[DNSOP] Re: Orie Steele's No Objection on draft-ietf-dnsop-must-not-ecc-gost-04: (with COMMENT)

Wes Hardaker <wjhns1@hardakers.net> Tue, 20 May 2025 22:45 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E4E4E2AF0073; Tue, 20 May 2025 15:45:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5RQh1GBLrgCw; Tue, 20 May 2025 15:45:31 -0700 (PDT)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C771F2AF0060; Tue, 20 May 2025 15:45:31 -0700 (PDT)
Received: from localhost (unknown [10.0.0.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.hardakers.net (Postfix) with ESMTPSA id 2C2EB23938; Tue, 20 May 2025 15:45:31 -0700 (PDT)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 2C2EB23938
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1747781131; bh=FkvHSzcqpdXBsAO5Mru9qnrIq6oZL5peaLf2MAbo298=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=M2/PgtYvbExjb07P/WK+j88HYlrI0I9623KZjHpBCAjCjuFPWlAn7RWGp1TrUcg1J Wgy5Yjw/a0ZnYMEYPjft49hKtXaIX+y0APHQy7sDoeaA2GAG78RwBvhqwnzropmX5T Hdx8zrQyAPUG4JVfWtKfO6pgalFVnXi05qy/f+0s=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Orie Steele via Datatracker <noreply@ietf.org>
In-Reply-To: <174768959548.469278.17853877136259212564@dt-datatracker-59b84fc74f-84jsl> (Orie Steele via Datatracker's message of "Mon, 19 May 2025 14:19:55 -0700")
References: <174768959548.469278.17853877136259212564@dt-datatracker-59b84fc74f-84jsl>
Date: Tue, 20 May 2025 15:45:30 -0700
Message-ID: <yblikluaol1.fsf@wd.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Message-ID-Hash: B3Y5DGE6B7KNZZPT7DRPXBZNMKGQ2UZ5
X-Message-ID-Hash: B3Y5DGE6B7KNZZPT7DRPXBZNMKGQ2UZ5
X-MailFrom: wjhns1@hardakers.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, Orie Steele <orie@or13.io>, draft-ietf-dnsop-must-not-ecc-gost@ietf.org, dnsop-chairs@ietf.org, dnsop@ietf.org, tjw.ietf@gmail.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Orie Steele's No Objection on draft-ietf-dnsop-must-not-ecc-gost-04: (with COMMENT)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/lQlrUOEKy-XDDMEJyk_fAOcMzic>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Orie Steele via Datatracker <noreply@ietf.org> writes:

Comments inline, thanks for the feedback Orie.

> Perhaps use similar text to draft-ietf-dnsop-must-not-sha1-06:
> 
> ```
> Validating resolvers deployed in more security strict environments MAY wish to
> treat these RRSIG records as an unsupported algorithm. ```

SHA1 has a bit more leniency than gost intentionally.  No one should
really use GOST (2001) at all any longer, while SHA1 still has some
deployment.  That's why the text is different.
-- 
Wes Hardaker
USC/ISI