Re: [DNSOP] rfc4641bis: NSEC vs NSEC3.

"W.C.A. Wijngaards" <wouter@nlnetlabs.nl> Wed, 17 February 2010 16:57 UTC

Return-Path: <wouter@nlnetlabs.nl>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id F2C523A7EEE for <dnsop@core3.amsl.com>; Wed, 17 Feb 2010 08:57:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.477
X-Spam-Level:
X-Spam-Status: No, score=-0.477 tagged_above=-999 required=5 tests=[AWL=1.027, BAYES_00=-2.599, HELO_EQ_NL=0.55, HOST_EQ_NL=1.545, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id phyOdFda8z3q for <dnsop@core3.amsl.com>; Wed, 17 Feb 2010 08:57:54 -0800 (PST)
Received: from rotring.dds.nl (rotring.dds.nl [85.17.178.138]) by core3.amsl.com (Postfix) with ESMTP id 01B2F3A79AD for <dnsop@ietf.org>; Wed, 17 Feb 2010 08:57:54 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by rotring.dds.nl (Postfix) with ESMTP id 45075585D9 for <dnsop@ietf.org>; Wed, 17 Feb 2010 17:59:32 +0100 (CET)
Received: from [192.168.254.2] (195-241-9-117.adsl.dds.nl [195.241.9.117]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by rotring.dds.nl (Postfix) with ESMTP id 8C94C5857F for <dnsop@ietf.org>; Wed, 17 Feb 2010 17:59:26 +0100 (CET)
Message-ID: <4B7C206D.7000901@nlnetlabs.nl>
Date: Wed, 17 Feb 2010 17:59:25 +0100
From: "W.C.A. Wijngaards" <wouter@nlnetlabs.nl>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.7) Gecko/20100120 Fedora/3.0.1-1.fc11 Thunderbird/3.0.1
MIME-Version: 1.0
To: dnsop@ietf.org
References: <200904282021.n3SKL3sg051528@givry.fdupont.fr> <59A58419-FDBD-4810-B2FA-0D293FFA00A5@NLnetLabs.nl> <alpine.LFD.1.10.1001211245180.12114@newtla.xelerance.com> <1AEAE091-2EB3-41DC-A51B-8DD49C10FAD5@NLnetLabs.nl> <24C8A8E2A81760E31D4CDE4A@Ximines.local> <8E6C64ED-A336-4E8B-996F-9FB471EB07C6@NLnetLabs.nl> <alpine.LFD.1.10.1002170942020.23587@newtla.xelerance.com> <38407369-DB49-4501-AB37-67CD676C8561@NLnetLabs.nl> <alpine.LFD.1.10.1002171127470.23587@newtla.xelerance.com>
In-Reply-To: <alpine.LFD.1.10.1002171127470.23587@newtla.xelerance.com>
X-Enigmail-Version: 1.0.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.95.3 at rotring
X-Virus-Status: Clean
Subject: Re: [DNSOP] rfc4641bis: NSEC vs NSEC3.
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Feb 2010 16:57:55 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 02/17/2010 05:37 PM, Paul Wouters wrote:
>>>> 5.3.  NSEC3 parameters
>>>>
>>>>  The NSEC3 hashing includes the FQDN in its uncompressed form.  This
>>>
>>> "over its uncompressed form"? The hash does not 'include' it.
>>
>> I overlooked this when I copied the text from P.W. who originally
>> supplied it :-)
>>
>> How about "hashing algorithm is performed on the FQDN ..."
> 
> Works for me.

Does not work for me, because the salt is also included in the hash, the
old text was technically true because the buffer that is hashed has the
FQDN as a substring.  Can the line be removed?  Otherwise, change active
vs passive: The uncompressed FQDN is used for the NSEC3 hash.

Best regards,
   Wouter

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iEYEARECAAYFAkt8IG0ACgkQkDLqNwOhpPgxIgCfQTMxa2SVQi/9McXVeRYszMQm
L8YAnRWH9UCHyIu09bnVO98xbkU/MW+M
=y4LW
-----END PGP SIGNATURE-----