[DNSOP] Re: [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Petr Menšík <pemensik@redhat.com> Tue, 12 November 2024 23:44 UTC

Return-Path: <pemensik@redhat.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 93127C1840FF for <dnsop@ietfa.amsl.com>; Tue, 12 Nov 2024 15:44:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.252
X-Spam-Level:
X-Spam-Status: No, score=-2.252 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=redhat.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Ej06_RSLSkJ for <dnsop@ietfa.amsl.com>; Tue, 12 Nov 2024 15:44:43 -0800 (PST)
Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D52A3C1840F7 for <dnsop@ietf.org>; Tue, 12 Nov 2024 15:44:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1731455081; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=Ld9ewLcP8mavZA9V3RynwFXItDRTTYr04dygAofh/cU=; b=bUtaoTj8TtgLUXbyDQiLCCsfZaYcMvQxyCCW6Y83Nvj87IQhvh+nGB8We5Ie7Is5kPSOqI /pI9MbfsUcFhE0gMItn4+Y8QG38vCKOLUIGh4wIG1OiOniX34Y3tLyMFg8qN4KSVjL7ybj RBJ4bBs2X8GjWw+71Vdy/Ervj22l3uM=
Received: from mail-ed1-f70.google.com (mail-ed1-f70.google.com [209.85.208.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-631-4NtAfXtROpyrWaScKhncmw-1; Tue, 12 Nov 2024 18:44:40 -0500
X-MC-Unique: 4NtAfXtROpyrWaScKhncmw-1
X-Mimecast-MFC-AGG-ID: 4NtAfXtROpyrWaScKhncmw
Received: by mail-ed1-f70.google.com with SMTP id 4fb4d7f45d1cf-5c934ceea1fso4995714a12.2 for <dnsop@ietf.org>; Tue, 12 Nov 2024 15:44:39 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1731455079; x=1732059879; h=content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:to:subject:user-agent:mime-version:date :message-id:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=Ld9ewLcP8mavZA9V3RynwFXItDRTTYr04dygAofh/cU=; b=gR/H5CeoxF6gKWDa/ccgdINum4yS0H5J5bM/L9S6rnTDEIxgVqLItJ0elPMFmMxZ5T 7LyS82HZDVchd2IKyhDs+yzKOTlpuVmwFx7NcThDGsQGC0bGqfFjcIyqSbJRPX+q29iC twhjYvsv/MgwlviDzVP4teGV3ixaIWU6FtzJA+bru2f4wzOpWxQOHCYZPWJkUUi8lNIT 9eNEJSqHVnlS1R9RoSMIfJiOKjNkJD5vJSXGBAFYKQuzl0Hz7xpDEIq4LgCfM1MOMky4 XWveqNpG5dorf9hEwunzNRVIY/xjIonvq8eLceqOS7q+TMYn5BHqeN7TGczj/SxQKJWg F/wA==
X-Gm-Message-State: AOJu0YyOBQVfO3f7O63RSUHhZGe9g/TfRJGOcC+ezlO8Ig55Ko2An2jT e0ZRyB7tjOR4V3tiZQWYZ3S7r0LLHDSy9l/2FzViIYuUT340yH5oIJ+PNGxtJg7mWmTEL/z+Fee gmLydDtG/RzjqhOhici81Bsn3/WW0Nrgt8oeZKSTG5iHtrQ4d/3ROlYqvnN4MZXLnIG1V6NJlDs jBWrH4vN/ZN+Ms6ZQ0rBZIqK68woU=
X-Received: by 2002:a05:6402:5251:b0:5ce:fa29:5459 with SMTP id 4fb4d7f45d1cf-5cf4f361b0bmr3939669a12.15.1731455078655; Tue, 12 Nov 2024 15:44:38 -0800 (PST)
X-Google-Smtp-Source: AGHT+IGo9xyTXtD/3SrU1i4UK51mzQLqKDqlZUfyaYO5vowP1V61RXieFTztLclLcjfWbs5GoifUPg==
X-Received: by 2002:a05:6402:5251:b0:5ce:fa29:5459 with SMTP id 4fb4d7f45d1cf-5cf4f361b0bmr3939656a12.15.1731455078170; Tue, 12 Nov 2024 15:44:38 -0800 (PST)
Received: from ?IPV6:2a03:3b40:296:0:f482:3914:642b:42fb? ([2a03:3b40:296:0:f482:3914:642b:42fb]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-5cf03b7e80esm6527660a12.21.2024.11.12.15.44.37 for <dnsop@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 12 Nov 2024 15:44:37 -0800 (PST)
Message-ID: <bfad23b8-01ab-4e45-9d52-c6f670b1d9ba@redhat.com>
Date: Wed, 13 Nov 2024 00:44:36 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: dnsop@ietf.org
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org> <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl> <m1s1Wur-0000LDC@stereo.hq.phicoh.net> <f0f9c0ce-2911-9b4c-0d60-47c204add2d4@nohats.ca> <m1s1mGR-0000PPC@stereo.hq.phicoh.net> <fbce2996-346f-29fa-3534-45eaa142b96e@nohats.ca> <d73fc09e-c0c4-44f2-a67d-4cf5fafa0863@desec.io> <m1s2R59-0000MgC@stereo.hq.phicoh.net> <97900eaa-b190-472a-9d35-e3fa412b724c@desec.io> <m1s2Reg-0000LsC@stereo.hq.phicoh.net> <0072f7ef-7394-4e81-8206-d0b7040cbf34@desec.io> <m1s2Rwm-0000MGC@stereo.hq.phicoh.net>
From: Petr Menšík <pemensik@redhat.com>
Autocrypt: addr=pemensik@redhat.com; keydata= xsDNBF17vwQBDACso9gM0++XOzm/b//dGE1bgYyIch8xqCDHe2YXDUL2a65LCmNQUnS7PTxf 8psG4DdBayWlRvA/33L3YQD8gULaZX/KsHbSQov4Np4E2rG9PCljcDqHFCKjHEmmzQ86Z4+r euHoTwUpEroz2xa1XAIsy4fjqro0GHc6H3BVwXQ8Vfrmllq6tW+ubegI/tZSDDfOlnkHyMsh /mX893qn1Sb+A/RqyDDV6voAv4YfoNJyDfBB0jMshEiSLO+S0vspw42ElbAdLO6SHOX8Dy/a yPVTGDe2Jopy3YrbUWtu5HIs8X0vsKbF6tegO1l/m1y3t2Aa153k6NKOWv+79iNiY2ygGefm o1TRzlS/d+xacOxnGO3RCSlvm3xDEUuqNqrSQNF2yVRYAMwh75VWefeTu+/erXR4MGDpTTSA Ebaen0+uuiG4LGCNzZdYOyj7OMHW14e9JX4eujP0DtoJC9TWpDwHwbApbf83ZdmxxrU4yTPi 7fkXe4qkPulRFV7LOmlkAAUAEQEAAc0jUGV0ciBNZW7FocOtayA8cGVtZW5zaWtAcmVkaGF0 LmNvbT7CwRQEEwEIAD4CGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQTfz5CNt8h+jlKZ JbxJMcpbbJ/FywUCZPHFVgUJCzhtUgAKCRBJMcpbbJ/Fy1fxC/47crKpMrPsX0LHs05fpiS+ tgemYCvezN0So0x9Wc0Otl7L4qa2y4IiCfIS6G8gNEClEuatI1xfFVMxCU+BYFw5NRXNSZj+ 2Pb4DS69lhGJoFctwJ8mPIhPOr9SDQKAYw0EPbk+nWXB4fo3cKKN/EbKD++a/lLOecajGoF1 3N27l6fyfZHxm1tM/6TSm/2QyAau6MF6k9o4gA9/VjV6PYNKehicO7CkKO820F3OazPW9iFp dsmscKOEb79xZOq/W6vTPisHreBM7oB129PZxJrhOks3F/gfxG62kAUBGezFgFqWu4IFhsnM cMBokXUd6yurRBndljG0lW/P1pIH6TIrnCYzQ8XVA4hZFhfWdlCJqcPrbaQocnKzOdaa/fe3 xQHRiHOvvRvTkBCLFYcLVqXvWcAlj8jgsCbM3lakVPBLAYDjUdTqwrnTQ+vgJtx/4OCQuGkr 6sEKUQvxl/mWrN7+ThZJQ0ITWbP1ay5MA6QGulo2PyH5nV8/A6dnjS+M6UbOwM0EXXu/BAEM AMe+2Xxem4Uzjy2MG9cT3aX7suGVCgYmJV2CACSMncqN2MC0PjxGiV37wv+Cyq9QaOF/MiuF 568YYim2Cz1RURRjDxDeslMqj+6NKwepwABPTdlGOOvnMBmH5gfBeBJuRcx+1cHVTHBpoSTi waDUg+rtyfRXZYCGqvG9fUcJzWeCkiYbqaLHzxt9sTPhAv3rE0MdGib8Igg86Txge3b55i/7 MbYGtw+lqtVoYpsV1LoqfoQgW8j0Ac1Objch34iKvbAR75z6dJ1Tg5aFJyhYCbB8NwrE31Pd aXUHyr47y3IoNXNlc0s7dg542OA6m2FkvQYgfbZlQb66J0PTAl31zvYN/G2C024DDqU1wOpV hn1RYkoc0UTAse2IdP/t2mqE4me2gZ7NrjWwFSzXlGIh08T7KxHLrGtA3Mm2I3XnPHO1ppf6 xBoeGMfESeNfoR8sGWOnYyd52CKdnp7DtJ3TlGLlafnkauwHrHnHdkJb4pkKjXKavKy/DjUG yWG74jexhwARAQABwsD8BBgBCAAmAhsMFiEE38+QjbfIfo5SmSW8STHKW2yfxcsFAmTxxYsF CQs4bYcACgkQSTHKW2yfxct9DAv/YIBB1dENrLjMhh+Y11s++p2VFeP4gxawrrXc6tXRcfXj aEvubqNTG34HIUhIIFKbl7S4HGLFhcCtLdzn6nW3e/jH6Gen2InSLHyHVUpt8U0ysSKFoTpM BgP95IWYhx2I3FtKBpjSmTx/Vwdgf1D2QBBLwEWFYazuUIVY8IxwWOlfwpN56jujdSPrcxZD HGDz5gBKy9bKaoTQT6IZXHTanTi7XVJShtWJsX9pot3dPMi+5W+mTaocEc+gnPyEKI9WoQJ/ Ow5At3mQqJ1CEaRF4BXDK0bXIzOrejHDhv4n3RSrvnFlV2e+BcbfS7uj4rYRPsjZ4nffFpog CiM0Yg6RihUbZ8h6BMghOt0F07LAV3ISpaPeVsp4F6pnFedS5NgMufiBSopSJTc8wLked9E3 PlSxMeSMfi21E/eLg024Wx2c9JdKNFrYGEkgdr+w9WBA7AMKFCIQKDAwb3vPgxO3owDNC+ka AJs6m+d2kZSDzqUdFMZLrqbp0vt3GnIF8l3Y
In-Reply-To: <m1s2Rwm-0000MGC@stereo.hq.phicoh.net>
X-Mimecast-Spam-Score: 0
X-Mimecast-MFC-PROC-ID: pfXlOa5Ht6dXSG81iIKxE1Z_3S9Qb4ijUJAWWif5m4w_1731455079
X-Mimecast-Originator: redhat.com
Content-Language: en-US
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: GPUDACSC66ZVV5U5LDO6NFLOXC2BHZVJ
X-Message-ID-Hash: GPUDACSC66ZVV5U5LDO6NFLOXC2BHZVJ
X-MailFrom: pemensik@redhat.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Uvfcr3S8ySmx5bz-S_sxUhZhlgU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

I would propose not removing support for SHA1 based signatures. But 
maybe renaming the algorithm name to DEPRECATED-RSASHA1. It would 
require some change from the user and he or she could not ignore there 
is some change. But for some intentional usage, such as signing 
rootcanary.org test subdomains, it would still work.

Especially if needed for rolling algorithms in the zone, it would allow 
signing the zone as before. Remove it only after it has been long enough 
clearly marked deprecated, minimally in a new minor version.

On 02/05/2024 10:37, Philip Homburg wrote:
> In your letter dated Thu, 2 May 2024 10:27:17 +0200 you wrote:
>> I'm not following what breaks based on the wording I suggested, and I'm not su
>> re why you keep bringing that up. :-)
> Let's say I sign my zones using some scripts and ldns-signzone. This
> has been working for years so is now on autopilot.
>
> Then an RFC gets published that signers MUST NOT support signing using SHA1,
> so ldns removes those algorithms. Then a software update brings the new
> version of ldns my system. Now an unsigned zone gets deployed, and the whole
> zone is considered bogus by validators who see valid DS record but not a
> corresponding signed zone.
>
> My reading is that this is what the draft tries to do.
>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop

-- 
Petr Menšík
Software Engineer, RHEL
Red Hat, https://www.redhat.com/
PGP: DFCF908DB7C87E8E529925BC4931CA5B6C9FC5CB