Re: [DNSOP] Simplified Updates of DNS Security Trust Anchors, for rolling the root key
manning <bmanning@karoshi.com> Mon, 29 June 2015 23:04 UTC
Return-Path: <bmanning@karoshi.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D2F71B2E26 for <dnsop@ietfa.amsl.com>; Mon, 29 Jun 2015 16:04:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.81
X-Spam-Level:
X-Spam-Status: No, score=-2.81 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R81IKHIhT6hi for <dnsop@ietfa.amsl.com>; Mon, 29 Jun 2015 16:04:48 -0700 (PDT)
Received: from vacation.karoshi.com (vacation.karoshi.com [198.32.6.68]) by ietfa.amsl.com (Postfix) with ESMTP id 0C2191B2E51 for <dnsop@ietf.org>; Mon, 29 Jun 2015 16:04:46 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by vacation.karoshi.com (Postfix) with ESMTP id 09B039FD0B2; Mon, 29 Jun 2015 16:04:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at karoshi.com
Received: from vacation.karoshi.com ([127.0.0.1]) by localhost (vacation.karoshi.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YvvDRRe0VxF0; Mon, 29 Jun 2015 16:04:40 -0700 (PDT)
Received: from [192.168.0.12] (cpe-23-240-123-116.socal.res.rr.com [23.240.123.116]) by vacation.karoshi.com (Postfix) with ESMTPSA id 768279FD08B; Mon, 29 Jun 2015 16:04:21 -0700 (PDT)
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: text/plain; charset="us-ascii"
From: manning <bmanning@karoshi.com>
In-Reply-To: <FBEB0A0C-C749-4B40-AA63-271E6B073A4B@fl1ger.de>
Date: Mon, 29 Jun 2015 16:04:17 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <73D482C3-01FD-4309-AF1C-A6226D1D40F9@karoshi.com>
References: <CAHw9_iKmhA+f8QyuLkWeXQDfwprydVaGkR+LVJACGtsTB0+Pfw@mail.gmail.com> <FBEB0A0C-C749-4B40-AA63-271E6B073A4B@fl1ger.de>
To: Warren Kumari <warren@kumari.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/aRjYLWOEAZ-RyjrhDYKnw-8t9XI>
Cc: dnsop <dnsop@ietf.org>
Subject: Re: [DNSOP] Simplified Updates of DNS Security Trust Anchors, for rolling the root key
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Jun 2015 23:04:58 -0000
This looks very much like the draft that Olaf, Johan, and I wrote at the same time MSJ was proposing what we have now. You might want to talk to either Olaf or Johan for more details. And yes, this will fail if any of the loopback drafts are deployed. manning bmanning@karoshi.com PO Box 12317 Marina del Rey, CA 90295 310.322.8102 On 29June2015Monday, at 14:59, Ralf Weber <dns@fl1ger.de> wrote: > Moin! > > On 29 Jun 2015, at 22:48, Warren Kumari wrote: >> I've written a draft that proposes a different way of performing root >> key rollover that exposes who all has which key - this allows one to >> know that 99.8% of resolvers have the new key, who has the old one, >> and who will break. >> It does this by encoding the current set of TAs that the resolver has >> into a query, and using that to fetch the new keys. By watching >> queries at the root one can see the population of people with each TA, >> and watch that change over time. This was written for root key roll, >> but is applicable to any TA in the tree. > So while this might work with future root key rollovers, I think it's to late for this one, as it requires all software (root servers and validating resolvers) to be updated, and one concern that we have with the root key rollover is old software. > > On another note, how does that interact with the root loopback draft, where the resolver doesn't ask the root at all, but the local copy of the root zone? > > So long > -Ralf > > _______________________________________________ > DNSOP mailing list > DNSOP@ietf.org > https://www.ietf.org/mailman/listinfo/dnsop
- [DNSOP] Simplified Updates of DNS Security Trust … Warren Kumari
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Ralf Weber
- Re: [DNSOP] Simplified Updates of DNS Security Tr… manning
- Re: [DNSOP] Simplified Updates of DNS Security Tr… David Conrad
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Olafur Gudmundsson
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Warren Kumari
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Warren Kumari
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Paul Vixie
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Olafur Gudmundsson
- Re: [DNSOP] Simplified Updates of DNS Security Tr… manning
- Re: [DNSOP] Simplified Updates of DNS Security Tr… David Conrad
- Re: [DNSOP] Simplified Updates of DNS Security Tr… manning
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Tony Finch
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Olafur Gudmundsson
- Re: [DNSOP] Simplified Updates of DNS Security Tr… John Dickinson
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Tony Finch
- Re: [DNSOP] Simplified Updates of DNS Security Tr… manning
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Tony Finch
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Edward Lewis
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Warren Kumari
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Warren Kumari
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Paul Wouters
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Tony Finch
- Re: [DNSOP] Simplified Updates of DNS Security Tr… Bob Harold