Re: [DNSOP] New draft on delegation revalidation
Shumon Huque <shuque@gmail.com> Mon, 04 May 2020 12:20 UTC
Return-Path: <shuque@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F8F33A0841 for <dnsop@ietfa.amsl.com>; Mon, 4 May 2020 05:20:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MBhqJxSBHFLl for <dnsop@ietfa.amsl.com>; Mon, 4 May 2020 05:20:12 -0700 (PDT)
Received: from mail-ej1-x633.google.com (mail-ej1-x633.google.com [IPv6:2a00:1450:4864:20::633]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1355F3A0843 for <DNSOP@ietf.org>; Mon, 4 May 2020 05:20:12 -0700 (PDT)
Received: by mail-ej1-x633.google.com with SMTP id s3so13686700eji.6 for <DNSOP@ietf.org>; Mon, 04 May 2020 05:20:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=j4OAneTeYF8rdlWRhXEj22zXXHof4NuOH9Chh2o8cdo=; b=Q5/qbo+d0ku81ULXFO7AlhBXc3Jn9NcixxrNb7gx1Q37bLJyugo6B9LCeesSKw0LhQ O//vsXCZ9ZabqFzbabnloAzwXJYFYZda3AOAInrrOOqj9nJtvfBwuP1Y8qgcPSRbykke MyBDI6hO7qIPXIclxJrPzXqF9HXSsBaEcyXZpCkRm5R5iIGYC+/neYPULOaxFQuFpb6J LCURtbD+qKJnZLa2fgWafsu59+t+YGt/Gr3qV2+b1gZIZqWr09UeLxDQ3D1jNmddCdWw IWz6jrNjM8Lqv5tNQXArrdknQbKRxxRE8w31C9JHmAR+JmZXaRgYWhPUpFAMfD7pl2Ox yhGQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=j4OAneTeYF8rdlWRhXEj22zXXHof4NuOH9Chh2o8cdo=; b=NOr8BGC1lgZ494SF3uXT93zi2PAffCesBwnjY2wgR/ePdykOWO8sZx4k8Z6tSpT8f6 Oi9Iw68sR2hZ80Ov3bEiSQEJbxbhX0g8bHdxZ5BXF5U0W67Uizq9MxG0eYpJX1QPppwU HKr/8rDovcR/+/qh73B+lRf0vfGqgFRBA9LvNJ/vuTImry/B2+5Hq21NDOEIYhEPqRcu 68vg+dGh741CdUzxbTfuRdM3exysWicl2fVu27Y9kOeSivFi+vX8s64+ZmxwO+a01ILw L9oD7QAF8bZTGPfUGDMP3qHCdlbx+7PlimCCR/LTVv8jVc32ET0Pmf8+Y7qJhuCVf0qb t2Rw==
X-Gm-Message-State: AGi0PuaodstIPRSnsZEoAZFEataKJssrYn6riupgH6AeFxLLEuNdzko+ Z6kq5+vqzD5IaH1x17IYDfuOTiXabcmeMC+UQLw=
X-Google-Smtp-Source: APiQypJSLYn30wjtXxfjgtsJFv1j3mgSNEw+mYCN0lYauwjfqyQ5HVvGqS8tpico2xCyojcJxGGQ7xESm6uabdbE2ok=
X-Received: by 2002:a17:906:131b:: with SMTP id w27mr14581253ejb.230.1588594810457; Mon, 04 May 2020 05:20:10 -0700 (PDT)
MIME-Version: 1.0
References: <CAHPuVdV9eSCLQOqMF0cq8fHcuSZs7nCgjhHMfMoaV5H=ekbtSA@mail.gmail.com> <4feca627-79d6-374e-402d-f50d49e03469@sidn.nl> <CAHPuVdVkTbV6o5sVCZzOcE4y0yEFUa3rmtcsWooxQK0nO_eMvw@mail.gmail.com> <058d760a-7400-e407-4d12-c744d949538e@sidn.nl> <CAHPuVdWR6MTsWK0xBBnRj3JkgncORUWptt=VYZW+R-cDO4G1ig@mail.gmail.com> <CADZyTkm2t9-bL478dtMShkQQKW-Y1_H8nh0xmAwQHOZEnREcnQ@mail.gmail.com>
In-Reply-To: <CADZyTkm2t9-bL478dtMShkQQKW-Y1_H8nh0xmAwQHOZEnREcnQ@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
Date: Mon, 04 May 2020 08:19:57 -0400
Message-ID: <CAHPuVdUcBdVVWXp2oRKNwa7vHYEc1QOybvDmcdouxChO8rkgRg@mail.gmail.com>
To: Daniel Migault <mglt.ietf@gmail.com>
Cc: IETF DNSOP WG <DNSOP@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000005e90fc05a4d18d1f"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/NQ4WPdSnQmPJjcC3xxLB7wV5UKQ>
Subject: Re: [DNSOP] New draft on delegation revalidation
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 May 2020 12:20:14 -0000
On Wed, Apr 29, 2020 at 11:57 AM Daniel Migault <mglt.ietf@gmail.com> wrote: > Hi, > > I discovered this draft during the interim meeting. We had similar > thoughts in our "Recommendations for DNSSEC Resolvers Operators". Our > motivation for supporting this work are that it 1) improves the > reliability of the resolution as well as 2) removes the temptation to > (inadvertently) break resolution by fixing in appearance a > misconfiguration. In other words it eases the operation. > Thank you Daniel. Will read your draft shortly, but in the meantime .. Your note reminded me of the question you asked during the interim meeting about why we can't just use the DS TTL as the revalidation interval. Our response was that the main impediment was that DNSSEC deployment is far from ubiquitous, but also that there is no reason that it could not be factor, when available. Here's what the draft already says about DS: Technically, if both parent and child zone are DNSSEC [RFC4033] [RFC4034] [RFC4035] signed with a corresponding secure delegation between them, then expiration of the DS record will cause revalidation of the current child zone's DNSKEY set, so responses from the orphaned child nameservers would no longer be trusted. However, delegation revalidation is still necessary to locate the current nameserver addresses. In practice, the DS and delegating NS TTL do not always match. COM for example uses 2 day NS and 1 day DS TTL for all its delegations. So where DS is lower, that could be used as the upper bound. We'll queue up some text on this subject for the next revision of the draft. Shumon.
- Re: [DNSOP] New draft on delegation revalidation Mark Andrews
- [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Bob Harold
- Re: [DNSOP] New draft on delegation revalidation Tim Wicinski
- Re: [DNSOP] New draft on delegation revalidation Brian Dickson
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Stephane Bortzmeyer
- Re: [DNSOP] New draft on delegation revalidation Stephane Bortzmeyer
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation John Levine
- Re: [DNSOP] New draft on delegation revalidation Paul Vixie
- Re: [DNSOP] New draft on delegation revalidation Paul Vixie
- Re: [DNSOP] New draft on delegation revalidation Puneet Sood
- Re: [DNSOP] New draft on delegation revalidation Ólafur Guðmundsson
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation John R Levine
- Re: [DNSOP] New draft on delegation revalidation Bob Harold
- Re: [DNSOP] New draft on delegation revalidation Gavin McCullagh
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Patrick Mevzek
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Patrick Mevzek
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Joe Abley
- Re: [DNSOP] New draft on delegation revalidation Vladimír Čunát
- Re: [DNSOP] New draft on delegation revalidation Giovane C. M. Moura
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Gavin McCullagh
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] Privacy and DNSSEC Vladimír Čunát
- Re: [DNSOP] Privacy and DNSSEC Paul Vixie
- Re: [DNSOP] Privacy and DNSSEC Masataka Ohta
- Re: [DNSOP] Privacy and DNSSEC Vittorio Bertola
- Re: [DNSOP] New draft on delegation revalidation Joe Abley
- Re: [DNSOP] New draft on delegation revalidation Paul Vixie
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] Privacy and DNSSEC Shumon Huque
- [DNSOP] Client Validation - filtering validation? Brian Dickson
- Re: [DNSOP] Privacy and DNSSEC Paul Vixie
- Re: [DNSOP] Privacy and DNSSEC Mark Andrews
- Re: [DNSOP] New draft on delegation revalidation Giovane C. M. Moura
- Re: [DNSOP] Client Validation - filtering validat… Vittorio Bertola
- Re: [DNSOP] Client Validation - filtering validat… Paul Wouters
- Re: [DNSOP] Client Validation - filtering validat… S Moonesamy
- Re: [DNSOP] Client Validation - filtering validat… John Levine
- Re: [DNSOP] Client Validation - filtering validat… Paul Vixie
- Re: [DNSOP] Privacy and DNSSEC Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] Privacy and DNSSEC Paul Vixie
- Re: [DNSOP] Privacy and DNSSEC Shumon Huque
- Re: [DNSOP] Privacy and DNSSEC Paul Wouters
- Re: [DNSOP] Privacy and DNSSEC Shumon Huque
- Re: [DNSOP] Privacy and DNSSEC Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Daniel Migault
- Re: [DNSOP] Privacy and DNSSEC Paul Vixie
- Re: [DNSOP] Privacy and DNSSEC Paul Vixie
- Re: [DNSOP] New draft on delegation revalidation Giovane C. M. Moura
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Daniel Migault
- Re: [DNSOP] New draft on delegation revalidation Giovane C. M. Moura
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Petr Špaček
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Giovane C. M. Moura
- Re: [DNSOP] New draft on delegation revalidation Petr Špaček
- Re: [DNSOP] New draft on delegation revalidation Paul Vixie
- Re: [DNSOP] New draft on delegation revalidation Gavin McCullagh
- Re: [DNSOP] New draft on delegation revalidation Shumon Huque
- Re: [DNSOP] New draft on delegation revalidation Paul Vixie