Re: [DNSOP] SIG(0) useful (and used?)

Joe Abley <jabley@hopcount.ca> Wed, 20 June 2018 23:30 UTC

Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 43A2E130E7D for <dnsop@ietfa.amsl.com>; Wed, 20 Jun 2018 16:30:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=hopcount.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XnuTrpZUxRoh for <dnsop@ietfa.amsl.com>; Wed, 20 Jun 2018 16:30:06 -0700 (PDT)
Received: from mail-lf0-x233.google.com (mail-lf0-x233.google.com [IPv6:2a00:1450:4010:c07::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E934D130E72 for <dnsop@ietf.org>; Wed, 20 Jun 2018 16:30:05 -0700 (PDT)
Received: by mail-lf0-x233.google.com with SMTP id i15-v6so1854553lfc.2 for <dnsop@ietf.org>; Wed, 20 Jun 2018 16:30:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hopcount.ca; s=google; h=from:mime-version:references:in-reply-to:date:message-id:subject:to :cc; bh=90ig6cfdrkaonSCTqk+zsW+dWifqC793OpfhJhwNdY4=; b=RyjD2hhd/gw7EqbTuXTBF/XBeLK94fxMMyY/FfhmfaVD6THXdylhKR6bu2sMiq5jkM w5PNDdE0sTypyJgPkJdkcXqJMUi6UdjUeLzSnUXRn3x0QmeLpNav0EPplrrnU/URDsIV 6u/KIU1z2KMQ5TdYLbSPj3g7CLOrHDJTnUhrA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:references:in-reply-to:date :message-id:subject:to:cc; bh=90ig6cfdrkaonSCTqk+zsW+dWifqC793OpfhJhwNdY4=; b=gSYF8bnQaoHb6Z0AC7LKrVrdzGT9ceRlbI692+aP03tiMPKVkyiQ/lxSQdsUjcQ6Ez qKCWJE9Kh57XLTiVoztWuBVM2lPZBZNZUe9S+jDYp6jxRT+2nUfGlw4HlAL5NfsuiVAd HED0S6aVnWDz8hCskr4ShIzWixsMKxZdfGzc/amTGH72+4bgmE8yam5XxE+U3JlZtMwh E08nPXjDG8a0TixwSDtH6Te+IzrSvw2ooFc9R7GezkTER6TtNBxJ3VZ0Bzo4iqcv5LFP K08omt214agzTAWuJFcRH5LNwonDRV6Zz5Al8HpfZIUUYND9uizDdPvBfBRntpV1XN/G Fbjg==
X-Gm-Message-State: APt69E2UhAAoVtKdLQfX+KSPgB8SGYtgxHNnL8HKSokXf1Nmdg8DW+jg W0vwCYjL75Ftawmg53lJoatsJa9gVPJODMEMXwOvsg==
X-Google-Smtp-Source: ADUXVKL0s2eM9kDDFBlp8QxBlpfEHhRKAwBmf1Af3oVvLuVoSNuM8TxLVcq6qKYHs+6IS31hXhSraXyE7G+flAXFDPE=
X-Received: by 2002:a19:a947:: with SMTP id s68-v6mr3171094lfe.70.1529537403901; Wed, 20 Jun 2018 16:30:03 -0700 (PDT)
Received: from unknown named unknown by gmailapi.google.com with HTTPREST; Wed, 20 Jun 2018 16:30:02 -0700
From: Joe Abley <jabley@hopcount.ca>
Mime-Version: 1.0 (1.0)
References: <6C8533C2-6510-4A0E-A7EA-50EB83E43A7D@isc.org> <alpine.DEB.2.11.1806192154190.916@grey.csi.cam.ac.uk> <CAHw9_i+KWdEQEyXE3AVKChrnYWOvhdm5uAZHpaz+tATyh0EmJA@mail.gmail.com>
In-Reply-To: <CAHw9_i+KWdEQEyXE3AVKChrnYWOvhdm5uAZHpaz+tATyh0EmJA@mail.gmail.com>
Date: Wed, 20 Jun 2018 16:30:02 -0700
Message-ID: <CAJhMdTNqSq9fVpf6MrkJqsghKB40MP3BUBfq7xcGZ6_9W72Ggg@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>
Cc: Tony Finch <dot@dotat.at>, Ondřej Surý <ondrej@isc.org>, dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a16f74056f1b2dbd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Hvs3CwkjA-w0i0tHop9ilFYNj88>
Subject: Re: [DNSOP] SIG(0) useful (and used?)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Jun 2018 23:30:08 -0000

On Jun 20, 2018, at 19:07, Warren Kumari <warren@kumari.net> wrote:

​... what I'd alway wanted[0] was to be able to setup my own recursive name
server somewhere on the Internet, and then only allow myself (and a few of
my closest friends) to be able to query it.

For this particular use-case, why is SIG(0) better than TSIG?


Joe