Re: [DNSOP] RFC 6781 and double signature KSK rollover

tjw ietf <tjw.ietf@gmail.com> Tue, 25 October 2016 15:35 UTC

Return-Path: <tjw.ietf@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B4DCE12957D for <dnsop@ietfa.amsl.com>; Tue, 25 Oct 2016 08:35:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id InzxJYvmOoZd for <dnsop@ietfa.amsl.com>; Tue, 25 Oct 2016 08:35:29 -0700 (PDT)
Received: from mail-oi0-x244.google.com (mail-oi0-x244.google.com [IPv6:2607:f8b0:4003:c06::244]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0FA951296A5 for <dnsop@ietf.org>; Tue, 25 Oct 2016 08:35:24 -0700 (PDT)
Received: by mail-oi0-x244.google.com with SMTP id i127so7749874oia.0 for <dnsop@ietf.org>; Tue, 25 Oct 2016 08:35:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=6Jk51HNINcxEg6nfoCfbJBBY+EXbWGZHaJNprcIiPh0=; b=k1GPVkrABc3Y1RMwgOr8oCP7eFbe1IOm4V+BmuarM6MIfpqUhhK6Ba6BirlSOrtuuF mjYatqrcZvz7SbxWA/gYNKv8cpUZd9oBw159n7Vmj+g4i/6eN8IG74X5OPCLz5ZljHlB vfGhjFjrHZ33S6USW7ZluyWBN0pl0tAfcaC6i0uTNKvKHCe0dDOEBu1GS0jkkh51xFr4 RZUKqIr8edtkehfiCNt9UpUznl3Y2O0guV4mzIBQjtS+tDjZH/hZiNbbel5OopWKe5/d hgTstKV8vUbCVCMzIC0llIBWIENl0dI7BuPUQASYg8G8eovgwTsWqfRuY9a6S5UOoSNR fa6g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=6Jk51HNINcxEg6nfoCfbJBBY+EXbWGZHaJNprcIiPh0=; b=OpJ/yLZ302uLFPbSC4a5mKDmBfRcGpcVxMMiy2ORREbYnAWPKFF/Hmpq4ZbAIFM7KJ ccDhPBg0aFiavOgO5eL27B2Bei5Suj6E9TbHkg9mG0kXPmXrEEmN7scNKtj76YdRqFwN vWh0g1I5GrSqszONbqL5HArp/AVnz+/Zabs7PO1yE/hXpvIEFF8b/vmEtMM2ktDrMYw3 2bDVlhw2dJoGMDimWoL22tJe/qr610LuP892FB5upYiBcS7bw4yqh+jUIkg1xOGxpA+A tK8mpCY4ALU0etuui10RE6s0MHv15ye5mmCZoy8P7hHFMGKr+dub+qCW9URq8/Ft8Tk3 EbWg==
X-Gm-Message-State: ABUngvd2ZWaot2MkpmMFwGK+yKWzC0Ptl/BIaPPXXCDqxyzFS1jFKKYi9TA2Wzveiz1u7Akm1xQcEeVaeGtICw==
X-Received: by 10.36.112.210 with SMTP id f201mr2317473itc.107.1477409723354; Tue, 25 Oct 2016 08:35:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.79.19.195 with HTTP; Tue, 25 Oct 2016 08:35:22 -0700 (PDT)
In-Reply-To: <85941abd-d589-309e-6947-20376c7666e0@pletterpet.nl>
References: <OF5B3B3222.83E22422-ONC1258056.00536355-C1258056.0056B9D8@notes.denic.de> <d8285e11-9d99-227d-e0cd-0210abdf431a@pletterpet.nl> <OFE34929BE.2E0C8D50-ONC1258057.00488BB5-C1258057.0048D848@notes.denic.de> <85941abd-d589-309e-6947-20376c7666e0@pletterpet.nl>
From: tjw ietf <tjw.ietf@gmail.com>
Date: Tue, 25 Oct 2016 08:35:22 -0700
Message-ID: <CADyWQ+FidHG_hFt7S7jeVDX6R7jVyOaEZ+ud6mUwY2vejFB=LQ@mail.gmail.com>
To: Matthijs Mekking <matthijs@pletterpet.nl>
Content-Type: multipart/alternative; boundary="001a1143ff40bf95de053fb24168"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/HL2R4iziXR_TWoImkzcwdHYxBYs>
Cc: dnsop <dnsop@ietf.org>
Subject: Re: [DNSOP] RFC 6781 and double signature KSK rollover
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 15:35:34 -0000

I agree with Matthijs.  Looking at 6781 that makes the most sense.

tim

On Tue, Oct 25, 2016 at 8:17 AM, Matthijs Mekking <matthijs@pletterpet.nl>
wrote:

>
>
> On 25-10-16 15:15, Marcos Sanz wrote:
>
>> Matthijs,
>>
>> my attention has been brought to the KSK rollover double-signature
>>>>
>>> style
>>
>>> described in 6781 and what I think is a mistake/oblivion there.
>>>>
>>> Section
>>
>>> 4.1.2 states
>>>>
>>>
>> [...]
>>
>> You are right: DS_K_2 may only be provided to the parent *after* the TTL
>>>
>>
>> of DNSKEY_K_1 has passed. RFC 7583 has more accurate timings for
>>> rollovers. The corresponding timeline is described in section 3.3.1.
>>>
>>
>> thanks for the pointer. RFC 7583 does it right.
>>
>> That begs for the question: how to deal with the wrong information
>> propagated in 6781? Submit errata? Label it "Updated by 7583"?
>>
>
> I think an errata is appropriate.
>
> Best regards,
>   Matthijs
>
>
>
>
>> Best,
>> Marcos
>>
>> _______________________________________________
>> DNSOP mailing list
>> DNSOP@ietf.org
>> https://www.ietf.org/mailman/listinfo/dnsop
>>
>>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
>