[DNSOP] Re: [Ext] Persistence of DCV, including for Delegated DCV (for draft-ietf-dnsop-domain-verification-techniques)
Ben Schwartz <bemasc@meta.com> Mon, 09 June 2025 14:50 UTC
Return-Path: <prvs=22552bd91b=bemasc@meta.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3312632B2FE9 for <dnsop@mail2.ietf.org>; Mon, 9 Jun 2025 07:50:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.293
X-Spam-Level:
X-Spam-Status: No, score=-2.293 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URI_NOVOWEL=0.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=meta.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MR8EcmmGU6Nq for <dnsop@mail2.ietf.org>; Mon, 9 Jun 2025 07:50:41 -0700 (PDT)
Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com [67.231.145.42]) by mail2.ietf.org (Postfix) with ESMTP id 4D67E32B2FDF for <dnsop@ietf.org>; Mon, 9 Jun 2025 07:50:40 -0700 (PDT)
Received: from pps.filterd (m0044012.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 559CvHnI005944; Mon, 9 Jun 2025 07:50:39 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=s2048-2021-q4; bh=vwmpeKR+iSeHCi/35/e6 V8jr8fZURmlnCde4Yvzc0zU=; b=WCV8xlJlDsYr8WV2JVUR/YZFINtcUYMVWYeK 57gvYHQn2Z6guP7nx9ebWw5zXV+ixDGo7BDQXrw2ahazHk8VtQ1ImLRkj5k5h2Rl HIcZSoyWpby2XQRkXkQ0bWy/3lyNcIxq8q0diCdEu3HHEdlR4YWnYWcez9iA+sHK o/i2l5TmLQXYu5w5FI5v9OO7BEj7/m8+sIXfwW2KEXpmMz2+0jfAbOY5DZxODE1H 6WQSjxZM6vVNBM8DsSfpzBE9EbmAoI9aNP6dvfkupRT+p7nHJH9GoDbWNCBRM4qG nmKgqk+T3Mk2WMif27nVv6i3AZuNWLao3OmovPJrGKrc8x5PiA==
Received: from nam12-mw2-obe.outbound.protection.outlook.com (mail-mw2nam12on2054.outbound.protection.outlook.com [40.107.244.54]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4755a4p4nh-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 09 Jun 2025 07:50:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=rv+D6MKy1zjbbMoRFp/e8AxLUV8nn5oUWwVpQ+kXL0YoInrHF8id3iAZ5q/Zvc1ieXouqtXB4kboi6OFrCVgBKzOmDoOt0lWLg08rQigx1xXwp6UymVk7Kj7YkLwJeEaJ4ttBT8zpiSoZoAser6EBuUkZ0uTBiDrFjyX1SQW8eXVsVzc7MDt4Wy3YRuWqozvA73qXSQ/IXZkAehBlFfGTkfUtL0uDwx/l3SRjV7sukWkw6cWa/4djiOmvPxTATY1H9ze8+lk5De44QbOAzs/Nj0f0UCW09zYogBB02Saq2qd/PJMrToXrdK9s0Y/e8eNAGLWXv7uBOnBloHqtaU3KQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oNXVTljlLpBF1ZmzMQFeg9jiuf2u6Tpdlbm8bKrPPVM=; b=YKb4kqqZ8whp2uyILrSJTrRbYxuFOq9i/R2v3hPeUkjjHw5UYbhcFXNiK/fxH1c39CGP1u5OazqzG7d7lYA0VR26nT2YiFAEXGioRgRR80r0Jcy2Bx2g0t2NKaMMQ1GKQrgIWkd8/FMXnJ2ecpOJfGeHhzcWa++gKb68xcGy4ziYUQaoJQ/tNGVpCvw9H7HfUBNVSreMs+7qetpWScl4bnqWz096rg8thq129DhPg8jQeBRNkOJtH+Q0Ty0jOeVOqbWN9uKvOM81gSI8m2hU2hESGsgm6ZKqLOOmUkj+4dkxHHHQIGLwW1+QB84bVc1Jblf0mq+APTSX6nLeKQzPag==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=meta.com; dmarc=pass action=none header.from=meta.com; dkim=pass header.d=meta.com; arc=none
Received: from DM6PR15MB2361.namprd15.prod.outlook.com (2603:10b6:5:82::33) by CH0PR15MB6296.namprd15.prod.outlook.com (2603:10b6:610:185::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8813.30; Mon, 9 Jun 2025 14:50:37 +0000
Received: from DM6PR15MB2361.namprd15.prod.outlook.com ([fe80::33bb:f6d1:d19f:95b6]) by DM6PR15MB2361.namprd15.prod.outlook.com ([fe80::33bb:f6d1:d19f:95b6%6]) with mapi id 15.20.8813.024; Mon, 9 Jun 2025 14:50:37 +0000
From: Ben Schwartz <bemasc@meta.com>
To: John R Levine <johnl@taugh.com>, Erik Nygren <erik+ietf@nygren.org>
Thread-Topic: [DNSOP] Re: [Ext] Persistence of DCV, including for Delegated DCV (for draft-ietf-dnsop-domain-verification-techniques)
Thread-Index: AQHbvp+M3AnOaq0ojUaBCQcWT05HUbPPNvmAgAAE7oCAAANIAIAABl7EgAAYbACAAZHnAIAVx2IAgACh3oCAAaesAIAAA3GAgAEJYwCAAAGvAIAAB4GAgADlKgCAAMm4AIAAA6gAgAAJWACACtrSgIAAJaYAgAAGaACAAQpdgIABsygAgAANAYCAAXEwKg==
Date: Mon, 09 Jun 2025 14:50:37 +0000
Message-ID: <DM6PR15MB2361CDD15CABAEDA7CE91E45B36BA@DM6PR15MB2361.namprd15.prod.outlook.com>
References: <CAKC-DJhS4_1P5Bqu-0YWWr9jkxBOt40rx5804UAUp7DhAsc31g@mail.gmail.com> <40408285-974A-4790-B653-DF4C3798F1E0@nohats.ca> <F7E48A3F-DA2C-4E54-92DA-90CD0EDE78DA@icann.org> <478e1879-93d4-4b0b-a99f-bbdb422bc073@taugh.com> <CAKC-DJh4ck_okAmdssMTfj5iq9X2o_-_Z6MzLQRSfZyjUJ3t6g@mail.gmail.com> <fcb3b846-7d2a-c567-2566-ba1614df31fa@taugh.com>
In-Reply-To: <fcb3b846-7d2a-c567-2566-ba1614df31fa@taugh.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM6PR15MB2361:EE_|CH0PR15MB6296:EE_
x-ms-office365-filtering-correlation-id: 59e938b9-5b1e-42ba-84d3-08dda764fee1
x-fb-source: Internal
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|10070799003|4022899009|366016|376014|13003099007|8096899003|7053199007|38070700018;
x-microsoft-antispam-message-info: rLobhPVp8CtwyJjj5MZkxnHNjM4Ye2Wq7nHApm9xrCZ2MUKEu96HclpPL5JwnmhIR9Lb+VKU35cWKE/bafJKc9wubSpG0Gmjc3cHh2qdxfGCP7VrTdrrZibLSKbvZk8dTNkvEPeiR5yC7fNHlKAc02MYBIm5Ta44Arjs1pOPpEfNfdwmSazxsZ0oHZBDPWC6pXJOxufuhRhNqS3c6iMD3ERjoNeYxzhHIFS3++91LAGK4ED74KlaDPReXVEVP7rO7app80tg3vdlEY8TJJNU7igw/VQ7fPZkVc2ysjq5v6gkV4YexafTNXpQMGr0DwwjViUVtL0dq+TfRJELKzRIVsEqWOrqrqYSgtk5WNh6UBRlMu+4lnkf631Q2EhtXZXf/23foyeoF2p3g9sISJ6B4RHxbL34HtFGuYHhuJTzPzqe4OGt36ZxOkcjwPWNQ3KCR6oX+NY8aAmOfAkCNJy0jGDeQN59xEZcNzHuF9QLn5MKEJ4CHayaImV+iT+TBj0GfCFLy8zLhIQByzc/Gap4ikqZUWYQTHpL+B40CENFiYBzcNW1vr9uTe8IdqAtZaV65jl0NmBx9tudYkyg5wWVDhMpv5jJkiLmsMZbkeYvxrCPZQ/bmDLwia6N5+jxCS8S7dIle6zznGSTFpky2fsTEH9PvW5m7NDVJgSlI3rLf7Cg4Nbeqh9JaQyljTcR7IJah4viLZ9/Ly5N5fuDFaZ8vBRBvosuAVDNGtkZyZL6YZCk8ZcBsOZIQ/KWlAdpFxrpD6GD04dS7pq+NNo3IVHIiEEAoHTfLNHZ/nTJjUWlRs5WIlv9Zn5o5icDJAx/faBpaI3suzkyICfzDXhorZ25P4S0bLqL/W9xbjxDThseoD25nI/7RktLD+X9GZugm10ZH3gMFXcNjCSwcUB3KdMt7Zynnm5yeR1pGstr7018PIUgWcbHUgVTWd/POn5tgyAKEj54/EOz+WPL78/JYAE6NDD8A+iM0XHAdqlZp6Bgy9f1KDgU/nYrMp1fZFrHTjhbNCovb2oBSouNL5MvU1Ntb7hcOi3mpBSrUT91CmAX0B4FjLMpWRmXoWXtqswwHQaSottcPnQNSO3HiaJAELyQf4Tay+LxlsFaS4W5YXiOKpWVnqnbe2LdkZmR0czJMv7LYwQZJadEjo1smv5/QlyjrHvXrp02DOvD+yN2P/etUaZI7rbM+KM9TEKZbKTqIsTan8sK+phPucZPYrosd6hecvc+59JNikU6p1b9aNvDS8hjsN+r437KxkjFqTLtIHQ4tb0DQBKkyjHyfanb9Ola6s+lK3cEOHp33ll/519Rve5QmlTIGIx2CA2Kso4qrcD385q8KFaH64KsfvlAB1MWYRT5aJS8RDCu16C+RqVnn7kJmIDsbCYdkB6Flz+94xlkk+71jQYOkxK5Rkwh8UBI1lHkggmClkdfxof2BGnFm7M=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM6PR15MB2361.namprd15.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(10070799003)(4022899009)(366016)(376014)(13003099007)(8096899003)(7053199007)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: qHHtdFz6H6vTdaHZ5FR+BS4JXACZRBK3SOyArWOnJsRTa5o52zeFfRY3GtvrNDjnEaWQbw8Wjo+dds3EjQAtrqWr3gNuClFCXXfLiwkSkpyogeZV00zy83pot/Z6JdwALbAnpiflfAmtVis/M1L1B3uwwK7mPWHmXVTcUeYUQahCr3BXb3pb82H/ohQ3X8XbC7FxCdzxQn6dm3EQKu8gGNfiTI3YGYuwtaMYPbHxDDcgEqhQ8KzqnoBqeuRRNspwiWudqLEa3TurJsnlXY5QIgP/BNsKl4zdfSj3wVvgZfCzD7xyvJAn2hI1cASmzm0yJ6OrxHih4cswuFakMuS5MokuRcdVPRGY/SRqEuGNDUXT7HgcNkc81AYy1WyDCraNdm5Lf/Fg6DRsBJYMr/S8fFp0OpCqFd6TJI9ZTHUjmJbHqDfEEBftgmA0LHTRm9xOhQJxfuSTYAK961xTJ6fZCOJ68chshkRXt+I7jPYx+FK+LjCyeQYRMyLv4lA55fZWyg6liJJcXH/cS0mFKNdJniapaJWBC4bvAcyPBx9a7664QXrqiOKx2hdE5Iiip+3HPVnIccZrto2J4Z/wRzAHfF+qGn7sAhyDZq1yE6/P70wwuNRf0tQiv+rRUyBl30NzNlcqtgnqy34RL4auKU+bbdd4BgdV4hQiapSylPO9tqF7QHm9CvFcGsVFU9WMwDBkRnHbtOq1NRNYMErJoRzWVsOxrhT48n4RfwEhdl0eTYW5Cccai5CF5eoFa4Ht402RMmG8H2fX4wmiU3FmCFDXz98jr37YD1YNu327LMf2VL7uWS73zo+M315S7eS0VgXhRHnGKtXDg7nmcaOw5r+Z5YVMp9/taHfnEc5yWY/nSnrp1uodzUJNYgkbktvzh1/zCNvZV+Vb8SFMD8CdYSPTszhj27V/kSgv0lXtasElQhdmSkpZT+UaVgy9n5idV14BvnngFUyQeeOUxFwxB5N9qnNBj7DcS7DVPEebm9MmM0DmmF7mJy9IBYD3ryUCJAGNLYDcOkI8AlRE8bknATgypnUbgjUgSdTss+G5JmrJwXSggkjgchxLDq1k8pXKnmTC/ICDH9i+QcyWbeGDgtdeD9ry2Iv6B0ssGA34Wl9uGWZK/1Lg+rFOVXdPG3j9qwhMJplsDBkqOjIZVqTQ9NRgRRInieYZqXyrjFqBu2ufoLNWFdLajp4UeIkbuQkXCpltmuPmy7Q/XEkJkEUJ8WJk7A5Qu637fRRLTtivwsv0ymjMZHFduOLP3+kGXUU4Qx1EfecLbc3KmQ9jCZTQREMAmjd2ubTFxUGuXvapmGaQHSTEi/jKX7uU0B8BEaDsDZrzeMPRA4SBHQB4rgoN34HSoEngDwA+BuBOMKCO5HFWsDPStJiGEAcNZ976coOxUViyKNgK4doZ2g3d9qRzKaI+jtYvH5VQ4jFRGcX80QVOu87uGDeYQJieCrmFgqr2jklOKd9WHQqvfTHFvFpeXyy/wrbVVwy+/83800IArpkkE8QoaEKP60iasaCuOQ+QFrwcBN0PLSvc2pzLTjWHp2uyGMAnp51E5XxtOGM4YLS1tvuq67XXPF1KUo/5gA46Uex/
Content-Type: multipart/alternative; boundary="_000_DM6PR15MB2361CDD15CABAEDA7CE91E45B36BADM6PR15MB2361namp_"
MIME-Version: 1.0
X-OriginatorOrg: meta.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR15MB2361.namprd15.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 59e938b9-5b1e-42ba-84d3-08dda764fee1
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Jun 2025 14:50:37.0702 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 8ae927fe-1255-47a7-a2af-5f3a069daaa2
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Y2wZd3FsBZDmKoMFtXaNLy4WrwP0zpBMUJDyyjr+FRHcrA69smkoNr4H2cXcfZ5+
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH0PR15MB6296
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUwNjA5MDEwOSBTYWx0ZWRfXyMw3HMQihUdS +sbhjwZ1z5eUjAMYasHVI2fnXp98AyyfTRUNIn+Bmp+cTeKOBUhbNrlriy1oAKzZAA97KauqDjL yLoMzxyXaw25JRBEX9Ic7Es/gHsvdmwxFLDP7E3tMsnDy9AQP1unnL4ltbknNFjJDrRfyRH9bBX 3dGMjirCR5eIbnw4qtNvZVPnJIQRkcP/Gm2KmBUMPdofXTpepNiqqgslfPjqUN4DmVZ4Mnn+kXZ 7k9hKdABPNb/TJATeL4EK8MUW0geJnNVBkHSGG1ygmzninqNNJd+M4G+a7ldkm81ad3NvDcstdD FgtakW/3hywRbNsHC6XjpMEcL7ScPvmdTy0ICntNWe0G6tCMosxoZdeqFo85TEVFjkvK9r+8p0+ 68pdgsZd0iOs4APesR8kk2K2Confn+E6vVJR4n8e+/gUntwyQpjvSS8HI7aHPPgKgirre+/c
X-Authority-Analysis: v=2.4 cv=WcYMa1hX c=1 sm=1 tr=0 ts=6846f4bf cx=c_pps a=G/jdwU3w1YLlpruHN4AJiQ==:117 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=wKuvFiaSGQ0qltdbU6+NXLB8nM8=:19 a=Ol13hO9ccFRV9qXi2t6ftBPywas=:19 a=xqWC_Br6kY4A:10 a=6IFa9wvqVegA:10 a=HHdnZQ_pAAAA:8 a=QLhupLqRAAAA:8 a=uZw_3lL1AAAA:8 a=48vgC7mUAAAA:8 a=A-pl1HzDzviEopZeN34A:9 a=CjuIK1q_8ugA:10 a=XBT_DB81R0KPLcGn:21 a=frz4AuCg-hUA:10 a=_W_S_7VecoQA:10 a=0URaEJdcxAOFAwsxFTuA:22 a=tar-a19HCcU9EdznJS_w:22 a=izJwDFX-b3pl2plFB0Pf:22
X-Proofpoint-GUID: DG8HibcrWQX8s0uxP2-yQE8pldoCv-In
X-Proofpoint-ORIG-GUID: DG8HibcrWQX8s0uxP2-yQE8pldoCv-In
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1099,Hydra:6.0.736,FMLib:17.12.80.40 definitions=2025-06-09_05,2025-06-09_01,2025-03-28_01
Message-ID-Hash: FQYGTJOZ45UYJUYGVSPSQBEHE72PJOTX
X-Message-ID-Hash: FQYGTJOZ45UYJUYGVSPSQBEHE72PJOTX
X-MailFrom: prvs=22552bd91b=bemasc@meta.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "dnsop@ietf.org" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [Ext] Persistence of DCV, including for Delegated DCV (for draft-ietf-dnsop-domain-verification-techniques)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/ALmBbVbD9QdtO6HV4SreRnqMYLw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
I think this PR is a fine direction, but it still seems to contain a certain amount of internal confusion. If the security "relies on the causal relationship", then how can it be secure for persistent validation? What is the value of knowing that "either the DNS Administrator of the domain has not chosen to remove the Validation Record or that a new owner of the domain has re-introduced the Validation Record"? In my view, the core problem is that the draft is dancing around an unstated but essential requirement, for all DNS zones on the internet: 0. We define Validation-Controlling Entries (VCEs) as any records or delegations at underscore-prefixed or wildcard names. 1. Zone owners MUST NOT allow other parties to add or modify a VCE unless the owner name's next label is uniquely assigned to that party. 2. Zone owners MUST NOT add a VCE without understanding and approving its function. 3. When acquiring a zone, the new owner MUST promptly remove all VCEs whose function is not understood and approved. With these requirements in place, we can now speak about validation or authorization in a coherent way: adding a VCE demonstrates approval, so we can confirm approval by requesting a new VCE. We can (and should) also talk about the real reasons that we recommend high-entropy tokens: * As the easiest way to ensure uniqueness in distributed ASP implementations. * As an optional mitigation for failures to comply with requirement #3. * To obfuscate certain vendor-specific identifiers. * To guard against entries accidentally placed in the wrong zone. * etc. --Ben ________________________________ From: John R Levine <johnl@taugh.com> Sent: Sunday, June 8, 2025 12:16 PM To: Erik Nygren <erik+ietf@nygren.org> Cc: dnsop@ietf.org <dnsop@ietf.org> Subject: [DNSOP] Re: [Ext] Persistence of DCV, including for Delegated DCV (for draft-ietf-dnsop-domain-verification-techniques) On Sun, 8 Jun 2025, Erik Nygren wrote: > Rather than saying "I authorize this action" in a one-off validation, > persistent validation is saying "I authorize this User/account" I don't see a useful difference. Either way the entity issuing the token uses the unique token to identify whatever it is that it wants to verify. As I said before, I do not see any reason to make any technical changes here other than an option for the token to say it does not expire. We can wave our hands about on-path attacker but since I've never seen one attacking a validation token, I'm not aware of any practice we can describe, and I do not want us to guess. Regards, John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY Please consider the environment before reading this e-mail. https://urldefense.com/v3/__https://jl.ly__;!!Bt8RZUm9aw!9ExScallA0c6qWTIY0LOowCs2r3m3FqIUcAOawol_XK3gU9ZSnPWJj3xGJCWlbZMuqz7dEd2$ _______________________________________________ DNSOP mailing list -- dnsop@ietf.org To unsubscribe send an email to dnsop-leave@ietf.org
- [DNSOP] Persistence of DCV, including for Delegat… Erik Nygren
- [DNSOP] Re: Persistence of DCV, including for Del… Ben Schwartz
- [DNSOP] Re: Persistence of DCV, including for Del… Paul Wouters
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Hoffman
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Wouters
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Erik Nygren
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Ben Schwartz
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Wouters
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Ben Schwartz
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Watson Ladd
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Erik Nygren
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Hoffman
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Ben Schwartz
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Hoffman
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Hoffman
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John R Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Joe Abley
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John R Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Wouters
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John R Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Erik Nygren
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Wouters
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Paul Hoffman
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John R Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Erik Nygren
- [DNSOP] Re: [Ext] Persistence of DCV, including f… John R Levine
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Ben Schwartz
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Erik Nygren
- [DNSOP] Re: [Ext] Persistence of DCV, including f… Ben Schwartz
- [DNSOP] Re: everything bagels, Persistence of DCV… John Levine
- [DNSOP] Re: everything bagels, Persistence of DCV… Ben Schwartz
- [DNSOP] Re: everything bagels, Persistence of DCV… Erik Nygren
- [DNSOP] Re: everything bagels, Persistence of DCV… John R Levine
- [DNSOP] Re: everything bagels, Persistence of DCV… Paul Wouters