Re: [DNSOP] Fwd: New Version Notification for draft-pan-dnsop-swild-rr-type-00.txt

Mukund Sivaraman <muks@isc.org> Wed, 16 August 2017 05:45 UTC

Return-Path: <muks@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C065132415 for <dnsop@ietfa.amsl.com>; Tue, 15 Aug 2017 22:45:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.235
X-Spam-Level:
X-Spam-Status: No, score=-1.235 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cY-KrFtBYC8q for <dnsop@ietfa.amsl.com>; Tue, 15 Aug 2017 22:45:45 -0700 (PDT)
Received: from mail.banu.com (mail.banu.com [46.4.129.225]) by ietfa.amsl.com (Postfix) with ESMTP id 1ED241321A5 for <dnsop@ietf.org>; Tue, 15 Aug 2017 22:45:45 -0700 (PDT)
Received: from jurassic (unknown [115.117.171.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.banu.com (Postfix) with ESMTPSA id 6667356A014C; Wed, 16 Aug 2017 05:45:41 +0000 (GMT)
Date: Wed, 16 Aug 2017 11:15:39 +0530
From: Mukund Sivaraman <muks@isc.org>
To: Matthew Pounsett <matt@conundrum.com>
Cc: Lanlan Pan <abbypan@gmail.com>, dnsop <dnsop@ietf.org>, Petr Špaček <petr.spacek@nic.cz>, Vladimír Čunát <vladimir.cunat@nic.cz>
Message-ID: <20170816054539.GA12897@jurassic>
References: <149908054910.760.8140876567010458934.idtracker@ietfa.amsl.com> <CANLjSvU23OPMM=cETxBiV7j8UhMzMd426VuivxAtboMAB0=7jw@mail.gmail.com> <alpine.DEB.2.11.1707031317070.21595@grey.csi.cam.ac.uk> <CANLjSvXE4q9PSEc4txKM4OPKXVpT38N_PC2-fDHmihpk29ahcw@mail.gmail.com> <1197245d-6b9a-3c3b-82a0-dc6a1cc3de58@nic.cz> <CANLjSvVe99q4vtTW0TRopmQ0s9hC8HdMze5B6COs8Y_3unir5w@mail.gmail.com> <CAAiTEH8ntOerB6MGKMS2xcCK3TL9n4fyLq6F+bpUY6oTUpWN8w@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAAiTEH8ntOerB6MGKMS2xcCK3TL9n4fyLq6F+bpUY6oTUpWN8w@mail.gmail.com>
User-Agent: Mutt/1.8.3 (2017-05-23)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/91dSANd2elQUSfouymgELOEznEo>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-pan-dnsop-swild-rr-type-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 05:45:46 -0000

On Fri, Aug 11, 2017 at 10:39:50AM -0400, Matthew Pounsett wrote:
> It sounds like you're assuming that SWILD would be supported by caching
> servers that do not support DNSSEC or NSEC aggressive use.  Why do you
> expect implementers would adopt SWILD before adopting these much older
> features?

(Without commenting about SWILD)

It does not have to be due to implementation support alone. Many
operators stick to unsigned zones. There are many reasons, some of which
I'd mentioned in the unsigned NSEC thread. Resolvers have to deal with
cache pollution and unnecessary upstream queries, but they have no
control over whether the authoritative zones are signed.

2 mails up this thread, there is a comment about "New features are
provided only by the latest version of the protocol." This seems to mix
unrelated things together. The latest version of DNS (if there's such a
thing) doesn't mandate operational use of DNSSEC. Use of unsigned zones
is not obsolete and may well outlive us. Most zones today are unsigned
and a carrot like NSEC agressive use is unlikely to change the level of
adoption of DNSSEC significantly.

Alexa Top domains and DNSSEC:

24 / 500 top domains (4.8%)
20548 / 1 million top domains (2.05%)

(12 years after introduction of 403{3,4,5})

		Mukund