[DNSOP] Éric Vyncke's Yes on draft-ietf-dnsop-rfc8109bis-06: (with COMMENT)
Éric Vyncke via Datatracker <noreply@ietf.org> Tue, 20 August 2024 15:38 UTC
Return-Path: <noreply@ietf.org>
X-Original-To: dnsop@ietf.org
Delivered-To: dnsop@ietfa.amsl.com
Received: from [10.244.2.52] (unknown [104.131.183.230]) by ietfa.amsl.com (Postfix) with ESMTP id EA295C1519AC; Tue, 20 Aug 2024 08:38:19 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Éric Vyncke via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 12.22.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <172416829960.2132394.15730111982574053913@dt-datatracker-6df4c9dcf5-t2x2k>
Date: Tue, 20 Aug 2024 08:38:19 -0700
Message-ID-Hash: ORHQR5DE5Q7BEZIUHTIUFFNMQDKIWRPI
X-Message-ID-Hash: ORHQR5DE5Q7BEZIUHTIUFFNMQDKIWRPI
X-MailFrom: noreply@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-dnsop-rfc8109bis@ietf.org, dnsop-chairs@ietf.org, dnsop@ietf.org, tjw.ietf@gmail.com
X-Mailman-Version: 3.3.9rc4
Reply-To: Éric Vyncke <evyncke@cisco.com>
Subject: [DNSOP] Éric Vyncke's Yes on draft-ietf-dnsop-rfc8109bis-06: (with COMMENT)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/4F66BrJ4GI8-kG92kWjUc6l6Vyc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Éric Vyncke has entered the following ballot position for draft-ietf-dnsop-rfc8109bis-06: Yes When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-dnsop-rfc8109bis/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- # Éric Vyncke, INT AD, comments for draft-ietf-dnsop-rfc8109bis-06 Thank you for the work put into this document. Please find below two non-blocking COMMENT points. Special thanks to Tim Wicinski for the shepherd's detailed write-up including the WG consensus but it lacks the justification of the intended status (and uses the old template). Other thanks to Dirk Von Hugo and Patrick Mevzek, the Internet and DNS directorates reviewers (at my request), please consider these reviews: - https://datatracker.ietf.org/doc/review-ietf-dnsop-rfc8109bis-06-intdir-telechat-von-hugo-2024-08-19/ (and I have read the Paul's short reply) - https://datatracker.ietf.org/doc/review-ietf-dnsop-rfc8109bis-06-dnsdir-telechat-mevzek-2024-08-19/ (it was posted yesterday and contains some valid points that should be replied to) I hope that this review helps to improve the document, Regards, -éric # COMMENTS (non-blocking) ## Section 1.1 Nice to remove "man-in-the-middle" but it is replaced by "on-path attacker" and not by "machine-in-the-middle" ;-) Should there be a note in this section asking the RFC editor to remove this section ? or move it in appendix? This is a matter of taste of course. ## Section 3 Like Patrick Mevzek, I also wonder about `The priming query can be sent over either UDP or TCP`, of course Do53 is currently the only supported way for the root servers. With the experimental RFC 9539, should it be stated that only Do53 must be used for priming ? I.e., a stricter text than now, e.g., "MUST be sent over either UDP or TCP to port 53" ?
- [DNSOP] Éric Vyncke's Yes on draft-ietf-dnsop-rfc… Éric Vyncke via Datatracker