Re: [DNSOP] Strong objection to draft-wkumari-dnsop-alt-tld-04

hellekin <hellekin@gnu.org> Mon, 16 February 2015 04:14 UTC

Return-Path: <hellekin@gnu.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 26ADC1A8732 for <dnsop@ietfa.amsl.com>; Sun, 15 Feb 2015 20:14:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.511
X-Spam-Level:
X-Spam-Status: No, score=-0.511 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KCYWjZudWCA8 for <dnsop@ietfa.amsl.com>; Sun, 15 Feb 2015 20:14:12 -0800 (PST)
Received: from fencepost.gnu.org (fencepost.gnu.org [IPv6:2001:4830:134:3::e]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6650A1A19E4 for <dnsop@ietf.org>; Sun, 15 Feb 2015 20:14:12 -0800 (PST)
Received: from ol168-138.fibertel.com.ar ([24.232.138.168]:57197 helo=raiz.hellekin.gnu) by fencepost.gnu.org with esmtpsa (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from <hellekin@gnu.org>) id 1YND4S-00085q-NE; Sun, 15 Feb 2015 23:14:09 -0500
Message-ID: <54E16E84.6010309@gnu.org>
Date: Mon, 16 Feb 2015 01:13:56 -0300
From: hellekin <hellekin@gnu.org>
Organization: https://gnu.org/consensus
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Icedove/31.4.0
MIME-Version: 1.0
To: dnsop@ietf.org
References: <20150212063638.GD6950@mx1.yitter.info> <20150214165630.GB3616@sources.org> <CAHw9_iKS1JotXn3OUQk8wBfHDjYnicmsimK-6kVVWZnASLxa=Q@mail.gmail.com>
In-Reply-To: <CAHw9_iKS1JotXn3OUQk8wBfHDjYnicmsimK-6kVVWZnASLxa=Q@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/LoMj_fLHNhiDi3jcOroZWxv98y8>
Cc: draft-grothoff-iesg-special-use-p2p-names@tools.ietf.org, tor-dev@lists.torproject.org
Subject: Re: [DNSOP] Strong objection to draft-wkumari-dnsop-alt-tld-04
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Feb 2015 04:14:16 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 02/15/15 21:00, Warren Kumari wrote:
> 
> draft-grothoff-iesg-special-use-p2p-names-04, Section 3 (Terminology
> and Conventions Used in This Document):
> "The abbreviation "pTLD" is used in this document to mean a pseudo
> Top-Level Domain, i.e., a Special-Use Domain Name per [RFC6761]
> reserved to P2P Systems in this document."
>
*** The terminology in draft-wkumari-dnsop-alt-tld-04 for pseudo-TLD
conflicts with the one in draft-grothoff-iesg-special-use-p2p-names-04:

  pseudo-TLD: A label that appears in a fully-qualified domain name
  in the position of a TLD, but which is not registered in the
  global DNS.

If P2PNames is accepted, "our" pTLDs *will* be registered in the global
DNS as Special-Use Domain Names.  So, your definition is in direct conflict.

Moreover, draft-wkumari-dnsop-alt-tld-04 mentions:

  Unless the name desired is globally unique, has meaning on the global
  context and is delegated in the DNS, it should be considered an
  alternate namespace, and follow the ALT label scheme outlined below.

Therefore names reserved in draft-grothoff-iesg-special-use-p2p-names-04
are not concerned by .ALT: not only some of the P2PNames are globally
unique (.ZKEY, .ONION, .BIT), the others (.GNU, .I2P, .EXIT) have
privacy requirements that cannot be delegated to a DNS zone: the draft
says: "pTLDs are not manageable by some designated administration."
Instead, the DNS software must be aware of these pTLDs and return
NXDOMAIN *without* passing them on to the DNS for resolution.  The
draft-wkumari-dnsop-alt-tld-04 does not cover this case, and cannot
cover it in a better way that RFC6761 and the Special-Use Registry.
(Please review
http://tools.ietf.org/html/draft-grothoff-iesg-special-use-p2p-names-04#section-2)

Meanwhile, draft-wkumari-dnsop-alt-tld-04 suggests that the Tor project
"could 'root' their namespace under onion.tor.example.com."  This is not
only technically mistaken, it's also irrelevant to this draft, as .onion
names are (probabilistically) globally unique, they have
(self-referential) meaning [in] the global context, and they (will be)
"delegated" to the Special-Use Registry (which prompts for clarification
of what "delegated in the DNS" means--I suppose it means to a registrar,
which is not the case).

Can you please remove any mentions to the Tor project in this draft, as
it is irrelevant and can confuse people into thinking that .onion names
can be delegated to the DNS?

Regards,

==
hk

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQJ8BAEBCgBmBQJU4W58XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFQ0IyNkIyRTNDNzEyMTc2OUEzNEM4ODU0
ODA2QzM2M0ZDMTg5ODNEAAoJEEgGw2P8GJg9kiUP/0H4ohVtJ/TVLYZOnZQ7ux2G
snY/KiLGKBmNoh6i4K4aY4vwBaN+5CFekRvR9I02MXXZcGmAQGCmutl08bxyICq2
aK3UDAvYlUJ25uulcgLI3zdRXxPyQJpEdSHn1cbH++XixbRPfOldQQmc/7R7II5R
lniX5+2ONCxFQ0d9iur0vcxcCrm+jZnxSULKSMSqtdHIPJDiFzA2FPm2gT/gfUeC
mpAP6MK/QbC3MrvPs/TEqgOnodaYVLezR/7vdGSk2FpxrAQHvg8bwRiqnO5vWBzH
u04aqFTf2AMW8BqGwzwhOLseomfNwGa+rKSe+1dPR4t/UZgTiU366gv/HLnxgD5s
4oWqeTe7w2Dyi7mN9okmNlcg1TbT11N79vz4QA9GiJ86VdfjeFD9Sm9lAtV8gi5j
9Wu5FcAT4+MhJ2AyOh8SuYOT6ovkhlqcBoBPIIK0NQxZND0XR+KuTonXFolXMmd6
5FGsGOiNEI2eNRIi/NUyZ7sHWuI3/K2CbtO8OALfgC5j87zifqq7hdvIAsU5OMoH
XnsremBGazIw24Y/t60bynsvdGuMxgz9UQe+Xgm1/vEt2uExo6WdF5FQuj2s78qW
/slT00UmzrwRrR52/CsA5cvWjFyHxwlad6hSiwNfC6xrphXJJC+Nz4jDyseZXpWT
PIQ9coQG6LpL+tTi/X6S
=LDL6
-----END PGP SIGNATURE-----