Re: [DNSOP] [Ext] Call for Adoption: draft-hoffman-dnssec-iana-cons

Paul Wouters <paul@nohats.ca> Tue, 29 December 2020 18:46 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B878D3A07EA for <dnsop@ietfa.amsl.com>; Tue, 29 Dec 2020 10:46:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KGxmOq33iyHT for <dnsop@ietfa.amsl.com>; Tue, 29 Dec 2020 10:46:21 -0800 (PST)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1BFDC3A07E8 for <dnsop@ietf.org>; Tue, 29 Dec 2020 10:46:20 -0800 (PST)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4D53KQ3M7nzDyw; Tue, 29 Dec 2020 19:46:18 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1609267578; bh=GPpyYQfZ89VZvkch+iLr6Nr1Rl8whMYUEORBEPZYX8Q=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=HJ6Ht/lUxvqPj5fx0SEf5N4bVRRZsIvezv+4GXh/igDL9wS6ooUPdENcJD4usr3IF hp2ztSZJJ1Bd01gTeZKtIxOUaU6KMVJ+5MgoNPvV20ImzDQMhKoh69VEqM8E9H8+Ho 24qX4ng6UIUQE95KeZ2TV10E2htGPn9ELR02b8O8=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id PeTuQ1HPIW0t; Tue, 29 Dec 2020 19:46:17 +0100 (CET)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Tue, 29 Dec 2020 19:46:17 +0100 (CET)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id B6EE16029B54; Tue, 29 Dec 2020 13:46:15 -0500 (EST)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id AC830384C9; Tue, 29 Dec 2020 13:46:15 -0500 (EST)
Date: Tue, 29 Dec 2020 13:46:15 -0500
From: Paul Wouters <paul@nohats.ca>
To: Tim Wicinski <tjw.ietf@gmail.com>
cc: Olafur Gudmundsson <ogud@ogud.com>, Paul Hoffman <paul.hoffman@icann.org>, dnsop <dnsop@ietf.org>
In-Reply-To: <CADyWQ+Fq2YvHQeq_k9ntnJMdhpmUtu_ainuR1pNCcXDpJ0yc_A@mail.gmail.com>
Message-ID: <1e776456-21e1-a5c-4056-60fe248545e2@nohats.ca>
References: <CADyWQ+FpwL=MBbBU=QrAGeDT+j2Jm3aE5fFkYm+VbH-up6mdgg@mail.gmail.com> <1CA7153F-2D70-466E-9DB5-216D3118030C@icann.org> <CADZyTkngFzo2fzpVxbYFo=eXCcYzraVcvb5DFZzSDpGVWOUe=Q@mail.gmail.com> <9774B325-FD8E-416F-B553-4EDB058FF98B@icann.org> <44FC25E1-A0AF-4726-8B3F-0520DD7A5D0F@ogud.com> <CADyWQ+Fq2YvHQeq_k9ntnJMdhpmUtu_ainuR1pNCcXDpJ0yc_A@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/9Ik5YUFW_47ZPWCjZKslV2RKwek>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hoffman-dnssec-iana-cons
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Dec 2020 18:46:23 -0000

On Sun, 27 Dec 2020, Tim Wicinski wrote:

> How about instead of loosening the requirement, we take the top 64 values, allocate them as
> either Experimental or FCFS, and it is explicitly noted NOT REQUIRED (or NO ONE WILL IMPLEMENT
> THESE FOR YOU).
> 
> That would leave the registry with the strict requirements and allow items to get code points. 
> 
> Too simple an answer?

I think this is the best solution. There just will be nation state
crypto, and this allows those to exist. And we still keep control
of limiting the international ciphers by the IETF to the small
subset we think is good, hopefully preventing new long tails of
obsolete ciphers.

Paul