[DNSOP] Re: DNSOPMike Bishop's Discuss on draft-ietf-dnsop-cds-consistency-09: (with DISCUSS and COMMENT)
Wes Hardaker <wjhns1@hardakers.net> Mon, 01 December 2025 16:57 UTC
Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1E0FB935A70F; Mon, 1 Dec 2025 08:57:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dbnoct_dU--Z; Mon, 1 Dec 2025 08:57:52 -0800 (PST)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 27211935A69D; Mon, 1 Dec 2025 08:57:32 -0800 (PST)
Received: from localhost (unknown [104.133.196.214]) by mail.hardakers.net (Postfix) with ESMTPA id 7AB2E219E9; Mon, 01 Dec 2025 08:57:30 -0800 (PST)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 7AB2E219E9
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1764608251; bh=t/NycStfNCLlmQDpkbDbjNzmtzA0R7VUOiot/bnFqIg=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=AABNOg7ugwLskiU9GaszFY5sT43IUXV6knkgNV2a/Mj+sSwKW/ol4QbmCTMNaY0Xv RxbFKFr3AGGVh5HD44lW2p/tYkrbtiYHEg6rNbZhfOlBG5QI1W0qPQ/LEOnRowG4uu WEeB3jdGHWE1OJUmNgCIv3qNeEfcvllE0XEOv4d4=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Mike Bishop <mbishop=40evequefou.be@dmarc.ietf.org>
In-Reply-To: <IA0PPF726CD7A1FF656CD69F32C242D668EDAD5A@IA0PPF726CD7A1F.namprd22.prod.outlook.com> (Mike Bishop's message of "Fri, 21 Nov 2025 21:03:14 +0000")
References: <176358377775.1349105.4302928747665329216@dt-datatracker-5bd94c585b-wk4l4> <3cdf57ab-4f7e-42db-8b90-43c6190e61d1@desec.io> <IA0PPF726CD7A1FF656CD69F32C242D668EDAD5A@IA0PPF726CD7A1F.namprd22.prod.outlook.com>
Date: Mon, 01 Dec 2025 08:57:30 -0800
Message-ID: <yblfr9u2l8l.fsf@wx.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Message-ID-Hash: SPYUGTTKD5SM6QZMVPVOD4ZBUGOOR354
X-Message-ID-Hash: SPYUGTTKD5SM6QZMVPVOD4ZBUGOOR354
X-MailFrom: wjhns1@hardakers.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Peter Thomassen <peter@desec.io>, The IESG <iesg@ietf.org>, "dnsop-chairs@ietf.org" <dnsop-chairs@ietf.org>, "dnsop@ietf.org" <dnsop@ietf.org>, "draft-ietf-dnsop-cds-consistency@ietf.org" <draft-ietf-dnsop-cds-consistency@ietf.org>, "ondrej@sury.org" <ondrej@sury.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-ietf-dnsop-cds-consistency-09: (with DISCUSS and COMMENT)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Z067b3ldk5eX7JzyW8GYBtU-_W4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Mike Bishop <mbishop=40evequefou.be@dmarc.ietf.org> writes: > No. I noticed that the (even vague) requirement was missing for CSYNC processing (as Paul pointed out), but there > is a non-breakage requirement defined for CDS/CDNSKEY processing in RFC 7344 Section 4.1. It simply reads: > > o Continuity: MUST NOT break the current delegation if applied to DS > RRset. > > My thinking was that it's reasonable to hold CSYNC to the same standard. > > [MB] That's frustrating. I agree that the same standard of not breaking things should apply here, but I'd like to > see the process spelled out in a little more detail. Well, to some extent it becomes an implementation specific decision. I don't know how much we should dictate exactly what must be checked. There are certainly many ways to implement this (Paul W. suggested one involving putting the new records in a validating resolver cache and then check resolution). I suspect that there are many ways to perform such checks, and I doubt we should specify one. The important bit to me says that we should protect against service downgrades. Whether that's implemented on the registrar/registry side using a simple "query and check the crypto works (CDS)" or "send a query to the new NSes to verify they aren't broken (CSYNC)", that's up to them. Back when I was assigned the role of checking arpa changes for the IAB, I did things manually: when a new DS was to be inserted, I verified (with tools) that the DS did belong to a new key that I could also query for. This was a manual process, and I'm sure I could have been fooled into not checking by waiting a TTL as well though. But at least I did some level of due diligence to ensure things wouldn't break. TL;DR: it's right we should add a requirement that things shouldn't break. But it's wrong that we should specify exactly how in great detail that requirement must be executed. All IMHO. -- Wes Hardaker Google
- [DNSOP] Mike Bishop's Discuss on draft-ietf-dnsop… Mike Bishop via Datatracker
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Paul Wouters
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Peter Thomassen
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Mike Bishop
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Peter Thomassen
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Mike Bishop
- [DNSOP] Re: Mike Bishop's Discuss on draft-ietf-d… Peter Thomassen
- [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-i… Wes Hardaker
- [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-i… Peter Thomassen
- [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-i… Wes Hardaker
- [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-i… Wes Hardaker