Re: [DNSOP] Fwd: New Version Notification for draft-pan-dnsop-swild-rr-type-00.txt

Mikael Abrahamsson <swmike@swm.pp.se> Wed, 16 August 2017 06:21 UTC

Return-Path: <swmike@swm.pp.se>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73DAE1252BA for <dnsop@ietfa.amsl.com>; Tue, 15 Aug 2017 23:21:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level:
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=swm.pp.se
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tBnYSNCXICe9 for <dnsop@ietfa.amsl.com>; Tue, 15 Aug 2017 23:21:40 -0700 (PDT)
Received: from uplift.swm.pp.se (swm.pp.se [212.247.200.143]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF970124217 for <dnsop@ietf.org>; Tue, 15 Aug 2017 23:21:40 -0700 (PDT)
Received: by uplift.swm.pp.se (Postfix, from userid 501) id 98FEEAF; Wed, 16 Aug 2017 08:21:37 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=swm.pp.se; s=mail; t=1502864497; bh=NddMwPci93djrfc4vVEhSpJ7rS/5HIrc6NdYwd1EZeU=; h=Date:From:To:cc:Subject:In-Reply-To:References:From; b=wnvFi876kyybUvIuHapjG2S8FKDNgwhIoFh0rCGSxhjLNzIGqd1i5WAEjBYlHfAIW lbz8Mtq3d/8jQqVkddcdv8dWJ4hCt+gPvncg5E9p7GqAeDtLROOvmlzzlyXX67zKiV ZCySu6swotTsF3KQCvY1BtfwND/Ci2kuCqff8sSY=
Received: from localhost (localhost [127.0.0.1]) by uplift.swm.pp.se (Postfix) with ESMTP id 81B5584; Wed, 16 Aug 2017 08:21:37 +0200 (CEST)
Date: Wed, 16 Aug 2017 08:21:37 +0200
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: Mukund Sivaraman <muks@isc.org>
cc: dnsop <dnsop@ietf.org>
In-Reply-To: <20170816054539.GA12897@jurassic>
Message-ID: <alpine.DEB.2.20.1708160816580.3655@uplift.swm.pp.se>
References: <149908054910.760.8140876567010458934.idtracker@ietfa.amsl.com> <CANLjSvU23OPMM=cETxBiV7j8UhMzMd426VuivxAtboMAB0=7jw@mail.gmail.com> <alpine.DEB.2.11.1707031317070.21595@grey.csi.cam.ac.uk> <CANLjSvXE4q9PSEc4txKM4OPKXVpT38N_PC2-fDHmihpk29ahcw@mail.gmail.com> <1197245d-6b9a-3c3b-82a0-dc6a1cc3de58@nic.cz> <CANLjSvVe99q4vtTW0TRopmQ0s9hC8HdMze5B6COs8Y_3unir5w@mail.gmail.com> <CAAiTEH8ntOerB6MGKMS2xcCK3TL9n4fyLq6F+bpUY6oTUpWN8w@mail.gmail.com> <20170816054539.GA12897@jurassic>
User-Agent: Alpine 2.20 (DEB 67 2015-01-07)
Organization: People's Front Against WWW
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Uq-aUvtSIl_L9iSy2QORyEDdB5k>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-pan-dnsop-swild-rr-type-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 06:21:42 -0000

On Wed, 16 Aug 2017, Mukund Sivaraman wrote:

> 24 / 500 top domains (4.8%)
> 20548 / 1 million top domains (2.05%)
>
> (12 years after introduction of 403{3,4,5})

https://stats.labs.apnic.net/dnssec/XE?o=cXAw1x1g1r1

20% of European users is behind a validating resolver, in some countries 
it's 70% plus.

So this is now happening, albeit at a not high enough pace. But at least 
it's going in the right direction, and I do believe that there is enough 
people behind validating resolvers that people can't mess up signing their 
zone and push away blame on who needs to fix things.

So at least there is benefit in signing your zone now, there wasn't as 
much before when nobody was validating.

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se