Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

Joe Abley <jabley@hopcount.ca> Thu, 09 September 2021 16:13 UTC

Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23FB23A1AC7 for <dnsop@ietfa.amsl.com>; Thu, 9 Sep 2021 09:13:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=hopcount.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ku3E8m863qgp for <dnsop@ietfa.amsl.com>; Thu, 9 Sep 2021 09:12:56 -0700 (PDT)
Received: from mail-qk1-x72f.google.com (mail-qk1-x72f.google.com [IPv6:2607:f8b0:4864:20::72f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 92BC63A1ADC for <dnsop@ietf.org>; Thu, 9 Sep 2021 09:12:56 -0700 (PDT)
Received: by mail-qk1-x72f.google.com with SMTP id b64so2396191qkg.0 for <dnsop@ietf.org>; Thu, 09 Sep 2021 09:12:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hopcount.ca; s=google; h=content-transfer-encoding:from:mime-version:subject:date:message-id :references:cc:in-reply-to:to; bh=yNrW/HiMh/luHrcjBLsRq6TWu9OcdpbAexcDseh/ErQ=; b=A8RJJ0pwgjXyzgJG6beJBbs/+6bvXTqkdryjkkE5DEKvkGZXkrVvz2/dSKa4ny0svE FBzIVka5+jAkMwQj2cSAZ2iH5j7wt3bu2C6hjTQY2sHo0TbUFrAwTUbt7ElO9RuTPvbY /kv8MLG427CFf5tmzpTs2XJEp8CXvEdItcKFg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:content-transfer-encoding:from:mime-version :subject:date:message-id:references:cc:in-reply-to:to; bh=yNrW/HiMh/luHrcjBLsRq6TWu9OcdpbAexcDseh/ErQ=; b=RtERHikmE8LcGum4ay90XgMkwrxDkSzbGiWKtOnfKfXwQGtYC2H7kRTgasnBXqaCGf GWEWI7bMvKucEwqtyQHBLN/N4JfpGogqjSFUuNNPBzYgvVcCdJd1JXhBH+KwOlLUNBDs 0Aqk0F9cwbELMINpsxOVQcj0l1zA5fZW8c2u22MpFIVeVz24I5ZkfO88LXKKt1mKryF8 nlsHjOyggceI6El32SedCM8dS5Smi0HyXtSjAPMj2qR2ooAO29pKNElwTIEEDxKPxSN1 h2trQgJc/U4EwNhQkAWb4ILYL5vyPqfGdkarzZaUiz+IOA4zwtdnH6LeDRDNhn/MD0jW K/Ww==
X-Gm-Message-State: AOAM5315wh2/WSMjw97XHJbyD6ZNLyvY83+42usXJMD9z5UL3ECbNnir tH7q0VNOxVJCZIsMFts5wcCZGmRqSPwTstOH
X-Google-Smtp-Source: ABdhPJwklHx2O+fKogUdwiguiHx1YXfgaMHlIBUNkB/+SClwPXbNX5v3L79rGdgXSKmjBqcxxSO4nA==
X-Received: by 2002:a37:a08e:: with SMTP id j136mr3457975qke.195.1631203974225; Thu, 09 Sep 2021 09:12:54 -0700 (PDT)
Received: from smtpclient.apple ([2607:f2c0:e784:c7:2053:3396:4d8b:a2aa]) by smtp.gmail.com with ESMTPSA id w6sm1603379qkw.91.2021.09.09.09.12.53 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 09 Sep 2021 09:12:53 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: Joe Abley <jabley@hopcount.ca>
Mime-Version: 1.0 (1.0)
Date: Thu, 09 Sep 2021 12:12:52 -0400
Message-Id: <AF814A51-78E8-47AE-96F2-0AB861D25DD8@hopcount.ca>
References: <4734e0b9-c8ad-29ef-c63b-58c459b7e31e@nohats.ca>
Cc: Paul Hoffman <paul.hoffman@icann.org>, dnsop <dnsop@ietf.org>
In-Reply-To: <4734e0b9-c8ad-29ef-c63b-58c459b7e31e@nohats.ca>
To: /dev/null@nohats.ca
X-Mailer: iPhone Mail (18G82)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/6B8ozQaCut0CdxBD7cuSAtKar5E>
Subject: Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Sep 2021 16:13:02 -0000

Hi Paul (W),

On Sep 9, 2021, at 12:05, Paul Wouters <paul@nohats.ca> wrote:

> On Thu, 9 Sep 2021, Paul Hoffman wrote:
>> 
>> Did you first ask the administrators of the zone in question before sending this message to a grooup that has no administrative power over the zone?
> 
> No, I used this group as the umbrella contact, as I assumed the
> knowledgeable people are here.

The IETF (well, the IAB) has administrative control over the contents of the ARPA zone. I do not know in practice whether this extends to the machinery of how the zone is provisioned. 

The operation of the zone is carried out by PTI, I think. It is distributed to its authoritative servers (which are also root servers) in a process that is similar in some respects to the way the root zone is managed.

I would drop a note to Kim Davies and ask his advice if you want to make some kind of progress. While it seems perfectly plausible to make this kind of change by way of a published RFC with IAB review, it's not at all clear to me that such a heavyweight approach is necessary. 


Joe