Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt

Joe Abley <jabley@hopcount.ca> Mon, 09 July 2018 01:27 UTC

Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 37B27130EBC for <dnsop@ietfa.amsl.com>; Sun, 8 Jul 2018 18:27:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=hopcount.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ypmekGU7zuzX for <dnsop@ietfa.amsl.com>; Sun, 8 Jul 2018 18:27:31 -0700 (PDT)
Received: from mail-lj1-x235.google.com (mail-lj1-x235.google.com [IPv6:2a00:1450:4864:20::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ABBD3130EEA for <dnsop@ietf.org>; Sun, 8 Jul 2018 18:27:30 -0700 (PDT)
Received: by mail-lj1-x235.google.com with SMTP id p10-v6so7423234ljg.2 for <dnsop@ietf.org>; Sun, 08 Jul 2018 18:27:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hopcount.ca; s=google; h=from:mime-version:references:in-reply-to:date:message-id:subject:to :cc; bh=i9OAS0bXhvd+joFGb/tvbzlBQelhd3U4XYt24vHKWbA=; b=AMxnHs4B33tQzP0kueDGNp8z10mQpTorAAJHtTe5/zqaszysUht1Zab+R/nFtBerKe 4OUWl+Dk8IV1wVnB02DLscGDSpiUAjhLe5JCUKR3Ha7p1mZWn4tLfKqua8M4567recJv S/YakPN/OE7cCt2xYRb9HHyNxi+VPj5WD8JlI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:references:in-reply-to:date :message-id:subject:to:cc; bh=i9OAS0bXhvd+joFGb/tvbzlBQelhd3U4XYt24vHKWbA=; b=MLND/KImgQ2myd2SMoCOC4VNWYiW7N2DQcdt0OGGwjX+Ct6FV2ML1DaKD7EmSs94K3 /t9+kss5AoxdDXgghk9b2TJtpCXUGtXVnkQVeEYnC0dCugM9SPNN7Ib0mmq+BXwRZEUs lWRGhIe2qP57eaAfxFfjaQvPrCN+x/xHes5nVpzaK+6rLIqsZxVbJXF+AN7yJ+ZrP3Cp UpCEewsHxefT1Dke0Wz037h6AmzUPE1qAGTFQk0eJdjjc6+58ZNLyA4dGgAiDpcbga20 +SApjliiyDl8dpKJx1yMpRCh+GqhJAuFRUR2Lji2bqOkS6BklKX8Vs6OK+vx9GyaE8aX acqw==
X-Gm-Message-State: APt69E0ma3QdbQMFY5BErSzuqqZLYwa/+KybHKxmHtY4kpF/k2rbFPpL RBhrXz7+sf0/b0P7Zvrcr5ytiXxdsVjgbaq46VnQmw==
X-Google-Smtp-Source: AAOMgpcu0NM2YZNwnaEcc9uVG8Mtr2Z9Ek5X/n08vdoVhkWjZZ4VQ6YmdMlQiTft6Gi5gci3/rV4N4U4/AD9IeWfljU=
X-Received: by 2002:a2e:205b:: with SMTP id g88-v6mr11847027ljg.39.1531099648790; Sun, 08 Jul 2018 18:27:28 -0700 (PDT)
Received: from unknown named unknown by gmailapi.google.com with HTTPREST; Sun, 8 Jul 2018 18:27:28 -0700
From: Joe Abley <jabley@hopcount.ca>
Mime-Version: 1.0 (1.0)
References: <4DCC5A51-1AB0-47B6-92B5-79B6894F9A9C@verisign.com> <CAJE_bqcELQbQeHPvvEBHOxpRyWYL76BmT_-G4jW4pTnUUXFMUw@mail.gmail.com> <27C44216-581A-4991-A739-ECE8B7F8AA35@verisign.com> <884c2d11-9db0-7668-59c9-baa8574a03f7@time-travellers.org> <37873808-8354-b26b-34f4-880ea7a5f0da@nic.cz> <e9f99fce-c240-7f23-c580-1fb8bd0a0687@time-travellers.org> <20180621203116.a7kv4ysotfe7kw5k@nic.cl> <3ba53c28-8895-b0ec-badc-7ce31a8df8fc@nic.cz> <C027F687-BE37-42D4-959B-269BA2F49837@ogud.com> <CAKr6gn0BZgKGExweF2Hawh_shZSD+WxJ460YO-mbRQjg09uo_A@mail.gmail.com>
In-Reply-To: <CAKr6gn0BZgKGExweF2Hawh_shZSD+WxJ460YO-mbRQjg09uo_A@mail.gmail.com>
Date: Sun, 08 Jul 2018 18:27:27 -0700
Message-ID: <CAJhMdTNYEKcxdgqtRs-g1wE-RXbnKSpNxcBQHqn4UmbHEjGOAQ@mail.gmail.com>
To: George Michaelson <ggm@algebras.org>
Cc: Olafur Gudmundsson <ogud@ogud.com>, dnsop WG <dnsop@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/hA1Elk1Fr42dApTIEWlT1hV_zY8>
Subject: Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Jul 2018 01:27:32 -0000

On Jul 9, 2018, at 02:02, George Michaelson <ggm@algebras.org> wrote:

> wow. Firstly, I thought canonicalization was a given: we have
> definitions of canonical zone order for other reasons (NSEC*) don't
> we?

NSEC is concerned with the ordering of owner names.

RRSIG is concerned with the ordering of individual RRs in an RRSet.

Unsigned RRSets (e.g. glue, NS RRSets above a zone cut) are unordered.
You could apply the same rules (RFC4034 section 6.3) to sort them into
canonical order, but I think you could also not do that and still have
a compliant implementation of DNSSEC.


Joe