Re: [DNSOP] Call for Adoption: draft-wkumari-dnsop-extended-error

Tony Finch <dot@dotat.at> Wed, 02 August 2017 14:12 UTC

Return-Path: <dot@dotat.at>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCE29126BFD for <dnsop@ietfa.amsl.com>; Wed, 2 Aug 2017 07:12:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level:
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9spAyC9xneVg for <dnsop@ietfa.amsl.com>; Wed, 2 Aug 2017 07:12:40 -0700 (PDT)
Received: from ppsw-30.csi.cam.ac.uk (ppsw-30.csi.cam.ac.uk [131.111.8.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1643C126C83 for <dnsop@ietf.org>; Wed, 2 Aug 2017 07:12:40 -0700 (PDT)
X-Cam-AntiVirus: no malware found
X-Cam-ScannerInfo: http://help.uis.cam.ac.uk/email-scanner-virus
Received: from grey.csi.cam.ac.uk ([131.111.57.57]:43465) by ppsw-30.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.136]:25) with esmtps (TLSv1:ECDHE-RSA-AES256-SHA:256) id 1dcuO6-000asX-d0 (Exim 4.89) for dnsop@ietf.org (return-path <dot@dotat.at>); Wed, 02 Aug 2017 15:12:38 +0100
Date: Wed, 02 Aug 2017 15:12:37 +0100
From: Tony Finch <dot@dotat.at>
To: dnsop@ietf.org
In-Reply-To: <20170731201310.GI8146@mournblade.imrryr.org>
Message-ID: <alpine.DEB.2.11.1708021507210.1665@grey.csi.cam.ac.uk>
References: <20170731171107.GA42492@isc.org> <306070B3-DD80-41F2-A0AA-2004131D0F23@nohats.ca> <CADyWQ+Ffu8JOn6co184PC-Uvv4G1qYU3d0ZchupRJEDDmfYKaw@mail.gmail.com> <CAJE_bqf7R7ZW5ixcZdOcaHDso+C5QbtGbz+Z1mOs+p9_C2_cAg@mail.gmail.com> <alpine.LRH.2.21.1707290851010.26738@bofh.nohats.ca> <53F8E12A-85F9-44F1-9CA5-F546244832D0@time-travellers.org> <8506D4D8-E31B-4AEB-AC7E-4C89EAEEA9DC@hopcount.ca> <20170730074253.GA33522@isc.org> <alpine.LRH.2.21.1707310953260.21291@bofh.nohats.ca> <20170731171107.GA42492@isc.org> <20170731201310.GI8146@mournblade.imrryr.org>
User-Agent: Alpine 2.11 (DEB 23 2013-08-11)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/FRKFguobOU4zuezXLFpo_C3OPqY>
Subject: Re: [DNSOP] Call for Adoption: draft-wkumari-dnsop-extended-error
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Aug 2017 14:12:42 -0000

Viktor Dukhovni <ietf-dane@dukhovni.org> wrote:
> On Mon, Jul 31, 2017 at 05:11:07PM +0000, Evan Hunt wrote:
>
> > Are there applications specifically trusting AD=1 and behaving differently
> > than with AD=0?
>
> On Mon, Jul 31, 2017 at 02:16:37PM -0400, Paul Wouters wrote:
>
> > Postfix is one but last I knew only when resolv contains localhost.
>
> Not only Postfix, also Exim, and perhaps also Sendmail some day
> if/when DANE support appears there,

And ssh can be configured to use the AD bit for SSHFP authentication.
There are a few alternatives for ssh + DNSSEC and they interact in ways
that are not always ideal - see http://fanf.livejournal.com/130577.html

> The AD bit is exactly the right DNSSEC interface.  All that's
> missing from the traditional libresolv (and not missing from recent
> innovations in res_ninit(), res_nsearch(), ...) is the ability to
> specify the loopback address as the sole resolver in the application.

Yep.

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  http://dotat.at/  -  I xn--zr8h punycode
Forties, Cromarty: South 3 or 4, backing east 5 or 6, becoming cyclonic, then
southwest 4 or 5 later. Slight becoming moderate. Rain or showers. Moderate or
good.