Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD

Geoff Huston <gih@apnic.net> Wed, 04 April 2018 04:30 UTC

Return-Path: <gih@apnic.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 08871126D05 for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 21:30:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=apnic.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vdP1NX8wLxHW for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 21:30:34 -0700 (PDT)
Received: from APC01-PU1-obe.outbound.protection.outlook.com (mail-pu1apc01on0078.outbound.protection.outlook.com [104.47.126.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E5C9124207 for <dnsop@ietf.org>; Tue, 3 Apr 2018 21:30:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.onmicrosoft.com; s=selector1-apnic-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=UvmTWUFDf/6tPhxSzKgmGWUuvWllteShf/eEjVNgwIA=; b=UBPAJc6xMzkHTDvZup0izczwLnpaW31AsKe/Y5cfZd7xSDnPEmQBZ2hRHeoyIguWrPiknpgqH3evP4sCE4frjkfo93CeL9h0i6J6ojgcXYUEvr8GQyeTZr9JAHS5+4VQinUERHypQ8gtkxX/76N1vzbKjofliB30/RVX0NuZz9o=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=gih@apnic.net;
Received: from [IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c] (2001:388:1000:110:68a8:aacd:ca4f:a91c) by SG2PR04MB0693.apcprd04.prod.outlook.com (2a01:111:e400:520a::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.631.10; Wed, 4 Apr 2018 04:30:30 +0000
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.3 \(3445.6.18\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <3282A858-194C-4E28-AA2B-28F0881B9BAA@isc.org>
Date: Wed, 04 Apr 2018 14:30:20 +1000
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsop <dnsop@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <50B1B4C2-29EC-4CF1-946F-95D823A15860@apnic.net>
References: <039408B0-89EE-4038-B9C9-CBCC35EC24EC@isc.org> <64816369-700A-4413-B1F0-160FB145EE6C@gmail.com> <BF3E4F4D-027C-4A2B-8026-14AF3FBA4603@isc.org> <2F103A8E-72F6-4159-900D-B7006D0AC647@gmail.com> <6D617FAC-D981-4AE1-8943-4F0D12C46397@vpnc.org> <0B0775D9-B5E6-4778-A199-FE4D09A0BE17@apnic.net> <D19F6299-922A-4DCE-8E95-85CA72E63129@vpnc.org> <A4AA3F56-12A5-4951-B01A-450B493E0E4A@apnic.net> <412D2533-2332-4F38-BAC6-4C5AF391C124@isc.org> <756BFAD3-2867-4646-B028-7D93C05BA8F3@apnic.net> <167E8357-FE53-43DC-84C6-B720BD8069E4@isc.org> <E7EFB44E-09C8-492D-AF9A-7EAAECD729D5@apnic.net> <3282A858-194C-4E28-AA2B-28F0881B9BAA@isc.org>
To: Mark Andrews <marka@isc.org>
X-Mailer: Apple Mail (2.3445.6.18)
X-Originating-IP: [2001:388:1000:110:68a8:aacd:ca4f:a91c]
X-ClientProxiedBy: HK0PR03CA0010.apcprd03.prod.outlook.com (2603:1096:203:2e::22) To SG2PR04MB0693.apcprd04.prod.outlook.com (2a01:111:e400:520a::19)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: e31d80ad-8ce4-45fd-4f0b-08d599e4ccfa
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4604075)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:SG2PR04MB0693;
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0693; 3:ZsT3vcR0MuKhbajYx2Gt1FqpPRvldB9VtPtlDFh8Y5/amY8sZZYIlZQg0L9AH1nOrIIwxFEXz8DHk1teZU/ziyshP/H3ObQJWO2KA2/ViidnCFhFeve2u5Vd/dkR7klqsR8dqTjY9CrFlNgRykid7Xi+NjOPnYDUrLUQIk8xaGGZtydhqM+JvvhfcIfjLg51HtgEZppCpKTn1Tt9dnnhJDI10bqPKCXeYEBu5U2gttXsW9buTLldLovXVEU7ggf5; 25:lqoAW8ApZll3C09b5CoL12pH1yE7dgebKFaThRl0iWpB5rreJRtR8yzIFRRZEwGx02cgpy8trAC3RdWhOe7NH9RMhmU4Dykw3V11bL3dxvy5sRChdsGxdU7KC8EZsbg3atGPML/MpebWxEbV5h1YWSXTQnSkWdgddKUvtZ39GT1c+sLOBM8V4bemztcryPTekZdZziu1u09UJFMY6lC/IMMgwnuFBaRHicPQ7xbivV7CCGV7aPrkQypv9pTbe4B+Ld5kiPYEXriFbRAXSyJ+IU0Fi9Yj+sTxmesUKCV93OQff/LUp4KdBei9CKxna5jp8vp+ly+2oGZaDny7bv6cWQ==; 31:eo+WN2d7dimunRlfVBb/emodunD/N+ngk8rJ/M1SMhHaFshSyY4Dc70kAEu0x/HxeWYx5L743l+6cCC1EPwXYf0L2qqnkPhStBf2mdPswwhsUt4EiAZqrNwL0kSebcRdpTgWNz+M373tLbkxJWDlFsl4kc/Bs75DNmRYQrzXsJKV9nUFZKXKod279XjRnAOK9fpZFZ0nQG/bfvktpKUivlKTspkp8LDubaEEIphxGS8=
X-MS-TrafficTypeDiagnostic: SG2PR04MB0693:
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0693; 20:5slRlWufStCObL4eZ5sT7ZHleltkxCyty72vl/q+fyS1GrmrhmhKGBgMiJ3qFklz9JnafQKiYaln69z1Xtk+k9dgTMyDoWt5SvhzlwNK5BSYsWC9IwEKmcBQ8bvu8j/pNWLMMp+i2Ab2WEL53gA3GVnuRYF1EHLcKoKQ4qK3ueenAPgxzKwLMTTEP7zcfNbr/W191F6OTvvA550hzHym5wcVagQ5B+E/awSvvxry1W3MugMQSoBqg2asB+q/GLOp; 4:LgPSXubVujU8kaH36ByYaElmkrM1ShAtwuHqYaaBnfD8ebXZjV976DTB3GsUX8a3+94UIH4v5IAunytcvb0cStrSQZWzDxv4NqtC/6B+JuuqBkUOHTYtLViMxv2c9GylXftewqZgWuYAWl7rlgGRwIjIM+rc+FFEbh7BiZOSr2FeHM95jVUPy8bqll4d9/SKIM/6dCXQqwH0ZLB5dvXWe9zdMzw9YQkZ0y8n6C21Ze2z0W4kZWmDYSobkM6MNdrF5fQ/e8RGPv70FZY4yGNDR9XOnPijDN7ryJM+n5W1S1JWyiJSTBuvOHsNkKsIWx8o
X-Microsoft-Antispam-PRVS: <SG2PR04MB0693B55DC021DDF897923878B8A40@SG2PR04MB0693.apcprd04.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(17755550239193);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(8121501046)(5005006)(3231221)(944501327)(52105095)(3002001)(10201501046)(93006095)(93001095)(6041310)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123558120)(20161123560045)(6072148)(201708071742011); SRVR:SG2PR04MB0693; BCL:0; PCL:0; RULEID:; SRVR:SG2PR04MB0693;
X-Forefront-PRVS: 0632519F33
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(39850400004)(39380400002)(366004)(396003)(376002)(346002)(189003)(199004)(476003)(16526019)(8936002)(6666003)(52396003)(186003)(23676004)(59450400001)(1706002)(52146003)(76176011)(52116002)(82746002)(86362001)(4326008)(106356001)(47776003)(2486003)(105586002)(2616005)(2906002)(81156014)(6116002)(81166006)(11346002)(8746002)(446003)(57306001)(50226002)(83716003)(229853002)(386003)(46003)(8676002)(50466002)(97736004)(54906003)(68736007)(316002)(6916009)(93886005)(5660300001)(478600001)(33656002)(7736002)(6486002)(25786009)(305945005)(6246003)(36756003)(486006)(53936002)(42262002); DIR:OUT; SFP:1101; SCL:1; SRVR:SG2PR04MB0693; H:[IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
Received-SPF: None (protection.outlook.com: apnic.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;SG2PR04MB0693;23:GHHSGukcy06TMhF7oQQIOpdC3aTTdUlcdONK5Wal+aYl41yhNcftLVJkP77qRCrWz9f3P9u7qPgpV0qij/DKhYB/YimRVWeQbdM0xy7/Zq66MsZ/cDzQz1fXCtkr5GphH9yAeInRWs+7SeatIKjQG/0EPJgd+sYV26UWOKQVsjJV8t7XaiaSTCgIakQwHuRiyaThC1vIoszxp2eWMyqChjnoaGbMZSb4WyjMzp2uJy010Qm2W5FsZpGkfr+CFYJzltFUkNNBvlkH3EVbD/m8VTphFYzkKmNacYGhdcJkHmHNWYAuO5D3GIq+o927v9rc0maqTSgiCS66phGtIGOP0vgwDOkEnz/WpwDLckIAkiqonFGGb/F/cjE1W2djP55KXIoBupyA1RJoqyVpkkaaeBF7E6C/qtCiNrYXV6+SgP0HF9MJ+EBcjIQuQ8cYRc+DtpnNL4Rg0OVJobT+Xz7QIHq6g/HDNKsjJBprwgPxg2Jqb+a6I84HCkhKehkS1zJej4LE1hnJvne95GKXeEHDJFs9wX1AuTbPiHuC+0qAu2e4upa3SAMUCitVm6fkGGy3p6zluL2pbdJ/mV+3H3AuExNpOEX4SM2/imtc8C3f5e9tyFprIqh7g5TngWvq7c3yPUsDhzOzj7xuLbEJM/kAIp4i90or4NLFQiO7PAxKb6qbWfptJMrYWtw4wO1xFSPP5I67mWgH80UCnMUUu2vboi73AbiBhg5dU2jGB1fXk7ipw9yrOaywVQk4K5KI6Umg0tUAzoork/eKKoyEl7irMGUh3dsExWKKlubTLo/OCej8FX2evERpFohBOFABMsP3e5tJSNWu39O6cagK9ifyLWRMVGbl6W3lZgiZZMRc9pF+SPVnUfMM8XSEDXOCj4/7mPD6Y8TDUxQHpWdZtdtWXW3Ccn+SEUg+fNxEj3olZaRIUPZG47FMgYtacC9VZ8F8Omanm9o5Oo642qRbMOVGM2CwQUbt4H7uwrMRX1w0b5mYrbuR9qBIZq/tAhsJjrLF2FIR+wPuN5nYHRJNH0aVIynb2Y8OJlcGlmqvpw6gUFPlnHWj/e7cYOjjWIStgjuE0t0+8bG0x0T8Y+Jr9dEYXf5udobQ5AjigsBf4pAgJ1+QNpUIeJvfIBjkmRd29ggWPGFAaN57Z/cmocRrx6x+ApPR9d9nLmpAhT2V0gjBqwYJZ+z+tlTIUySAI4MnG1Yun2sWRaiKnAx3z0rjTN+XBtOphAb/DEyZgwh61k17bABKXCcYwkcdswSvMJjHpgqfWfrsTojb72V/vo9neELqF7ghMAS8EL9+4GZM1iMMAqRSfJwmSjs9k8+kj/M8lEC+w9ahHrq7x+sWVe7/UR9o5Q==
X-Microsoft-Antispam-Message-Info: /Sv8PKHfW4LOX4vGl0yCGl62JQsCA9MaUa8dXCOlvCiGS/ZbFA/rCGm3S3ElQjPfBrmWeTK+gLPpHCKDHCIW1h18q8DOCNsyfGAxd0W6ktuh43rcbwRY9lxOC0qRViAET+49bopeztgqo0NTP+6PwxVsDbcw2bArCT0D3DQqPhHVK3pVHmpOPLq9+WU6Tn3r
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0693; 6:36qCzqJO1BvZBFpkSEIdEMfb6DucsxT+dJPhYEj8ZZ5VTAdP+GCvf/q9F6dGUM04By+Ea3id8vtyTbG7mumx3wIiQfsLnzIU/a1190zAoaPk1qkqog7c3N+nJr487OVaKSOvo9sldSdQ1Lh2twvR9tntBZDLxeV7tf1iTee5dB/g7gRF3VEQ/XYLT2OzQBGM61zn5LiZPa+7rdT4W/Aorm39ySamEktewX1IlPGrQbLIOLYjw1JL7T2qlA1hUKqfUzulbBVuSwsST6c6criDXHpgc5Py7kunQU6WEWXSs91VdcBSmSujlfUqDo4HKl4QT3N1WP/dozW+u6ZlXB02ErDpsLAp3KnwtmDSGr7YyP9IL4cB2EXOY8bYy9HN8viAGLBbEaKwjOdOVQyEYDOcX3f1/dzrRgHMGneiHRjwiQ8h/ikTgKPS0hJj6tpzOka8JxOyrIYfVesX1SQqKlPbhA==; 5:Hf1b7Oi4oE0xHk4xNgPaJRUUGbRaJSc9z5X69EG/lt5zmf7YQi3EUM6GNnh8ZPDOKlWSt0fpY9nTxCFVYJ8O+ruB2BXur0zE0drFUfOxjSypXmiA9MHPv6JhCfXm/1X8OTSSNZpJgcX3UoDd5ub5N/6ZGP1iBxr5Dr3Ig606dxU=; 24:avQ1jRaomD9ahYSrlp7XWzmkasjeg5cTB/mQ+vQMgbAsGpyyLEb9l9CHIKxagiEQq0iyyAORJtnUBGe4b5FuoC7xTgvfoeQc+rZLegZBz0o=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0693; 7:zj/4M2zvGKI6i7nWgdy5CFUl1HtAn0K/yQPMZD/2W1gVJbN/VHExmb0+4TNEbyXfpmIr9uuMvuwBzdTdE3zi29lj6apMszT+rMEhkX5AoUFDUV24LPZG4nV2KQs37n9lzWZ0lxtLSOZtx8i3bxvSE6z0ll36/MEVxV0En9DDlgNIsk58kamR/+YGVi7ZePPqwiHMtwOyqIyLAha+1Pg6C3rM6vTAvQhPB092SM8J9JCRPz2uoHvHUEUmXhNv4eWk
X-OriginatorOrg: apnic.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Apr 2018 04:30:30.5373 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: e31d80ad-8ce4-45fd-4f0b-08d599e4ccfa
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 127d8d0d-7ccf-473d-ab09-6e44ad752ded
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SG2PR04MB0693
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/1AFL6DX2zxdrJQ5PEQhAQjmtX68>
Subject: Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Apr 2018 04:30:38 -0000


> 
> No.  Below is self contradictory. Condition 1 requires that
> CD=1 be turned into CD=0 and condition 3 requires that no special
> processing happens for CD=1.
> 
> How CD is handled determines what you are testing when you have
> resolvers in series.
> 
> Do you want CD=1 to disable special processing?

yes

> Do you want to only test the first validator?

yes

> Do you want to test the entire chain?

no

> Do you want consistency?

err, umm - yes? (is this a trick question? :-) )

> 
> All the scenarios need to be worked through remembering that there
> is a cache that may be populated.
> 


Mark, would it help if the phrase “regardless of whether DNSSSEC validation was requested.” 
was removed?

i.e.:


 All of the following conditions must be met to trigger special
 processing inside resolver code:

 o  The DNS response is DNSSEC validated

 o  The result of validation is “Secure”.

 o  The Checking Disabled (CD) bit in the query is not set.

 o  The QTYPE is either A or AAAA (Query Type value 1 or 28).

 o  The OPCODE is QUERY.

 o  The leftmost label of the original QNAME (the name sent in the
    Question Section in the original query) is either "root-key-
    sentinel-is-ta-<key-tag>" or "root-key-sentinel-not-ta-<key-tag>”.


Geoff