[DNSOP] Re: AD review of draft-ietf-dnsop-structured-dns-error-19

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Fri, 08 May 2026 13:27 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1AD42EB32BC9 for <dnsop@mail2.ietf.org>; Fri, 8 May 2026 06:27:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778246879; bh=mjt5Ulle7iYFNnhvh0lWoIlmytbptlKqyIuiNNIE6Vs=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=JOA96y9OFgXziRXxvpAc8xAdd8pAwg0N3t4Yvct3BdAjesgc9zH2s4HF7RZAOu602 E6q7YZDRbURN2dBrw+XBI+c5MEvKQ4vN/YOSM362JRw89YxSja8csyRvR2bmOhsIvr TDR0nyzjQxN5XEw/42iiiWMrKq/RVP881xTIWlVs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -11.885
X-Spam-Level:
X-Spam-Status: No, score=-11.885 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cisco.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5cDJfiAd02DP for <dnsop@mail2.ietf.org>; Fri, 8 May 2026 06:27:55 -0700 (PDT)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0D8A1EB32BC2 for <dnsop@ietf.org>; Fri, 8 May 2026 06:27:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=40750; q=dns/txt; s=iport01; t=1778246875; x=1779456475; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=/cVXwi4U/t1BRMl0Vqi5IPk8TjFBz4TaASWGdQJrE+E=; b=A1d4FMjTBSHgEcgI0WYHLgxUkXWjJt7fQF2En7vKR7OlUa0vSECjUR8V uRBtaed+zJ6dMCb8YZLHoPb8zCAVB52U/4UMoMiK0yV6AVZzsGUcQIsZW /U0jEQTTYkuC5EOebStq7iqmtFjQKVa1K7mZ1umEZzxVdV8y5d+LWJe/L NYbON9vu1AQxFSLxxl/uV0focA7/Wy4SFHaPoBTnsUo3YOz7I1IoKozof YhzvEe0h0TlbPOkAJP8+Rzg+URcQ+QXU4nX0YKS7Oi5bzYLnjAJVvrYMV tX/LB6t9jOgiBbqMNQeoCsgTocY5SpEtEVvvW8xV73yR2W9Lie48yXPQG Q==;
X-CSE-ConnectionGUID: cM3zsbcmQQWnuV2Ygt+xZw==
X-CSE-MsgGUID: xPkFnTNBQoKwXTXYYAkhZA==
X-IPAS-Result: A0BoBgAr5P1p/5P/Ja1QCh+BD4ErgT0xU4EIeBcSSYgjA4UsiHkDi2SFZoY1gTuCAYJzgWsPAQEBDQJEDQQBAYUGAo0yAiY3Bg4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4ThhUHMw2GWgEBAQEDEmcQAgEIEQMBAiEBBgcgERQJCAIEDgUIGoJhgh0dAzYDAQIOqmYBgT0Ciip4gTSBATvdCQ2CWQaBTYU/gnoEHAEqSWyDfhgBRIQ3CB8bgUlEgRVCgmg+gh9CAoEiCQEHCwEJGh4Wg1+CLwSCDRV6FB2BQ3CCYlKIelJyIgMmMywBVRMXCwcFgSNDA4EGI0sFLR2BIyEdFxUfWBsHBRIhKm5KZCxcGgMDDSEkEVk/OAtJBYFyAoIeGV8jLwNOgQIDC209FCMUGwMEgTUFiVxEGR0PgT0BAislGQYHJBMmBBQ3BgEBCgYBDwJZFg4kAgcBBwYPFAUBAQEOAgEWBQwLAi0DklcRFSyCawGMKYEtT4JmiX2UJnEKhByMHo8+hjIXhASNEwOGf5EsP2eZBoJYizGECZErLCABhQwCBAIEBQIQAQEGgX4maXBwFTuCZ1MZD1aFMIgig3vCNXk/BwIHDgKTE10BAQ
IronPort-PHdr: A9a23:xxqSqxdVGxo15mLpVvDZky9klGM/gIqcDmcuAtIPgrZKdOGk55v9e RCZ7vR2h1iPVoLeuLpIiOvT5rjpQndIoY2Av3YLbIFWWlcbhN8XkQ0tDI/NCUDyIPPwKS1vN M9DT1RiuXq8NCBo
IronPort-Data: A9a23:2ys3zq+wD+DwT3aMxn7QDrUDxn+TJUtcMsCJ2f8bNWPcYEJGY0x3y WdNWDrXPq2LNDHzc4p1bNyypE1Su5aGzdYxQAZq+XtEQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mpyyHjEAX9gWAsbzpEs/vrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2k9GNYK4ex8BFh3y voFFmo8YQzAl9CplefTpulE3qzPLeHxN48Z/3UlxjbDALN/GdbIQr7B4plT2zJYasJmRKmFI ZFGL2AyMVKZP0In1lQ/UPrSmM+lmGj5eD5VgFmUvqEwpWPUyWSd1ZCya4aEJYzQHpQ9ckCwt lrF0WLFJDsjM/+A+Qa1w0OFhe/9tHauMG4VPPjinhJwu3WfwHcUEDUXWEe15/6jhSaDt8l3M UcY/G8q6KM17kHuF4G7VByjq3nCtRkZMzZNL9AHBMi24vO8yy6SB3MPSXhKb9lOiSP8bWVCO oOh9z8xOQFSjQ==
IronPort-HdrOrdr: A9a23:LWwINq2I9tGR327AxHyTtQqjBWVxeYIsimQD101hICG9Lfbo9P xGzc566farslcssSkb6K690cm7LU819fZOkO8s1MSZLXjbUQqTXc9fBOTZskfd8kHFh4pgPO JbAtdD4b7LfBlHZKTBkXSF+r8bqbHtntHL9ILjJjVWPH1Xgspbnn5E43OgYzZLrX59dOIE/f Snl616jgvlU046Ku68AX4IVfXCodrkqLLKCCRtOzcXrCO1oXeN8rDVLzi0ty1ybxp/hZsy+2 nMlAL0op6kr+y6zRHk0WrS5YR9mdfqyNdPbfb8yvT9LA+Cti+YIKBaH5GStjE8p++irHwwls PXnhsmN8Nvr1vMY2Ccu3LWqkvd+Qdrz0Wn5U6TgHPlr8C8bik9EdB9iYVQdQacw1Y8vet7zL lA0wuixt9q5FL77WDADurzJldXf3mP0CMfeCko/iRiuL4lGfhsREokjRho+dk7bXjHAcscYZ lT5YnnlYVrmBWhHjPkl1gq5sCwVXIuGRrDaE0DtsuJlwVyphlCvhYlLAh1pAZeyHr7IKM0u9 jsI+BmkqpDQdQRar84DOAdQdGvAmiIWh7UNnmOSG6XXp3vFki946If2o9Fr92CadgN1t8/iZ 7BWFRXuSo7fF/vE9SH2NlO/grWSGuwUDzxwoUGjqIJ9oHUVf7uK2mOWVoum8yvr7EWBdDaQe +6PNZTD+X4JWXjFI5V10mnMqMiZkU2QYkQoJI2SliOqsXEJsnjsfHaau/aIP7oHSw/Um3yD3 MfVHz4JdlG7EqsRnjk6SKhFk/Fawj659Z9AaLa9+8cxMwEMZBNqBEcjRCj6sSCOVR5w+ULlY tFUcXae4+A1B6LFDzznhBUEwsYClwQ+7npWW5LowgRWnmEA4rrk+/vDVxv4A==
X-Talos-CUID: 9a23:YpBBQmy3o39SJktJms8tBgUfP5s3aXfWyU7pHEmlNzxYR6HWWW2PrfY=
X-Talos-MUID: 9a23:Ta5YsA/OymlO9ErPW5I5H5eQf9dQ4IqoNGYnqJIlpPm4BR1BEjSdvh3iFw==
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-l-core-10.cisco.com ([173.37.255.147]) by alln-iport-6.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 08 May 2026 13:27:54 +0000
Received: from alln-opgw-4.cisco.com (alln-opgw-4.cisco.com [173.37.147.252]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by rcdn-l-core-10.cisco.com (Postfix) with ESMTPS id 1BE7018000897 for <dnsop@ietf.org>; Fri, 8 May 2026 13:27:54 +0000 (GMT)
X-CSE-ConnectionGUID: rzTvTPymQj+aCsI0Ywj7nA==
X-CSE-MsgGUID: MSLeg5L2S1CSA5/3E/a58Q==
Authentication-Results: alln-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.23,223,1770595200"; d="scan'208,217";a="74354670"
Received: from mail-ds2pr08cu00102.outbound.protection.outlook.com (HELO DS2PR08CU001.outbound.protection.outlook.com) ([40.93.13.74]) by alln-opgw-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 08 May 2026 13:27:53 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=TNimoiyPrW13XuhGbrufWqNp3Yitx2HDLPj9EoICBmm95+1mMbG3Ez9E1/SuP1jPWwLs0d3oCnu1hS9HwbmI8V86+7R3OoC+ObNpaeYreE+usxzR865TQ+4S5V1aH/rldXsJk1sXN9VD8weDoXV9xjQtIea/jhjWHLyBUHhqAxxUvR0gOuN7BgKy7DV6PzhiuoFy4XEcQp9DnNScGDXUXOHXZ9EIm9YiGiUvM1yGWhd86CaqwN/EZvyUZMsldgRY5m7zIigWz0xSzIsR1YtRAFtNjVuSkrqj0OLwuwGtQ2QVwv2GxDDEj/4OUcnAgse2xRRJsQxiUlijKdGIrFI+Og==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=/cVXwi4U/t1BRMl0Vqi5IPk8TjFBz4TaASWGdQJrE+E=; b=R53ndgjm5a4gm6ivcUfbr3DS/CnIQH8QfwF010zo8CX7KkuQK50mjIDiKp0zeDsIz1fzPHQFilo5dtw50dbIXlUpEIBCmAckL5Cx4x8aSzICun7fzBYP1xJfE4zTOoGOGhkgJ6M8D7IKGjlVcjIHISObjABii0+lG95vVjeQKRpH6enxVBgED92n0nrs3nMZD3zmhyAE/4/yvd+21u5aCzOeXx3+rylAChMQodkmQx0MZwLiImy7wUjuM7Gsmyg03BVj3fJPzn4U+qt40OyytDRjUngfHyx+ALrm1+PvXfy9gmd7aRrq3Ru7PK+tAGPsDIOGiY+RGPOsAxDQ09MqwA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from SA2PR11MB4972.namprd11.prod.outlook.com (2603:10b6:806:fb::21) by SJ2PR11MB8370.namprd11.prod.outlook.com (2603:10b6:a03:540::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9891.15; Fri, 8 May 2026 13:27:51 +0000
Received: from SA2PR11MB4972.namprd11.prod.outlook.com ([fe80::e2b5:5f32:83d1:29a3]) by SA2PR11MB4972.namprd11.prod.outlook.com ([fe80::e2b5:5f32:83d1:29a3%6]) with mapi id 15.20.9891.019; Fri, 8 May 2026 13:27:51 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: tirumal reddy <kondtir@gmail.com>
Thread-Topic: AD review of draft-ietf-dnsop-structured-dns-error-19
Thread-Index: AQHc3JezM0vhbP9Q2ECm27z9ZdqRXLYCDIqAgAIVjTo=
Date: Fri, 08 May 2026 13:27:51 +0000
Message-ID: <SA2PR11MB4972BEA47D1E95384D5A82AFA93D2@SA2PR11MB4972.namprd11.prod.outlook.com>
References: <PH0PR11MB49665D117EA1C0C920A1ED0FA93E2@PH0PR11MB4966.namprd11.prod.outlook.com> <CAFpG3geNkMs=_HeeirUcRX2-GXW5wEHZiYTLUj0Q_5CYVeVmWQ@mail.gmail.com>
In-Reply-To: <CAFpG3geNkMs=_HeeirUcRX2-GXW5wEHZiYTLUj0Q_5CYVeVmWQ@mail.gmail.com>
Accept-Language: fr-BE, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA2PR11MB4972:EE_|SJ2PR11MB8370:EE_
x-ms-office365-filtering-correlation-id: 3fd05e0b-8a3f-49eb-8a92-08dead059aae
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|10070799003|38070700021|13003099007|56012099003|18002099003|22082099003|8096899003|3023799003;
x-microsoft-antispam-message-info: Sk00mYdn+fkmF81N8b5OUPHLZxuF4CG1hDHlZZhyTrAmAUD93x1e9dO3qrwRYBEULn4mOb6dNcoP2aigxXwkkNAkCLXyTLyP/3vYt1EpJIWf8GU69gjn913WJDifRlIHjdTXyBkqjp9K6f9KZLwF5cO0HtYnFRNwtB4rj6ZKDNk5BNXHmMQuzKzEDNaltwOIe3KM78FiA+sbb0pJOSGgQ8ofexFf8ijq5S87K7/RO1d/aQwcPyUpS3Xs7a1nal9Zd32TvSiHapvXxkEOio9IVAOuBUtKORMmJQmWl7sl4Xhw1Y47rrHIMs3h6EIwmpepO1FozNIjUKSHqzUf/BaAIru6bMDhS4kSqr9fVqbKx9Ax7MnBSDB2GrEvns6J/iLM8ksNAUnah2aUg1jgn0IRdLDPDz1H5tcEKU4hr/nvl6FRB5nqHpyKAllWg3bxpFr9y6Asv7We6BiuU0lJ6NXByinoE0yT36eODTF95wiibatNCqeM9HkNahVJzGj9TCwHFlBpzlgxUPnsg8eIJc/UwwiVeYufrnWe3PlGhIdB3KGKhZ5QIPO8Ha6GFJw0Hbm0U5iifcQu3cDrgOkboTj7FjTNYXphkB5iJYNSjST4Q8Ny5IBaJgDcdgLJ9QwZw2D1NQa/dPFdZpHxsmdHa9VtupQmW8lD1++r1hvfeKuPSSIiMR7O2N3p1K0UfiN7294D0M8suA5tuonzN63w3wPmbUz5S8CwXxvhDrFgXT1jV/fY6k3kzLY4pAycTXtjhMSI
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SA2PR11MB4972.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(10070799003)(38070700021)(13003099007)(56012099003)(18002099003)(22082099003)(8096899003)(3023799003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 2
x-ms-exchange-antispam-messagedata-0: h2kfO/wRiHEpDFNR53kRwS2WFO2N0eMNtWXdKVhV2r5wuDfYt1AUdTtysIcAgkyN3+xVTJDiSdR/hOND402Pgkqi0pQvNu4ugas5BqUc7oOHlyxJkU2xc+CT3CoC/yBB4Y9nrQYj49EDLpIH2Zg0rRxq/4mCOWlRX/pqzmDZFY5QslP2BOrlb8ip/b2mwoUznGCO8S+SKC2jJjvF5VXEqV9EnmSAlsB+ClGsWjbnTyzQv3NH9TbUqsoOUXDP89bRQm2C2nB9pAIEyHyLVvGO8iejYsKjN6i9Cdr+RCE503BKtg5Y0dgVdlbm9zdPAOanKIQQiVHDzUJUECJslKZYVkKg49N6HI4qOvhEPxgGgT9s45PXcpiheGRuN+rsC4YIODZZ+trzHQu1Caqojomw+6wDdQwDbeDgnhmZQePhMcnO8XEBF6srS/GCYjvzhP8yfqkZoa60uuaOqBo8R8+cVIdCtnheRPWyc4j37AS1g6rO01jAt1sLeqg91mfpKiHQJIaTpMrcDIC/F0kbOOqrjCgN5rKHPVAnzNe52kojKdwZs4Sk4S7y/DSWMRAECtbgGS28vZvVZiLRFONkUz78XHjt0kwwxcjto/WzyTp9MyA3KmvplKuv6i8Fh9SduOqinV8unGin5bjM+m8zBi4CqKZHkGOuw4nt3B1s9OsfghIZUZCiHGufTkEE/9fBgBCsf+J9qqaj/ZbDldI+/SdqhgIiN46F9rWjD6CBUm4kVUsl25drI9HFG37x/RdJKT0KqZjwNTmTCMs0FDwToUnITvWgFaz6HjnlG4zlsZhCpxL0ttmuiUwzytENcne7fSwVP9E5jkDhFDoWv1gtHxc6ZUTkurHKleRHMnB3FSTMPCen56lHqCLA15RpuHPZK+3McqsGYqZbPyyMlyxsfeIYHcz6VkikAUz20QKEjqLHqUHYJOHe6CmUTyG4WgsebfpWxanZ6zNkD7Na2cptohMZKXIXMTuqkHRfUc5TAHuQlUDH/HgoUPuUi70VPDbXWNNrVywEbnVtDe9I4mSEkxgY228JHDbQTB8A/8q6laMoYI06NUlSYhIuQ4QARl9b/3b5oVpkIpsBvJgiEn5+ngPoWjdsskBlZd6EU3gZUJ1+7IqpEn42neUmeiY9GrPZJBSG8UQqP6b0a6wA1Ub1NZRIsI19Q7bxT3Bczb9QIFYpHIE2HrrikCew30lCOpJP/jQ3xy5vLPDeF6gqk2Q21mg+dKElczHi7y0Glbl8oP1JXPfx3tBhh1S21Kt1Zf7tTHKa7U1vLrPHrX3eTRKBISITf2lisweV955KTLB1GyTlJ1kDUnsfCdmVON8SLreES0eUUGS0d7r4l1O3voWGi01laOpTxxzEJFjTex08T8vICSVSgyeeMZOpHAvEH55bbZf92wOqNRM0b1PJE1+q9tLdf9MsonEdnzHn5mvnZO2EGcBoViKQjfVLh77ot9cf+p+DSL6dEx9JlZfSMe1gKsxnuZN5VV92Fg+Hn/eWBLaOvGaxJxhxC3Dq/o7HhWrXIgbiabXkmKLfsNkxkKbHvdCgeRiykGKxiWzE84n49uMFgtIytkwB0M29gRCVyI2vHXQeVQW5RnmQYYJcNPMysOz3+hV6+UJAjXlMXIYS5hqmr9cLiqSzUs6k1gt4Jc9mPDq1XJNO5No4DOtOOTQTQCvPnAfj2OcF1+99MDtpfeg/n/e9jVCgSoc8z0eqcnVWDZEZpU7ztvpHT9u+kEWF57unOhjL9D3XTr2Yn3hBd2hH0+dSh+A3/raxo0G2oMAULeJ1pVUyswk6
x-ms-exchange-antispam-messagedata-1: Kwzdmak/F5D/tg==
Content-Type: multipart/alternative; boundary="_000_SA2PR11MB4972BEA47D1E95384D5A82AFA93D2SA2PR11MB4972namp_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: cLXqvP2TwvoGOqr2P2E3XNrUQe19+AxDL5Y88lCwLjyr9T9iWDqpMMCZ5QI+cyf/9/GAstJzd1Koteczg0AIYJSOJZbrbWcYlmd2rENH+nIdXFu09vuQ7++qR2kmQHI0n2vbqG1Vka5uiqaNCy4d52j4cbnLQmLcJ92KBsjR9RS8ZeJZa+dAatGteIpGwEUmAc0kRsY+zLLTStzBo/L0zrfyPss96JnwJucEFPocq2Kfe1dqASsMMBFuWpOLkYLsPurHdgUmU1MYY2xlBcLltNSoEHufarSmasGa3nq1aJM5/VMvSi+W7BuvHrxuXZ5Lo0UfQhSnOdkL5DfQZrIU4g==
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA2PR11MB4972.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 3fd05e0b-8a3f-49eb-8a92-08dead059aae
X-MS-Exchange-CrossTenant-originalarrivaltime: 08 May 2026 13:27:51.4385 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 9RTG3AQAxmY3WcphqWbHbMeNfriXzIOBk/lDy0jJ2BTZaMkJJG+ZYisv5Pa1TVzin4EDQp8XfSKD15SPy5034Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2PR11MB8370
X-Outbound-Client-TLS: ANONYMOUS;alln-opgw-4.cisco.com [173.37.147.252];TLSv1.3;TLS_AES_256_GCM_SHA384;256
X-Outbound-SMTP-Client: 173.37.147.252, alln-opgw-4.cisco.com
X-Outbound-Node: rcdn-l-core-10.cisco.com
Message-ID-Hash: CRD6XGHQYMJKKPGDO74JOCESQGDI6DLJ
X-Message-ID-Hash: CRD6XGHQYMJKKPGDO74JOCESQGDI6DLJ
X-MailFrom: evyncke@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "dnsop@ietf.org WG" <dnsop@ietf.org>, Dan Wing <danwing@gmail.com>, "neil.cook@noware.co.uk" <neil.cook@noware.co.uk>, Mohamed Boucadair <mohamed.boucadair@orange.com>, Benno Overeinder <benno@nlnetlabs.nl>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: AD review of draft-ietf-dnsop-structured-dns-error-19
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/LuKPNQeGmEpJdx1ToY0-VJvitC0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Hello Tiru,

Thanks for your reply.

See in-line for EV>

Basically, I still a problem with the support of only one language in a *human readable* reply. I will think more over the weekend, but I am afraid that a change in the I-D s/human-readable/machine-readable/ or the support for multiple languages is required. And, I know that your own country have more than 3 languages (and possibly different character sets).

Regards

-éric


From: tirumal reddy <kondtir@gmail.com>
Date: Thursday, 7 May 2026 at 07:33
To: Eric Vyncke (evyncke) <evyncke@cisco.com>
Cc: dnsop@ietf.org WG <dnsop@ietf.org>; Dan Wing <danwing@gmail.com>; neil.cook@noware.co.uk <neil.cook@noware.co.uk>; Mohamed Boucadair <mohamed.boucadair@orange.com>; Benno Overeinder <benno@nlnetlabs.nl>
Subject: Re: AD review of draft-ietf-dnsop-structured-dns-error-19

Hi Eric,

Thanks for the detailed review. I raised PR https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/pull/88 to address most of your comments. Please see the inline responses for comments where the draft is not updated.

On Tue, 5 May 2026 at 19:38, Eric Vyncke (evyncke) <evyncke@cisco.com<mailto:evyncke@cisco.com>> wrote:
[As Med is a co-author, he cannot be the responsible AD for this document, hence, I have been selected as the responsible AD]

# Éric Vyncke, INT AD, AD review for draft-ietf-dnsop-structured-dns-error-19
CC @evyncke

Thank you for the work put into this document. It is very easy to read.

Please find below my AD review.

As the responsible AD, I expect all the points below to be addressed, either by a revised I-D, or an email reply. Of course, authors and WG can reject my points, but this needs to be justified. Once all the points are addressed, I will proceed with the publication process, i.e., IETF Last Call.

Special thanks to Benno Overeinder for the shepherd's detailed write-up including the WG consensus, the history behind the 2nd "publication request", and the justification of the intended status.

I hope that this review helps to improve the document,

Regards,

-éric

Note: this AD reviews follows the Markdown syntax of https://github.com/mnot/ietf-comments/tree/main, i.e., they can be processed by a tool to create github issues.

## Critical issues

### Shepherd's write-up

Q18 got it wrong as sections 11.2 et al. request the creation of a new registry.

### Abstract

I am not sure whether `including *network* security` is correct as it does not really protect the network per se but more the IT system or the end users. Suggest either rephrase it or remove it.

"network security" is appropriate: an endpoint infected with malware can scan the attached network for vulnerabilities and perform lateral movement. DNS filtering that blocks communication with C2 server serves a network security purpose.

EV> sure that in help network security, but it is more often used for policy enforcement. Suggest to add this to the abstract.


### Section 1

Why not adding a reference to RFC 7754 section 6 `promptly informing the endpoint that blocking has occurred provide necessary transparency to redress any errors, particularly as they relate to any collateral damage introduced by errant filter`?

### Section 3

In bullet 1, `The HTTPS server hosted on the network security device will have access to the client's IP address and the hostname being requested. `, isn't this the same issue with DNS server in all 3 scenarios ? The difference there is for the *path* component and not the *host* part of the URL.

Yes, the block-page server additionally learns the URL path component, revealing more about the specific resource the end user attempted to access. Updated text accordingly.

EV> thanks


### Section 4

`IT/InfoSec team` or "DNS operator" or "DNS administrator" as used later in the section?

The "c" field contains the contact details of the IT/InfoSec team that the end-user needs to reach to report misclassified filtering. "DNS administrator" elsewhere in the section refers to the party operating the DNS server. These are distinct roles.

EV> please add these terms in the terminology section


As a resident of a country, Belgium, with THREE national languages (not to mention the common use of English), I find *VERY* limiting the use of a single language... Why not an array of languages ? or a 'accept language' in the DNS query SDE option? Relying on `optionally translate it` is wishful thinking (especially for small messages).

Adding a preferred language field to the SDE option in the query is appealing, similar to the HTTP Accept-Language header where the client sends a list of preferred languages and the server picks the best match. However, it would require a non-trivial wire format change to the SDE option, which currently has no OPTION-DATA, as well as updates to the client request and server-side processing.

Furthermore, the "l" field already allows clients to identify the language and invoke machine translation.

If you insist on this change, I am open to discuss with my co-authors to update the draft.

EV> I am insisting.


Can the JSON object be empty as all JSON names are optional ? Should there be text about this special case ?

This case is already handled in Step 5 of {{client-processing}}, which requires the client to discard the JSON object if none of the "c", "j", or "s" fields are present or all have empty values.

EV> ack


Why JSON and not CBOR ?

JSON was chosen over CBOR as the structured message is sent over an encrypted DNS transport (e..g, DoT, DoH, DoQ) which handles fragmentation.

EV> Humm true of course. Is it worth mentioning ?


### Section 5.2

What can the server do when there are several blocking causes (e.g., malware + court order)?


When multiple blocking causes apply, the "j" field can be used to provide additional context about all applicable causes.

EV> So a single SDE ? Please add text then.


### Section 5.3

What is the client behavior when receiving more than 1 EDE option ?

{{!RFC8914}} already addresses this: "Senders MAY include more than one EDE option and receivers MUST be able to accept (but not necessarily process or act on) multiple EDE options in a DNS message."

EV> ack

Should bullet 2 and 3 be swapped ?

### Section 10

Should there be a 'privacy considerations' sub-section ?

### Section 11

"IETF review" seems like a pretty high bar to me, why not "specification required" ?

The "IETF Review" policy was deliberately chosen to prevent registration of sub-error codes that could conflict with IETF policy. A lower bar like "Specification Required" would not provide sufficient oversight to prevent such registrations.

EV> not convinced but OK

### Section 11.2

Please add a field in table 1 for "Mandatory (Y/N?)".

  All current fields are optional and the draft already requires that future extensions must not introduce mandatory fields for backward compatibility.

EV> the IANA initial registry MUST match the format of the registration data


## Non-critical / cosmetic issues

Note: these points must also be addressed.

### Section 3

s/succesfully/successfully/
s/a end user/an end user/ (more than once)

For readability, I wonder whether `This document defines a structured, machine-readable....` part should appear either as a new paragraph in bullet 3 or even outside of the bulleted list (of course adding a reference to bullet #3).

### Section 8

Consider using a 'dig' request to show the SDE & EDE encoding. BTW, the length of the example is about 100 octets... hence a justification for not using CBOR is mostly required.

### Section 11

The formats and apparences of the sub-sections are all different (use of bullet, bold, ...), please fix.

Could you please elaborate on the formatting inconsistencies you observed in Section 11 ?

EV> different format (at least over HTML)

Cheers,
-Tiru