Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt

Davey Song <songlinjian@gmail.com> Fri, 27 July 2018 03:00 UTC

Return-Path: <songlinjian@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C796112785F for <dnsop@ietfa.amsl.com>; Thu, 26 Jul 2018 20:00:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I8u38UO_Hx0P for <dnsop@ietfa.amsl.com>; Thu, 26 Jul 2018 20:00:08 -0700 (PDT)
Received: from mail-ua0-x229.google.com (mail-ua0-x229.google.com [IPv6:2607:f8b0:400c:c08::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E699A130DFA for <dnsop@ietf.org>; Thu, 26 Jul 2018 20:00:06 -0700 (PDT)
Received: by mail-ua0-x229.google.com with SMTP id q12-v6so2463745ual.2 for <dnsop@ietf.org>; Thu, 26 Jul 2018 20:00:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=pI9SB9ufCWrg5MESXbHbW/H9GXmfBQfpedD4x6m1pxk=; b=D33Ytenwi2hDvV7pZQQdJPoJBDnNS0Dt6zAMbhjz8cKJuccp/+RTYGMr+zrfZ+Y8tG M83bCdFGgnbIGZufKuFlZ8EvaGIk4UO+LkQcULwx5TBI8Xe8970ish17KJtpzy9XKcR/ wI9W4o5rgxshJE6N1MdZyPs5hRo11MHLPYJ/YsYbRiPOCB88k3Nwt/0Mf9H/FquhzPW9 0mMB4A6KGEv1NY2AiwgMryjyMXVkYnLt/iuOEOzDNJKZEaqVZCxOy7EnZzSGQqmVGlnd rCDEuJEuO9pJ4t+WHB00M0fPeg5cMDVgertypMVTopUlBg7tFrIm1nMkn7H0bTwAET72 xR+w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=pI9SB9ufCWrg5MESXbHbW/H9GXmfBQfpedD4x6m1pxk=; b=SnrmjTnzM+s4HPPjRBPcVFyVozkHcHePhczdjCNlOqdd+opE/Oy7NOZPvalF89yvwS KTGp1xkOgE/yPcaO3IROSsNY+zzSYE6Xh2fj52V9YPBuY1c/DGaRQ2xmRQvLd7oLgjKq RHhOWM8honaONik2SMU/5uZhZUCx2MeXNHf6314VGHG05somqvRt+S/DTJ2Z7VpPOzSL FcWY32J2UH+5t4l9fyUzkiOUg5NngbLU+oUMRYW/taD3FBYp+QvnvhRmXPimURM73/lv G5eCHI/374gqShtMgYH2347HM88UaBasS6epWVOWwTx2WbtsEp51/KHNM+PinmT4qt1Q 2fXA==
X-Gm-Message-State: AOUpUlFLz8oP1pps3JqHUid+dkoGnuRTVd19R/oDrR722aNdT6oG3Q5w jh8KyDoWSiJYZr99wSdYfVgPJPbyONc2BknJWD0=
X-Google-Smtp-Source: AAOMgpdKjb+cNv6slyV+IfK20+yalfmRhle61HrplXcjSVy/Id4ZMz1TIoSlwkLjpDhllwIRiD00t1gAb9Lb1c4nqhs=
X-Received: by 2002:ab0:59c2:: with SMTP id k2-v6mr3250193uad.124.1532660405791; Thu, 26 Jul 2018 20:00:05 -0700 (PDT)
MIME-Version: 1.0
References: <4DCC5A51-1AB0-47B6-92B5-79B6894F9A9C@verisign.com> <CAJE_bqcELQbQeHPvvEBHOxpRyWYL76BmT_-G4jW4pTnUUXFMUw@mail.gmail.com> <CAAObRXL2LoB3f=296ZPE1Pp1nHkG---pRPAmyO1trTROxneHDQ@mail.gmail.com> <FF0A0A24-705F-46E3-BF31-314078636EE2@isc.org>
In-Reply-To: <FF0A0A24-705F-46E3-BF31-314078636EE2@isc.org>
From: Davey Song <songlinjian@gmail.com>
Date: Fri, 27 Jul 2018 10:59:53 +0800
Message-ID: <CAAObRXLjnOeaGZyHhvxH3xPwGBp=zxx6AjLSSm=CXR33NM-LjA@mail.gmail.com>
To: Mark Andrews <marka@isc.org>
Cc: 神明達哉 <jinmei@wide.ad.jp>, dnsop <dnsop@ietf.org>, mweinberg=40verisign.com@dmarc.ietf.org
Content-Type: multipart/alternative; boundary="0000000000000c70850571f24fc2"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/cVqqRYjNmax7AtcqOx4ELDyBpRM>
Subject: Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Jul 2018 03:00:10 -0000

>
> The problem is that when you have every recursive server in the world with
> a copy of the root zone from “random places” you want to reduce the
> possible error spaces into manageable chunks when things go wrong which
> they will.  Being able to verify the contents of the root zone you have are
> not modified helps.
>

Generaly speaking it is ture for any file replication. But it is not
relevent with DNS context. And your arguement of potential privacy issues
seems reasonable to me even though I know some cases people intentionaly
edit the NS and glue of root zone for preventing privacy leaks :p

Davey