Re: [DNSOP] Last Call: <draft-ietf-dnsop-algorithm-update-05.txt> (Algorithm Implementation Requirements and Usage Guidance for DNSSEC) to Proposed Standard

Michael Sinatra <> Tue, 05 March 2019 00:39 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id EFF0D13123B; Mon, 4 Mar 2019 16:39:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id yAaoo6x-tIBL; Mon, 4 Mar 2019 16:39:54 -0800 (PST)
Received: from ( [IPv6:2607:fc50:1:9d00::9977]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 83C3313122D; Mon, 4 Mar 2019 16:39:51 -0800 (PST)
Received: from ( [IPv6:2607:f2f8:a544:0:0:0:0:2]) by (8.15.2/8.15.2) with ESMTPS id x250djZ7019073 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Mon, 4 Mar 2019 19:39:47 -0500 (EST) (envelope-from
Received: from ( []) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by (5.65c/IDA-1.4.4/5.63) with ESMTPSA id 0350F6536A; Mon, 4 Mar 2019 16:39:46 -0800 (PST)
Cc: Tim Wicinski <>,,,
References: <>
From: Michael Sinatra <>
Message-ID: <>
Date: Mon, 4 Mar 2019 16:39:43 -0800
User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:60.0) Gecko/20100101 Thunderbird/60.5.1
MIME-Version: 1.0
In-Reply-To: <>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-4.6.2 ( [IPv6:2607:fc50:1:9d00:0:0:0:9977]); Mon, 04 Mar 2019 19:39:48 -0500 (EST)
Archived-At: <>
Subject: Re: [DNSOP] Last Call: <draft-ietf-dnsop-algorithm-update-05.txt> (Algorithm Implementation Requirements and Usage Guidance for DNSSEC) to Proposed Standard
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 05 Mar 2019 00:39:57 -0000

Section 8 - Acknowledgements:

"We wish to thank Michael Sinatra, Roland van Rijswijk-Deij, Olafur
Gudmundsson, Paul Hoffman and Evan Hunt for their imminent feedback."

Paraphrasing one of my colleagues, is the part about "imminent feedback"
a prediction, or a hint that we are supposed to give more feedback? :-)

My most imminent feedback--right now--is that I think the language in
Section 3 has come together really nicely and does a good job of
informing operators of the trade-offs of using the different algorithms,
and it provides good recommendations.  I certainly support advancing it.


On 2/13/19 11:29 AM, The IESG wrote:
> The IESG has received a request from the Domain Name System Operations WG
> (dnsop) to consider the following document: - 'Algorithm Implementation
> Requirements and Usage Guidance for DNSSEC'
>   <draft-ietf-dnsop-algorithm-update-05.txt> as Proposed Standard
> The IESG plans to make a decision in the next few weeks, and solicits final
> comments on this action. Please send substantive comments to the
> mailing lists by 2019-02-27. Exceptionally, comments may be
> sent to instead. In either case, please retain the beginning of
> the Subject line to allow automated sorting.
> Abstract
>    The DNSSEC protocol makes use of various cryptographic algorithms in
>    order to provide authentication of DNS data and proof of non-
>    existence.  To ensure interoperability between DNS resolvers and DNS
>    authoritative servers, it is necessary to specify a set of algorithm
>    implementation requirements and usage guidelines to ensure that there
>    is at least one algorithm that all implementations support.  This
>    document defines the current algorithm implementation requirements
>    and usage guidance for DNSSEC.  This document obsoletes [RFC6944].
> The file can be obtained via
> IESG discussion can be tracked via
> No IPR declarations have been submitted directly on this I-D.
> _______________________________________________
> DNSOP mailing list