Re: [DNSOP] I-D Action: draft-ietf-dnsop-nsec3-guidance-00.txt

Florian Obser <florian+ietf@narrans.de> Wed, 26 May 2021 18:30 UTC

Return-Path: <florian+ietf@narrans.de>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C92C83A0E55 for <dnsop@ietfa.amsl.com>; Wed, 26 May 2021 11:30:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Alpl21AFCa-R for <dnsop@ietfa.amsl.com>; Wed, 26 May 2021 11:30:00 -0700 (PDT)
Received: from imap.narrans.de (michelangelo.narrans.de [45.77.55.97]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE8D13A0E53 for <dnsop@ietf.org>; Wed, 26 May 2021 11:29:58 -0700 (PDT)
Received: from nyarlathotep.local (2001-1c00-270d-e800-14de-729e-9158-eb17.cable.dynamic.v6.ziggo.nl [2001:1c00:270d:e800:14de:729e:9158:eb17]) by michelangelo.narrans.de (OpenSMTPD) with ESMTPSA id 64fec7a5 (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO) for <dnsop@ietf.org>; Wed, 26 May 2021 20:29:53 +0200 (CEST)
From: Florian Obser <florian+ietf@narrans.de>
To: dnsop@ietf.org
References: <162198004172.25576.6244609119457957364@ietfa.amsl.com>
Date: Wed, 26 May 2021 20:29:48 +0200
In-Reply-To: <162198004172.25576.6244609119457957364@ietfa.amsl.com> (internet-drafts@ietf.org's message of "Tue, 25 May 2021 15:00:41 -0700")
Message-ID: <m1zgwhmjqb.fsf@narrans.de>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (darwin)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/MPJhtGi0LJWZWewzeyu4e1rXjDI>
Subject: Re: [DNSOP] I-D Action: draft-ietf-dnsop-nsec3-guidance-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 May 2021 18:30:02 -0000

I finally got around to use a more sensible setting for my personal
domains, i.e. the recommended one.

I did have to refresh my memory on how NSEC3PARAM works by glancing at
RFC 5155 though. Maybe something like this at the end of
"3. Best-practice for zone publishers" would be helpful:

| Since the NSEC3PARAM RR is not used by validating resolvers (see
| [RFC5155] section 4) the iterations and salt parameters can be changed
| without the need to wait for RRsets to expire from caches.  A complete
| new NSEC3 chain needs to be constructed and the zone resigned.

Section 2.4 is already hinting at this, this spells it out.

Thanks,
Florian
-- 
I'm not entirely sure you are real.