Re: [DNSOP] Fwd: New Version Notification for draft-ogud-dnsop-any-notimp-00.txt

Mark Andrews <marka@isc.org> Sun, 08 March 2015 01:26 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A9AD91A1A48 for <dnsop@ietfa.amsl.com>; Sat, 7 Mar 2015 17:26:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jyTZYdrDCH8e for <dnsop@ietfa.amsl.com>; Sat, 7 Mar 2015 17:26:35 -0800 (PST)
Received: from mx.ams1.isc.org (mx.ams1.isc.org [IPv6:2001:500:60::65]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9ACA41A1A47 for <dnsop@ietf.org>; Sat, 7 Mar 2015 17:26:35 -0800 (PST)
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) by mx.ams1.isc.org (Postfix) with ESMTP id B5F051FCCD0; Sun, 8 Mar 2015 01:26:32 +0000 (UTC)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id D8009160067; Sun, 8 Mar 2015 01:33:33 +0000 (UTC)
Received: from rock.dv.isc.org (c211-30-175-41.carlnfd1.nsw.optusnet.com.au [211.30.175.41]) by zmx1.isc.org (Postfix) with ESMTPSA id A551216005A; Sun, 8 Mar 2015 01:33:33 +0000 (UTC)
Received: from rock.dv.isc.org (localhost [IPv6:::1]) by rock.dv.isc.org (Postfix) with ESMTP id C674C2B02CFB; Sun, 8 Mar 2015 12:26:32 +1100 (EST)
To: Tony Finch <fanf2@cam.ac.uk>
From: Mark Andrews <marka@isc.org>
References: <20150306172715.24305.58649.idtracker@ietfa.amsl.com> <CAN6NTqw4n_mTqjGDsOc4kT3fvm1PaCWKt+AUPw+4GevQqG3Ymw@mail.gmail.com> <20150306182444.GA50555@PorcupineTree.nominum.com> <54F9FC8D.9050003@redbarn.org> <20150306213856.GA51222@PorcupineTree.nominum.com> <54FA2179.3000403@redbarn.org> <20150306223336.GA60793@PorcupineTree.nominum.com> <54FA2FEE.7000304@redbarn.org> <C5299BB5-46A8-4B36-9446-0725A8FB68DA@cam.ac.uk> <6D934B5F-4E15-406B-960E-97939A0CE4CD@cam.ac.uk> <E1FC7C5C-7693-496C-B169-AA0637F69C3E@cam.ac.uk>
In-reply-to: Your message of "Sat, 07 Mar 2015 22:01:36 -0000." <E1FC7C5C-7693-496C-B169-AA0637F69C3E@cam.ac.uk>
Date: Sun, 08 Mar 2015 12:26:31 +1100
Message-Id: <20150308012632.C674C2B02CFB@rock.dv.isc.org>
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/LmbAX7n-tc3xPbapdr7yGnnTRmY>
Cc: Olafur Gudmundsson <olafur@cloudflare.com>, Paul Vixie <paul@redbarn.org>, "dnsop@ietf.org" <dnsop@ietf.org>, Ralf Weber <dns@fl1ger.de>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-ogud-dnsop-any-notimp-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Mar 2015 01:26:36 -0000

Personally RRSIG is worse for a implementer than ANY.

I remember a time when there was a hope that you could do DNSSEC
through a non DNSSEC aware server.  RRSIG queries come from such a
time.  I would be happy to ban RRSIG queries.

That said banning RRSIG or ANY queries won't help with amplification
issues.

Mark
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka@isc.org