[DNSOP] Re: [Ext] Re: what problem are we trying to solve, was Call for Adoption: draft-davies-internal-tld

Benno Overeinder <benno@NLnetLabs.nl> Wed, 18 June 2025 17:57 UTC

Return-Path: <benno@NLnetLabs.nl>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id DB9B2368E54B for <dnsop@mail2.ietf.org>; Wed, 18 Jun 2025 10:57:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=nlnetlabs.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F_vMXFYS2HdE for <dnsop@mail2.ietf.org>; Wed, 18 Jun 2025 10:57:01 -0700 (PDT)
Received: from mout-b-203.mailbox.org (mout-b-203.mailbox.org [195.10.208.52]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 33EC7368E544 for <dnsop@ietf.org>; Wed, 18 Jun 2025 10:57:01 -0700 (PDT)
Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-203.mailbox.org (Postfix) with ESMTPS id 4bMrzD5XgJz9xNH for <dnsop@ietf.org>; Wed, 18 Jun 2025 19:56:56 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nlnetlabs.nl; s=MBO0001; t=1750269416; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=3OF7wbqGnxPQ+y+UCpGIf6ImDmeSnaJoOtsu2AoXIXo=; b=hHVjzO0OcV7vvxF0gDY0oDAU0OhBN0x1umy5ZLgenCjdzobK8G0OMy16nCHCZLBF/jiaPU FQPZ18mqvhto01EUF9NWrnwfs/FH353UTuWMgmMegl9SXh2wSBq9Mf58Teuxlq/srebzN0 4/ap6FeSo+E6TXIAuB+wETlMVJ0fIwClNOj8iyKaFp8ivPoD2dzYH/hDgMTe7aj5aQ9ijy 3OAOl2j1XppClxfkrcTKK9vdOi1VFXVxcu+WCcbN4b0DQPS4sEMdTl13AA165jX9DxwZ9k 6q3REiFPYYg77SZmWZRZUEh3Bvb2xXm3qlw40n0ehnvz7enLBP3KBOS3/rauWg==
Message-ID: <795dcccb-5f6e-479c-95fd-ed165961f447@NLnetLabs.nl>
Date: Wed, 18 Jun 2025 19:56:54 +0200
MIME-Version: 1.0
From: Benno Overeinder <benno@NLnetLabs.nl>
To: DNSOP Working Group <dnsop@ietf.org>
References: <20250617171743.87B03CE96906@ary.qy> <DF7161E9-F4CE-42AE-A449-A65A8819B410@isc.org> <0d090f95-cf5f-3552-84f6-c475d039c229@taugh.com>
Content-Language: en-GB
Autocrypt: addr=benno@NLnetLabs.nl; keydata= xsFNBE2vPv0BEADE2LbwfYmwzLAiPe4DJ1FlhYQNFEKik7CLTzdmgUrLldhoQBu+UbzKWrqo 4B61d3jRwgEVXkXzUucwzwJxU0hHoQTdLNWf2xjvyBwtG/I/lim2tm8MT9NhRQgGjfi3emHS QeuyfWHntrVRO6hOqGBGjjeVDmAwA9Mq8Lg1i/pH/0fPBNCJgfGv7W+PIGD/HslwAXJJyetN GoFiSp7A0GpPFQcF3e8ZFuHWGeeLCazPZTEESXR4gQhW0uD1Rin0F5Nn+GP/u3A48RiVRYip hoQU2Y/ZFBowXA9kD+Gk1/4mZ3WExkqbWp9k50uC0eUUJyM8MPFSu+PhXQtXYNAXh+d7Dqua nQEWHOD3UfGPIeH8O8xlkFskDxQKqEFQqbkAsODuute+ogbfME3ET9imDGLuiV2ma98zZS4Y 4ABuYmfV8Uj1PanDN2bCBCHOTzMa5U5LB+YbRDSI6bePs86r/ifICofs8W7yqC9U9eV3Vd3A R7p4Ncu5rN5JK0E/4ydBH/2T/3Nbzd6FKvoFPrjR2fsNfi41RaTQ96Zs2igzdW3Q4KbNiZHx 1VhGDCFLJyW9amZJsM7nBDNg1HnNjg6+Wbc21VjCRGYwgejImaJzqG9BJQJV7PH79GP5Mh/0 AqIwkejZkQmnZCnpyRl69cSJ4N9urKpRGHdo7eCJeYCpvzE3owARAQABzTRCZW5ubyBPdmVy ZWluZGVyIChXb3JrIEFkZHJlc3MpIDxiZW5ub0BOTG5ldExhYnMubmw+wsF7BBMBAgAlAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAUCTa/1awIZAQAKCRCsiZiNy3/98UrAD/9HRXg7 wFP4E+kIMEz6T2j6lpcLUAbBrZwLsxOD5zH/ClTuRrfDd7nMCGpPtGJVT5pgLurZloRqPBYe QDZn1+a37DUl9t85d4D9J+B6NYP8uxAXZqbSDvDeRPt+NO6wHL1rStv3ZIugX5voJKYlNmvh 3ljvF+VeYjTwZykTd7hXWTwZc4K6Rq3eVfP1aZcDvmjXPWfT4So7VnJTH5XwnDd1zFTjztNM U405uXOM1z9tRYZeDbbSpWidvap+IWHt/OA2Vymd+EKH87yfIxFZsSxT+FGRnxC1Ll3I6TX7 IID1bGP7/SgeZ5yHAq54WTrvTwhib7WWCWmAMnEzdYHTF9bOtiVrGg3LMvfX+g4cuM6aEwqS VOB6zfxwJBcFwYlZ/YhyerhmpIPr4AxnuhEVRX35VSf0XX9Hlb/ETNauCJEKfLFN9VjJ1FC3 7fWOZ+KqvHdFO+gmZ48+5OOqoID8T3QyqoO/MKluV/XTQKkxYXoh3Pf5ZBHshffMUMshFrQi FoZkbkv1DBBtM0YpcDL0+oPH9S8oIpRD0PgpPOrVVC2f23KZ60Lf2vzLJW28/aKEfnGvjU2A ZP7ujjBnQ3bVqdV9iuES6j5W6TpGguvUZ8cjY/n1qfGPvkTgqAG6pQ1UrUMP7Oa+eCml8Ssa GeQkl77jGBjabFnIsW3SVCNOU+waTs7BTQRNrz79ARAAqjjs83KQNdBLyfsl3qqLi0iRoW79 N5FRD7uCmnQiPjfi3m81mzSlLv0X1AIchDww2Gp/ZFLIkuGxtVobRtIrBlyoOuE4FNdmd+da ByZU8yoB1tIa5Exb5tssDQIRiEX4cs/qsSqEaDD15/nk3ZmdhLvHLdcCoClWWCIE+ttWa7rs yJ+5UERfujxK5tszMOjHWCMS3bNUTTpehyOKv//qJLAI8ExlYAIJrvHtT+kdmgN+o7G6ZOIi rhoHdJ3elVTWOsG0G+rWafYaD7AGrtip1vd8orogBXZFVMI5BEHD2kZgp/flIdWzqz9D3tLT k6/IHwx9yaSiafa1nEvi188LToPMSY2TB7pmBISYlDDraYKG8SEFVZrDejMVJgMmrRTpd+Qk vKN7YULaYik7LM8VzvjxgyuMTpgtTxGcdtX560UlQhHXXSyQKkRBOmdaW5R8gQzmpwbAJNFV ASIW4O4m6Ko33QbXBWNQWKRZyWQEgcOTrBUHcjC+VJVyr61qNjEKRUTJVJlU3ZWA93itGVYX dTF5WioyNj7SWg61kC/+OPIwUuv1jBjeHvAKu0SX9+tjR5NQPG53Lw94H3sYjGE3s4mz6y/6 P7lXJ16JCT4ktegRbzcZLcap9kPMYbhjAh4DclqKieH6egtw8yi09fDT5I6X1DMMstXsfItt bdp+j3MAEQEAAcLBXwQYAQIACQUCTa8+/QIbDAAKCRCsiZiNy3/98YLrD/0WbDCHFKlj2wt1 K5I9KmySPV7OXpoeHyV6NX+5lKrRaAI/b7Exg+VqR09thoM5KbKOe5h3wJGie8jzE4CYk5TQ zKSohP/oqV6ZGoLHE49E/pS0AFkEINAFZIyyk9n5YRAwwCgXiK20dVofxkmWwO72AZRQl+yv GarVSlJ2ygKVILcdP6fMLu0+jlGH/EPNNtWPdJaOSPfTTxXa+BfM+YMNbRqM/ci8xNNV+9zl SQBL/QvTZpIP3dUg4oF1ssk2hq7rFFNUeUdkzhQwyKs2QHPPMsPaGdQrB4Dcntzfw+vTygko 0mXoUTyrhL3xE0Kt4T6qtNE16Vbl4CtS5atiShipEAR8pMQGnNsjTopweI8mCKTaOm5jnZi+ CvXpiIqj4gglxsI6X2ooLSCZAjWmd3FUtDetKbFAiWZPf8Nv77g44SIErWR054QvljdemIVh ru17z9Sk904RlIK2n9Y88GWpNiVyRkvNg2I/evVkXkqMuLhY4kO7K56o6AUsfHXbB6joIj46 vvv06KplgwYkFsSIHrgAD0YzYDqbtJ0FPu4Hzr0hXMYKSu8g9pexxeS/F+77LC4ebDslX/33 Vkg7Je1PZTslp4tca1kqkcRux75+qFKcPzPqfe/mnEQyjlccp7OE/uFOR1+5rF3bWY+sX5CD R6+3QluMy9sOr8lilmvQ7w==
In-Reply-To: <0d090f95-cf5f-3552-84f6-c475d039c229@taugh.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Rspamd-Queue-Id: 4bMrzD5XgJz9xNH
Message-ID-Hash: SIZ5XEJLLGNBINZFC4GCAHM67YK5B4PI
X-Message-ID-Hash: SIZ5XEJLLGNBINZFC4GCAHM67YK5B4PI
X-MailFrom: benno@NLnetLabs.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [Ext] Re: what problem are we trying to solve, was Call for Adoption: draft-davies-internal-tld
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/6sfK3s9yErNtdTG4Mm2BSOp7liY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Hi all,

Joining in on the ongoing conversation.

In the email thread, we have seen a number of messages from DNS 
implementers and operators arguing that insecure delegation is required 
for the proper operation of validating stub resolvers.  See also RFCs 
6303, 8375 and 9665, which mention insecure delegation. The new draft by 
Joe Abley et al. discusses this issue in general terms with regard to 
private namespaces.

The chairs have asked the IETF liaison to the ICANN Board of Directors 
to also discuss this issue with the ICANN technical community.  We hope 
to report back to the DNSOP Working Group during the Madrid meeting.  We 
would like to ask the WG not to repeat the same arguments until there is 
news.

Thanks,

-- Benno
for the WG chairs and secretaries


On 17/06/2025 23:08, John R Levine wrote:
> On Wed, 18 Jun 2025, Mark Andrews wrote:
>> And if the stubs are validating then the answer for 10.in-addr.arpa DS 
>> is a provable NOERROR NODATA response that says there is a delegation 
>> at that point in the tree.  That validator does NOT need to be 
>> configured to say ‘DO NOT VALIDATE THIS NAMESPACE’.
> 
> We're going in circles here.
> 
> IF you have a validating stub resolver AND it gets all of its data from 
> the local cache AND even so it doesn't believe the cache's AD flag AND 
> you have some locally served zones AND none of those zones are a TLD you 
> picked yourself before .INTERNAL was reserved AND even though you're 
> sophisticated enough to do stub resolution you don't configure local 
> trust anchors THEN yes, the opt-outs are helpful.
> 
> On the other hand, if you think that's a rather narrow scenario and most 
> systems aren't quite like that, not so much.
> 
> Like I said, I don't see us coming to agreement any time soon.
> 
> Regards,
> John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
> Please consider the environment before reading this e-mail. https://jl.ly
> 
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org

-- 
Benno J. Overeinder
NLnet Labs
https://www.nlnetlabs.nl/