Re: [DNSOP] KSK-Sentinel -- "Walkin' on the SUN"?

Matthew Pounsett <matt@conundrum.com> Tue, 15 May 2018 16:25 UTC

Return-Path: <matt@conundrum.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1344B12E87C for <dnsop@ietfa.amsl.com>; Tue, 15 May 2018 09:25:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.608
X-Spam-Level:
X-Spam-Status: No, score=-2.608 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, T_DKIMWL_WL_MED=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=conundrum-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IoP-NcxSP60H for <dnsop@ietfa.amsl.com>; Tue, 15 May 2018 09:25:28 -0700 (PDT)
Received: from mail-it0-x230.google.com (mail-it0-x230.google.com [IPv6:2607:f8b0:4001:c0b::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A923012E8D3 for <dnsop@ietf.org>; Tue, 15 May 2018 09:25:26 -0700 (PDT)
Received: by mail-it0-x230.google.com with SMTP id p3-v6so3018600itc.0 for <dnsop@ietf.org>; Tue, 15 May 2018 09:25:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=conundrum-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=vfS/mHBNdaUbr+fa2Rz/aIA170ZpqaWoDjX/VWXPtMw=; b=URag+2Oze8SHM30/ulkGGgdJi0eWgrNHwAdhxrNyoR96/2iz0tqjUKjq9/msbG/GZ0 N6SabF5GxYNJH3fwEUlj+eckWHl2jwhjbPO8ZuqTD/gVrZ1FdyGpuQPOs42AZpk0gksi n+vlM3wsiDkg3st5iTkTcJ/qW6hyK40AIo0UhDTPvtdLQj7+suHQP5esxDHXLWHyMa50 dCIg6VNq6fDwZ3WCOtbvhCXpyRvpCkeuytaBcqRG112rGfe4nHL6naMLA3x+Snq6JTTS PpH0AHxE8DyD5Wro0sPB9s7IdNR2sc7R8DT23jzVVIWpcPQPoCQDyNtQ3kZBSR1sCdy3 5wvw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=vfS/mHBNdaUbr+fa2Rz/aIA170ZpqaWoDjX/VWXPtMw=; b=hguGUfsMX6k4JB+01vuCfRW3RiqarMegpO1fSsEOrNAnvfvRJtWuhJNNFRUdRooOI7 WgOVsSywLzXS86359U2KwLoRQ9BEGwsCoIgRfqNyICXY05cgzgaamquxajISJC3NWN3/ xXEPf5SUyJ8lA0OAyDDEhAkBZW6YUr27ieukaJ2uTGaAcaPUIFpWllCWc4sDI29d4ISl bS0qIWKAH6pgn3xuxNvYsVb9eCCFC3yPOD7LDmPGnMBQIFRkxqTXSGBELy0JX8TaqeQk gEgT6dYmNJcTpug1+JNC2EAQ8+UIaZAKinuhRpVQsDIqc0D0mtUtjME7w40xWxW9bvTT q+Yw==
X-Gm-Message-State: ALKqPwf8d7aESpO5PuLH3j9igYF9ZFHAJXv3djIrtzzaxGHL9zYhYNhe 9SFvmxLX7Kx9TRB3MQ2x2Llk/NjG4kh/+RHlegT1HBcq
X-Google-Smtp-Source: AB8JxZpDFl576HX9rh0ILU3epYhSVN3ZKV9NmJSbNJ66dHa2IjGibOS3K6hLQ9H2inuSG6cruA/oJtvZT40CqjXNXc8=
X-Received: by 2002:a24:8189:: with SMTP id q131-v6mr16304583itd.100.1526401525959; Tue, 15 May 2018 09:25:25 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a02:5ccd:0:0:0:0:0 with HTTP; Tue, 15 May 2018 09:25:25 -0700 (PDT)
In-Reply-To: <CAHw9_iKPTT686F8piMGJG=ESnioaunJDTKurabvMA6NucqvBow@mail.gmail.com>
References: <CAHw9_iKPTT686F8piMGJG=ESnioaunJDTKurabvMA6NucqvBow@mail.gmail.com>
From: Matthew Pounsett <matt@conundrum.com>
Date: Tue, 15 May 2018 12:25:25 -0400
Message-ID: <CAAiTEH8ua_jhxCQ6Z9xy8UoepA=qX6rPsGN-=O1EcZHfDgH=Wg@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>
Cc: dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000bd668d056c410c01"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/3WFxeKhCW22_X3NjaUCABXWNoGo>
Subject: Re: [DNSOP] KSK-Sentinel -- "Walkin' on the SUN"?
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 May 2018 16:25:33 -0000

On 14 May 2018 at 14:10, Warren Kumari <warren@kumari.net> wrote:

>
> So, please, *clearly* state if you think that this:
> A: is a SUN
> B: is not a SUN
>
>
> I think this is not a SUN.

6761 has a lot of opportunity in its text to refer to leftmost labels and
doesn't do that, not even in what could have been fairly obvious examples
(e.g. localhost.*).  Also, the SRV registry is not encapsulated in the SUDN
registry, and that seems to me to be the same issue.