Re: [DNSOP] Is DNSSEC a Best Current Practice?

"Livingood, Jason" <Jason_Livingood@comcast.com> Thu, 10 March 2022 20:33 UTC

Return-Path: <Jason_Livingood@comcast.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D4173A1BC7 for <dnsop@ietfa.amsl.com>; Thu, 10 Mar 2022 12:33:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=comcast.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 46QuF9DeYRw1 for <dnsop@ietfa.amsl.com>; Thu, 10 Mar 2022 12:33:29 -0800 (PST)
Received: from mx0a-00143702.pphosted.com (mx0a-00143702.pphosted.com [148.163.145.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 449B73A1BC1 for <dnsop@ietf.org>; Thu, 10 Mar 2022 12:33:27 -0800 (PST)
Received: from pps.filterd (m0184893.ppops.net [127.0.0.1]) by mx0a-00143702.pphosted.com (8.16.1.2/8.16.1.2) with ESMTP id 22AKQbAR016713; Thu, 10 Mar 2022 15:33:06 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcast.com; h=from : to : subject : date : message-id : content-type : content-id : content-transfer-encoding : mime-version; s=20190412; bh=kJ3gntqjitv2Xw0a0mLLZz+OFzU97hgIKmzrwxiB9Fs=; b=fPG+V7qaXKjwIbnXYRcpWDYh9nOqBVSeRp1Dd7AMWaQaFsy9KIN20tkQfRLE4zQ7UvVs 0Y2WdXlCIVLJK9RZdXqqbisjkxx6HGSrSAl/FoW9l2oKppFCbaRbrr5FPkuftZxk49lh kYFft0+Ue0h0YnXIBhp0LPTEebnnnEGGGjx9M36jZwrZ6AIdiO9ENcZlozRbdPzBmMLs JqI1brArVvAm7xZ1ufiNc+wb7thrHWXj1KKqges0Hmiml+l/WY0T9bUyEzYxgniOA75r ka0arqPxJuFsV0KEOBff/K+FD2N6GJ0ntzaswngdQqkd8KNoGNIxWP/KejggpY1RUhPm iQ==
Received: from copdcexop02.cable.comcast.com (dlppfpt-as-1p.slb.comcast.com [96.99.226.135]) by mx0a-00143702.pphosted.com (PPS) with ESMTPS id 3eqm6sb2ae-3 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Thu, 10 Mar 2022 15:33:05 -0500
Received: from COPDCEXOP01.cable.comcast.com (147.191.124.156) by COPDCEXOP02.cable.comcast.com (147.191.124.157) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.15; Thu, 10 Mar 2022 12:32:38 -0800
Received: from COPDCEXEDGE01.cable.comcast.com (96.114.158.213) by COPDCEXOP01.cable.comcast.com (147.191.124.156) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.2.986.15 via Frontend Transport; Thu, 10 Mar 2022 12:32:38 -0800
Received: from NAM11-BN8-obe.outbound.protection.outlook.com (104.47.58.174) by webmail.comcast.com (96.114.158.213) with Microsoft SMTP Server (TLS) id 15.0.1497.28; Thu, 10 Mar 2022 13:32:30 -0700
Received: from MN2PR11MB3709.namprd11.prod.outlook.com (2603:10b6:208:f3::22) by BN6PR11MB3922.namprd11.prod.outlook.com (2603:10b6:405:7b::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5038.29; Thu, 10 Mar 2022 20:32:26 +0000
Received: from MN2PR11MB3709.namprd11.prod.outlook.com ([fe80::adcb:3a1a:cfa2:8070]) by MN2PR11MB3709.namprd11.prod.outlook.com ([fe80::adcb:3a1a:cfa2:8070%6]) with mapi id 15.20.5038.027; Thu, 10 Mar 2022 20:32:26 +0000
From: "Livingood, Jason" <Jason_Livingood@comcast.com>
To: Paul Hoffman <paul.hoffman@icann.org>, dnsop WG <dnsop@ietf.org>
Thread-Topic: [DNSOP] Is DNSSEC a Best Current Practice?
Thread-Index: AQHYNL30N0S7EhW12E+AzvH1k4vn/w==
Date: Thu, 10 Mar 2022 20:32:26 +0000
Message-ID: <AB8BE583-6875-4625-BBD7-8D71377566FE@cable.comcast.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.58.22021501
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: e015697b-778a-479a-06de-08da02d516fd
x-ms-traffictypediagnostic: BN6PR11MB3922:EE_
x-microsoft-antispam-prvs: <BN6PR11MB3922F2B387EDF026F45B28CCC70B9@BN6PR11MB3922.namprd11.prod.outlook.com>
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: hXhe7sO2JmX8O05dUh1QtO2ust8wQVcUh154mEAvcxpi4k1xMGtAc84In99UDgrZRlzo5ymqb/RwjT7z0sVuUc8kF731d6tQm7vP2kuRzNE/eqRurBeLSSoHJKJoh1dh3P4sManl6U7p2uIjFX982apm84Ep2DXhNScBiwQL6liSiPq0CWqMaqOA8JBfZf8rhygJ91oE9PstfoBLYrwt4aXRMb+wSuHaQ6qRCbW1+lj7iXgnJJqwkTZiZMo/b3r4aWGvb3f46rWDF5rIFHVyM9LHLkxcszwNQYNjuFMRiLreE/8n9Ztj36KXYDi3FNRtR18UXg7LjVqgvJC0hpWrocLW5EwOWPn5v4B2OJ++V1EQtPgQqO5w22FGm2199pH4Fgt9KcLY5dp5UfuanuBX2DTMryBf1tKCsmQ9PPO3/6L54Zr9mZhiIOOFjUuud742FTM1QsnCFdKbNdW3uWYVhSHrBMfru8xpQTBgLjAqsIbNaMl8aIe/JDx8iZdFHpte9oCkBfKU9uG5ImRWauNla+ehYmIKDbB6PIblj8fGtabnWb5oDb9YgxYrJwsMAfJUhe53C7RPPcEtk+ZOfbXFIgVmRgEc4mU21K0AMgUb7mKdSf9t5qUrTWSOPHQka89hJhJidYvxkjitlwNznbAvUd/amsCdjl2PkXaCIHWPz0/NwmXGBqXukxAhNsnOxY28B8DT3IT1oM8IypNbJK0ro+1Bk6p0JTHKKAAT33ud7Eu0sgM6t9fbvoOBBxxVDMdUnQ848BMJwvI+g3QO9p7Hh/ZzWFI0/V7EPuUbaYTW9Omm+ag574wiX4U2VF0IXzJv
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB3709.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(966005)(6486002)(110136005)(71200400001)(38070700005)(8936002)(33656002)(316002)(508600001)(122000001)(66446008)(66946007)(66476007)(76116006)(8676002)(64756008)(66556008)(6506007)(5660300002)(2616005)(186003)(82960400001)(83380400001)(6512007)(86362001)(2906002)(38100700002)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: joPeKi/Rgen9mAdLLSuRWogvuZ1wFdZMeW/vy5uV8HjRt2eBxRJAjfRqQbfgI8igIHfZB/wrlZmXtvwkU52nMwpwtHJDcdXZDS2BcJhsqmCSzlLKuLy+nTzGRbsRXmfyswGSPeM0ru0470znAiUkZqF0AgbMD1h7nRSoz3mQi2DUNDO5vI1041VC4PJyOwv+2Zh3FX9R0YCrTHzcrOnfjXBnyAIQXyBjtyEvlWP5T/7T7xlSzN4Vfgf8+85x2JOzZy1j7EoTdayzRUx3TC/6WyXLV7FMZnjYoiwYBaXR6q9FJtmtPS0dx8gZlQcGm5TBUyqKmsrl/MsHMe9K3tNzl49WagG3hK4pCH1MkphdwvY1oomTvUsQJFTCApeIKuBT6hsfvCdPkXG8d4WpX2RWoCHfSwe7LH8B9tW4QmLD8W/oIRasjjkD62Jczb5vB2Jh5i+ZdVM5yMTko3MdnlxuUhaLuTEzuluY+ELPveA4BuUO8Rr8LAcacmt+11gHZzJVC3fpWidCv7KR/EA72acxvlJ2QhHZ2wzJSuIBi7Qzg6M7H3xns807VOn/XbZWgjgy8DEF5nXZFjT7sFSaK8iZig1qGskqCuSA+ot6fZPFMqJHLvp6mybRz7slrVZfDzB/L/sfcr2/CLUsRCiBNvmnAzv4xl2XCVo6wlNnxAUpeV2jWnEZUdYq/G2VFYlBfiALUZo8aBUqSEcILijHqbyJncz2BxPCTZsRDLF+9WWzgjBLcCKTOIfgiTspleCmS/cTSQvdwLopgE405GSwqdW2Fu6tCY1R6YT3swRnHWXESvWU3s4CFipYgKFGmEhnDhZJ3jVtPQOjo8kAyd4hcqKs4V6pH0xumZNN1onSO6s/G5siiorjiZIywz3N1zzE5EK2llibBIcGLai2E0BLVU/wteSZGKSosXg2lllpJvyDJlQKz+N/ew0Y0VQ4T50sxcv/pFFzV6LTNPxdVM8i1BYX5naQlCEgqbdKkVQt2GpvQnvUuLzm3RJtl/nmLLydiNj9Gel11/YgbmJH6S7DqGATJPu80XCQ7nQX9lSTGsxao7k2mo8m+RNMczZ5nPhpRCAGiYRiW0b0Iv4cH81l5JEA95Nhu1RMxt1QXRN1bi0XqtFfoJsrHj2kXPZMJhtHhr5hbZQda196YsyUVne0nY/MsaX+4cJDa6LAR1vL6GEbJo5WtroXy6PEjwKmfoqMsWci4yDAfj97NyKQ9mJDWncb0iti8FYrTDocJAGfqoDFps63DEF03/BDu6MbwVtlqIt3YGvhocvLJbmT94zaflgitVmma5QfrVu8aoO3RGYUKYJxd/Ryjxf2RQPQP3B7Ud8jbmbYWHDjqm0UI9DJdTtgZjol4rBY60wlS8n65VYsD0oF9ScddtWr0Fc5mkxbYlQn2kUoJKvGa4P0b+idVC9QjcgySeJm0izgqfCOc6sQzvcfRra5VtIclMC8FSVVyv2TLgL1hZS6C7a8FNZc8PJv/VTpOC2qwiKru7BCsaTcPYvADurTCF9whh9xP08es7Fk3lWEFN4G8NV22Sn3Ogz1QWn78vjoLAv90cIOg15kmEZ2Egz4SufmpBTtiVkMOVspXa32IVz5R0RWX+MnlEaMEwpBCdOFqDrqjsoWbooDfCQuwQcG73E/dvVh+Y8wOWghlmfj9YoRPcAXJ3MWzFVKFNcV2EOj0SxfkIiarHPvP6KsWTJ9A7JTKDAR/MMqt9eP8AoXUHKMEE/fesvUdrk1pxIlieB90GowV0B9fKKd7ZU=
arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UtfjNDE4RM7Cr33qGWhKBj1WI5ncvFqHmFYG7h6D2pwDQMD3xfee28AmjTjIy6m5GoGCNXlqKblsL7F2E+a4GjTm0i4PJnbRUNEFmpAOBbaz1Szkuxp3YXazDiGbAKiCPQzJe3ZUyj68vhaFzUy3yyAJp//x7DqvIR3oovrtlm75c5exceBfT0lUONpeSahzJNzy1z5RvDhefc0ROmav3GrfWw+IqQPmLtPMVfR/ETwYIV1tJBJwJUVhOQCArqMmHYipb6yzDCKOH5UdYDdPHiaqZwGNhHgnh2z6sMIDa6V4GEgwXQkWML8sy2ubagU0Or/MOvZSv3ZPT7Szxnjshg==
arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=wtOg59EY0GD2IYqgWr5RcApXvnTCBDKxeTsrhUvT63s=; b=UXOq5XEbZsIwq8Rjw2TA5eluGmNXbPCIgrwbZeaLHtpa6kA6e4UUXeVbTRAoqpFV0OF/N1nod0NDoZSA8tt/Y9FQzuYDJkOa3tX8HZkVBrf1GJyeZAtERAdjAaHcJtqpZ6f7Sb+OtZCKDQ9H6ppHvYxqOCKih8stdEIACDqNPiP0PnPs/YRf+kOihACDKmcat7IZVeOiAgmKJxvxW3ytWN+3YDPttv1bBRmllBUlv+xG7RKNKEMeGS+O94FR17UB8jQIXVDF2/GJeyYM5j0h5ffOvyzITcn3A9+ERTbliy3KRK6yZUXZ27IBgP4o/L3RtTidJnpwYknDSjzETaH7OQ==
arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cable.comcast.com; dmarc=pass action=none header.from=cable.comcast.com; dkim=pass header.d=cable.comcast.com; arc=none
x-ms-exchange-crosstenant-authas: Internal
x-ms-exchange-crosstenant-authsource: MN2PR11MB3709.namprd11.prod.outlook.com
x-ms-exchange-crosstenant-network-message-id: e015697b-778a-479a-06de-08da02d516fd
x-ms-exchange-crosstenant-originalarrivaltime: 10 Mar 2022 20:32:26.2379 (UTC)
x-ms-exchange-crosstenant-fromentityheader: Hosted
x-ms-exchange-crosstenant-id: 906aefe9-76a7-4f65-b82d-5ec20775d5aa
x-ms-exchange-crosstenant-mailboxtype: HOSTED
x-ms-exchange-crosstenant-userprincipalname: LqXsO1b87KAEhnoSmLI+axULBVJtrgosG6WUJj0F8VmPVLfRAqlRSqUFQ/bRNAnKArIA6mc+ABGLnoHd8cC7llkyc8olm4QGKDamKBq+6LY=
x-ms-exchange-transport-crosstenantheadersstamped: BN6PR11MB3922
x-originatororg: cable.comcast.com
Content-Type: text/plain; charset="utf-8"
Content-ID: <7241AEF53F85CE4FB7A490180153142C@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Forward AAETWI
X-Proofpoint-ORIG-GUID: fecrzyN_ETv_JFHlEFb6_LhEZmKoZzeX
X-Proofpoint-GUID: fecrzyN_ETv_JFHlEFb6_LhEZmKoZzeX
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.816,Hydra:6.0.425,FMLib:17.11.64.514 definitions=2022-03-10_09,2022-03-09_01,2022-02-23_01
X-Proofpoint-Spam-Reason: safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/J2eRBudW5u0JDQHJu3ZEZjP0NOQ>
Subject: Re: [DNSOP] Is DNSSEC a Best Current Practice?
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Mar 2022 20:33:34 -0000

Good idea, and I volunteer to assist if you'd like. Some stuff that may be good to consider including:
- Negative Trust Anchors - https://datatracker.ietf.org/doc/rfc7646/
- In case of DNSSEC validation failures, don't switch resolvers - https://datatracker.ietf.org/doc/draft-livingood-dnsop-dont-switch-resolvers/

__

Jason

On 3/10/22, 13:54, "DNSOP on behalf of Paul Hoffman" <dnsop-bounces@ietf.org on behalf of paul.hoffman@icann.org> wrote:

    Greetings again. My motivation here is kinda trivial, but I've heard it is a common complaint. When writing a about DNSSEC, I need to reference the RFC. But it's three RFCs (4033, 4034, and 4035), and possibly another (6840). It would be awfully nice to refer to "DNSSEC" with a single reference like "BCP 250".

    To get there, we need to update the RFCs and say that we want an BCP. This is mostly a paperwork exercise, but this WG isn't terribly good at getting those done. Maybe we could create a short-lived WG for moving DNSSEC to BCP that just the DNSSEC-y people need to pay attention to. If we do it, that WG would not take up any new DNSSEC-related work, just spruce up the base RFCs.

    In the big picture, I think it would be good for the DNS to be able to refer to DNSSEC more easily. Thoughts?

    --Paul Hoffman