Re: [DNSOP] New version of draft-ietf-dnsop-rfc7816bis after WG last call

Peter van Dijk <peter.van.dijk@powerdns.com> Wed, 21 April 2021 08:20 UTC

Return-Path: <peter.van.dijk@powerdns.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B56CB3A1AD5 for <dnsop@ietfa.amsl.com>; Wed, 21 Apr 2021 01:20:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.197
X-Spam-Level:
X-Spam-Status: No, score=-4.197 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cVUJi26JZB7D for <dnsop@ietfa.amsl.com>; Wed, 21 Apr 2021 01:20:37 -0700 (PDT)
Received: from mx4.open-xchange.com (alcatraz.open-xchange.com [87.191.39.187]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D0AC3A1AD4 for <dnsop@ietf.org>; Wed, 21 Apr 2021 01:20:37 -0700 (PDT)
Received: from imap.open-xchange.com (imap.open-xchange.com [84.81.54.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx4.open-xchange.com (Postfix) with ESMTPSA id A0B646A0CF; Wed, 21 Apr 2021 10:20:33 +0200 (CEST)
Received: from plato ([84.81.54.175]) by imap.open-xchange.com with ESMTPSA id gLtcJlHgf2B0JAAA3c6Kzw (envelope-from <peter.van.dijk@powerdns.com>); Wed, 21 Apr 2021 10:20:33 +0200
Message-ID: <3fd9043f43c92e81b90edf97399e95d0735e098a.camel@powerdns.com>
From: Peter van Dijk <peter.van.dijk@powerdns.com>
To: DNSOP Working Group <dnsop@ietf.org>
Date: Wed, 21 Apr 2021 10:20:33 +0200
In-Reply-To: <0053F712-2701-42E0-9B7C-8B3A0757210C@icann.org>
References: <0053F712-2701-42E0-9B7C-8B3A0757210C@icann.org>
Organization: PowerDNS.COM B.V.
Content-Type: text/plain; charset="UTF-8"
User-Agent: Evolution 3.30.5-1.1
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/JniraLrXHtaDtxwQOxjorzTdHz0>
Subject: Re: [DNSOP] New version of draft-ietf-dnsop-rfc7816bis after WG last call
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Apr 2021 08:20:42 -0000

Hello Paul,

On Thu, 2021-04-15 at 23:15 +0000, Paul Hoffman wrote:
> Everyone (but particularly resolver developers): please review the document carefully, particularly the algorithm in Section 3, to see if it matches what you expect.

PowerDNS implementation notes: 
* we combined step 5 and step 6d (and call it step 5); we fall back to 'no minimisation' on anything that's not a NoError response (but the fallback might be handled by the RFC8020 code, especially if that non-NoError response was NXDOMAIN) (the default for RFC8020 is 'on signed domains only')
* we use 1-1-1-3-3-.. label steps, which is not exactly what section 2.3 describes

(you can find some more details at https://doc.powerdns.com/recursor/appendices/internals.html#qname-minimization )

Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/