Re: [DNSOP] Consensus check on underscore names and draft-ietf-dnsop-rfc7816bis

Viktor Dukhovni <ietf-dane@dukhovni.org> Tue, 13 July 2021 17:01 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B07893A0D0E for <dnsop@ietfa.amsl.com>; Tue, 13 Jul 2021 10:01:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3zWM_olAShFo for <dnsop@ietfa.amsl.com>; Tue, 13 Jul 2021 10:01:16 -0700 (PDT)
Received: from straasha.imrryr.org (straasha.imrryr.org [100.2.39.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 209333A0D0B for <dnsop@ietf.org>; Tue, 13 Jul 2021 10:01:11 -0700 (PDT)
Received: from smtpclient.apple (mobile-107-107-59-252.mycingular.net [107.107.59.252]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by straasha.imrryr.org (Postfix) with ESMTPSA id D2A20D99AF for <dnsop@ietf.org>; Tue, 13 Jul 2021 13:01:09 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.100.0.2.22\))
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
In-Reply-To: <832f7712-1dc3-e563-f98e-8ec0ede25577@isc.org>
Date: Tue, 13 Jul 2021 13:01:08 -0400
Content-Transfer-Encoding: quoted-printable
Reply-To: dnsop@ietf.org
Message-Id: <73FDFFF0-5C05-45B5-82C1-0D909219DFAF@dukhovni.org>
References: <CAHw9_iKhvHwUfJMOp-YhJkimmnN0f3DLbh+JWYxhCiZ9CjEEQQ@mail.gmail.com> <0ed6efa6-c981-fa64-472c-eef0c5453f4a@isc.org> <CAH1iCipP2C0fPgFYBGeR3Esvzf4eMxVv+EJKgKkfSiVX3MCqnA@mail.gmail.com> <c225cb3d-7682-4bf0-831d-c841540d1f74@isc.org> <CAH1iCirP64PV1a7mAqUgi0mrg05WJySy8jq62HiEUuftQEF2TA@mail.gmail.com> <832f7712-1dc3-e563-f98e-8ec0ede25577@isc.org>
To: dnsop@ietf.org
X-Mailer: Apple Mail (2.3654.100.0.2.22)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/ARZ04UaJiXOn_wExQbX9an7sRdo>
Subject: Re: [DNSOP] Consensus check on underscore names and draft-ietf-dnsop-rfc7816bis
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jul 2021 17:01:21 -0000

> On 13 Jul 2021, at 6:22 am, Petr Špaček <pspacek@isc.org> wrote:
> 
> As Viktor pointed out in https://mailarchive.ietf.org/arch/msg/dnsop/w7JBD4czpGKr46v-DlycGbOv9zs/ , it seems that this problem plagues roughly tens out of 150k domains he surveyed. I think this makes further discussion about _necessity_ of the workaround kind of moot.

Full disclosure, I only tested TLSA records.  I can't speak to what
one might expect with SRV or other record types.  Yes, failures are
not that common, for what is worth another example:

	https://dnsviz.net/d/_tcp.mail.ncsc.de/YO3DpQ/dnssec/
	https://dnsviz.net/d/_25._tcp.mail.ncsc.de/YO3Bsw/dnssec/

Here the "A" query for the ENT was unexpectedly "REFUSED". :-(

If implementations at least seriously consider the advice to treat
special-use labels *specially*, I'll declare victory...

-- 
	Viktor.