Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD

Geoff Huston <gih@apnic.net> Wed, 04 April 2018 01:17 UTC

Return-Path: <gih@apnic.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1CB9F12D943 for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 18:17:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=apnic.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m_fUdQd21ohe for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 18:17:26 -0700 (PDT)
Received: from APC01-SG2-obe.outbound.protection.outlook.com (mail-sg2apc01on0088.outbound.protection.outlook.com [104.47.125.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20B571200F1 for <dnsop@ietf.org>; Tue, 3 Apr 2018 18:17:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.onmicrosoft.com; s=selector1-apnic-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=R4mQZvdaBTfUwhV+0cSH5wts0gd9Rt3Ol07Hcq+zn0Q=; b=R1imP7TeCClGrLSPuck111Ko00peqBNiW6a+CVlULGkzFy73dEwjjNCFItwyffEVKR+fWb1Gvue9MFJeym7FHrwejAXtL8REuRpRwnnVbCcVPfZdHXP/jiqvEGa+wlvRHxPZguSr5FMhNgFiJq3CGmGRl9jmUVFxFQ8BJAWGif4=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=gih@apnic.net;
Received: from [IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c] (2001:388:1000:110:68a8:aacd:ca4f:a91c) by SG2PR04MB0695.apcprd04.prod.outlook.com (2a01:111:e400:520a::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.631.10; Wed, 4 Apr 2018 01:17:22 +0000
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.3 \(3445.6.18\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <167E8357-FE53-43DC-84C6-B720BD8069E4@isc.org>
Date: Wed, 04 Apr 2018 11:17:10 +1000
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsop <dnsop@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <E7EFB44E-09C8-492D-AF9A-7EAAECD729D5@apnic.net>
References: <039408B0-89EE-4038-B9C9-CBCC35EC24EC@isc.org> <64816369-700A-4413-B1F0-160FB145EE6C@gmail.com> <BF3E4F4D-027C-4A2B-8026-14AF3FBA4603@isc.org> <2F103A8E-72F6-4159-900D-B7006D0AC647@gmail.com> <6D617FAC-D981-4AE1-8943-4F0D12C46397@vpnc.org> <0B0775D9-B5E6-4778-A199-FE4D09A0BE17@apnic.net> <D19F6299-922A-4DCE-8E95-85CA72E63129@vpnc.org> <A4AA3F56-12A5-4951-B01A-450B493E0E4A@apnic.net> <412D2533-2332-4F38-BAC6-4C5AF391C124@isc.org> <756BFAD3-2867-4646-B028-7D93C05BA8F3@apnic.net> <167E8357-FE53-43DC-84C6-B720BD8069E4@isc.org>
To: Mark Andrews <marka@isc.org>
X-Mailer: Apple Mail (2.3445.6.18)
X-Originating-IP: [2001:388:1000:110:68a8:aacd:ca4f:a91c]
X-ClientProxiedBy: HK2PR02CA0155.apcprd02.prod.outlook.com (2603:1096:201:1f::15) To SG2PR04MB0695.apcprd04.prod.outlook.com (2a01:111:e400:520a::21)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: ed6b0836-8193-44a2-1a3b-08d599c9d1d0
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4604075)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:SG2PR04MB0695;
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0695; 3:EJ4TE9+rdXMNggR/iNA43HPZ8kgUM9/SmWZCeo1YTGBjY0gmu9LIG9h3XbcxEsiCegLtiZiMuWrh6kshias7EeAUThp1emvXqHMZTOtNfo3Q6PUTdRUScGqkehsao+hclYgiPCzpfzrClNggvrJIBnv31AcduANEVD2XGVm37VDgoA0UhKnEwsBv0H6QylMIs9O803211YS7oGb6liczEI4ORhNVQEPVJVtad3+c8eSQG63wEBOfFuhxJNHn1Oh9; 25:RQrkDGnNwIAFMFbjQtLSBkeowg+6UoNwMG/49Buce3rBbiccHDZr4ogH+JMG6hGkjiUl4HS0d+JzMGbMOAi8SlBkOkHdtl6T9pMpvtoL6yUTHYNTFfhJ6WI2HWnanDAeKadDpEUs4FIv9Q/UUTUj29D5SUB9ZCiJM+BD2bOUSkAklkaWZIU2pV4dGTLg2PPDVnpmF76lmtDPfJHXYhfr9pm25jAFTaLCO5xPaHS/43WjcfxPf9TqPey3ofEb3AXZUYAeNqBrhUive37R2WAeSby1DbEnQZQshM4JEFRUtF0m1hMp0oW1LxJ8LS54cz/og3E4DjkhqqcIiBftB2qGHA==; 31:25ZyVphcOaFARAR52jlwFV+PtlsGbxhy+R7iwNJjG+78Ybbd2Pt76MVBDjArHNeyCprliETtRzjModwAmyC3wAB7MV1erubcXfNZF5AyYrxQjlbl+M/32MpQwY0IJAAEm9ZG+zNgtJv0ZztMH2FaKZR+WpC1WHwrw1T8rbXwVAD6B6pyhgcHqKugd/PJgTlF4WEoXjlEzVWbTm+vNNPHV3j3Q3Gv7rYJE+kVRkHD0Qc=
X-MS-TrafficTypeDiagnostic: SG2PR04MB0695:
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0695; 20:DKb0y36vNkRsp6T6GpnPtaztz4lb8qONY5sxc0GH9lFi7Uwepa6JjIyaW/yCgDE5DBBcDDVpZ0X0NPmrIn0nKi+NnyLi8gvEoGsWhL3G6heR9OC+45PXge5cjKr4/WOth7/yB9U1Dwe8ejV8F8SRnlwPCct5hwVfDyFdPCgIs5Hup6FcRHkNeCYAq6avtPw1tPkq3TtBUr/9fPmhnid0G7BtuxdVur4rHLEkL5ynOZZIpIr7TQ8nFcYEiEdKkkl2; 4:tK2mQ+qqXDeb7m1BA02sSCMNFDXQqD/SGfVcdYVtZzT9FN7eZl1trgxJjQRznxbSFZ/7jcLM0518CUz4CKy4qSlaHPjVJa43ZtFUmNpIEFd1MqFYE2pJUVyRAhq7KQxIOBUbgG0ZNIXcH3umvDFuFREhUyFy1MsKI7izQpk5/tk6EsveIof0bpdDPK0j56KrC3hwdst0tFwEtHnatYbnrtI4Mu+uqroPi4bJ5TwLXNF4s9VxVwCOOFbJTINes1U//WjoLvMFoGjjItQlzXg7MaiA1LBgJeMarZH8KDWZK6FZfx/WrNAw9gkqOM2WX55R
X-Microsoft-Antispam-PRVS: <SG2PR04MB0695E794B9999397DA6ADB3EB8A40@SG2PR04MB0695.apcprd04.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(17755550239193);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(5005006)(8121501046)(10201501046)(93006095)(93001095)(3002001)(3231221)(944501327)(52105095)(6041310)(20161123560045)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123558120)(20161123562045)(6072148)(201708071742011); SRVR:SG2PR04MB0695; BCL:0; PCL:0; RULEID:; SRVR:SG2PR04MB0695;
X-Forefront-PRVS: 0632519F33
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(366004)(346002)(39840400004)(396003)(39380400002)(376002)(189003)(199004)(5660300001)(16526019)(1706002)(446003)(81156014)(11346002)(305945005)(81166006)(68736007)(50226002)(83716003)(8936002)(97736004)(8746002)(106356001)(6116002)(82746002)(186003)(46003)(93886005)(476003)(6916009)(4326008)(86362001)(316002)(2616005)(6666003)(2906002)(2486003)(53936002)(33656002)(6246003)(76176011)(105586002)(53546011)(6486002)(52116002)(59450400001)(8676002)(36756003)(50466002)(386003)(7736002)(478600001)(57306001)(54906003)(47776003)(23676004)(52396003)(25786009)(229853002)(52146003)(486006)(42262002); DIR:OUT; SFP:1101; SCL:1; SRVR:SG2PR04MB0695; H:[IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
Received-SPF: None (protection.outlook.com: apnic.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;SG2PR04MB0695;23:Tv16ieO705fYnbX4e6cvX0+49wV497NXnJLTW4SoeeVkA4t6iAQaEoWJvN+7/Rtg0EM8dQOtxFvgFBBV3r7ISFwskXmIKlh6IRz0V6eArhno1e77qw2NnlYJRB1YAxPY2Om7Pdk6JhXQlB3NVNJ1WvM6AaIvMwPIiUcGXA4gasbXmOCcFoiob77Vcmgv+QsF4XM6gksaf+T9fY2VvyI+rcKpFjpu7PpqhMTKrjabQSHfNBCvmwSmewrSaZi8xLCM9kyR9berQrscSrGejRIzkLTe9Kv+alUcYa5Q0RkSldk2Tc28dPs3yAEA4uOVK0ahf43JajNTGSwGGP0CgRPzM+ruJFsvo4P8YXsOMKesCEzU/gsMWhbHvq6Ys+w29w3dkp6kJRel4q3sU6acaXLuaZmJ4HBISzc3IGdQYzdAJUsGFET7DsRqMINsbP5p/BlaQ2QPqEfgqtvE4ztpuACSnyD4uEr7PwQEx+o0SwuQ1UbpGSDsOVXRV0INLST0Fkg887rOc+vEyvE9MT7X6tzRIDyfmqw78JcoRXa7xT6gbKUYatS9/Gy4Kl4VUwDoxusowU+cjDzeULuQU6EneqF+HvLfabL9vyoaToEDZOZ2JW3g/flhbTE+ZVIhWOzYjc1xBUGouYljATp4AiGNRi+eFpINLwe4YvXIdMh6/fKywzp+1D8alJWz3GUUw+bMyCssTRP1IWuogYcHczh5Lw3JrNKYBGYTXTiCAztfoFy6RZCVLDuYW1IMPnYVoTb0gjPZel7U6sWXIij5G5XiLjL/G3fvCCZvw4Qn79wHy0RBhWP60cWPjJovqxRReIQnMIsFbPco426ArWWC9TO+RbPDxDt3eVFvgffESvmm3lc57bmTkfhFegSrATODaZvt+maQ47L3kuAUdRkNJGRObiuAIMFHVWf5b2cRYHC7gO+nXj8OKiPX2cTIb0P/uPFmoh46erPJ6tGrHsGUgmKGg6oN0FnCygnqF/yHX95K2595Bi1pqafTRgCZ/U53NMKtGz86pApbmDF9WupWsWjDSReIVZ31fWJcZpDU2uxHqGJF1GsIdJgGXYAP5mC9wHTfaH6y0qWFTER6vC5qUDtuew8czwSPTpU6Cf0uvkhJb7fdkD+vrJ5HcJ2NLHg9iafiI/sNRj2gELp9Mes0w+ntWmq5mIVtv1esXiVaqFq8Kee1KQ5W/YG6uXQgwK9ty1XBbcX8EQ4AsmtfBqzDyTVU3GtpQu63o7d2ZYNtAae18LuUhlZPpAvjk/ZRlkqgYX37I3R1+KK2PNHSDRthaKjZj3WNmfob/q889fSkW0hTznA/GBFTDT1KR/5ynDvie0kJB6JKngAhwCe2vFUhdVocqsnUpUvzMdIhf7tWkdBrckgyLLY=
X-Microsoft-Antispam-Message-Info: 0BsKxl2fXE8AlFTxU8AYrel+mtwLdSKBHi97CivwLcEdsU6ugCXNl1luwttMgCAknGrbk7TN0VHadQJNmf9binW+huN0daSpTdIMD2v6GHcV6t2CLCEQN9aOmd9dxPv1Splkwp+ONCGV6vIo2MRi3f95WbjjoDMturyK4g2yezZoOcgVt3zBqefJp2COXkH6
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0695; 6:trAGKqVbby+MEaLaYOt6jmVkKvLMJMbqNQvEWd6JHkoyPuL6zcK97Z8VoHKstDklyIwWHAZypLnwdA0lYqET0bipd6raMXu8NRTwcFRouvVrAykrDVBy0pmHsoykBunQ5C3rok6MPH7qq13X4JdOw34bwoQFkNjWO99WqgyhcTmLcAyuSTpRX5hWA8g1SOH5z6GepsQ4fIE54X8G867LVokL6FwrhANR4THx/EhizRHntMGhMLFdE7uM/KrDyp9S1rIVWJVAu8He19msqynfDLLDyO1dP//c9iR/XCaI2pj1HHuRy58RhnI0WK1NTGBcC/jGkMTcip9Q4d0S5N2nrDgIQ5Br7SQY2XrkNBFPDd0yLbtPxKJCdjCnhvfDe8oHt0onQqBw74KgCdvkpmBJBERVlyBWc4z5JCCsIHI1LmoKqoHheGo7VjxWdA7PQl8Bru2BfYxRwrqsX6gF1WsRIw==; 5:efyotgurwaYSFc2r6cR2/2q+ET/VmjnYazXwbXukJSOPraDa4bTtXgPSEen4150s1wHkIS7MwBp+EquN2otrMtitERXNDUndaaCSza8EGANglb96gNjNEA2PxT79esxg2lpbmzVhiOBjmuP74vvSIYw3E812sAnFNZccV/sGE0Q=; 24:jXtPywnnHa2Gjxc1oDh9kMw2HTiQLHY2dJdSoBxp2k9dUB3acPapZV/tbHxNybubXGmoIrePZXWvTRjtCH8djL/p0cFNOQ4E3UB8OPkmdIs=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SG2PR04MB0695; 7:4iyIwkBWFQSpdfv2fIHJZaD12Mq3zj0t3P7NwKzdb2oGvlAmUIUXS5pujkxvYIKvrk6wkTnrVANhsuLmG/WE8kYQ2XMkPHl2/onJa1rka0N14Ute+uGKgrGgvO2+YvOrr7bM5EembxPFujQvj2uHCx3vAH3j68/sEQs0LIemOplo/wRFbPWWhFbO6LnFTG0jF688vOnmcit9wNC6xtFqM/EUxmpwI735xNSu0Wi4ApSIFdrG/QjJLwbWoqmBCR0m
X-OriginatorOrg: apnic.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Apr 2018 01:17:22.2064 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: ed6b0836-8193-44a2-1a3b-08d599c9d1d0
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 127d8d0d-7ccf-473d-ab09-6e44ad752ded
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SG2PR04MB0695
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/6ZEieIqG65Onfy0yZHmNBwIwF9Y>
Subject: Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Apr 2018 01:17:29 -0000


> On 4 Apr 2018, at 10:59 am, Mark Andrews <marka@isc.org> wrote:
> 
> 
>> On 4 Apr 2018, at 10:28 am, Geoff Huston <gih@apnic.net> wrote:
>> 
>> I thought that if the query contained CD = 1 then the DNS response
>> would not be validated,
> 
> This ONLY applies if the answer is NOT ALREADY CACHED.  If the answer
> is already cached then CD=1 queries will get this processing as the
> answer returned from the cache will be “secure” or “insecure” depending
> on ealier validation.  If you don’t want CD=1 queries to get this processing
> you need to explicitly exclude it.  You can’t depend on the answer NOT being
> cached.
> 

Mark,

If I understand you correctly, then the preconditions need to include
an explicit provision that the CD bit is not set. 

Does the following wording work for you?


  All of the following conditions must be met to trigger special
  processing inside resolver code:

  o  The DNS response is DNSSEC validated, regardless of whether
     DNSSSEC validation was requested.

  o  The result of validation is “Secure”.

  o  The Checking Disabled (CD) bit in the query is not set.

  o  The QTYPE is either A or AAAA (Query Type value 1 or 28).

  o  The OPCODE is QUERY.

  o  The leftmost label of the original QNAME (the name sent in the
     Question Section in the original query) is either "root-key-
     sentinel-is-ta-<key-tag>" or "root-key-sentinel-not-ta-<key-tag>”.


regards,

   Geoff