[DNSOP] Re: draft-ietf-dnsop-integration text on ASCII-or-not

Andrew Sullivan <ajs@anvilwalrusden.com> Mon, 20 July 2026 20:27 UTC

Return-Path: <ajs@anvilwalrusden.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 19C6B11AC28C6 for <dnsop@mail2.ietf.org>; Mon, 20 Jul 2026 13:27:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784579271; bh=VisD6Neh218iroX45rQMzIRqZ7STBBIz0pUVPkIALFo=; h=Date:From:To:Subject:References:In-Reply-To; b=pDj47QeZULjS7q6VeAbCiVcv6N+MZa/pF2KszSAA1a0ozzxWKGpuMz4FGZMOeontQ AZvopdggC9eT8LRgNoRXLTp2zIAgKD8bPycxc838tnMK5IyY2Yy1qGOsUdn+1nUE3u wb64ScuOdlBHLciGUEtrlh879/rRyoU+jaL6v3Wc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=yitter.info header.b="JILQY8Gh"; dkim=pass (1024-bit key) header.d=yitter.info header.b="ZkT4vdlu"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d4J8nCqfM9KZ for <dnsop@mail2.ietf.org>; Mon, 20 Jul 2026 13:27:50 -0700 (PDT)
Received: from mx5.yitter.info (mx5.yitter.info [159.203.31.152]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6C35B11AC28BD for <dnsop@ietf.org>; Mon, 20 Jul 2026 13:27:50 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mx5.yitter.info (Postfix) with ESMTP id BE6ADBD52E for <dnsop@ietf.org>; Mon, 20 Jul 2026 20:27:14 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yitter.info; s=default; t=1784579234; bh=RjqwIqc5Pv05XVxR4m6KR9EekIO/pJUE6EDURb0eMKs=; h=Date:From:To:Subject:References:In-Reply-To:From; b=JILQY8GhJPGcFvSR4jjSk70aHgbMVfwXtLfzfpu4fS/HtH6L4ydqIcoTKpm+e0uYU Q3XfdZkw1ytDhPjnhfd6gws2Rk+5zdFU9brUg5Vyq8pvV0eD397UaOuIqc0NZP7Jyc ewGxWunDXvPzV6kwWf26X5AdmdJM2I/u40xnkrl4=
X-Virus-Scanned: Debian amavisd-new at crankycanuck.ca
Received: from mx5.yitter.info ([127.0.0.1]) by localhost (mx5.yitter.info [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pCu216U221fQ for <dnsop@ietf.org>; Mon, 20 Jul 2026 20:27:13 +0000 (UTC)
Date: Mon, 20 Jul 2026 16:27:09 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yitter.info; s=default; t=1784579233; bh=RjqwIqc5Pv05XVxR4m6KR9EekIO/pJUE6EDURb0eMKs=; h=Date:From:To:Subject:References:In-Reply-To:From; b=ZkT4vdluATl1BezRWRQT5wnRWQ/fg8j2jpiCN/VAbelhaCWXM2f6vTuXDyQvwCy15 j9T4Jgs5hW0nq5T8k2Ra0cEpx5t7CtIkeRO+7QtuYTXwSU7+gTLz94p0hblo/bhCkB v3+QSVid7R9HI4WQr7rY2Sa39PmWiyxyep027vC8=
From: Andrew Sullivan <ajs@anvilwalrusden.com>
To: dnsop@ietf.org
Message-ID: <al6EPN2VuUS6jv7K@crankycanuck.ca>
Mail-Followup-To: dnsop@ietf.org
References: <CAOdQrVO7jgYk6JW4oCTYCJRXmYvUGR0kNFUYq_9T4BLzCoe5nw@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Disposition: inline
In-Reply-To: <CAOdQrVO7jgYk6JW4oCTYCJRXmYvUGR0kNFUYq_9T4BLzCoe5nw@mail.gmail.com>
Message-ID-Hash: MXIHZXBE4N4HJRTKN4FHB3X74ZY77HQC
X-Message-ID-Hash: MXIHZXBE4N4HJRTKN4FHB3X74ZY77HQC
X-MailFrom: ajs@anvilwalrusden.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: draft-ietf-dnsop-integration text on ASCII-or-not
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/W2Rv8JudMLv91gNV_907ouV51Po>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On Mon, Jul 20, 2026 at 02:45:24PM -0500, Ben Schwartz wrote:
>   Domain names in wire-format should be checked for non-compliant
>characters (e.g.
>   labels containing ".", uppercase, whitespace, or non-ASCII characters) due to
>   security risks.

I'd be pretty surprised to learn that labels containing uppercase characters have wire-format labels that are not compliant.  The protocol documents explicitly say you're supposed to preserve the case but ignore it for matching purposes.

A

-- 
Andrew Sullivan
ajs@anvilwalrusden.com