Re: [DNSOP] draft-ietf-dnsop-rfc7816bis: hopefully ready for WG Last Call

Brian Dickson <> Fri, 12 March 2021 02:56 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 98BDB3A19F9 for <>; Thu, 11 Mar 2021 18:56:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id y4SAg5lHlQ_a for <>; Thu, 11 Mar 2021 18:56:58 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4864:20::e33]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id DB96D3A19F8 for <>; Thu, 11 Mar 2021 18:56:57 -0800 (PST)
Received: by with SMTP id z65so11786849vsz.12 for <>; Thu, 11 Mar 2021 18:56:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=pMSXCAHN6rLSwadfl1NuBbJhGrSJ4i6ed+nkgEKLuME=; b=mfBs77821c4SGFbtZQSIwzajnAJ1fqvMgTKx1vR6gyobVH2/+iRHnvsN3t4Nnx+PFU oMygajxNUd0o5w/7joTSfOPNRDUlSLQQ9ygJiRIdW1uYd7vvaDYo+oF25gxkV33mNJYa c9OihsCa5Evj0E06kg7Dh/NVIeO+0/EWSgbYbhg8w27cUsEKZlE4D1ut6KQfa2CGVPJL CcCzf1BRYIHLS+5P6vrPuZxmx8fSUv3ZzSFYN1/WtTNXxOYMuJ+B5TolPEHDSdt9qMVj e4TKX8Rv/iPo4M1AJYyEA2xJA7UEv87T/7OcHv5RQSCM7Vcv3H9N6WteKvtJk7PYBKpY r0oA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=pMSXCAHN6rLSwadfl1NuBbJhGrSJ4i6ed+nkgEKLuME=; b=r7yPzOfBi8mFfZsuV5ZTmJHhtFezUa5zQsBqCB9y2baR852Y/T9T1+dCPcja9hjGak NuiYeuUG30yQDlNDmZZyAoTeGoMEdvoClyMr/6TOiBKxUsHtulEVtUg45PM3KH4/Z4kX sWdnnGV+sYw/FUigBGUzZ2/PT6xMd+Dps9fP4Qcf2PZbIJL3AZ01nwK8kx5i2Pq+guy+ 48gC+TPOsKCsfeg4cpSUp+NeskU5rBeEMz2NY5cam9s2LMJEatah2m93Qx3zIgQH1XtD p2WUS8hf2SJ1UWPafDkv1QtyDHwZjLQfi/TkbeAmKHAdjzAUfGX3lMAlPMisuuk6/IVL DoDg==
X-Gm-Message-State: AOAM533OpPgQgTArp9isnLZtm0gsjwsb+5MluXbzJ/HQ21XYMCyFLDbe 2rqAX8RCa0uyxa45TQGFkc2x7JwZKmo533S7DPY=
X-Google-Smtp-Source: ABdhPJzpgtwjXOzXOL2gtMbXRAc2/yvECZaecXDt6O/zSPukaVAzxNMBPUGNIeSnvlax+AhyVwAzP93hVN1XG2NOVqQ=
X-Received: by 2002:a67:df05:: with SMTP id s5mr7196759vsk.58.1615517815852; Thu, 11 Mar 2021 18:56:55 -0800 (PST)
MIME-Version: 1.0
References: <>
In-Reply-To: <>
From: Brian Dickson <>
Date: Thu, 11 Mar 2021 18:56:45 -0800
Message-ID: <>
To: Paul Hoffman <>
Cc: dnsop <>
Content-Type: multipart/alternative; boundary="0000000000008acfb605bd4e0df0"
Archived-At: <>
Subject: Re: [DNSOP] draft-ietf-dnsop-rfc7816bis: hopefully ready for WG Last Call
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 12 Mar 2021 02:57:00 -0000

Sorry for not thinking of these earlier, not sure if they would add
anything or clarify anything or potentially protect resolvers from DOS

   - Maybe some text warning about queries with excessive numbers of
   labels, and suggestions for limiting their impact? E.g. "If NUM_LABELS is
   more than 6, follow the algorithm for the first N labels (TBD for N), then
   do a binary search on the remaining labels at each zone cut discovered."
   - Would it make sense to address ENTs (empty non-terminals), or use one
   of those in an example? Also, in zones signed with NSEC, is there any
   potential advantage to using NSEC records to "skip ahead" through the list
   of labels, if ENTs exist with no non-ENT siblings between the CHILD query
   and the actual zone cut?

Either of these might reduce the work, while still preserving the benefits
of QNAME minimization, I believe.

On Mon, Sep 28, 2020 at 12:17 PM Paul Hoffman <>

> Greetings again. We have not heard much recent input on the draft other
> than "remove the parts about it being experimental". We have done that,
> reorganized it to make it clear that QNAME minimisation is already
> well-deployed, and a few other cleanups.
> We think the document is read for WG Last Call, if the chairs do as well.
> --Paul Hoffman_______________________________________________
> DNSOP mailing list