[DNSOP] Re: SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05

mohamed.boucadair@orange.com Wed, 13 May 2026 07:09 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A471CED8FD90; Wed, 13 May 2026 00:09:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778656155; bh=25mTXpCwezcChEL7SiR2D3p6Z15AvajFrPNw6wSFz7Y=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=Y2tgOw0lC23SXZhCT7M6QDDBBXxQIw6L93raWFN8vQw6RMAEqH/sl1dKhgzH27bNP 2J6RQMQ6tSI+nGijDo49QtsLRe3BqDS+wPVkM41fV3VX4+3ytwYAyWQrgLiHYBj7BX GoOFv2b/9Fn206MwnkeVkkT6wc7f8OsqmHYG/bpc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.794
X-Spam-Level:
X-Spam-Status: No, score=-2.794 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PENq9p6wWwzS; Wed, 13 May 2026 00:09:14 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.126.236]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CFFA0ED8FD80; Wed, 13 May 2026 00:09:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1778656154; x=1810192154; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:from; bh=25mTXpCwezcChEL7SiR2D3p6Z15AvajFrPNw6wSFz7Y=; b=guc02TJr4wZ1RIqoo0Af6wAObtVPvGbfx+cPw3wHOoBtaLW0p/1B+Flj dsqzzn2uJqi4VrvbzEXvyfzh39JMnYz6yKmRoHBM4NPFo3YaTpKZyhoD1 Ex60cSTAW9coXOMk1FhC2EsA7iqoR/kyqHBaad4agSpacOyK+1IHrZwAe WRetLgv5ouT04925wU7BZqKPQ+MlBYPD3Rp2oON78hzjVA9F3Dv29YDor vnMLZLuSWaeR/pnO3uESMyF+q3DRearnZAiHqVWtXv+cMuHxp3U50K0Kn 8FGsrlOFr9SImlzgp2EAEFgcfnPuI8xkXEtXKYhUhYTUSdCqQJI0y6A65 w==;
X-CSE-ConnectionGUID: Rjo8EVe1QFewSCcMN7zM9A==
X-CSE-MsgGUID: NRLNM7jCTW+QXEgnntjUOw==
Received: from unknown (HELO opfedv3rlp0h.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 13 May 2026 09:09:13 +0200
Received: from unknown (HELO opzinddimail21.si.fr.intraorange) ([x.x.x.x]) by opfedv3rlp0h.nor.fr.ftgroup with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 13 May 2026 09:09:13 +0200
Received: from opzinddimail21.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id A39B41387740; Wed, 13 May 2026 09:09:06 +0200 (CEST)
Received: from opzinddimail21.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 95213138773D; Wed, 13 May 2026 09:09:06 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail21.si.fr.intraorange (Postfix) with ESMTPS; Wed, 13 May 2026 09:09:06 +0200 (CEST)
Received: from mail-francesouthazlp17010021.outbound.protection.outlook.com (HELO MRZP264CU002.outbound.protection.outlook.com) ([40.93.69.21]) by smtp-out365.orange.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 13 May 2026 09:09:06 +0200
Received: from PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:52c::5) by MR1PPF5FC210CC6.FRAP264.PROD.OUTLOOK.COM (2603:10a6:508:1::2a7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9913.11; Wed, 13 May 2026 07:09:04 +0000
Received: from PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM ([fe80::8b83:578b:5221:8deb]) by PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM ([fe80::8b83:578b:5221:8deb%4]) with mapi id 15.21.0025.012; Wed, 13 May 2026 07:09:04 +0000
From: mohamed.boucadair@orange.com
X-CSE-ConnectionGUID: IhOkJKV8QCalCnHWeGQGgA==
X-CSE-MsgGUID: wtJ5hyq/SSGK7tz2fLvgcQ==
X-TM-AS-ERS: 10.218.35.131-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
X-CSE-ConnectionGUID: enYueBlHS/uuTOxYiAyDxA==
X-CSE-MsgGUID: Nez+UNxuRuq4ALKh/5bkyQ==
IronPort-Data: A9a23:VIryYawJvE+uVrpK8lJ6t+fJxirEfRIJ4+MujC+fZmUNrF6WrkUAz DRMDWiDOf6PYmbzc9twaYrk9EwDsJPUmIVgQFdvqy00HyNBpPSeCIXCJC8cHc8zwu4v7q5Dx 59DAjUVBJlsFhcwnj/0bP656yM6jPjSLlbFILasEjhrQgN5QzsWhxtmmuoo6qZlmtHR7zml4 bsemOWBfgX+s9JIGjhMsfzb9Uo05K2aVA4w5TTSW9ga5TcyqFFFVPrzFYnpR1PkT49dGPKNR uqr5NmR4mPD8h4xPcium7D9f1diaua60d+m0yc+twCK23CulwRqukoJHKN0hXR/0l1lq+tMJ OBl7vRcf+uL0prkw4zxWzEAe8130DYvFLXveRBTuuTLp6HKnueFL/hGVCkL0YMkFulfDGd/6 PEyLBA2KQ2eu8Wm8bOSW8V8r5F2RCXrFNt3VnBI6AvrNax4Hbv+G/2Qo9hFwD03m8ZCW+7EY NYUYiZuaxKGZABTPlAQC9Q1m+LAanvXL2Ue+QnT+/txuTG7IA9ZiNABNPLQfdyDQMhZ2Eyfu 2nP8234GDkdLtWZxjfD+XWp7gPKtXqhCNtPT+PpqpaGhnW1y35QNTsGSGGmuKWQrm2+HI9VK F0tr39GQa8arxfxEoaVsweDiHLfs0URAPJfFuQ77EeGza+8ywqfHW8cZj9MdNJgs9U5LRQx2 1SFnsnBBDFzvvuSU3313ruOpD2ufCkYMWFHaSkfShNA78KmqZwviRfGUtdkFui8itndGDzsz XaNtidWr7EaltJO3Ky/+XjGji6i4J/TQWYd5wjMUUqk4x93Iom/aOSVBUPz6P9BKMOXVFCHt 3UfnNWC7OkcCYnUy3TUGL1XRfeu+uqPNyDajRh3BZ49+j+x+nmlO4dN/DV5I0QvOcEBEdP0X KPNkQ5X1YJeFn+KVuhqfr6WG/Ur5LnMBf2wA5g4ceFyjo5NmBiv0hsGWKJ992XkkUxpn7s2P 5yWasGxEXYTG6B/lWXuHr9Fi+ZtwT0iz2TOQ5y91w6gzbeVeH+ST/ECLUeKaec6qqiDpW05E uqz1ePUlH2zs8WnP0E7FLL/y3hWdhDX4riq+qRqmhareFYOJY3YI6a5LUkdl3NZc1R9zbySo i7Vtr5wzVv0n3rcLguWIntkcquHYKuTWUkTZHR2VX7xgiBLSd/2sM83KcFrFZF5r7YL5aAvE JE4lzCoXq4npsLvp25FNcGVQU0LXEjDuD9iyAL8P2FuJsU8GVShFx2NVlKHyRTixxGf7aMWy 4BMHCuCKXbfb2yO1PrrVc8=
IronPort-HdrOrdr: A9a23:cnDIpqu8DtbD/63IDFfC/z9y7skDX9V00zEX/kB9WHVpm5qj5r iTdZUgpHrJYFR4YhsdcLW7VZVoLkmxyXcY2+Ys1M6ZLW7bUQiTXeNfBOnZowEIQBeOj9K1vJ 0IG8ND4bvLY2SS5vyKgzVQfexA/DEpmprY/ts3Yx1WPGVXgwAL1XYeNjqm
X-Talos-CUID: 9a23:pIyg+m73U9M6yvZ5fdss+UglB80Pdl3mi2rNH2ioOGdAWZGFYArF
X-Talos-MUID: 9a23:cXe23Q+MQvat4uYYqF/bF5WQf+Fl8eeTLlAQq4gf5+CgFiw3Zj2enQ3iFw==
X-IronPort-AV: E=Sophos;i="6.23,232,1770591600"; d="scan'208,217";a="128153694"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=dsRlbb4ykJiMawSFuhjmDsZNASmn4KXLxNyYvJZltOVF9j7RfJwwstKJP50Y9zbq46LP205hGq8/GhEEckMF/UWnTVeI/SvTluBmGt8z4dj0SjcdEnOH6Ky1clJ2BK95mUTJUTAI4Zp+nm4X9mVPGOwS6LfBhlshwXs9lWe+ch6zkQ6D792QKJA1OMBpnRWNY7NbWNMdY7DvWMaIb/2d58pXw5kJ1iT6Tyr+k6EhoaR+i2wZ7//G/4wlzuLOSsMrZ79w2mQK6BLMiq2bwx/S9Cr34ydZ7YcQT/5XPAs261hu8FD0MyMaA63k850RYTWgnD0rUMkIoX8Er/l1cWlC0A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=CB4S3P2rGNvMLM4HGrPirrdBhq79SMXKPYdq6viOFUE=; b=HfSGyzs2tIaJKLy3plQHej+27QmlWFsLWcVlIfJXMw7RHXURPjR5S830OeoVEaLIcYVD8wpIhGBHyeuRpqA/TTNxN3k0Y2D1j6hXG6KN06aOyQ6Wx/gaUqCE+OvMrAQdBBcGs0WqLNUQ2WiZd/evvTCjIY9RFb0Vz6CynlL4SHmsRDNJ6NKo59pFgOPi/8DeT9CmWxMJOzaHTahS9311nCXMQVZ1Ss7Pe4425t/OKsgTNPboSv8vi4+EFfrbhb2VR8w4qlgHG9zoJvpx97Az67yBV6GOhOiaVzHFrsnhUO/Vnbd2QYHSWvW1Jt8sOxGs5VdLXITAjy1AKSf8+DHn1Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: Donald Eastlake <d3e3e3@gmail.com>, "dnsop@ietf.org WG" <dnsop@ietf.org>
Thread-Topic: SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05
Thread-Index: AQHc4NNZHeQjQGlsJUu3rGeZmOCADbYLjGzg
Date: Wed, 13 May 2026 07:09:04 +0000
Message-ID: <PAUP264MB6756A25263C53F9529885E6188062@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
References: <CAF4+nEGTJq-_GOAdFWiW8q-Ci7GU9giP8asn0LojZaZQZCTYXw@mail.gmail.com>
In-Reply-To: <CAF4+nEGTJq-_GOAdFWiW8q-Ci7GU9giP8asn0LojZaZQZCTYXw@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=9ffdf734-1882-40eb-a3e9-2a48db641d25;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2026-05-13T07:06:46Z;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Tag=10, 0, 1, 1;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=0;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=orange.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PAUP264MB6756:EE_|MR1PPF5FC210CC6:EE_
x-ms-office365-filtering-correlation-id: ce9ba29d-8adf-43fa-6163-08deb0be8456
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|1800799024|18002099003|22082099003|56012099003|8096899003|38070700021|11063799003;
x-microsoft-antispam-message-info: zdY7kPK1Qf+BptO12cLyjIKEvCHc1hKyMouCkcYm34FlwfjNz2D6KvfBuravJGwsNPBWY6gotBniKBk1UwvpqUL4vaEUd5dAeG6apwiVoLJZqoqCfM1My8XlxfSaPOlLGHAdNIRiUC6kjKAkAQFLpr+TZ7zskGNahb51nU+1UurUyAJP8pyOLFz9Osm2D059psEer3v++2lo9UF/UL2nKeQkBZ01Pr2gG3hXawsEDXq93XFb7zKZAPOdqKRYUZQm8AWnghN2cTFV7Ff0NCB5G4ZusiSSCA9MVOkki0we8+7GM0/yw+dlNggIKqAOe4qpvzDLELcPThJ06N89CII6v1SeH793QOtWa6cHUyiXkfPmm09UezZvLm/wo/H5PPwPrKkurTIfFSFpJ2Ymtty6BBI09v8CZEnsP/fKLjm6dXE/GJlN/n8Q05WnzKVFtsNnnSvGGHMZGYyeKIo4PRpZoW0hKvVUSE5cDD36nJyFa0hDUk/URYVxZJoQidCjAj/dTFTajhD25s5Ik/cUSp53tmGLSa/BeDlLhwYqIv9Dj3r09u91xEBEcsVsZ0iNL/6O5mk0xlJxli3okx2vn+P+2NDufNfSw1vaO/p18VGJDPNy3nS5lEMsy3Eiu6OwzzZ/Xc9pNGzMbCqNM0+mXFRXl8HAZuG44z1n8qr87YpC0eVGtZE+mkJd7H6Sb3WggC06yYFRWblns9cBsjWqUBu3r5G9eO/RducIJ2SDJnWY0IHpdQqWEWoPVbC1JWzBguVq
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(18002099003)(22082099003)(56012099003)(8096899003)(38070700021)(11063799003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: f8opLcCnxX4UqiOADYVLuTN2dhmQpxrXfUU8866d5ThKJmLTOZS7fwfqmr2tm5jcGIeTlOzKN5o3qkkgMj62yHKIQCG6NmaWOLJyZGR7OkUUvkatjOu7O8POGRQNeV1VOEKdpfp652QMf7GeaGQRFjGH+AE4dWGiOwPlprF1ZFe+zwXotw4fsHds+kPNPaEBUPkB/czCIwaWs39u8U84SnJOKeqS6Qz3QlFSzZl9AAG/G2aJIYZF6X/xCFNC2qXhIFPt6Hf/xSih9+/HIJZiPdcKELhYsffKp3kaJdHdbniMvFaPiQaCnXplY1ZvmR+8hfnfNumaG7oaB/HIiD+EtkD/0C2uM9owy/E5yKV48SZw0xugGRJA7waeT9HZ5gQEp8F3cV3z26AGwzS6wogvF4O5dj2x6mEC1CLQ+z7LSkky5mdIGg/xl4qJ7i9r8cEU/5LUTyss4ryM0Eo62xbEhIHr4YYOLH6h2/BldIhmyx69ey12vbaSuU4zyIV5TiNKrtCI/CmvdR0c1F/EFKZgvngXLpX5M3vMlj4p9DIcg/cjZjO64I8eWAIzLG7P5SADMkT91Tl9wvxakc3IH9C4Vl19oWgqGQYnHEf13DH2Jr6H2shzMpWRK56TgyB2L6uuRm9L9kNLHwVH4zsj9f3tOyDpaZT/7V+yEJG4fJOh3aKG59msXqljVj0Q0dpiZJQO4dCRa9lNjaM8mESHextvLIXkVtOwOH62nuAw5Bto2HYK47qPhnWVuS1KOQW0p/kIzrwAzim5Rfk7GqhLqqwhe31I6izim1J5YEBTxkprbKoKJ9V0Hh+19t1EvOlwhKbaDdEj3cEt+S5IY4ML0M2/svjtAKrZDIe958w6YtD6rUVLyfv1grFrNJ7+w3hi6oSKEL7YYPA37ZVLsulBDOWgjeh7QnGQ8WavjKDhy3xpWWS31keXjXEjbmNdnZTi+rvkfki68QNn/+6Xh+y3ZrsvEcGGKHuQLFAdiKFh+YvsEUQtHbkQNdSKT1Gkg5HtVYWVFIqGcwfs+92sJvhCsm0juU1oxu8Ehcq4U7Xy7RfU/LpLjyQ+xVcMe8rFI855CcIAxio/KW7/EX8LQ/PHU0rUEnKBTHezbi9hzGVfqLMLz69+CvTzOJzDbTsOCXPDACanktIG++ucN6C+tTqmeQPAO6WpScr8UCIFGKEKMv1pQGyzYcGKmIvOnEip32qfIwLwGFzS0PGlhNOGdI51wchVZgztkozrxj+SPQX3zgDj6aa8h1JoFa5DcqwchgnV3MTWfvDeFE7GfA5+AwV3oL8tNO1Y/L4JszRpxQgjGyQ6gZ2hnisMZwkrd9mHcWwCMtR6IgGOwttn5Byz/mL8vbgCmZkfM6FuO3VBt7h1zHEf7VUc6Rju2J1wafGVJyM75FyfssMop+Sk1xPd9GwoAwU0hCTRkJERG0ERfbDP+nPIE6CJtRYKpnKIali+x6oewcuaW+CYV8MACczEDnIAs8FPgqrek/Lp50RFe8Fttu1AduAYEgV+CnpvchiQ6QLwmCQPz+mO6sc+HUotfByXVjmKGpVQHoeHpZz2ibXBs2C7MlptXDmzyOpYdpMGWq1dXRdxb7Zhy0huqZt6ZVIGfmyKD8mIRKCAqIsDN+SdSQSXzDRKuG8i8k7ViabIPQ1QoaxsugYwAW97bQ5RLR7StSP6iDsHx0Z9QG/AV29dpwcdCqygraGtmlTurafyXM23r7rm9Mxw0bgMFTJ5uayw3z5xdA==
Content-Type: multipart/alternative; boundary="_000_PAUP264MB6756A25263C53F9529885E6188062PAUP264MB6756FRAP_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: cF/RpEh/nFegxTH3ZvfCoLEF8FwZ/mJk1Cau+l2AJidgRLSjr+rP4UQIAbT8MhUjpdzrRgXfI4Za1yEPWl7+oDSuohpQRUaKEMFmPDXuYTgm+Zcqdf1glh9max2zj8k/cWhTTJ7Ziv2LGdqHWiF7+MQ3q94CIkRzG/VCHWtZvzefjYCAMA0znDbSVkU9W+7xTdXJ3DKIevpU9UsoVdcvHKWql3CHW5LKwxaD8scoz6rPPgZYn8oRU4ivyU7v633Jbpzdulp8HFw2+ouiI3ViBh8BsYQV62HxMHEJuW0Rl+YgMkx8sMLlmQhLM9oB1jOYm/ZJgH0r1TBPbqJ1mUnAxg==
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: ce9ba29d-8adf-43fa-6163-08deb0be8456
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 May 2026 07:09:04.3156 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: dci1g+1ANWJiXZkrQaDxMRZaqGiqs8MR2/csr37bCE/qLi8jjGjOjyK5v2AmNZzF+okLoY0a+Udrrjy581yCg5Yc1lUS/cYx7kqS9/dBRww=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MR1PPF5FC210CC6
X-TM-AS-ERS: 10.218.35.131-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-29940.005
X-TMASE-Result: 10--43.340600-10.000000
X-TMASE-MatchedRID: CxmI61mtwh+kmOzIPyadd0EOfoWOrvuOkg40k3K8nNSUkE5/Yx+7mqQx A9genngP1Ug2VvRhaJVTMXpLOeGctAlASHYeoezr+Basxm9uZ4ef3vz+spHZTp6kzGIOnjuGm0I 5Q/LYFVqYwUcPfyF0+3CTmnujr22d7VzWdf1uCr/ww+675HNN/qn/3nyhTdZwhextWx1dUiE50Y kGzAMoodI/2mgOAPYenWVVErZH4BmFwLGqhAa9VRqkhv3OdF4D/+eqpqk2S+uQOW2niPOSabo1U ZA4Jquz+7QmOJudfuNTijz/Q8m+/S65jVeGqOLfRN+FMKVZBhHYUDvAr2Y/17mgXtxPLsXiLBX6 LSmQ/gFUR3Kkd40aqcs3O65lP++0LkXZg1jsHsqHZXNSWjgdU8ot0tGMsqGnwr6OgzsUYhqH6m2 iFisd0Kwglxty6Z/Ev8jtJ17vtiyrGsh59N+IlPSG/+sPtZVkRG14opRJMfHfUZT83lbkEB5b9Z 2ozr7niIAAZbpsm0ndWnBX+pHNnZpiU2kgoGALox5cBdU3pAf4uJ1REX4MHSchfAaDKwjQ7/+9s wuISRXT7QbuKj/gda1DnvO5cSZco5RUoF1j1rjmnV13DpXhGzeXamXCCu1YAy6/bz1VsIjFQNPE ve+5IF1bBFlamKmoZmGkOF0fx8xvzOix9zo1q2K3N9p/OFh6z8j+bxoiWAwHAA5cb5vjSv88tmN gCCDW5dRKIQyvabZkLJvGr25cc0UuXkWTSi/R3BZE3fQo7k/3rOH/F+TVqLjXwg7sFIZQriuZAg OgHpLYMPFYAn4//wAWZv/M6/wIo27w8ee4WC/Oj/hxK35Y1X0tCKdnhB58r10pknZXGJr5kvmj6 9FXvEpZ1N/CwmPL9xS3mVzWUuC1PimItaljun7cGd19dSFd
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: NULL-NULL-7-0-1
Message-ID-Hash: CANIKS6VGCCLNWJHXKZMZJD6USA2JWJN
X-Message-ID-Hash: CANIKS6VGCCLNWJHXKZMZJD6USA2JWJN
X-MailFrom: mohamed.boucadair@orange.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir <secdir@ietf.org>, "draft-ietf-dnsop-ds-automation.all@ietf.org" <draft-ietf-dnsop-ds-automation.all@ietf.org>, Last Call <last-call@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/_qM7MslkmrpVd9TV6ZPgz7UeCIc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Hi Donald,

Thank you for the review. I trust the authors will follow up soon.

Adding the WG list so that DNSOP is aware of this review.

Cheers,
Med

De : Donald Eastlake <d3e3e3@gmail.com>
Envoyé : lundi 11 mai 2026 01:18
À : iesg@ietf.org
Cc : secdir <secdir@ietf.org>; draft-ietf-dnsop-ds-automation.all@ietf.org; Last Call <last-call@ietf.org>
Objet : SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05



I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. Document editors and WG chairs should treat these comments just like any other last call comments.

The summary of the review is Ready with issues.

This Best Current Practice draft provides operational recommendations for DNSSEC DS automation. Although it concerns DNSSEC automation, this is much more of an operations BCP than a security BCP. It has an interesting structure where Sections 4, 5, 6, and 7, which are the heart of the document, each start with a number of operations questions that are addressed by that section. A copy of the recommendations in those sections is then gathered together and listed in Appendix A.

# Security

I believe there are security threats addressed by this document but it seems to mostly focus on potential operational problems of "inconsistency" and "unexpected and confusing" behavior. It might be useful to give some examples of security problems that can be caused by ignoring these recommendations or, if you are sure, to state that there are none (which I doubt). How do these recommendations interact with the compromise of various of the parties in the RRR model or with an on-path attacker?

# Minor

Section 4.2.2, last paragraph: Wouldn't there be some advantage to lowering the TTL of the old DS RRset if you did so early enough before the DS update?

Section 4.2.3, last paragraph: I found this paragraph a little hard to understand. What exactly does "Child DNS operators are held responsible for publishing contradictory information" mean? Isn't it just that when a Child DNS operator publishes contradictory information, the parent rejects it? Also, doesn't a parent always have the power to publishes whatever DS or other records it wants?

Section 5.1, point 3: Since there are specific recommendations in many other cases, can something specific be said rather than "unnecessarily frequently"? Like, for example, "a few times initially and once a day thereafter".
On the other hand, Section 5.2, next to last paragraph says "no more than twice in in a row" so maybe that is what is meant.

Section 5.2, after the numbered points: Consistent with the tone of other parts of this document, I suggest "would be justified to attempt communicating" -> "SHOULD communicate"

Section 7.1, point 1: "SHOULD" -> "MUST" ?

Section 7.2.3, 1st paragraph: I understand the basis for saying DS flapping will only occur for a limited period of time. Is that the only basis for saying it will only be a minor nuisance?

# Nits

Section 3, 2nd paragraph, first sentence. Not grammatical. Simplest change would be to delete "as" but it is also too wordy. Suggest shortening to "Recommendations in this document optimize interoperability and safety."

Section 4.1 point 1a and Appendix A.1, point 1a: "ambigious" -> "ambiguous"

Section 4.2.1, first line of last paragraph: perhaps the "may" should be "MAY".

Section 6.2.2, last line: Some superfluous waffle wording here. "It therefore appears that DS initialization and rollovers should ..." -> "DS initialization and rollovers SHOULD ..."

Section 7.1, point 5: "has declared to be performing automated" -> "has declared it performs automated"

Section 7.2.1, 1st paragraph, 2nd sentence: "the key used by for authentication" -> "the key used for authentication"

Section 7.2.2, 2nd paragraph: suggest "It is therefore advised to not follow this practice." -> "This practice is NOT RECOMMENDED."

Section 7.2.2, 4th paragraph: ends with a parenthetical where I believe the parens are not needed. Check for other cases of this in the document.

Section 11: Spell out SSAC on first use.

# .sig

Thanks,
Donald
===============================
 Donald E. Eastlake 3rd   +1-508-333-2270 (cell)
 2386 Panoramic Circle, Apopka, FL 32703 USA
 d3e3e3@gmail.com<mailto:d3e3e3@gmail.com>
____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.