Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Wes Hardaker <wjhns1@hardakers.net> Tue, 30 April 2024 22:32 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7480CC14F6B0 for <dnsop@ietfa.amsl.com>; Tue, 30 Apr 2024 15:32:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hAV3KmJjYkVF for <dnsop@ietfa.amsl.com>; Tue, 30 Apr 2024 15:32:04 -0700 (PDT)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87BF7C14F75F for <dnsop@ietf.org>; Tue, 30 Apr 2024 15:32:04 -0700 (PDT)
Received: from localhost (unknown [10.0.0.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.hardakers.net (Postfix) with ESMTPSA id 3BF2F22B99; Tue, 30 Apr 2024 15:32:04 -0700 (PDT)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 3BF2F22B99
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1714516324; bh=yeAsEQza1e1rBVZNdh8CjLqnfrtWKqNLp2EUOarwLxM=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=J0H9ABFlC2TRCLArNjafZ/cIKh4DdvLNSaVAkhynA8BNu1G7zbWaUwrpeuH2UMFV3 ejddir3h7fvL74/1EOO4eM+I9brTdY0YB950O7Wo7iCOfPk7pw7Ab2x8gMbQirTz7I 0kR96grKbGpxOPqgOjS3iTSEwTfoybfj+9+Pvv6c=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Paul Wouters <paul@nohats.ca>
Cc: Paul Hoffman <paul.hoffman@icann.org>, dnsop <dnsop@ietf.org>
In-Reply-To: <7dd5f090-b8b7-ea5e-82f2-d622298c7299@nohats.ca> (Paul Wouters's message of "Mon, 29 Apr 2024 16:30:00 -0400 (EDT)")
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org> <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl> <m1s1Wur-0000LDC@stereo.hq.phicoh.net> <f0f9c0ce-2911-9b4c-0d60-47c204add2d4@nohats.ca> <DB9D1C93-95D1-4B76-AD74-4C60433D479A@icann.org> <7dd5f090-b8b7-ea5e-82f2-d622298c7299@nohats.ca>
Date: Tue, 30 Apr 2024 15:32:04 -0700
Message-ID: <ybl7cgejxcr.fsf@wd.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/7Zsw9ieqhZaFLvc41T0_9mBQSpc>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Apr 2024 22:32:09 -0000

Paul Wouters <paul@nohats.ca> writes:

> Perhaps Viktor can share his updated numbers with us.

Viktor's daily scanning numbers are host on our USC/ISI server at:

https://stats.dnssec-tools.org/#/?dnssec_param_tab=0

Click on "DNSSEC Parameter Trends" followed by "KSK algorithm", etc.

KSK usage (click on the "domain count" column to get the sorting to
match this):

    13      11145536
     8      11065103
    10      205662
    14      144076
     7      119678 (rsash1-nsec3-sha1)
     5      19750  (rsasha1)
    15      13497

The SHA1 counts are 2 orders of magnitude lower than the EC and SHA256
based algorithms.

To see trends, you can click on labels on the graph to remove them from
the graph to zoom in on the nearly flat lines at the bottom.

ZSK counts are similar (oddly 7 is slightly higher and 5 is slightly
lower).

-- 
Wes Hardaker
USC/ISI