Return-Path: <paul.hoffman@icann.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id D6EE6BEF3DCF
	for <dnsop@mail2.ietf.org>; Thu, 26 Feb 2026 10:44:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level: 
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3,
	RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001,
	RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=icann.org
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 3NzVWDaqUf_8 for <dnsop@mail2.ietf.org>;
	Thu, 26 Feb 2026 10:44:36 -0800 (PST)
Received: from ppa2.lax.icann.org (ppa2.lax.icann.org [192.0.33.77])
	(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id 7D870BEF3DCA
	for <dnsop@ietf.org>; Thu, 26 Feb 2026 10:44:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icann.org; h=cc
	:content-id:content-transfer-encoding:content-type:date:from
	:in-reply-to:message-id:mime-version:references:subject:to; s=
	able; bh=bwOnC3y+B+Yp+rkrHxETEMuR1RObwy7cDEQgdvn+Cg0=; b=FfY8DSy
	hhz79i6XkwfJXbEl8p3J7kQjq+7Lz70TLNuSMGAjd/UW387DvIEt93x+7/6SRBxy
	1LaCTuypw/A6uN3SkqFoFIunIhrBe42s+Bs1l0slDu1Aj34AyIqZJkDwHJ8TwgUp
	fFvuuHh/OziPuisX61TeuaEGjDuYlm8jnRPmjvhB2wweSkuld/QK6lonLie2b78W
	l0bdBZyLZAc79JRQLmny/FvkTG5SGV249IhZ4BPQTsq4i5MCbX/2ntUqGnb2l6z+
	hLgl5ZzCBxs0ZGgP8P9cXJfx5MO/aSjlciQR0FBzc+QWUvH0uj3Xtgx+b4MPqzVO
	lWBYsjVhoMYuMnA==
Received: from MBX112-E2-CO-1.pexch112.icann.org (out.mail.icann.org
 [64.78.33.7])
	by ppa2.lax.icann.org (8.18.1.7/8.18.1.7) with ESMTPS id 61QIiYHX017665
	(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT);
	Thu, 26 Feb 2026 18:44:34 GMT
Received: from MBX112-W2-CO-1.pexch112.icann.org (10.226.41.128) by
 MBX112-W2-CO-2.pexch112.icann.org (10.226.41.130) with Microsoft SMTP Server
 (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
 15.2.2562.35; Thu, 26 Feb 2026 10:44:33 -0800
Received: from MBX112-W2-CO-1.pexch112.icann.org ([169.254.44.235]) by
 MBX112-W2-CO-1.pexch112.icann.org ([169.254.44.235]) with mapi id
 15.02.2562.035; Thu, 26 Feb 2026 10:44:33 -0800
From: Paul Hoffman <paul.hoffman@icann.org>
To: Wes Hardaker <wjhns1@hardakers.net>
Thread-Topic: DNSOP[Ext] actual expire time for http-based xfrs
Thread-Index: AQHcp0xJALp9OVmIG02ghodXXQcrLLWV12mA
Date: Thu, 26 Feb 2026 18:44:33 +0000
Message-ID: <920168F5-1F55-49DA-9FE2-6D41B1E73A8E@icann.org>
References: <ybla4y6lwjf.fsf@wx.hardakers.net> <m17bsdf74s.fsf@narrans.de>
 <yblfr6ol783.fsf@wx.hardakers.net> <m1jyvza6b9.fsf@narrans.de>
 <93B4FB22-BA75-4DCE-8350-44AB28BCB136@rfc1035.com>
 <CA75B08F-EA52-4282-9A40-27AC743341C7@icann.org>
 <ybla4wv8j3m.fsf@wx.hardakers.net>
In-Reply-To: <ybla4wv8j3m.fsf@wx.hardakers.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [144.125.144.255]
x-source-routing-agent: True
Content-Type: text/plain; charset="us-ascii"
Content-ID: <9E95D7AB29C8BE4E9538643D3A03F7D8@pexch112.icann.org>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=baseguard
 engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49
 definitions=2026-02-26_02,2026-02-26_01,2025-10-01_01
Message-ID-Hash: PO7K65PK76TNSGMYERO46AXHIM44T6NA
X-Message-ID-Hash: PO7K65PK76TNSGMYERO46AXHIM44T6NA
X-MailFrom: paul.hoffman@icann.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: "dnsop@ietf.org" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BDNSOP=5D_Re=3A_DNSOP=5BExt=5D_actual_expire_time_for_http-based?=
	=?utf-8?q?_xfrs?=
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/dnsop/_rwPIs8m28KAXLTUf92ahqbqAMY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On Feb 26, 2026, at 10:17, Wes Hardaker <wjhns1@hardakers.net> wrote:
>=20
> Paul Hoffman <paul.hoffman@icann.org> writes:
>=20
> Hi Paul,
>=20
>>> And looking at the signature times is definitely one of the
>>> possibilities, but I'm not sure that's the perfect solution either.
>>=20
>> I'm interested in why not
>=20
> There is no reason it won't work, other than we would need a policy
> somewhere stating that signature lengths must be X long minimum and
> LocalRoot implementations must check the end-signature time as the
> method of determining when their data is too old.

It's simpler than that: the resolver just looks at the RRSIG inception time=
 and assumes that this is when the zone was first available. If that is mor=
e than the retry timer, it retries.

> It is doable -- it's just not how we currently consider what signature
> end-times are encoding.  We can add that semantic, certainly, if we
> document it carefully in probably multiple places.

The heuristic would be based on inception times, not expiration. That is, t=
he resolver doesn't wait for the zone to expire, it refreshes while the sig=
natures are still valid.

--Paul Hoffman


