[DNSOP] Re: SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05
Peter Thomassen <peter@desec.io> Tue, 19 May 2026 11:01 UTC
Return-Path: <peter@desec.io>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9D297F0A1C6A; Tue, 19 May 2026 04:01:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779188480; bh=rMly6BMf+bh+d7P6a5vqDP0cBQBOob4z1VuEskQ/F7c=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=sZsvquF8v1bz51rP/brYeEoSgpXdQXzKYuBDqnisHLQx7PhFMFi8gA5jwzjj2H2jf P4gC+2wrfLJZN5yEVS+SB9QsPDG71pykDQx7wdqn6ngW/OFnMiSS6IOQ6V4ZrrrsuG A25BvyWjL+4wLEdLWVqhK0pyDShF4IkMacS9Hosw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.8
X-Spam-Level:
X-Spam-Status: No, score=-2.8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=desec.io
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RZBaShdegI_O; Tue, 19 May 2026 04:01:20 -0700 (PDT)
Received: from mail.a4a.de (mail.a4a.de [IPv6:2a01:4f8:10a:1d5c:8000::8]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 15310F0A1C5E; Tue, 19 May 2026 04:01:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=desec.io; s=20170825; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:From: References:Cc:To:Subject:MIME-Version:Date:Message-ID:Sender:Reply-To: Content-ID:Content-Description:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=o/k5Doj1CUF+ZU0SRaBsQQH1YgnlCBnLpFc5dL7RTns=; b=jLktzByYtk7bzPGcxaPSca+Wvp Lm58mDCdkoocdEjFvPx/WAm9fBHVUYs81+UoqguMgD6lSI/mUVCmcoe/wXplt45VL0hMGdM21agP1 39Ot+2F963/FxzLiRcgHAIj4v6Wkdl4vGSnxgxTcvyXAXbdzBqe5lCSEbAYhIkXrA4zxl0PfZHTGA Hqv9OSCxQXFYL6AXX7DDE9FYIT9G6+czafIb4TdOtcTtved653z4q1Ynjg18PXT4EjjsVTxqUPNDf ny8PrJqAXDCS2Og7rCSRQMVJFAvoFLpczEh44xfAUlsKW7mpiV6YpZC73NHZecnXpDAhVLuw13Tzk jRGxG/SA==;
Received: from [2001:9e8:16c6:2d00:c44:f4e8:577a:2626] by mail.a4a.de with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.97) (envelope-from <peter@desec.io>) id 1wPICG-0000000BsVF-2Swz; Tue, 19 May 2026 13:01:12 +0200
Message-ID: <c4d54112-7cef-47d8-97ae-ecfb6732fbac@desec.io>
Date: Tue, 19 May 2026 13:01:11 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: mohamed.boucadair@orange.com, Donald Eastlake <d3e3e3@gmail.com>, Roman Danyliw <rdd@cert.org>
References: <CAF4+nEGTJq-_GOAdFWiW8q-Ci7GU9giP8asn0LojZaZQZCTYXw@mail.gmail.com> <d4b32903-8ad8-4c47-99bd-5a9236c5b039@desec.io> <CAF4+nEHVs8vA3XXNhDXsOiPR9SAOdptWJ398-PVwG_5C_nxK2Q@mail.gmail.com> <PAUP264MB6756A9E06F89F67A39D1A6AC88002@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
Content-Language: en-US, de-DE
From: Peter Thomassen <peter@desec.io>
Autocrypt: addr=peter@desec.io; keydata= xsFNBFRjVn0BEADXqtra70yxQrT4MQ9DEhN0mxG6XRAOHE6nP18mqxwSlcET7D6w+z3h4ole v0tyvUU02c2wg04X8WVfjoHnAvIa1dfUcNpB1+QmfFsw0xIJlbT1ogHkMiPQqR4ChDvE3ND/ 6YCS5+HT6hY+tfU+hpLsKw4l+u1Pg2NPVLYosET1jU84b7xhFnoicnCV3kUNltLtxLKSBAfk AXtp1AWWKJbfCr3y0qKElMriicoe5DUZfLrZK2iPcWBxh+n7KMO2g7aqx3aQqwW1+S7Sq7Is l6iSurYfIcHb4AfUy4o5nPB8kKACR6BuJmkEQ5WLuTGruWA2fcxaNpICmolMinTzW1CrIjgN PoskMYCNIZ2uWxS6LN8hBiGCRL4h9aL4wuT09SvR13oAPI1HD5ph+mH6wD37/ONBXrdjcFNb 1l/uVkHU/SwwcKDJOsX18T60Ao00fciTbFHgmKtFube0xGK/vjh461TyU+xKD8Orvyeovvxy MzCwM3UVq/dkdG2Ys/7Qy/4bUC1nJEwKlLv7ZTdtSckdoU2M6JpPX6i4KDB2YCMbwtqJ842z 8A/UuE2bL9aDimh/sF8WgPIhlxqF1STNqW1JTIbDPv8HeZnM4nyJOUWStj4uRiETQhBClPLz YWtnR+EUsfbSLy81vfupbMqRasDlt6aASobgn+K7Rb1Xs/mDnwARAQABzSBQZXRlciBUaG9t YXNzZW4gPHBldGVyQGRlc2VjLmlvPsLBeAQTAQIAIgUCVGNWfQIbIwYLCQgHAwIGFQgCCQoL BBYCAwECHgECF4AACgkQ79YUOj7yLS88Dg//SbHnFGrtaImEiM69wyj4GzWnuGk9/upCym/R RzdBALCYHU9FUFFHwusiO9A0pnO8qv/GEtqqTHrcL205a6FTivkdZmOsWuN4oo7r4HBc/taI FLLUDg2wd8q4m4387sYEqrc3olGfyRB6hrMtEWVJLXHJmpcrxAaI1F2QO4Bu7kcdTnyGFz/p ZD8XAof2TWHqJb2ux69DFhiAJeAZlV+h9QrxTedL84l4hq3x1VWsnOEFaCJiThDX920kTnhJ ijrDocgAbmQBCniPACpPHYhBhmCJxfVqgfMuLMNsukOmKxsGcGV6rO1zB5ZUhm3O/Ixk6ow3 6FDKALWihg6Z4P/cJYySMn0iqvHkO8ryT9oJKX//mKaYoF6henXDRLCcRjKwGxFQTEgX+6yc pjgvX3rlypjkPT5ho4yEc5ePkQ2gIIHhvZburm1Zr4nDPx6v8+3XUjpXBRTWQ8/0/h0rtLJe yOPwGJxcfKf/GutTCqiio0mS01mIY9c2i7JWcljlIuSEUit6CHotc5lBOm2GJwguRJG6cXPY SQecwBdcjH3RTzBOv/DN6xWAIV7BmbX/e7DSGAc60mBO1/M0ut+a6CkxRQK8TaE3B3zh1/QO nG0XvtZfIY8ZYdTrdEDSV1Pj5pof/fqhhegHRxN2qi4qIuVcrW0jsUsx10IgAynHR7qQKsvO wU0EVGNWfQEQAPBA8iPCS4ZRX8stW0WuW7579axSq/Luyik4MWDFalt68lzvUbV0f6faN15+ aV7VwMTw3rSa2tP0U8crYAAAZ5NrRHXlYms5BK9vsi1322dAvhyNRawdprP627SO+Ez/84tY xz1X3M9esbN7gpJtHP6mHW76zYpT447v6c2qlbldjobZTDb6kKSGFCIrPJz9M4jVfya+ovxe 2Ab7hn2R0CcyMHATV5g1Ry0XXaj5y3bWypActbG9nflRn3NjhHZynu+WEPDUJCO8kNVNYKOw HObNTeaLvgvU0ONB8pYJv35kDXMhZLwo5MJuJd5i54CXwpo9mECwLJT1RpJi7u98nBrWyyaH s2brG9LPCRKBKOhiHFu57H+cElh+kOvehuS7DFTzjqDwJlkQzP5Hq0G++hZxfdYocKdcdFoh RP3dtDAe+Lfiy9qzJicZ6ACbzoQIN58xj0VWAn1W7SuMErOjv84D/FiXHD2Kxtx09wQl8vH0 Nbh9UgyDBNupToM0ixT+8Ko8eBuYHR53RPxshQhFw4EMIhXiOaxNe1W2Z95QPnYhUGOMoy3I v4fxMQUHa4kZSF2qxsFB1Cxol/aBPGwkwoqUvzp23pLQtJ6youYXtLgvx3pR4L52Q5CUzHMa HvM67XWgW1KqtnvNBXN9PwtDz/a9fQX1YO4CegrXv8C9Ro+LABEBAAHCwV8EGAECAAkFAlRj Vn0CGwwACgkQ79YUOj7yLS8rXA/9EGX2QRfJS94JTdtseu7saTK9a3IKwk6E33GpfXyUVpMt sOqV756XQwULZSWoxInRQtWojA8pQxDUYrbA4MpX0Efr2Dx1xIsJ5F3JajOqViB1SbOD2m0f bxXbcoWKitsKoag2SlvNOd8rD9FcgDvrkacnaQZcZE8DyyGx0JU451tfoD/igu85NZpTDaWG 6fth7QRlxmdGWrGXRdXAP29jq1n0I1wIyF/bXlZ7MXjOSsfyPddzsnHFTvNMZKps0QXNF+hi ESg9chIeo/IFDDVu6pCtm6mftojx84rczTZiNk8r2T3TU4N8uwWtXn/nj9xd61pnxD0xkTPH zxJrCs59WSfYqj3aFNkWO3Lg0/HGnO9wHQKMXcGPsnKITHVzxCNBQtVHomNA7ds6Kt3/WJgS pU2ciICvrpvKgPNWQ0d/SeY3vYIRvDLZ12Svx6M3eXDrsgZOT5be7kGVr3t7dBOYKcRHkZUq kU1kCcgp0vetISVDOc5fkpdUkAtd5/13pIpz4ikVR3OM4Br4XMVShm6RvoP4pyA+ftCi1+bw 0UbRCrnHgnG+wtCf5nMDGVLc04vITnII+ESZqlF02a1IFj0Z2MuQK2Oszl2Nsx/LG60G1e/R pzKEXIIJgHfbwUCWtV1zQu6v9Ng5H8EqVeWcdaPUwSQMGcDg/sPa4s/OxhgrYBg=
In-Reply-To: <PAUP264MB6756A9E06F89F67A39D1A6AC88002@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Message-ID-Hash: P5WLMH6YNP2TXXP5SXT5HUDUKWY6R45O
X-Message-ID-Hash: P5WLMH6YNP2TXXP5SXT5HUDUKWY6R45O
X-MailFrom: peter@desec.io
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "iesg@ietf.org" <iesg@ietf.org>, secdir <secdir@ietf.org>, "draft-ietf-dnsop-ds-automation.all@ietf.org" <draft-ietf-dnsop-ds-automation.all@ietf.org>, Last Call <last-call@ietf.org>, "dnsop@ietf.org WG" <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: SECDIR IETF LC review of draft-ietf-dnsop-ds-automation-05
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/fKCJftrUql1Jtatp_l0rvXpjSdo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Hi Med, Donald, Roman, On 5/19/26 09:36, mohamed.boucadair@orange.com wrote: >> As below, I consider my comments to have been resolved except for >> my one comment that in Section 7.2, poiny 1, to replace "SHOULD" >> with "MUST". > > I tend to agree with Donald suggestion. That channel is needed for resilient/robust maintenance operations. OK, I've applied this change. I've used this opportunity to also address Roman's review [1], who rightly pointed out that the -07 text does not mandate anything (because everything was SHOULD), so any behavior would be compliant by the letter. Indeed, there are some defining features of DS automation without which one doesn't really have an implementation. I've scanned the document for those, and elevated them from SHOULD to MUST. I believe that this is in effect a no-op change, as claiming conformance with this RFC without these would amount to some degree of trickery ;-) The elevated requirements are (none of those are new themselves): A.1.1: Verifying consistency across authoritative nameservers and between CDS/CDNSKEY RRsets (already mandatory via RFC 9975 [in auth48]), and not breaking validation when deploying a new DS RRset A.3.1: Not suspending DS automation based on a registrar update lock alone (remains possible for other reasons) A.3.2: If registry is doing DS automation: not suspending DS automation based on a registry update lock alone (remains possible for other reasons) A.4.1: Keep some other channel for fixing DS RRsets (if child lost ability to publish CDS/CDNSKEY) A.4.3: When executing an automatic CDS/CDNSKEY "DS-delete" request, do not stop automation afterwards (but remain open to re-initialization) I've also clarified in Section 3 that conformance with this document requires to actually implement DS bootstrapping + updates under the implementation guidance of that document. I'll push a new version briefly; meanwhile, changes can be viewed at [2]. Best, Peter [1]: https://mailarchive.ietf.org/arch/msg/dnsop/4CYrv_D3GOAgdWlt6kpVAzmY9co/ [2]: https://github.com/desec-io/draft-ietf-dnsop-ds-automation/commit/3174ba4b8f0a5eb217087b8531c6b0b24414f8e5
- [DNSOP] Re: SECDIR IETF LC review of draft-ietf-d… Peter Thomassen
- [DNSOP] Re: SECDIR IETF LC review of draft-ietf-d… mohamed.boucadair
- [DNSOP] Re: SECDIR IETF LC review of draft-ietf-d… Donald Eastlake
- [DNSOP] Re: SECDIR IETF LC review of draft-ietf-d… mohamed.boucadair
- [DNSOP] Re: SECDIR IETF LC review of draft-ietf-d… Peter Thomassen