Re: [DNSOP] I-D Action: draft-wessels-dns-zone-digest-04.txt

"Wessels, Duane" <dwessels@verisign.com> Wed, 24 October 2018 09:49 UTC

Return-Path: <dwessels@verisign.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 52303130E70 for <dnsop@ietfa.amsl.com>; Wed, 24 Oct 2018 02:49:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EnzuuXVrtJyp for <dnsop@ietfa.amsl.com>; Wed, 24 Oct 2018 02:49:16 -0700 (PDT)
Received: from mail5.verisign.com (mail5.verisign.com [69.58.187.31]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 392A3130DC4 for <dnsop@ietf.org>; Wed, 24 Oct 2018 02:49:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=5445; q=dns/txt; s=VRSN; t=1540374556; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=sU4ct49V6ef2yngnUuTWtji7ZY1P4plJZjEVDTkxz00=; b=Y7Bm+upq4bnYcQYOR8YREVPeRRGDW100NsV7+VXuX0QI/Auu89kZtdH5 FJcTavn/GqPa0m79Zv4h0iUKUZaOZJruYy6z+rfkEuU4Sged0VyAI65nj zVZKKUe/TUwj+IonzHJS69aorrM8HSKooJxc0AGkD93EoZFKMANixXh9u D8zm+EhJa21OXpMZTFIHadmOGFcoIDnL/nH3fnAxdrPHl0dEcaEve9eKc 33XH9miH1GspG1iSq+qzMZ+8rw7YhgDFTtvkZVQcD45cnvVB63SQy2MCl TAGLW+lgS9uPnN5JYRrHeFtzOm0Bp4n9lvSnAUHpSTROjzX8EJ+Ejj/YK w==;
X-IronPort-AV: E=Sophos; i="5.54,420,1534824000"; d="p7s'?scan'208"; a="5898203"
IronPort-PHdr: 9a23:uyeqyxK7pZgou7NLJ9mcpTZWNBhigK39O0sv0rFitYgfK/XxwZ3uMQTl6Ol3ixeRBMOHs60C07KempujcFRI2YyGvnEGfc4EfD4+ouJSoTYdBtWYA1bwNv/gYn9yNs1DUFh44yPzahANS47xaFLIv3K98yMZFAnhOgppPOT1HZPZg9iq2+yo9JDffwdFiCChbb9uMR67sRjfus4KjIV4N60/0AHJonxGe+RXwWNnO1eelAvi68mz4ZBu7T1et+ou+MBcX6r6eb84TaFDAzQ9L281/szrugLdQgaJ+3ART38ZkhtMAwjC8RH6QpL8uTb0u+ZhxCWXO9D9QKsqUjq+8ahkVB7oiD8GNzEn9mHXltdwh79frB64uhBz35LYbISTOfFjfK3SYMkaSHJBUMhPSiJBHo2yYYgBD+UDPOZXs4byqkABrReiAAmhHv/jxiNWinLwwKY00/4hEQbD3AE4Ed4BsGrbrM7uNKgMVeC117HExijNYfNLwzj97pbHfh48qvyLQL1xf9TeyVI0FwzbilWQspfoPy2L2eQXsmib9OtgVe2pi2I9tw5xpT2vy94qh4LUhYwV0kjJ+ThlzIovONG1SkB2bcS5HJZQuSyWLYR7T8c6T211pCo20KAKtJyncCQQ1ZgqyB3SZ+aaf4WL+h7jWvieLDRkiH9gfb+wnRW//Ey7xeD5WMS4zktFoytAn9bXsn0A1h7e582JR/Zz/EquxDCC3B3J5O5eO0A7j6/bJoYkwr43i5Ucr1zOHjTzmEXqlK+WcVgk+vSw5+TnfLrmopicOpdphw/iKqoih8ywD/w3PAcPQ2SX5/6w1KP/8k3+WrVKluc6nbPEv5zAO8QbvLW5AwlP3ok/7Ba/Ci+q0NUenXYZMFJIYA+Lg5TzN13TIv31A+2zj0msnTpl3fzLMbnsDo3ILnfZkbfhebh961RbyAo21d1Q+pxVBa8aIPLoREDxsMfYAwQnMwOq2ebnCc591oIRWWKJGKOWLKTSsVqQ6uI1P+aMfJMVuCr6K/U9/f7ujWU2mUUafamtwJQYdmu1HuljI0WYfXXsgs0NHnkXsQojVObqkkGNUSZPZ3auWKIx/iw0CIS9DYfEXoCgm72B0zmnHp1YfGxGDUqMEXi7P7mDDt0LYmqyK9VmljBMAaKhQpUm0R2jnBL/yrFnaOfY53tLm4jk0Y0/2ODIjhw27ng8I9mU1WzHBzV4gW4TXDIyx4hhrFZ80VaM1+5zhPkORo8b3O9ATgpvbc2U9Od9Ed2nH1uZJto=
X-IPAS-Result: A2EfAgCOP9Bb/zGZrQpjDg4BAQEEAQEHBAEBgWWEEgqaAyWZEggEAYF3gnUCgyw4FgEDAQEBAQEBAgEBAoERgjYkAYJgAQEBAQIBeQULAgEIDgouAjAlAgQOBQ6DEwGBeakAhTuEWw+CbYkMgUI+gREnDBOCTIRog0qCJgKeYAMGAoQQgW+LDpA3llECBAIEBQIUgVqBd3AVZQGCQZAdOm+LI4EfAQE
Received: from BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) by BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1531.3; Wed, 24 Oct 2018 05:49:12 -0400
Received: from BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d]) by BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d%5]) with mapi id 15.01.1531.003; Wed, 24 Oct 2018 05:49:12 -0400
From: "Wessels, Duane" <dwessels@verisign.com>
To: Bob Harold <rharolde@umich.edu>
CC: IETF DNSOP WG <dnsop@ietf.org>
Thread-Topic: [EXTERNAL] [DNSOP] I-D Action: draft-wessels-dns-zone-digest-04.txt
Thread-Index: AQHUa37RINg+tPut9EaSOUuIPZ5GIQ==
Date: Wed, 24 Oct 2018 09:49:12 +0000
Message-ID: <601062EA-8853-47D9-B535-F71F25C80033@verisign.com>
References: <154020795105.15126.7681204022160033203@ietfa.amsl.com> <CA+nkc8CR3KL0EVfkWF2U1coRh+chhNxjGWNevOG++BAt0YDwXw@mail.gmail.com>
In-Reply-To: <CA+nkc8CR3KL0EVfkWF2U1coRh+chhNxjGWNevOG++BAt0YDwXw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: multipart/signed; boundary="Apple-Mail=_5A86792D-960B-4B8D-AC3A-3ADACC0CCF5F"; protocol="application/pkcs7-signature"; micalg="sha1"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/_KNjkGVnS1LWahE6XnqfWKteiSI>
Subject: Re: [DNSOP] I-D Action: draft-wessels-dns-zone-digest-04.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Oct 2018 09:49:18 -0000


> On Oct 22, 2018, at 6:53 PM, Bob Harold <rharolde@umich.edu> wrote:
> 
> Just my opinions:
> 
> Keep the Reserved field
> 
> Include occluded data - it is part of the zone, even if never served.  (Similar to glue data when a server has both a parent and child zone.)
> 
> If you might have multiple zonemd records not at the apex later, why not allow them now?  Otherwise, your choice whether to restrict them.  (Someone will find a use for them, like verifying glue records.  Everyone else can ignore them.)
> 

Thanks for the feedback, Bob.

My thought about non-apex ZONEMD records is that ZONEMD has some similarities to SOA.  They both say something about the zone has a whole, and I know some software at least rejects zones with a non-apex SOA record.  OTOH, I don't want to make things unnecessarily complex...

DW