Re: [DNSOP] HTTPS and SVBC key names.

Dick Franks <rwfranks@gmail.com> Mon, 20 July 2020 18:39 UTC

Return-Path: <rwfranks@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC23D3A0DCC for <dnsop@ietfa.amsl.com>; Mon, 20 Jul 2020 11:39:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wF7xBj09ZzK0 for <dnsop@ietfa.amsl.com>; Mon, 20 Jul 2020 11:39:53 -0700 (PDT)
Received: from mail-il1-x136.google.com (mail-il1-x136.google.com [IPv6:2607:f8b0:4864:20::136]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D87A93A0DCA for <dnsop@ietf.org>; Mon, 20 Jul 2020 11:39:53 -0700 (PDT)
Received: by mail-il1-x136.google.com with SMTP id e18so14196829ilr.7 for <dnsop@ietf.org>; Mon, 20 Jul 2020 11:39:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=s4wXaNRfVWZyf+UrqD8pNRaaYFRtSNhKaePozfeNWzc=; b=r9ASFjgt+7wb2/ivBw48f7VXbxoSZkgIhLpSIlYW8ESPZKIbwWPTSTyHivQN+zEmSS PDZ7vq0EOS4WzGb8yhwLR6o3VzbUORh0pUD868vdLKOgHdEDHvBp+s6518dGdswZ7+yM wgft+VuKkqdJRubMU19DrWUfyoNTMB4YK720ewNZFotYBxCFPABeFNiz2c1mVXXlKl+L 5gl0+ICqrgrsufSvWaWB5HWXuLc1MZEffm8VSHlrkg62Zjz4zm8UUkNuTl7vTU+CwZiV vjwotfGaA4KuYTJ9Ci3FflCRJKZgkJ+AfkRQV4oM1+2eneNAXMWHcoykSt/qmK/z32bB 7usA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=s4wXaNRfVWZyf+UrqD8pNRaaYFRtSNhKaePozfeNWzc=; b=R5n63gnITiIxXxKWl6WvWP/ODqlca9MCI+gXqahJS89Gz1x2377eyauzORFsy3rdnI HCGpaUmfT3bXjXGSHchYDJ1Iy6PKuA0gnc+nVc5CCcJhQv6elgbs7rZ6XsV4GA0dVoc0 sdesRaAmgVO7e5Z0Ao0PNNTG8oQo7NcS6MqcRqfvtCqWagwrFvq/kM68qqCTBfPpiKhV 9lI94m/VtmkXf9CTMa36ug9IGEN3R7zntIDlKyqmzvEjp1ulR3YoDq1/JIIGtyohVJ2g db7XTG5dInWb1CXBRAZ/lZ36H/dVwEff59Pm3W5YtxSasyF1bvqqV85H9thd1jS0qYC5 VB6Q==
X-Gm-Message-State: AOAM531CfwcAzyRwzHIhpc3bBmvWwE6qy8j5+atuxOxYqQrWbxRYR7Cc eMsWcjRDxl2UsLUpj59NItLVtNWvsEWeWu6VEG6bA5P1Cdc=
X-Google-Smtp-Source: ABdhPJwSofABwjnhYUr6WDDcQ4PWPx6UgJp6/Luauc1lUIs14v2vnneiWFNyqb+evtwN/xxzbmcOu/KCAltK0QURox4=
X-Received: by 2002:a92:1b8c:: with SMTP id f12mr10915093ill.93.1595270393219; Mon, 20 Jul 2020 11:39:53 -0700 (PDT)
MIME-Version: 1.0
References: <23FA2BA0-43B9-49A3-B288-3ADFCE1D1DB1@isc.org> <CAHbrMsDOyTXyJydro8enSePy9COOfK7AVL6Pqv94YGAGhg41Hg@mail.gmail.com> <CAKC-DJiBw7vDr_KA1sb+ephuagRCT84f1B0PGXJptPiZTh2CSg@mail.gmail.com> <CAN6NTqxGLF0tZ17TX8jy2YWPf=qHhW93=fKETJ4kScJbQUUgxw@mail.gmail.com> <CAKC-DJiMngJonCp2EPrHTWMHwV0VAGquf733YcTZ9JSTFtwAhA@mail.gmail.com> <CAH1iCipbR9D_Tqc4dW5zARpEgjZ=-b3d6ZywPzo0=jfBedppYw@mail.gmail.com> <CAKW6Ri7K7efEj81nKJq7W0MKyn9rDOL7bLt-zVUokodVfrjAwA@mail.gmail.com> <CAHbrMsC-5wvxsmrzHnrnfUZOG1wQsGmEF2m2jMt4a5vieK7Nyg@mail.gmail.com> <CAKW6Ri7aF0knx2SFJgx4OxxVJfeNWYJ3pJBmxXQH+UMZ0P4_Rw@mail.gmail.com> <CAHbrMsBTnFmJdj9KYfzGajKmbWJ1+XF_f8BGMPnLy=MFAhCygg@mail.gmail.com>
In-Reply-To: <CAHbrMsBTnFmJdj9KYfzGajKmbWJ1+XF_f8BGMPnLy=MFAhCygg@mail.gmail.com>
From: Dick Franks <rwfranks@gmail.com>
Date: Mon, 20 Jul 2020 19:39:16 +0100
Message-ID: <CAKW6Ri7Cmt43uH_yV0Hjz64b3PynR9WS3NgLf5YZ1K9kwEzXFg@mail.gmail.com>
To: Ben Schwartz <bemasc@google.com>
Cc: dnsop WG <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000001bd51605aae3d524"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/o31r8q5wN0FHXh8yE2fJUNG5dU8>
Subject: Re: [DNSOP] HTTPS and SVBC key names.
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Jul 2020 18:39:58 -0000

On Thu, 16 Jul 2020 at 21:17, Ben Schwartz <bemasc@google.com> wrote:

>
> Quotes are optional, as with <character-string>.  Quotes are only required
> if the value contains whitespace.
>

I was trying to establish if the quotes indicated the data type.  Clearly
not.


> The presentation format is optimized for humans and the wire format is
>>> optimized for machines. In particular, when using the named keys it's not
>>> obvious what the numeric ordering is, so keeping them in order when editing
>>> a zone file by hand would be hard.
>>>
>>
  blog.cloudflare.com. 300 IN HTTPS ( 1  .

key1=\005\104\051\045\050\057\005\104\051\045\050\056\005\104\051\045\050\055\002\104\050
     key4=\104\018\026\046\104\018\027\046

key6=\038\006\071\000\000\000\000\000\000\000\000\000\104\018\026\046\038\006\071\000\000\000\000\000\000\000\000\000\104\018\027\046
     )

"optimized" is not the word which springs to this human's mind.
IMHO, tarted up RFC3597 format is easier to read.

Example:

    use Net::DNS;

    my $rr = new Net::DNS::RR <<'END';
    example.net.        300     IN      HTTPS   1 target.example.net.
        mandatory=key0,key1,alpn,no-default-alpn,key99  ; with duplications
and other sins
        alpn=h3-29,h3-28,h3-27,h2
        no-default-alpn
        port=1234
        ipv4hint=192.0.2.1,192.0.2.2
        echconfig=base64string
        ipv6hint=2001:DB8::1,2001:DB8::2
    END

    $rr->print;

produces:

    example.net.    300     IN      HTTPS   ( \# 126 0001
        06746172676574076578616d706c6503 6e657400 ; target.example.net.
        0000 0004 00010002
        0001 0015 0568332d32390568332d32380568332d 3237026832
        0002 0000
        0003 0002 04d2
        0004 0008 c0000201c0000202
        0005 0009 6dab1eeb8b2dae29e0
        0006 0020 20010db8000000000000000000000001
20010db8000000000000000000000002
        )

Observations and complaints gratefully received.

--Dick

> _______________________________________________
>>>>>
>>>> DNSOP mailing list
>>>> DNSOP@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/dnsop
>>>>
>>>