Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost

Joe Abley <jabley@strandkip.nl> Mon, 29 April 2024 06:34 UTC

Return-Path: <jabley@strandkip.nl>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2B337C15152D for <dnsop@ietfa.amsl.com>; Sun, 28 Apr 2024 23:34:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=strandkip.nl
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pkItaDB8Kmww for <dnsop@ietfa.amsl.com>; Sun, 28 Apr 2024 23:34:14 -0700 (PDT)
Received: from qs51p00im-qukt01071501.me.com (qs51p00im-qukt01071501.me.com [17.57.155.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FA14C14F5EA for <dnsop@ietf.org>; Sun, 28 Apr 2024 23:34:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=strandkip.nl; s=sig1; t=1714372453; bh=gnPMt3mGbDSL+++WNiZtTh0fK9cJdY7PqAr4YrDdldA=; h=Content-Type:Mime-Version:Subject:From:Date:Message-Id:To; b=Y4F4zowSJ8LR+19xTXboXxrIx8FRpDKCzUYhsfuOwSkA/dfp/0RBvomefDu8e/f/9 60lDYF0C2tGyYTt2++lR+ghZx53foKcGE1iS0TKgsTtF5x5Ri3+n0xQHCDBSuP6DdJ U8z4lwS6fv3UIAWGBYuaT2pqFpP2lzrJEmew+vEQ6p7VBpwBIhNnS0VUtQJ457Qpz5 iFyn8PfKZXU2+DlKH6ZyHcQ4SEkeJI1qIVnctC/uOOxql2mlzi/hzd0X/d+G9ZLNp+ gcUV3sphSCT9ErUDAJGDEQLut4FWdl0jDHtBB2WtZCXXim+0wD8PU5wkSXQ6+dkctR vnKDkOtf6LACA==
Received: from smtpclient.apple (qs51p00im-dlb-asmtp-mailmevip.me.com [17.57.155.28]) by qs51p00im-qukt01071501.me.com (Postfix) with ESMTPSA id 147961C401C0; Mon, 29 Apr 2024 06:34:11 +0000 (UTC)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (1.0)
From: Joe Abley <jabley@strandkip.nl>
In-Reply-To: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org>
Cc: dnsop <dnsop@ietf.org>
Date: Mon, 29 Apr 2024 08:33:57 +0200
Message-Id: <67B93EF4-6B70-402E-9D78-1A079538CA18@strandkip.nl>
References: <D95A2D1F-1203-4434-B643-DDFB5C24A161@icann.org>
To: Paul Hoffman <paul.hoffman@icann.org>
X-Mailer: iPhone Mail (21E236)
X-Proofpoint-ORIG-GUID: EShNrg2cZgro-w6AreoQyF9lseItGp-4
X-Proofpoint-GUID: EShNrg2cZgro-w6AreoQyF9lseItGp-4
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.650,FMLib:17.11.176.26 definitions=2024-04-29_04,2024-04-26_02,2023-05-22_02
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 clxscore=1030 mlxlogscore=843 phishscore=0 bulkscore=0 malwarescore=0 spamscore=0 adultscore=0 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2308100000 definitions=main-2404290042
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/bY_gHfJL1oUL6lzgFHOlp2d-rKE>
Subject: Re: [DNSOP] [Ext] Call for Adoption: draft-hardaker-dnsop-rfc8624-bis, must-not-sha1, must-not-ecc-gost
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Apr 2024 06:34:18 -0000

On 29 Apr 2024, at 00:19, Paul Hoffman <paul.hoffman@icann.org> wrote:

> On Apr 27, 2024, at 17:38, Tim Wicinski <tjw.ietf@gmail.com> wrote:
>> Please review these drafts to see if you think they are suitable for adoption
>> by DNSOP, and send any comments to the list, clearly stating your view.
> 
> The WG already has many important DNSSEC-related documents that are not getting enough attention from WG participants. Each of those documents would have much more significant effects on the security of the DNS than these proposed documents. The WG should not adopt these proposed documents until the more important documents have been standardized.

I don't find the security value in these documents as easy to assess as you do. I think in general this is a difficult thing to determine and often only possible with the benefit of hindsight. 

I also don't think that simple, procedural documents that are straightforwardly-written and uncontentious ought to present a big drain on the resources of the working group. I think if we all tried really hard not to nitpick or to play amateur copy-editors we could probably last-call simple documents quite quickly and move on with our lives. 

There are costs outside the working group (write-ups, IESG telechat time, etc) but while we obviously don't want to dos the wider collective it's not obvious to me that we should make it our job to manage those resources. If we want to say something, we should say something.

To put it another way, if it's so hard to publish a document like must-not-sha1 that the best way to win is not to play, we are doing it wrong.


Joe