Re: [DNSOP] draft new charter

Edward Lewis <edlewis.subscriber@cox.net> Mon, 07 April 2014 16:41 UTC

Return-Path: <edlewis.subscriber@cox.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 457821A07D2 for <dnsop@ietfa.amsl.com>; Mon, 7 Apr 2014 09:41:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 89wm1Bl8Fcm6 for <dnsop@ietfa.amsl.com>; Mon, 7 Apr 2014 09:41:02 -0700 (PDT)
Received: from eastrmfepo101.cox.net (eastrmfepo101.cox.net [68.230.241.213]) by ietfa.amsl.com (Postfix) with ESMTP id 318C51A01C6 for <dnsop@ietf.org>; Mon, 7 Apr 2014 09:41:01 -0700 (PDT)
Received: from eastrmimpo305 ([68.230.241.237]) by eastrmfepo101.cox.net (InterMail vM.8.01.05.15 201-2260-151-145-20131218) with ESMTP id <20140407164055.PATN16123.eastrmfepo101.cox.net@eastrmimpo305> for <dnsop@ietf.org>; Mon, 7 Apr 2014 12:40:55 -0400
Received: from [192.168.1.110] ([68.98.142.232]) by eastrmimpo305 with cox id n4gu1n00M513AP0014guf7; Mon, 07 Apr 2014 12:40:55 -0400
X-CT-Class: Clean
X-CT-Score: 0.00
X-CT-RefID: str=0001.0A020203.5342D517.00D7,ss=1,re=0.000,fgs=0
X-CT-Spam: 0
X-Authority-Analysis: v=2.0 cv=Sv5OHoy0 c=1 sm=1 a=x3e9yDt9dqT69S6Zli6DPg==:17 a=G8Uczd0VNMoA:10 a=N659UExz7-8A:10 a=kviXuzpPAAAA:8 a=dmoAGAJnAAAA:8 a=pGLkceISAAAA:8 a=-3NwdCiod6rlxChyANYA:9 a=pILNOxqGKmIA:10 a=MSl-tDqOz04A:10 a=B07CLaolugQA:10 a=gwWCjD78Yp9J4iRp:21 a=bMd6ow9QnRaNG-Md:21 a=x3e9yDt9dqT69S6Zli6DPg==:117
X-CM-Score: 0.00
Authentication-Results: cox.net; auth=pass (PLAIN) smtp.auth=edlewis.subscriber@cox.net
Content-Type: text/plain; charset="windows-1252"
Mime-Version: 1.0 (Mac OS X Mail 7.2 \(1874\))
From: Edward Lewis <edlewis.subscriber@cox.net>
In-Reply-To: <lZg81n01y0xxhYs01Zg9kg>
Date: Mon, 07 Apr 2014 12:40:53 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <0B4A43E9-E8F0-4964-8A27-A1C2D2A52C26@cox.net>
References: <lZg81n01y0xxhYs01Zg9kg>
To: DNSOP WG <dnsop@ietf.org>, "<dnsop-chairs@tools.ietf.org>" <dnsop-chairs@tools.ietf.org>
X-Mailer: Apple Mail (2.1874)
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/0CWMvzvG8oVXynOjY0IrJs4fNXc
Cc: Edward Lewis <edlewis.subscriber@cox.net>
Subject: Re: [DNSOP] draft new charter
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Apr 2014 16:41:07 -0000

This charter seems to fly in the fase of the traditional IETF charter style, wherein a WG was deemed to have a set end point.  “Develop guidelines”, “publish documents” and “serve as a clearinghouse” are terms that engender more activity but don’t indicate progress.  (A long time ago, in a government job, I was taught terms that guaranteed one would never fail a performance review - like “participate in” and so on.  The terms here fall into the same category.)

Comment on …

… item 1.

Don’t attempt to list the functional roles name servers name servers fill.  Most roles have never had formal definitions and in the industry “roles” have been used confusingly.  E.g., many practitioners think “root servers” are the servers for a TLD or are the (authoritative) servers of any zone.  While terminology can be refined and new definitions given, the confusion today means that the role labels don’t fit in the charter.

To be more specific, what problems exist in the current state of DNS operations?  (I believe there are quite a few.)  The specific issues the WG is willing to look into should be enumerated.  (A blanket charter is a bad idea - a restrictive charter can always be updated, a blanket allows for “make-work” items.)

… item 2.

DNSSEC is a clumsy protocol extension.  Empirical evidence suggests that it is - (without a quantitative study, I’ll go out on a limb and say) most DNSSEC validation failures stem from operator or operations related errors than forged messages.  What can be done is come up with a way to counter the “lack of a child knowing about the parent” in the assembling of the signed chain of trust.  I.e., sending the key material from child to parent.  Other needed improvement is to develop practices for debugging (SERVFAIL means what?), monitoring, and measurement.   E.g., The RFC for DS hash algorithm 2 has a trigger in it for when algorithm 2 is well deployed - but there’s no means to discover that. (http://iepg.org/2012-03-ietf83/IETF83IEPGLewis.pdf, slide 23)

See also “Crypto Alg Undertanding.”

And another topic here - clear and understandable guidance on the parameters of DNSSEC - key lengths, durations, etc.

… item 3

Again - something specific is needed.  I am a loss here for suggestions.  Hasn’t DNS been ready for IPv6 for a very long time?

… item 4 and item 5

This is kind of like saying that one of my duties is “show up for work.”  Isn’t #4 just saying the WG should act as WG?  “Protocol maintenance” might just mean adding DNSSEC key algorithm numbers or it might mean a new zone transfer protocol.  The latter is something I wouldn’t think this group is wanting to take on.

(I had written that for 4, but then I saw 5 gave me the same impression.  In the sense I do see 4 and 5 are different, if I have the same reaction, they are two general to be “good” charter items unless the goal is to have a never ending WG.)

… item 6

Already commented on that.

On Apr 3, 2014, at 17:39, Suzanne Woolf <suzworldwide@gmail.com> wrote:

> Colleagues,
> 
> Here is draft text for the new charter we've been talking about for DNSOP.
...