Re: [DNSOP] I-D Action: draft-ietf-dnsop-edns-key-tag-02.txt

神明達哉 <jinmei@wide.ad.jp> Wed, 24 August 2016 18:52 UTC

Return-Path: <jinmei.tatuya@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4F6BF12D52F for <dnsop@ietfa.amsl.com>; Wed, 24 Aug 2016 11:52:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LDPqrYFZ-SJZ for <dnsop@ietfa.amsl.com>; Wed, 24 Aug 2016 11:52:56 -0700 (PDT)
Received: from mail-qk0-x22f.google.com (mail-qk0-x22f.google.com [IPv6:2607:f8b0:400d:c09::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E55B812D1A6 for <dnsop@ietf.org>; Wed, 24 Aug 2016 11:52:55 -0700 (PDT)
Received: by mail-qk0-x22f.google.com with SMTP id v123so24270312qkh.2 for <dnsop@ietf.org>; Wed, 24 Aug 2016 11:52:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=mz6LhhQU8QSVS37+qzzgcKCQoCE5ecQV8fU5/R33pes=; b=HUer8mixwtyhz8ngje5LJe8p0FKX4YzzkmiqTE/KH+uTvAG+fLWiX3hGgWG8ED/W1c OGLxDcMcnPIIBXqTTJfNRS/I74wDlJkMvHeC6OR45LBjI49qOD2vdtcxqQl8aclxRkrg PTPyWHZzeCS/mtnXczOCgRyugzbWsMJzdWVRHQljc+L3wuItkVo+26ENckv4Q5OqTuA9 nzltFtmO2xduCduPoBnrH/+p8CDgX2wpghat07hw0yS0OUOAC/fACWfmeecEY5tAsSa+ aPdISi5x28vrd8i8lkKz705Dq/X1sWCa7MWpdbEXPMZt3FexDeIGNyxssQvohC0EbgDE HkRg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=mz6LhhQU8QSVS37+qzzgcKCQoCE5ecQV8fU5/R33pes=; b=PhQYz5ch5PiF8FB7lEbIf20DxPbRuWcpuEQeI0KM/DaHF+7N6MXFJXV0D5tDpB8rTl sCX3Ebm3+Rfc1JSTdn+u8wz7vD2y2GII7Dl6PNqCeyOKMcs6DFnVgDpal4odWiPShURh rWoAyAGGl5My3F+M7qujBBgxQ5lepjM85mfcC5fF6GNnqq2VkprJgSEswmR9iSoFJUfp cn4QzjoWaX0k5PcUswGnb3Rw/482juI9jYCeTFNTf8FynLjS0yZFPIbxs0GMwrOggb45 mpt/DgFbvKP4awX7kUqwN+69gb+1HYo8dH/ZjZZUTUiGYMjkBSeh6IQ8gWoCcdV7YWMs kRjQ==
X-Gm-Message-State: AE9vXwPWn/ffHxBEsF4vC/K4Cc3rEayN6uQJU1CnXr0AnlXrH7xO4ijDRawulzsXtuF9Ifbr4QmQTblKfPiEkA==
X-Received: by 10.233.222.193 with SMTP id s184mr5285962qkf.154.1472064775017; Wed, 24 Aug 2016 11:52:55 -0700 (PDT)
MIME-Version: 1.0
Sender: jinmei.tatuya@gmail.com
Received: by 10.237.33.154 with HTTP; Wed, 24 Aug 2016 11:52:54 -0700 (PDT)
In-Reply-To: <170104B3-5A85-4DB8-BB03-09D8BED8A452@verisign.com>
References: <20160708223044.32131.72663.idtracker@ietfa.amsl.com> <8FD4B2FF-9E51-4FF3-829A-1D4D7CFAB19E@vpnc.org> <9E342C42-7649-4776-BA22-DF9F5A84654A@vpnc.org> <CAJE_bqfxADtCgk9nMBXGH5B_PxQDxdLQJN3hKUz-p+7A+GSiBQ@mail.gmail.com> <170104B3-5A85-4DB8-BB03-09D8BED8A452@verisign.com>
From: 神明達哉 <jinmei@wide.ad.jp>
Date: Wed, 24 Aug 2016 11:52:54 -0700
X-Google-Sender-Auth: vn6sZWYRKvJ2-6i9ECZZNpOzgE4
Message-ID: <CAJE_bqeego++F9-m8N3_84APkSXPcpLb2uHJgmtoH6n4mJYS8g@mail.gmail.com>
To: "Wessels, Duane" <dwessels@verisign.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Y_Ajl5wwn0xe6wYKKX-CgUmmtL8>
Cc: dnsop <dnsop@ietf.org>, Paul Hoffman <paul.hoffman@vpnc.org>
Subject: Re: [DNSOP] I-D Action: draft-ietf-dnsop-edns-key-tag-02.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2016 18:52:57 -0000

At Mon, 22 Aug 2016 21:57:12 +0000,
"Wessels, Duane" <dwessels@verisign.com> wrote:

> > - Section 5.3
> >
> >   Unless the zone operator has intentionally added
> >   "_ta-xxxx" records to the zone, the server MUST generate an NXDOMAIN
> >   response.
> >
> >  Perhaps a pedantic comment, but I suspect this is not 100% accurate
> >  in that it could legitimately result in other response than
> >  NXDOMAIN, [...]
>
> I can be convinced either to keep it or to leave it.  My rationale for
> that sentence is to state that a server should not have some built-in logic
> that determines the response to these types of queries.  The response code
> should be determined by whether or not they are in the zone file (or as you say
> covered by wildcard).

Okay, I see the point.  In that case I'd state that point more
specifically rather than through one such case of NXDOMAIN, but I'd
leave it to you.

> > - Section 5.3.1
> >
> >   When the response code for a key tag query is NXDOMAIN, DNS resolvers
> >   that implement aggressive negative caching will send fewer key tag
> >   queries than resolvers that do not implement it.
> >
> >  In the context of the interaction with nsec-aggressiveuse, I think
> >  this should be more generalized than the response to a key tag query
> >  itself, e.g.:
> >
> >   When a query results in an NXDOMAIN response with NSEC or NSEC3
> >   that covers the name of a key tag query, DNS resolvers that
> >   implement aggressive negative caching will send fewer key tag
> >   queries than resolvers that do not implement it.
>
> IMO your version adds a little unnecessary complexity to the sentence, while
> making the same point.

I don't think these two are exactly the same, but I won't insist on
the generalized text.

--
JINMEI, Tatuya