[DNSOP] Dnsdir early review of draft-ietf-dnsop-rfc7958bis-00

Florian Obser via Datatracker <noreply@ietf.org> Tue, 06 February 2024 15:17 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: dnsop@ietf.org
Delivered-To: dnsop@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id C8FEEC151070; Tue, 6 Feb 2024 07:17:33 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Florian Obser via Datatracker <noreply@ietf.org>
To: dnsdir@ietf.org
Cc: dnsop@ietf.org, draft-ietf-dnsop-rfc7958bis.all@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.4.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <170723265380.12216.1920561465383751473@ietfa.amsl.com>
Reply-To: Florian Obser <fobser@ripe.net>
Date: Tue, 06 Feb 2024 07:17:33 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/P7wVtYcCd42f16tc1Xjcb1U66Uw>
Subject: [DNSOP] Dnsdir early review of draft-ietf-dnsop-rfc7958bis-00
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Feb 2024 15:17:33 -0000

Reviewer: Florian Obser
Review result: Ready with Nits

I have been selected as the DNS Directorate reviewer for this draft. The
DNS Directorate seeks to review all DNS or DNS-related drafts as
they pass through IETF last call and IESG review, and sometimes on special
request. The purpose of the review is to provide assistance to the ADs.
For more information about the DNS Directorate, please see
https://wiki.ietf.org/en/group/dnsdir

I think the document is basically ready. I spotted a few nits, feel free to
ignore as many as you like.

* Abstract

> This document describes the format and publication mechanisms IANA
> intends to use to distribute the DNSSEC trust anchors.

while in "1. Introduction" we have:

> This document describes the formats and distribution methods of DNSSEC
> trust anchors that have been used by IANA for the root zone of the DNS
> since 2010.

Which one is it? Maybe this would be better:

> This document describes the format and publication mechanisms IANA
> uses to distribute the DNSSEC trust anchors.

* 1.  Introduction

> A detailed description of corresponding
> key management practices can be found in [DPS], which can be
> retrieved from the IANA Repository at <https://www.iana.org/dnssec/>.

It seems redundant to add a reference as [DPS] and then provide a link
in-line. Additionally the reference and in-line link are different:
https://www.iana.org/dnssec/
vs.
https://www.iana.org/dnssec/procedures

Maybe just shorten it to

> A detailed description of corresponding key management practices can
> be found in [DPS].

* 2. IANA DNSSEC Root Zone Trust Anchor Formats and Semantics

> IANA publishes trust anchors for the root zone as an XML document
> that contains the hashes of the DNSKEY records.

since IANA wishes to also publish the DNSKEY itself, maybe this is better:

> IANA publishes trust anchors for the root zone as an XML document
> that contains the hashes of the DNSKEY records and optionally the keys
> from the DNSKEY records.

* Appendix A.  Historical Note

Missing text:
> The second KSK for use in the root zone of the DNS was [ MORE GOES
> HERE ].