[DNSOP] Re: DNSOPMike Bishop's Discuss on draft-ietf-dnsop-cds-consistency-09: (with DISCUSS and COMMENT)

Wes Hardaker <wjhns1@hardakers.net> Mon, 01 December 2025 16:57 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1E0FB935A70F; Mon, 1 Dec 2025 08:57:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dbnoct_dU--Z; Mon, 1 Dec 2025 08:57:52 -0800 (PST)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 27211935A69D; Mon, 1 Dec 2025 08:57:32 -0800 (PST)
Received: from localhost (unknown [104.133.196.214]) by mail.hardakers.net (Postfix) with ESMTPA id 7AB2E219E9; Mon, 01 Dec 2025 08:57:30 -0800 (PST)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 7AB2E219E9
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1764608251; bh=t/NycStfNCLlmQDpkbDbjNzmtzA0R7VUOiot/bnFqIg=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=AABNOg7ugwLskiU9GaszFY5sT43IUXV6knkgNV2a/Mj+sSwKW/ol4QbmCTMNaY0Xv RxbFKFr3AGGVh5HD44lW2p/tYkrbtiYHEg6rNbZhfOlBG5QI1W0qPQ/LEOnRowG4uu WEeB3jdGHWE1OJUmNgCIv3qNeEfcvllE0XEOv4d4=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Mike Bishop <mbishop=40evequefou.be@dmarc.ietf.org>
In-Reply-To: <IA0PPF726CD7A1FF656CD69F32C242D668EDAD5A@IA0PPF726CD7A1F.namprd22.prod.outlook.com> (Mike Bishop's message of "Fri, 21 Nov 2025 21:03:14 +0000")
References: <176358377775.1349105.4302928747665329216@dt-datatracker-5bd94c585b-wk4l4> <3cdf57ab-4f7e-42db-8b90-43c6190e61d1@desec.io> <IA0PPF726CD7A1FF656CD69F32C242D668EDAD5A@IA0PPF726CD7A1F.namprd22.prod.outlook.com>
Date: Mon, 01 Dec 2025 08:57:30 -0800
Message-ID: <yblfr9u2l8l.fsf@wx.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Message-ID-Hash: SPYUGTTKD5SM6QZMVPVOD4ZBUGOOR354
X-Message-ID-Hash: SPYUGTTKD5SM6QZMVPVOD4ZBUGOOR354
X-MailFrom: wjhns1@hardakers.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Peter Thomassen <peter@desec.io>, The IESG <iesg@ietf.org>, "dnsop-chairs@ietf.org" <dnsop-chairs@ietf.org>, "dnsop@ietf.org" <dnsop@ietf.org>, "draft-ietf-dnsop-cds-consistency@ietf.org" <draft-ietf-dnsop-cds-consistency@ietf.org>, "ondrej@sury.org" <ondrej@sury.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: DNSOPMike Bishop's Discuss on draft-ietf-dnsop-cds-consistency-09: (with DISCUSS and COMMENT)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Z067b3ldk5eX7JzyW8GYBtU-_W4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Mike Bishop <mbishop=40evequefou.be@dmarc.ietf.org> writes:

> No. I noticed that the (even vague) requirement was missing for CSYNC processing (as Paul pointed out), but there
> is a non-breakage requirement defined for CDS/CDNSKEY processing in RFC 7344 Section 4.1. It simply reads:
> 
>     o  Continuity: MUST NOT break the current delegation if applied to DS
>        RRset.
> 
> My thinking was that it's reasonable to hold CSYNC to the same standard.
> 
> [MB] That's frustrating. I agree that the same standard of not breaking things should apply here, but I'd like to
> see the process spelled out in a little more detail.

Well, to some extent it becomes an implementation specific decision.  I
don't know how much we should dictate exactly what must be checked.
There are certainly many ways to implement this (Paul W. suggested one
involving putting the new records in a validating resolver cache and
then check resolution).  I suspect that there are many ways to perform
such checks, and I doubt we should specify one.

The important bit to me says that we should protect against service
downgrades.  Whether that's implemented on the registrar/registry side
using a simple "query and check the crypto works (CDS)" or "send a query
to the new NSes to verify they aren't broken (CSYNC)", that's up to
them.

Back when I was assigned the role of checking arpa changes for the IAB,
I did things manually: when a new DS was to be inserted, I verified
(with tools) that the DS did belong to a new key that I could also query
for.  This was a manual process, and I'm sure I could have been fooled
into not checking by waiting a TTL as well though.  But at least I did
some level of due diligence to ensure things wouldn't break.

TL;DR: it's right we should add a requirement that things shouldn't
break.  But it's wrong that we should specify exactly how in great
detail that requirement must be executed.  All IMHO.

-- 
Wes Hardaker
Google