Re: [DNSOP] Empty Non-Terminal sentinel for Black Lies
Ralf Weber <dns@fl1ger.de> Wed, 28 July 2021 11:43 UTC
Return-Path: <dns@fl1ger.de>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A24B13A0A4F for <dnsop@ietfa.amsl.com>; Wed, 28 Jul 2021 04:43:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kBWbaDQizc15 for <dnsop@ietfa.amsl.com>; Wed, 28 Jul 2021 04:42:59 -0700 (PDT)
Received: from smtp.guxx.net (smtp.guxx.net [IPv6:2a01:4f8:a0:322c::25:42]) by ietfa.amsl.com (Postfix) with ESMTP id 9A9F03A0A4E for <dnsop@ietf.org>; Wed, 28 Jul 2021 04:42:59 -0700 (PDT)
Received: by nyx.guxx.net (Postfix, from userid 107) id 3D6395F42371; Wed, 28 Jul 2021 11:42:58 +0000 (UTC)
Received: from [192.168.42.138] (p4ff53b1a.dip0.t-ipconnect.de [79.245.59.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by nyx.guxx.net (Postfix) with ESMTPSA id 739A85F402E7; Wed, 28 Jul 2021 11:42:57 +0000 (UTC)
From: Ralf Weber <dns@fl1ger.de>
To: Shumon Huque <shuque@gmail.com>
Cc: WG <dnsop@ietf.org>
Date: Wed, 28 Jul 2021 13:42:47 +0200
X-Mailer: MailMate (1.13.2r5673)
Message-ID: <A86DA98C-151F-425F-BC27-34EC1C79F4A5@fl1ger.de>
In-Reply-To: <CAHPuVdV6s1wM6Qc3uAhRQurVg2mMocRCTPmpVHHkBHW9FWV5Cg@mail.gmail.com>
References: <CAHPuVdV6s1wM6Qc3uAhRQurVg2mMocRCTPmpVHHkBHW9FWV5Cg@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/JZmDLPBeVIfpVyKLuxuNnDb1anA>
Subject: Re: [DNSOP] Empty Non-Terminal sentinel for Black Lies
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jul 2021 11:43:02 -0000
Moin! On 28 Jul 2021, at 1:34, Shumon Huque wrote: > The Black Lies method of providing compact DNSSEC denial of existence > proofs has some operational implications. Depending on the specific > implementation, it may provide no way to reliably distinguish Empty > Non-Terminal names from names that actually do not exist. This draft > describes the use of a synthetic DNS resource record type to act as > an explicit signal for Empty Non-Terminal names and which is conveyed > in an NSEC type bitmap. Hmm I may be sleep deprived, but the way I read this is that instead of giving back NoError/NoData and a standard NSEC responses I now have to give back an additional record type, so that some client can distinguish that as not being NXDomain, which according to the answer it never was? Does this mean we would have to change all existing authoritative server to add this record type to signal an empty non terminal responses? So long -Ralf —-- Ralf Weber
- [DNSOP] Empty Non-Terminal sentinel for Black Lies Shumon Huque
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Brian Dickson
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Shumon Huque
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Ralf Weber
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Shumon Huque
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Hollenbeck, Scott
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Shumon Huque
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Peter van Dijk
- Re: [DNSOP] Empty Non-Terminal sentinel for Black… Shumon Huque