[DNSOP] Terry Manderson's Discuss on draft-ietf-dnsop-maintain-ds-03: (with DISCUSS and COMMENT)

"Terry Manderson" <terry.manderson@icann.org> Wed, 31 August 2016 01:00 UTC

Return-Path: <terry.manderson@icann.org>
X-Original-To: dnsop@ietf.org
Delivered-To: dnsop@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id F0F0B12D850; Tue, 30 Aug 2016 18:00:41 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Terry Manderson <terry.manderson@icann.org>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.31.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <147260524197.23652.7741907589355573697.idtracker@ietfa.amsl.com>
Date: Tue, 30 Aug 2016 18:00:41 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/lRrGE8oyw3ZHQAiypM5uXmN-eCc>
Cc: tjw.ietf@gmail.com, draft-ietf-dnsop-maintain-ds@ietf.org, dnsop-chairs@ietf.org, dnsop@ietf.org
Subject: [DNSOP] Terry Manderson's Discuss on draft-ietf-dnsop-maintain-ds-03: (with DISCUSS and COMMENT)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Aug 2016 01:00:42 -0000

Terry Manderson has entered the following ballot position for
draft-ietf-dnsop-maintain-ds-03: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dnsop-maintain-ds/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

Thanks for writing this and I think its useful for DNSSEC adoption, my
DISCUSS is as follows.

I have a concern about changing the status of RFC7344 in this document
from informational to standards track, especially given that this
document builds on, or as I see it updates, 7344. This will surely be
raised on the telechat. Especially given I still see gaps in the larger
picture, such as:

  "In this case there is a possibility of setting up some kind of
authentication mechanism and submission mechanism
   that is outside the scope of this document.." for enabling DNSSEC via
CDS/CDNSKEY

Can you please promote the first 2 paragraphs of the security
considerations section to either the abstract or introduction. When
reading this document I had almost exactly those words echoing in my
head, and having them up front would better set the scene for why this
document should exist - since you have written them already.


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

can you please clarify:

"In many people's minds, those two operations carry
   more risk than the first one."

I read this as; 'In many people's minds, those two operations carry
   more risk than operation 2."

There are other nits in this document, but I think Stephen has already
identified them.