY6HGN4NDC
X-Message-ID-Hash: LXOGDRCVDORSTMACKQMT7FFY6HGN4NDC
X-MailFrom: daniel.salzman@nic.cz
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: scott.rose@nist.gov, nils@desec.io, dnsop@ietf.org, oli.schacher@switch.ch, q@as207960.net, christian@elmerot.se, paul@nohats.ca
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [DNSOP]Re: [IANA #1362913] expert review for draft-ietf-dnsop-dnssec-bootstrapping (dns-parameters)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/05RPkbpDu1sexDjqfQAb5rd7kyg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Hi, On 5/7/24 09:33, Peter Thomassen wrote: > Hi, > > On 5/2/24 19:59, David Dong via RT wrote: >> Following up on this; does the group agree that "_dnssec" is OK? > > Looking at what's been said in this thread: > - Two people have proposed to change the label, current proposal: _dnssec > - Two implementers have said they'd make the change but don't seem convinced > - The authors (hats off, but also implementers and authors of current drafts using the mechanism) are not convinced > > The authors don't feel comfortable declaring consensus in either direction (neither do we know whether that's our role), and we're not sure how to proceed. Perhaps the DNSOP chairs could weigh in, as > the discussion is happening on the WG list although the document is technically out of the door ... > > > I've been reluctant adding the following argument as to not seem insisting; OTOH it may have its own technical merit, so here is. > > The "_dnssec" label implies that the mechanism is not suitable for signaling unrelated to DNSSEC. That's an artificial limitation, and it's unclear why to impose the restriction. An operator could > very well want to publish other things, like > > - TXT at _abuse.example.com._signal.ns1.provider.net for an abuse address, > - PTR at _catalog.example.com._signal ... for catalog zone membership, > - ... Besides the fact that keeping the current label name is a little bit more convenient for our implementation, I like the idea of a general mechanism for signaling various states in DNS. Thus I would prefer staying with '_signal'. Regards, Daniel (Knot DNS) > > If the signaling method is generic, I believe it should have a short generic label. Any specificity to determine the kind of signal can go into the first label. > > I have no specific preference for "_signal" other than I don't know what a good alternative would be. Narrowing the scope with "_dnssec" doesn't seem to improve the situation. > > Thanks, > Peter > + Nils (for the "we"/author statements) > > >> Thank you. >> >> Best regards, >> >> David Dong >> IANA Services Sr. Specialist >> >> On Mon Apr 22 11:42:15 2024, scott.rose@nist.gov wrote: >>> On 20 Apr 2024, at 19:38, Paul Wouters wrote: >>> >>>> On Sat, 20 Apr 2024, Peter Thomassen wrote: >>>> >>>>> The authors certainly don't insist, but we'd need to pick a suitable >>>>> replacement for the "_signal" label. >>>>> >>>>> John proposed "_dnssec-signal" elsewhere in this thread. >>>>> >>>>> The authors would like to note that adding "_dnssec-" eats up 8 more >>>>> bytes, increasing chances that bootstrapping will fail due to the >>>>> _dsboot.<domain-name>._dnssec-signal.<nsname> length limitation. >>>>> Other than this (unnecessary?) use case narrowing, this choice seems >>>>> fine. >>>>> >>>>> That said, does this choice address your concerns? >>>> >>>> It would, but I would also be okay if it is just _dnssec. >>>> >>> >>> If the concern is that the label is too generic, “_dnssec” might be >>> too generic as well. If it is to be more precise, go with _ds-boot or >>> something more specific to the use case. I don’t have an >>> implementation in the mix, so it this isn’t a strong opinion. If the >>> group agrees _dnssec is fine, then I am fine with it too. >>> >>> Scott >>> >>> ===================================== >>> Scott Rose >>> NIST/CTL/WND >>> scott.rose@nist.gov >>> ph: 301-975-8439 >>> GoogleVoice: 571-249-3671 >>> ===================================== >> >
- [DNSOP] [IANA #1362913] expert review for draft-i… David Dong via RT
- Re: [DNSOP] [IANA #1362913] expert review for dra… Paul Wouters
- Re: [DNSOP] [IANA #1362913] expert review for dra… Peter Thomassen
- Re: [DNSOP] [IANA #1362913] expert review for dra… John Levine
- Re: [DNSOP] [IANA #1362913] expert review for dra… Peter Thomassen
- Re: [DNSOP] [IANA #1362913] expert review for dra… Oli Schacher
- Re: [DNSOP] [IANA #1362913] expert review for dra… Daniel Salzman
- [DNSOP] [IANA #1362913] expert review for draft-i… David Dong via RT
- [DNSOP]Re: [IANA #1362913] expert review for draf… Daniel Salzman
- [DNSOP]Re: [IANA #1362913] expert review for draf… libor.peltan
- [DNSOP]Re: [IANA #1362913] expert review for draf… John Levine
- [DNSOP]Re: [IANA #1362913] expert review for draf… Adam Burns
- [DNSOP] [IANA #1362913] expert review for draft-i… David Dong via RT
- Re: [DNSOP] [IANA #1362913] expert review for dra… Paul Wouters
- Re: [DNSOP] [IANA #1362913] expert review for dra… Paul Wouters
- Re: [DNSOP] [IANA #1362913] expert review for dra… Rose, Scott W. (Fed)
- [DNSOP]Re: [IANA #1362913] expert review for draf… John R Levine
- [DNSOP]Re: [IANA #1362913] expert review for draf… jabley
- [DNSOP]Re: [IANA #1362913] expert review for draf… Paul Wouters
- [DNSOP]Re: [IANA #1362913] expert review for draf… John R Levine
- [DNSOP]Re: [IANA #1362913] expert review for draf… Peter Thomassen
- [DNSOP]Re: [IANA #1362913] expert review for draf… Peter Thomassen
- [DNSOP]Re: [IANA #1362913] expert review for draf… Tim Wicinski
- [DNSOP]Re: [IANA #1362913] expert review for draf… Tim Wicinski
- [DNSOP]Re: [IANA #1362913] expert review for draf… Peter Thomassen
- [DNSOP]Re: [IANA #1362913] expert review for draf… Peter Thomassen
- [DNSOP]Re: [IANA #1362913] expert review for draf… Peter Thomassen
- [DNSOP][IANA #1362913] expert review for draft-ie… David Dong via RT
- [DNSOP]Re: [IANA #1362913] expert review for draf… Warren Kumari
- [DNSOP]Re: [IANA #1362913] expert review for draf… John R Levine