Re: [DNSOP] Updated cheese-shop.

abby pan <abbypan@gmail.com> Thu, 25 February 2016 06:18 UTC

Return-Path: <abbypan@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 25F4F1B3382 for <dnsop@ietfa.amsl.com>; Wed, 24 Feb 2016 22:18:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kCd2Xdhm2U5Z for <dnsop@ietfa.amsl.com>; Wed, 24 Feb 2016 22:18:10 -0800 (PST)
Received: from mail-io0-x22b.google.com (mail-io0-x22b.google.com [IPv6:2607:f8b0:4001:c06::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 59A401B336F for <dnsop@ietf.org>; Wed, 24 Feb 2016 22:18:10 -0800 (PST)
Received: by mail-io0-x22b.google.com with SMTP id z135so79115844iof.0 for <dnsop@ietf.org>; Wed, 24 Feb 2016 22:18:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=5H5juQm9NT4RwRehlGGM+yuVKHw8q9Q7Uo2qMDDc7N0=; b=TQAf7X2FqbnkHh377nuwYh5o9wb+fnrm1RSYXz9G7ehfoPGEI2VYjfaQ1pqe7SawYA cSkiiQmbdQCAgECZpFIone8qLiwWFhYEYwZCYuXIs9o7sbmJ9TakwQo18+eU2nbzt/hm 5E0inz2z7bnNb+gg+aqlfqs2PCzrefueHPBRoIVWfHMgEghElMNEU3bDWEpUF/hJxemI zru2BtNGBxT2N2IH7RXyYfGHMd476zJ9fBN323RqntDy0j7OTf/MYIjnTeXi6whjYvgd YSF3a9ZO4OL5wzmcyEU7WzDjWQa+a2LSdwCXtDUimILEkG3z3LMEpW9eKEAH7z1e7AGH 68gg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=5H5juQm9NT4RwRehlGGM+yuVKHw8q9Q7Uo2qMDDc7N0=; b=d00uaiPHj6xUfT+RXvwTJTOv4Jo0QuUf1ovGtWgD7xMbBhTy8DjznkrzqgyGXUZLPB aQYflPmCp+c6BSRs/VTAMDjug5XGnGJa95IjCmC/6jOrD2EZNyozAjP8E5eS2dldX4Za aLi/MApsg6mh6W8Cj/u6grf8m7Vk+m5p+YVn6wdgMW2+8WbWVhBCK86pAWI1SzzHzxIH pxRLPGqLZLvXtQ807s5+biFwcggghOJomhwqxNd2asaTfeA48W2wqm3fcS64ZIJtXubB wKjp/P+ZX0yxlDx6DCH41xcsjD2gLpZfRAfTt0dQ/KnMPGfWPDNoVjoQWskxyNpIJxNH PtjQ==
X-Gm-Message-State: AG10YORKqWx1SDxbeDekvftmDP+CwISVPCmh2wFzJKkkcShzA+JTxWO5BX+czpFgoDA+dJgCKgI+WdVTIFFeIA==
X-Received: by 10.107.46.151 with SMTP id u23mr1436523iou.136.1456381089708; Wed, 24 Feb 2016 22:18:09 -0800 (PST)
MIME-Version: 1.0
References: <CAHw9_i+qiU+rMcPHfv=EnogiwuMJzoaTi8a_KUWSepbLd7j6ug@mail.gmail.com>
In-Reply-To: <CAHw9_i+qiU+rMcPHfv=EnogiwuMJzoaTi8a_KUWSepbLd7j6ug@mail.gmail.com>
From: abby pan <abbypan@gmail.com>
Date: Thu, 25 Feb 2016 06:18:00 +0000
Message-ID: <CANLjSvWJON4NxxHPPaHaD0xcLLgiAq7yJLNrEoRcdEjOrkaWzw@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>, dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="001a113ad6c4827e0b052c92255c"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/TwQraNvv-K2slRo1lp8Y3Dw-mAw>
Subject: Re: [DNSOP] Updated cheese-shop.
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Feb 2016 06:18:12 -0000

root zone size is much smaller than TLD, and RR has long ttl.

NSEC is satisfied.

Warren Kumari <warren@kumari.net>于2016年2月25日周四 下午12:58写道:

> Dear DNSOP,
>
> We have recently updated "Believing NSEC records in the DNS root" (
> https://tools.ietf.org/html/draft-wkumari-dnsop-cheese-shop-01).
>
> This incorporates some comments, but also does a better job of explaining
> the technique, what the benefits are, and why we are only handling the
> special case of the root zone.
> We believe that, in this limited use-case the suggestions in Section 4.5
> of RFC4035 are not as relevant. We also believe that the NSEC case (and no
> wildcards :-)) is simpler to solve than the NSEC3 case.
>
> For these reasons we think that it is worth pursuing this in parallel
> with Fujiwara-san's "Aggressive use of NSEC/NSEC3" document.
> cheese-shop does not conflict with "Aggressive use...",  rather it
> complements it, and can demonstrate the technique (in this restricted use
> case).
>
> We welcome any feedback, including tomatoes, howls of derisive laughter,
> etc.
>
> W
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
>
-- 

Best Regards
Pan Lanlan