Re: [DNSOP] .arpa
Matt Larson <matt@kahlerlarson.org> Thu, 23 March 2017 21:43 UTC
Return-Path: <matt@kahlerlarson.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C27713167B for <dnsop@ietfa.amsl.com>; Thu, 23 Mar 2017 14:43:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KhUpliyEsCJD for <dnsop@ietfa.amsl.com>; Thu, 23 Mar 2017 14:43:09 -0700 (PDT)
Received: from mail.kahlerlarson.org (twister.kahlerlarson.org [104.237.149.128]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78591131678 for <dnsop@ietf.org>; Thu, 23 Mar 2017 14:43:09 -0700 (PDT)
Received: from [IPv6:2601:703:6:2f56:3c22:f097:d96d:1826] (unknown [IPv6:2601:703:6:2f56:3c22:f097:d96d:1826]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.kahlerlarson.org (Postfix) with ESMTPSA id 5541B1F42D; Thu, 23 Mar 2017 21:43:08 +0000 (UTC)
Content-Type: multipart/alternative; boundary="Apple-Mail=_56BFF812-60B5-4904-8DCC-95663423C100"
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Matt Larson <matt@kahlerlarson.org>
In-Reply-To: <F5854071-6507-444B-90DB-B0CF0C27B7D0@fugue.com>
Date: Thu, 23 Mar 2017 17:43:07 -0400
Cc: Ralph Droms <rdroms.ietf@gmail.com>, dnsop@ietf.org, Ray Bellis <ray@bellis.me.uk>
X-Mao-Original-Outgoing-Id: 511998187.037559-7561ad00a8a2300b0ad227b3d7532004
Message-Id: <12D27551-16F8-4379-B650-160E861666C2@kahlerlarson.org>
References: <20170323042741.79108.qmail@ary.lan> <2C6B4EB6-D0F0-44A8-95E4-68DF32244639@fugue.com> <20170323163205.GD19105@mx4.yitter.info> <500af1ed-5425-4452-ad8e-c2d511ee738d@bellis.me.uk> <850A8729-8762-4375-90EF-50CDF4AC232E@gmail.com> <47548136-78d7-8c53-462e-62439d6194ac@bellis.me.uk> <360B2807-049F-4707-95FE-AA279C583884@gmail.com> <F5854071-6507-444B-90DB-B0CF0C27B7D0@fugue.com>
To: Ted Lemon <mellon@fugue.com>
X-Mailer: Apple Mail (2.3124)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/OGfKl-_3XpC8obPcRma9Vb51sk0>
Subject: Re: [DNSOP] .arpa
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Mar 2017 21:43:11 -0000
> On Mar 23, 2017, at 2:30 PM, Ted Lemon <mellon@fugue.com> wrote: > > On Mar 23, 2017, at 2:11 PM, Ralph Droms <rdroms.ietf@gmail.com <mailto:rdroms.ietf@gmail.com>> wrote: >> No snark intended, but if "the protocol" were really just DNS, we wouldn't be having this discussion. Rather, it is the DNS wire protocol using a local resolution context rather than the root zone. In any event, yes, the locally server homenet zone can function with DNSSEC. > > So do locally-served zones, by this definition, use a different protocol? I think saying "different protocol" is not accurate and risks being a distraction. Rather, Ralph's comment about "resolution context" is important and gets to the heart of the issue. Before DNSSEC, a recursive name server could also be authoritative for local zones or use other mechanisms (such as stub zones and conditional forwarding) to "short circuit" resolution to handle the local context and not send traffic to the root, and everything resolved just fine. Now, with DNSSEC validation enabled, zones in this "local resolution context" need to chain up to a trust anchor somewhere. If there's not a chain of trust from the root, a local trust anchor is needed for validation to succeed. Consider a corporate split DNS example. Let's say Acme Corp maintains two versions of the zone acme.com <http://acme.com/>, one for external consumption (delegated to from .com) and another version for internal use. Their internal recursive name servers use some mechanism (local authoritative zones, stub zones, etc.) to ensure that internally generated queries resolve against the internal version of acme.com <http://acme.com/>. Let's also say that Acme Corp signs both the internal and external versions of acme.com <http://acme.com/> and that their internal recursive servers have DNSSEC validation enabled. The chain of trust from the root leads to the external acme.com <http://acme.com/>, so the internal recursive servers will need a trust anchor for the internal version of acme.com <http://acme.com/> or validation fails. homenet uses a local resolution context without a local trust anchor, hence the request for special casing in the root. Matt
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Hoffman
- [DNSOP] WG review of draft-ietf-homenet-dot-03 Suzanne Woolf
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 George Michaelson
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Russ Housley
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Russ Housley
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Jim Reid
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Russ Housley
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Vixie
- [DNSOP] Fwd: WG review of draft-ietf-homenet-dot-… Russ Housley
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Russ Housley
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Steve Crocker
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Steve Crocker
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Brian Dickson
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Wouters
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Brian Dickson
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Viktor Dukhovni
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Andrew Sullivan
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Steve Crocker
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Brian Dickson
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Viktor Dukhovni
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Wouters
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Andrew Sullivan
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Vixie
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Vixie
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Mark Andrews
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Mark Andrews
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Mark Andrews
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Suzanne Woolf
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Philip Homburg
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Wouters
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Jim Reid
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Philip Homburg
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Wouters
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Paul Wouters
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Jim Reid
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Suzanne Woolf
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Jaap Akkerhuis
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Suzanne Woolf
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Mark Andrews
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Jim Reid
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ted Lemon
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Suzanne Woolf
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Tim Chown
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ray Bellis
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Ralph Droms
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Tim Chown
- [DNSOP] .arpa Jim Reid
- Re: [DNSOP] .arpa Patrik Fältström
- Re: [DNSOP] .arpa Suzanne Woolf
- Re: [DNSOP] .arpa Tim Chown
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Tim Chown
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Tim Chown
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Ray Bellis
- Re: [DNSOP] .arpa Andrew Sullivan
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Andrew Sullivan
- Re: [DNSOP] .arpa Ralph Droms
- Re: [DNSOP] .arpa John Levine
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa John R Levine
- Re: [DNSOP] WG review of draft-ietf-homenet-dot-03 Matthew Pounsett
- [DNSOP] draft-ietf-homenet-dot review limits Re: … Suzanne Woolf
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Andrew Sullivan
- Re: [DNSOP] .arpa Suzanne Woolf
- Re: [DNSOP] .arpa Ray Bellis
- Re: [DNSOP] .arpa Ralph Droms
- Re: [DNSOP] .arpa Suzanne Woolf
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Ray Bellis
- Re: [DNSOP] .arpa Paul Wouters
- Re: [DNSOP] .arpa Ray Bellis
- Re: [DNSOP] .arpa Ralph Droms
- Re: [DNSOP] .arpa Paul Wouters
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Matthew Pounsett
- [DNSOP] Homenet implementation plans by vendors? … Dan York
- Re: [DNSOP] Homenet implementation plans by vendo… Ted Lemon
- Re: [DNSOP] Homenet implementation plans by vendo… Ray Bellis
- Re: [DNSOP] .arpa Matt Larson
- Re: [DNSOP] .arpa Ralph Droms
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] Homenet implementation plans by vendo… George Michaelson
- Re: [DNSOP] Homenet implementation plans by vendo… Ray Bellis
- Re: [DNSOP] Homenet implementation plans by vendo… George Michaelson
- Re: [DNSOP] Homenet implementation plans by vendo… Ray Bellis
- Re: [DNSOP] .arpa Ralph Droms
- Re: [DNSOP] .arpa Ozgur Karatas
- Re: [DNSOP] .arpa Suzanne Woolf
- Re: [DNSOP] .arpa John Levine
- Re: [DNSOP] .arpa Richard Lamb
- Re: [DNSOP] .arpa George Michaelson
- Re: [DNSOP] .arpa David Conrad
- Re: [DNSOP] .arpa George Michaelson
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa George Michaelson
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa George Michaelson
- Re: [DNSOP] .arpa Ted Lemon
- Re: [DNSOP] .arpa Patrik Fältström
- Re: [DNSOP] .arpa Ray Bellis
- Re: [DNSOP] .arpa Patrik Fältström
- Re: [DNSOP] .arpa Jim Reid
- Re: [DNSOP] .arpa Suzanne Woolf