Re: [DNSOP] Acceptance processing in draft-ietf-regext-dnsoperator-to-rrr-protocol-04 section 3.4

Matthew Pounsett <matt@conundrum.com> Thu, 17 May 2018 20:20 UTC

Return-Path: <matt@conundrum.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E325D12EB96 for <dnsop@ietfa.amsl.com>; Thu, 17 May 2018 13:20:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.908
X-Spam-Level:
X-Spam-Status: No, score=-1.908 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, T_DKIMWL_WL_MED=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=conundrum-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1g4YUD4OVVjD for <dnsop@ietfa.amsl.com>; Thu, 17 May 2018 13:20:31 -0700 (PDT)
Received: from mail-it0-x22b.google.com (mail-it0-x22b.google.com [IPv6:2607:f8b0:4001:c0b::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C229E12711D for <dnsop@ietf.org>; Thu, 17 May 2018 13:20:28 -0700 (PDT)
Received: by mail-it0-x22b.google.com with SMTP id 70-v6so10502391ity.2 for <dnsop@ietf.org>; Thu, 17 May 2018 13:20:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=conundrum-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=JsKhtmSLJxjD8wv4EaSvt6lPJcUeLOvCxbhVT/HsyeU=; b=bzUPpyI2rRVZZGYJ+JR1muAZBpX6ti9nIatMCbk1Zjla7dmDtVNTBnKWmHuoso6/lD Jd017voJoSowZqeNNuipNNU6DRvOUihkToTSGrm1vgWWUQtKOXich177ka+nJapxbb3Q tQ6vsSJB+iPRRyI19aHSDBbX0lv+A3LOnEzMd3pU4P/5ucQ0HewuMr1XyIawhjYN9u7a AL5ejlLdQ/OYuJo2fKCggo7zUN9kAbSfDHamWlUhJI8VOWy8BPNzaq5hfzy+ybC1OEKT NmqkE1PLapsUh8GawZdepa/kgKbmqWqRSkyUwSFL9V65CD4hPATDy83qYUiZi1FckH10 I9bg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=JsKhtmSLJxjD8wv4EaSvt6lPJcUeLOvCxbhVT/HsyeU=; b=f9RnFRXylqKfB270ALIEx7fKIO3IWTWgOfVPQtVauUnJjv42RBJOk55wDWXLCUHShv qdYxB6DHGQxVbaA/yVJh+uwoIhMXYZyhqG6UNNfCjJF3+i6dboeK0q/URkeXxxuF52uh HpdkfQhIrR1d+pEvflOQxKleEXiqpI4QCTdbjRyqQ/Drw4tZDzPMY9HjRaFobd4ptPNy 69Om32JgOuf1I5geIwUacoO9/j2yswMu1pnG7p6UngMUJZJmJbNTcHCGNXZF2c4KNn3E DYHuWdFbBY7P2k2/k4/HvSslLORsj+lVm1XCYRN6RewDDT0YblCW4lO4oUIkxF+gDFDj UaiA==
X-Gm-Message-State: ALKqPwckzoYDPEZcHmEhlrQI6QwK6eBppfR67EuQHDJxQ4nSFnS6ZJs3 zmlmhgAmNvRI88XN6smIgzpkD1Azyf/48oiu07IVnTVm
X-Google-Smtp-Source: AB8JxZpRApgTzGef4rCGs9Qx/+q5TcDuDPbSBYf2s7YZHrz3i7+5lXyrmH2QRR67P2bQwXJze9n9jPpyooG1MnuiW1M=
X-Received: by 2002:a24:f684:: with SMTP id u126-v6mr4493644ith.102.1526588428009; Thu, 17 May 2018 13:20:28 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a02:5ccd:0:0:0:0:0 with HTTP; Thu, 17 May 2018 13:20:27 -0700 (PDT)
In-Reply-To: <1D06889C-770F-4F92-BF06-A76338AEB320@dukhovni.org>
References: <72D91139-BD51-43A9-8AEA-177753A29F90@dukhovni.org> <CAAiTEH_iXs33YdWrRmn6_iQYH2ba-WxqbYbp27Q2gpzBL7=q5g@mail.gmail.com> <24D5D313-4F02-4A99-9E64-44B35331608E@dukhovni.org> <CAAiTEH9J_VWkQBF=Ytv0Von+YFG1EhxHDpP5Aj=iuXTDsFU0ZA@mail.gmail.com> <8930E547-6327-45B5-89AB-37282D2C245D@dukhovni.org> <1D06889C-770F-4F92-BF06-A76338AEB320@dukhovni.org>
From: Matthew Pounsett <matt@conundrum.com>
Date: Thu, 17 May 2018 16:20:27 -0400
Message-ID: <CAAiTEH9hnS5h6UQ9VSPdKUt8=kVxsGHRVmni4RmXbNL9+UFTcw@mail.gmail.com>
To: Viktor Dukhovni <ietf-dane@dukhovni.org>
Cc: dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000f8564d056c6c90d7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/6OruKA9rK6G9jqjdMrjTSLVOWD0>
Subject: Re: [DNSOP] Acceptance processing in draft-ietf-regext-dnsoperator-to-rrr-protocol-04 section 3.4
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 May 2018 20:20:34 -0000

On 15 May 2018 at 12:57, Viktor Dukhovni <ietf-dane@dukhovni.org> wrote:

>
>
>
> I see a new version -05, with (so far) the Section 3.4 acceptance text
> unchanged. I strongly feel broken DNSSEC adoption is much worse than no
> DNSSEC adoption, it not only has operational impact on the target domain,
> but also creates strong disincentives to enabling validation in resolvers.
>

Apologies.. I missed this comment in the thread when I went through it
earlier.

-05 was basically just a keepalive, since the draft had expired while I was
unable to keep up with IETF work over the winter.  The authors have a stack
of changes pending, some of which we're still discussing, and an -06 will
be out when we finish working through the backlog.

That said, we don't have any significant changes in mind for 3.4 that I
think are likely to make you happy.  As mentioned elsewhere previously,
general delegation hygiene and general DNSSEC hygiene rules belong
somewhere other than this draft.