Re: [DNSOP] Question about usage of and

Joe Abley <> Tue, 13 March 2018 15:27 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 705DC127342 for <>; Tue, 13 Mar 2018 08:27:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: 0.487
X-Spam-Status: No, score=0.487 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DRUGS_ANXIETY=1.483, RDNS_NONE=0.793, T_DKIM_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: (amavisd-new); dkim=fail (1024-bit key) reason="fail (OpenSSL error: data too large for key size)"
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id g11N7bgvUFiv for <>; Tue, 13 Mar 2018 08:27:03 -0700 (PDT)
Received: from (unknown [IPv6:2001:4900:1:392::156]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 69137126C22 for <>; Tue, 13 Mar 2018 08:27:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=simple/simple; ; s=hopcount; h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date: In-Reply-To:From:Subject:Mime-Version:Content-Type:Sender:Reply-To:Content-ID :Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To: Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe :List-Post:List-Owner:List-Archive; bh=Ikb8g3AIaXBDQMDNeInl0oIxTbROPKp70fWrZabMUug=; b=rVfnMILfsXQV4XxepUmsvULnOS t9vtMM7CoU9N4XCQRhwK6Ie7wOTkjqLZNc1JA53qKjM2OT4SgxxKLnNmLGGp+nsvqqmWkBzHEjFi/ Zcvwjl14+fejWIJDbOsDCrJ+bBbrSU85GRGvgO6Cf+5m2wCSPHDSwMiHrvVOn6GAcvnfEPTu1OAzu oGF+9xyDNVnHih7S1MUlm0Kw9j/9oKfG2Zo76On9uHyECN5ufRS2W/wJUyOlIgnqStZvIBXl8wh0f 0BX22bz66sacsvCuY+n381X4quHgQcveckOJ9yrJBBiy5JXZDtDcRruJfb0bPwV3n7GD0Eiu3G/vg tU0gUWRQ==;
Received: from [] (helo=[]) by with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.89 (FreeBSD)) (envelope-from <>) id 1evlpN-0009Ki-C6; Tue, 13 Mar 2018 15:27:01 +0000
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Joe Abley <>
In-Reply-To: <>
Date: Tue, 13 Mar 2018 11:27:00 -0400
Cc: Roland Bracewell Shoemaker <>,
Content-Transfer-Encoding: quoted-printable
Message-Id: <>
References: <> <> <>
To: Ted Lemon <>
X-Mailer: Apple Mail (2.3445.5.20)
X-SA-Exim-Scanned: No (on; SAEximRunCond expanded to false
Archived-At: <>
Subject: Re: [DNSOP] Question about usage of and
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 13 Mar 2018 15:27:04 -0000

On 13 Mar 2018, at 11:22, Ted Lemon <> wrote:

> On Mar 13, 2018, at 11:16 AM, Joe Abley <> wrote:
>> I think that if Tony can be, surely I can be
>> A zone is a zone. ARPA is only special by convention, not by protocol.
> Yup.
> Thinking through the threat model here, when would this even work?

The canonical service that is difficult to use (or at least bootstrap) by name rather than address is the DNS. If we imagine the intersection of the DNS and TLS to be non-zero, there's your use case. This was Paul's point.

DNS resolvers are normally referred to by address. This does imply a need for address stability, and a lack of the kind of agility that is possible in other services. People who have renumbered popular resolvers whose failure has real end-user impact are nodding right now. And possibly checking their pockets for valium.