Re: [DNSOP] I-D Action: draft-ietf-dnsop-7706bis-08.txt

Bob Harold <rharolde@umich.edu> Mon, 02 March 2020 14:48 UTC

Return-Path: <rharolde@umich.edu>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D6DA3A07D4 for <dnsop@ietfa.amsl.com>; Mon, 2 Mar 2020 06:48:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=umich.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hGTDgNdFAGoL for <dnsop@ietfa.amsl.com>; Mon, 2 Mar 2020 06:48:05 -0800 (PST)
Received: from mail-lf1-x12c.google.com (mail-lf1-x12c.google.com [IPv6:2a00:1450:4864:20::12c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 94FAC3A080F for <dnsop@ietf.org>; Mon, 2 Mar 2020 06:48:04 -0800 (PST)
Received: by mail-lf1-x12c.google.com with SMTP id n30so8303587lfh.6 for <dnsop@ietf.org>; Mon, 02 Mar 2020 06:48:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=umich.edu; s=google-2016-06-03; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=hDqi9ex0wPs+0bCKC9LQcra/eBNu8nWYPsbpgog6BGU=; b=VvsvOS0AFT9n5DXq0ot9sYT7kywXtTzVJg+wFKY2QLg+YQIcmJNDImhwKWmDzj3ApX xvnHr6MCjClBl1V6THxP1QWtWOuMp7QV2/v4Sy+M/32pRQDymKnYBx9PPBoLRCfe6xtw 7fsvya2nLecFuRJ20tHT7SnoTai3LffjpfN/uTLnbxHt51/zzBY2lEXXK6kE5a+0UzX2 i42IwpZNw57tLBmipdGjGhH4F1ZY3aNg9RWzHywGRsRuDif5i9Nyvt+1cHNKiJmi1KUG /rzO6RuLQNJS8dR8pjHZPEuZSdj/4EwuYyYdAgvLpD52Ov6Dms55GmJIe/km2QMCw0Aw r40g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=hDqi9ex0wPs+0bCKC9LQcra/eBNu8nWYPsbpgog6BGU=; b=Vh72cLO0r/yM+awKvjYhipSGyqv9KDQJlryVoGqOUq+ASyL/XVFrkWfkryFIjdoLxS YtTsFvB/3jVZxXrV5I+39Ffy9Ov7DXwbrt9KwjrJ7vh+gUSN2J1ndMF8pl7dLu8LnGjK DgsNnf7ej0p6R+v8+1c/+8YGjR1IuQtTYgu/MjMmjaJqX+rdG2szddAOj7enxNlTTpkO 6UEawuzGneruNQ0VE++aMldrP+wjVRS8mCKyF1I+B3I5P2+L5MNA58x72kANwZEo5ceU MAEogoiv1mxNx+4Z79jtDVU47XKxLaYfdDvOauxybATEsk09LparSZu5nL3++Ot8IrNS UmyQ==
X-Gm-Message-State: ANhLgQ23lQmPYuKtwiNa0bCO/8y/t7YUZpUR2iYuiqzwwJJDXfn9DZi+ AEZFlLCwcq96nGBL1+qGmkRjCfYt7Sm+FIGUd3kPzK5Ec/U=
X-Google-Smtp-Source: ADFU+vs7eMwrXfndQqWPQyfUYu0OwMuawZNE2RG70BYy3JO1GHHuHEjnlrjDi6JmoauRzh964BLjVfcsiM0uyd2iDZk=
X-Received: by 2002:ac2:5682:: with SMTP id 2mr10898164lfr.138.1583160482532; Mon, 02 Mar 2020 06:48:02 -0800 (PST)
MIME-Version: 1.0
References: <158311442702.32587.15635520413801088856@ietfa.amsl.com>
In-Reply-To: <158311442702.32587.15635520413801088856@ietfa.amsl.com>
From: Bob Harold <rharolde@umich.edu>
Date: Mon, 02 Mar 2020 09:47:51 -0500
Message-ID: <CA+nkc8CUc7gd4EVT5BdGZQJjniyNiEjhT49=fVar47P5Z82Oug@mail.gmail.com>
To: IETF DNSOP WG <dnsop@ietf.org>
Cc: i-d-announce@ietf.org
Content-Type: multipart/alternative; boundary="0000000000002f1ec5059fe04662"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/RcnpnjeLHj63g12CB_AWhgRttTY>
Subject: Re: [DNSOP] I-D Action: draft-ietf-dnsop-7706bis-08.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Mar 2020 14:48:07 -0000

On Sun, Mar 1, 2020 at 9:00 PM <internet-drafts@ietf.org> wrote:

>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the Domain Name System Operations WG of the
> IETF.
>
>         Title           : Running a Root Server Local to a Resolver
>         Authors         : Warren Kumari
>                           Paul Hoffman
>         Filename        : draft-ietf-dnsop-7706bis-08.txt
>         Pages           : 13
>         Date            : 2020-03-01
>
> Abstract:
>    Some DNS recursive resolvers have longer-than-desired round-trip
>    times to the closest DNS root server such as during a network attack.
>    Some DNS recursive resolver operators want to prevent snooping by
>    third parties of requests sent to DNS root servers.  Such resolvers
>    can greatly decrease the round-trip time and prevent observation of
>    requests by serving a copy of the full root zone on the same server,
>    such as on a loopback address or in the resolver software.  This
>    document shows how to start and maintain such a copy of the root zone
>    that does not cause problems for other users of the DNS, at the cost
>    of adding some operational fragility for the operator.
>
>    This document obsoletes RFC 7706.
>
>    [ This document is being collaborated on in Github at:
>    https://github.com/wkumari/draft-kh-dnsop-7706bis.  The most recent
>    version of the document, open issues, and so on should all be
>    available there.  The authors gratefully accept pull requests. ]
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-dnsop-7706bis/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-dnsop-7706bis-08
> https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-7706bis-08
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-dnsop-7706bis-08
>
>
Suggestions:

Abstract
"Some DNS recursive resolvers have longer-than-desired round-trip
times to the closest DNS root server such as during a network attack."

Suggested change:
Some DNS recursive resolvers have longer-than-desired round-trip
times to the closest DNS root server.  Some DNS recursive resolvers
may have difficulty getting responses from the root servers such as
during a network attack.


1.  Introduction

(end of fourth paragraph)
"The recursive resolver validates all responses from the
   root service on the same host, just as it would all validate
   responses from a remote root server."

"would all validate" -> "would validate all"


2.  Requirements

(second bullet point)
"The system MUST have an up-to-date copy of the Key Signing Key
(KSK) [RFC4033] used to sign the DNS root."

-- Should we clarify as "the public portion of the Key Signing Key" ?
(They do not need the private key)

-- 
Bob Harold