Re: [DNSOP] how to delete obsolete DS for obsolete DNSKEY using CDS/CDNSKEY

Joe Abley <jabley@hopcount.ca> Fri, 07 February 2014 19:56 UTC

Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 407DA1AD0EA for <dnsop@ietfa.amsl.com>; Fri, 7 Feb 2014 11:56:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kearbSacRtko for <dnsop@ietfa.amsl.com>; Fri, 7 Feb 2014 11:56:28 -0800 (PST)
Received: from mail-ie0-x234.google.com (mail-ie0-x234.google.com [IPv6:2607:f8b0:4001:c03::234]) by ietfa.amsl.com (Postfix) with ESMTP id EA4F61ACCDF for <dnsop@ietf.org>; Fri, 7 Feb 2014 11:56:27 -0800 (PST)
Received: by mail-ie0-f180.google.com with SMTP id at1so1961054iec.11 for <dnsop@ietf.org>; Fri, 07 Feb 2014 11:56:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hopcount.ca; s=google; h=content-type:mime-version:subject:from:in-reply-to:date:cc :message-id:references:to; bh=aGBZLQ5MP58tBrJOy/jxBIhUuqXwJh/8xUDocXkBui0=; b=DRaRCF17rbdn94LsyJv7trNEbSnxCDSr0M6uJpSAMeug5yfjcTMfFQYkqVZB5ZUPq+ zYyrKvyzh4zRP+GWJXl0ofEWkhqF4YU5cqL12qd5shruEhoe9HL5/Idb5BHG4G1kbSiQ xdVur2gD2opmsCMzjU2ljtbvlFAXB/maj8HRQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:message-id:references:to; bh=aGBZLQ5MP58tBrJOy/jxBIhUuqXwJh/8xUDocXkBui0=; b=UbXg0G0SCrz/VQnbxoejSHPyzIAg94/w+k+bF/neq43DVpOoByOr+Z/ciAxVFqPcbf bZ0vdyFZCxt8VfXJm6k3onY09tytrg1Wr/Xt5SwlBQXsViMrwy8LSt3EcVh6vP0GFKTj 2Mmo/a7Ky2upNUMMoR3aZPStZtmFCU4YixX59LchWzfusxHOiTv0wME85ynvp26bD5AH tQFyyyeuJ20BkABm7JnwC0bCLUqcpy+fkza8rvoGeIigU75kKH0NwpJqZgc4IsDnoHob zkCxIgc22BjNfkL53bZRAhzndkWEz9VJl8WQe5BIR5SosxcJ/WbCsUU4caKchjh6LK5w 102A==
X-Gm-Message-State: ALoCoQnIbGRrnm4HrhnrolK4niyBRt/mfTAPArxmjpx/L1lUE/coVdeGw/7f2Ym5pbo/YSBPaO2o
X-Received: by 10.43.153.138 with SMTP id la10mr8954263icc.10.1391802987737; Fri, 07 Feb 2014 11:56:27 -0800 (PST)
Received: from ?IPv6:2001:4900:1042:1:94eb:1bb3:5e14:75f3? ([2001:4900:1042:1:94eb:1bb3:5e14:75f3]) by mx.google.com with ESMTPSA id z5sm12880544igw.0.2014.02.07.11.56.26 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 07 Feb 2014 11:56:26 -0800 (PST)
Content-Type: multipart/signed; boundary="Apple-Mail=_F7624359-B49E-45E6-B0BB-F97198D97BB6"; protocol="application/pgp-signature"; micalg="pgp-sha1"
Mime-Version: 1.0 (Mac OS X Mail 7.1 \(1827\))
From: Joe Abley <jabley@hopcount.ca>
In-Reply-To: <CAHw9_iLw6+php0bNg4UTm0z2Xf8Luzbx-TRC8xxZBKvGcgz+ew@mail.gmail.com>
Date: Fri, 07 Feb 2014 14:56:24 -0500
Message-Id: <3F1E65D0-BD09-4465-8D94-EB601420C07B@hopcount.ca>
References: <CAJE_bqe95pn8rHvK3UffPDn+_rGYiq2G5sfdgqisH4JG7gFjBA@mail.gmail.com> <CAHw9_i+Jt4Ok+CddheGT_nA=e4srgbUSQy98GeQ9qGn_Cncjag@mail.gmail.com> <52F52215.9090709@dougbarton.us> <CAHw9_i+Aanz5NZVO5Q_x=1zyFzHZSmeU6yoLx3cDkwD2sC-XMA@mail.gmail.com> <52F52386.4070305@dougbarton.us> <0D3FD7ED-0A92-4B8E-9619-2B7D84013DD6@hopcount.ca> <CAHw9_iLw6+php0bNg4UTm0z2Xf8Luzbx-TRC8xxZBKvGcgz+ew@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>
X-Mailer: Apple Mail (2.1827)
Cc: dnsop <dnsop@ietf.org>
Subject: Re: [DNSOP] how to delete obsolete DS for obsolete DNSKEY using CDS/CDNSKEY
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Feb 2014 19:56:33 -0000

On 2014-02-07, at 14:22, Warren Kumari <warren@kumari.net> wrote:

> On Fri, Feb 7, 2014 at 2:12 PM, Joe Abley <jabley@hopcount.ca> wrote:
> 
>> On 2014-02-07, at 13:18, Doug Barton <dougb@dougbarton.us> wrote:
>> 
>>> On 02/07/2014 10:14 AM, Warren Kumari wrote:
>>> 
>>>> We are not allowing zones to go from unsigned to signed:
>>> 
>>> Right, and because it says not to do it in the RFC no one is going to do it? :)
>> 
>> I don't see how it would work. The parental agent has no automated way to trust the C* RRSets published in a zone with no secure delegation from its parent.
> 
> No no no... You don't see how it would work *securely*.

Fair enough. I had taken that as a given, but you're right, it makes sense to spell it out.


Joe