Re: [DNSOP] [Ext] Questions on draft-ietf-dnsop-private-use-tld-01.txt

Matthew Pounsett <matt@conundrum.com> Fri, 30 April 2021 00:09 UTC

Return-Path: <matt@conundrum.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7ED5C3A1911 for <dnsop@ietfa.amsl.com>; Thu, 29 Apr 2021 17:09:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=conundrum-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lu5B4Az9jCT1 for <dnsop@ietfa.amsl.com>; Thu, 29 Apr 2021 17:09:16 -0700 (PDT)
Received: from mail-lj1-x22f.google.com (mail-lj1-x22f.google.com [IPv6:2a00:1450:4864:20::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4580C3A190F for <dnsop@ietf.org>; Thu, 29 Apr 2021 17:09:16 -0700 (PDT)
Received: by mail-lj1-x22f.google.com with SMTP id v6so1850308ljj.5 for <dnsop@ietf.org>; Thu, 29 Apr 2021 17:09:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=conundrum-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=eyF5QHB4dvoo3pMq944PhP6Q6SwkAlenU7yGbAiEAqU=; b=IgD0c3Bdqv+m423ZnvviylLOphSj+fIMckCf9BAgA7U+Zu2e6p+98uB74mHAPFFbDM O/LlhbRn1V6p5HbZM7uv7LJCm4tWIehQo5wmMN4WCKrEDQVgdpEydO287xKxuWDaVTWz P/RUMPyxsJpi6L693vXfgEv281Isl8d3O1KfOOEOTrsjszcivqjKluqgdzkr6VYIHUH9 y5TkMd9yn0He9pPun5P9SSV+2MdwQox5EnP7ePUJ1uEw1TxBFSVinx19alPBVkHJ8sm1 xbXvEILEcCubiyI87dUGGadQLEYP2K616K1M5k/z4kuIy2eeIsf4oumKqJ0itzr2C8qj xFZA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=eyF5QHB4dvoo3pMq944PhP6Q6SwkAlenU7yGbAiEAqU=; b=aspynD/9/bsM5cy+T4hDKb+ixJl8wmdkZU8n0mZcRIL1WAI4JkXbZG7ZVzxuQ6b7fY JYQWsScTkdCkVLzBDHYqW842aURV73gz6Kb2ZJEyrpyEMmtMTODsqiqkVI98hPDRtyz0 VePHfWWCfohVuvbPCep6P0CvmSy5Fgy+nMOZg3n5v1BpUtbSqtbhDt0SjWpPRl0EDQgA ACC+0P/95cqXP5DRLMucO+P2cSaTwsfIWEQJatoO9OZ9jRR8/nlHsHuZOk0cpb91UfrK nLnVcASXw/k5vXNTI1o1AkEn+r/E6G86U9166uSQSt1lJrhEm/lZltmhdr55Fz/rb0I8 xaqw==
X-Gm-Message-State: AOAM5309/MsNafhwn+nz6v/5XnVtxReFgqysJzNpTkIiOPh70GTfg8R7 V7Gt15RCZGiBkYBa0ZeqgIsLmxnHQTEbx1gHYTIOig==
X-Google-Smtp-Source: ABdhPJzh5WyBpNVxIKTtBFgdd882n7AxYNzM4jrAuHtwU3OWwdTAtU19j6xuITjinerKRvKpYbelJShIRi1W2R4S2vU=
X-Received: by 2002:a2e:8184:: with SMTP id e4mr1638144ljg.311.1619741353408; Thu, 29 Apr 2021 17:09:13 -0700 (PDT)
MIME-Version: 1.0
References: <161805873252.19178.11471347094062424385@ietfa.amsl.com> <88395F35-AF22-489C-B9D6-2FFE4EB1A767@depht.com> <5F3F8198-23EA-4BA9-A07E-EF7AB035CE72@icann.org> <70F7005D-6F8B-4BC0-BDAF-A415F62A7E8E@depht.com> <8E609BE8-B440-4E29-B454-724055A0DFF2@icann.org>
In-Reply-To: <8E609BE8-B440-4E29-B454-724055A0DFF2@icann.org>
From: Matthew Pounsett <matt@conundrum.com>
Date: Thu, 29 Apr 2021 20:09:01 -0400
Message-ID: <CAAiTEH874LA+MqjoBu-2f1HGPW2wNHXAku7TNAydi01Uxc66ig@mail.gmail.com>
To: Paul Hoffman <paul.hoffman@icann.org>
Cc: Andrew McConachie <andrew@depht.com>, DNSOP Working Group <dnsop@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/HSbicD748RsTOh6La1mPo1byef4>
Subject: Re: [DNSOP] [Ext] Questions on draft-ietf-dnsop-private-use-tld-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Apr 2021 00:09:22 -0000

On Mon, 19 Apr 2021 at 12:34, Paul Hoffman <paul.hoffman@icann.org> wrote:
> That's correct, as it would be for any private-use TLD. In fact, it's not just about validating stubs: an organization wanting to use a private-use TLD cannot have validating stub resolvers or validating recursive resolvers anywhere in the organization.

* Unless they configure the appropriate exceptions into those resolvers/stubs.
(Spoken as someone who has set up validating resolvers inside an
enterprise camping on an unregistered TLD for use in AD).