[DNSOP] Re: DNSOP[Ext] actual expire time for http-based xfrs

Paul Hoffman <paul.hoffman@icann.org> Thu, 26 February 2026 18:44 UTC

Return-Path: <paul.hoffman@icann.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D6EE6BEF3DCF for <dnsop@mail2.ietf.org>; Thu, 26 Feb 2026 10:44:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=icann.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3NzVWDaqUf_8 for <dnsop@mail2.ietf.org>; Thu, 26 Feb 2026 10:44:36 -0800 (PST)
Received: from ppa2.lax.icann.org (ppa2.lax.icann.org [192.0.33.77]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7D870BEF3DCA for <dnsop@ietf.org>; Thu, 26 Feb 2026 10:44:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icann.org; h=cc :content-id:content-transfer-encoding:content-type:date:from :in-reply-to:message-id:mime-version:references:subject:to; s= able; bh=bwOnC3y+B+Yp+rkrHxETEMuR1RObwy7cDEQgdvn+Cg0=; b=FfY8DSy hhz79i6XkwfJXbEl8p3J7kQjq+7Lz70TLNuSMGAjd/UW387DvIEt93x+7/6SRBxy 1LaCTuypw/A6uN3SkqFoFIunIhrBe42s+Bs1l0slDu1Aj34AyIqZJkDwHJ8TwgUp fFvuuHh/OziPuisX61TeuaEGjDuYlm8jnRPmjvhB2wweSkuld/QK6lonLie2b78W l0bdBZyLZAc79JRQLmny/FvkTG5SGV249IhZ4BPQTsq4i5MCbX/2ntUqGnb2l6z+ hLgl5ZzCBxs0ZGgP8P9cXJfx5MO/aSjlciQR0FBzc+QWUvH0uj3Xtgx+b4MPqzVO lWBYsjVhoMYuMnA==
Received: from MBX112-E2-CO-1.pexch112.icann.org (out.mail.icann.org [64.78.33.7]) by ppa2.lax.icann.org (8.18.1.7/8.18.1.7) with ESMTPS id 61QIiYHX017665 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 26 Feb 2026 18:44:34 GMT
Received: from MBX112-W2-CO-1.pexch112.icann.org (10.226.41.128) by MBX112-W2-CO-2.pexch112.icann.org (10.226.41.130) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.35; Thu, 26 Feb 2026 10:44:33 -0800
Received: from MBX112-W2-CO-1.pexch112.icann.org ([169.254.44.235]) by MBX112-W2-CO-1.pexch112.icann.org ([169.254.44.235]) with mapi id 15.02.2562.035; Thu, 26 Feb 2026 10:44:33 -0800
From: Paul Hoffman <paul.hoffman@icann.org>
To: Wes Hardaker <wjhns1@hardakers.net>
Thread-Topic: DNSOP[Ext] actual expire time for http-based xfrs
Thread-Index: AQHcp0xJALp9OVmIG02ghodXXQcrLLWV12mA
Date: Thu, 26 Feb 2026 18:44:33 +0000
Message-ID: <920168F5-1F55-49DA-9FE2-6D41B1E73A8E@icann.org>
References: <ybla4y6lwjf.fsf@wx.hardakers.net> <m17bsdf74s.fsf@narrans.de> <yblfr6ol783.fsf@wx.hardakers.net> <m1jyvza6b9.fsf@narrans.de> <93B4FB22-BA75-4DCE-8350-44AB28BCB136@rfc1035.com> <CA75B08F-EA52-4282-9A40-27AC743341C7@icann.org> <ybla4wv8j3m.fsf@wx.hardakers.net>
In-Reply-To: <ybla4wv8j3m.fsf@wx.hardakers.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [144.125.144.255]
x-source-routing-agent: True
Content-Type: text/plain; charset="us-ascii"
Content-ID: <9E95D7AB29C8BE4E9538643D3A03F7D8@pexch112.icann.org>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-02-26_02,2026-02-26_01,2025-10-01_01
Message-ID-Hash: PO7K65PK76TNSGMYERO46AXHIM44T6NA
X-Message-ID-Hash: PO7K65PK76TNSGMYERO46AXHIM44T6NA
X-MailFrom: paul.hoffman@icann.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "dnsop@ietf.org" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: DNSOP[Ext] actual expire time for http-based xfrs
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/_rwPIs8m28KAXLTUf92ahqbqAMY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On Feb 26, 2026, at 10:17, Wes Hardaker <wjhns1@hardakers.net> wrote:
> 
> Paul Hoffman <paul.hoffman@icann.org> writes:
> 
> Hi Paul,
> 
>>> And looking at the signature times is definitely one of the
>>> possibilities, but I'm not sure that's the perfect solution either.
>> 
>> I'm interested in why not
> 
> There is no reason it won't work, other than we would need a policy
> somewhere stating that signature lengths must be X long minimum and
> LocalRoot implementations must check the end-signature time as the
> method of determining when their data is too old.

It's simpler than that: the resolver just looks at the RRSIG inception time and assumes that this is when the zone was first available. If that is more than the retry timer, it retries.

> It is doable -- it's just not how we currently consider what signature
> end-times are encoding.  We can add that semantic, certainly, if we
> document it carefully in probably multiple places.

The heuristic would be based on inception times, not expiration. That is, the resolver doesn't wait for the zone to expire, it refreshes while the signatures are still valid.

--Paul Hoffman