Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Joe Abley <jabley@strandkip.nl> Tue, 30 April 2024 22:56 UTC

Return-Path: <jabley@strandkip.nl>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 852ECC180B64 for <dnsop@ietfa.amsl.com>; Tue, 30 Apr 2024 15:56:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=strandkip.nl
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LlGNT6zitMyo for <dnsop@ietfa.amsl.com>; Tue, 30 Apr 2024 15:56:15 -0700 (PDT)
Received: from ci74p00im-qukt09082101.me.com (ci74p00im-qukt09082101.me.com [17.57.156.10]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6677AC14F70F for <dnsop@ietf.org>; Tue, 30 Apr 2024 15:56:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=strandkip.nl; s=sig1; t=1714517774; bh=+2gyetJy5a7zLzZunImq8cJK2qkLv3K7YAMKUOZ5uJM=; h=Content-Type:From:Mime-Version:Subject:Date:Message-Id:To; b=rkkf60M+QTcwzBf/O/5AnJl6NCaVzp29EJErhs+7qkcEAnh2csVM0zkWW9YcHJnil 98d3i5jQRbxk0JgUNQjAH6t+MY4qB/mJ2lfCAIaBha4slPbLpGlnH+q4pcUNH+KHAG IUkBPskT2gZ1A2qpShrQV7UlDtgnLmrOumxqXp4A1gjymi979Z8TBxOE1n42LPTJ5Y 7L/+NLfov8jEWMvqBWI86BrlRCWweDK0CinICfEo2+46MYOtk1HIbWoDNa/bvGw9Sw /XgnHaA9ly79AK1xriWwFNovqSCU591UK1RiXLJL9agb7A1kqQ0bqc6RluVPyWTVB3 WmStnP1P9+UHQ==
Received: from smtpclient.apple (ci77p00im-dlb-asmtp-mailmevip.me.com [17.57.156.26]) by ci74p00im-qukt09082101.me.com (Postfix) with ESMTPSA id 130B456002F6; Tue, 30 Apr 2024 22:56:12 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: Joe Abley <jabley@strandkip.nl>
Mime-Version: 1.0 (1.0)
Date: Wed, 01 May 2024 00:55:59 +0200
Message-Id: <B53C9169-118D-499E-9A28-19A5FA1F038B@strandkip.nl>
References: <4907A4B7-1EAE-460D-91E8-4F7D292C7302@icann.org>
Cc: Wes Hardaker <wjhns1@hardakers.net>, dnsop <dnsop@ietf.org>
In-Reply-To: <4907A4B7-1EAE-460D-91E8-4F7D292C7302@icann.org>
To: Paul Hoffman <paul.hoffman@icann.org>
X-Mailer: iPhone Mail (21E236)
X-Proofpoint-GUID: xmjuSsSohJLI77S5NUMi_-8JnB5B5yvv
X-Proofpoint-ORIG-GUID: xmjuSsSohJLI77S5NUMi_-8JnB5B5yvv
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.650,FMLib:17.11.176.26 definitions=2024-04-30_14,2024-04-30_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 mlxlogscore=660 adultscore=0 bulkscore=0 mlxscore=0 phishscore=0 malwarescore=0 clxscore=1030 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2308100000 definitions=main-2404300163
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Memgs8XHuawdZ2YjjOjvNfbLf28>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Apr 2024 22:56:20 -0000

On 1 May 2024, at 00:42, Paul Hoffman <paul.hoffman@icann.org> wrote:

> This cull-because-of-low usage thread incorrectly assumes that the DNS is flat instead of a hierarchy. The last I saw, there are 14 TLDs who use RSASHA1. Advancing this draft as-is means that all of the zones under those TLDs would be completely wiped out as well.

Wiped out sounds rather final. In reality things that break get fixed if people care about them. Sometimes a forcing function is useful. If we really didn't believe this to be true we would never deprecate anything. 


Joe