Re: [DNSOP] Consensus check on underscore names and draft-ietf-dnsop-rfc7816bis

Viktor Dukhovni <ietf-dane@dukhovni.org> Wed, 14 July 2021 03:54 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D15C3A173D for <dnsop@ietfa.amsl.com>; Tue, 13 Jul 2021 20:54:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zwFXigtFyDZ1 for <dnsop@ietfa.amsl.com>; Tue, 13 Jul 2021 20:53:58 -0700 (PDT)
Received: from straasha.imrryr.org (straasha.imrryr.org [100.2.39.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F2CA3A1753 for <dnsop@ietf.org>; Tue, 13 Jul 2021 20:53:58 -0700 (PDT)
Received: from smtpclient.apple (unknown [192.168.1.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by straasha.imrryr.org (Postfix) with ESMTPSA id AFB13DA082 for <dnsop@ietf.org>; Tue, 13 Jul 2021 23:53:56 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.100.0.2.22\))
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
In-Reply-To: <CAH1iCir53=pEvz+3Nhc6+pL0PWb8Dv7cSNkBU32xj7zVqKn-Sw@mail.gmail.com>
Date: Tue, 13 Jul 2021 23:53:54 -0400
Content-Transfer-Encoding: quoted-printable
Reply-To: dnsop@ietf.org
Message-Id: <42DEF11F-4ED9-4ADD-916F-7B5E47963A4F@dukhovni.org>
References: <CAHw9_iKhvHwUfJMOp-YhJkimmnN0f3DLbh+JWYxhCiZ9CjEEQQ@mail.gmail.com> <0ed6efa6-c981-fa64-472c-eef0c5453f4a@isc.org> <CAH1iCipP2C0fPgFYBGeR3Esvzf4eMxVv+EJKgKkfSiVX3MCqnA@mail.gmail.com> <c225cb3d-7682-4bf0-831d-c841540d1f74@isc.org> <CAH1iCirP64PV1a7mAqUgi0mrg05WJySy8jq62HiEUuftQEF2TA@mail.gmail.com> <832f7712-1dc3-e563-f98e-8ec0ede25577@isc.org> <73FDFFF0-5C05-45B5-82C1-0D909219DFAF@dukhovni.org> <CAH1iCir53=pEvz+3Nhc6+pL0PWb8Dv7cSNkBU32xj7zVqKn-Sw@mail.gmail.com>
To: dnsop@ietf.org
X-Mailer: Apple Mail (2.3654.100.0.2.22)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/qTit6J67H2iczmQfSdqKGNDJVPY>
Subject: Re: [DNSOP] Consensus check on underscore names and draft-ietf-dnsop-rfc7816bis
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jul 2021 03:54:06 -0000

> On 13 Jul 2021, at 11:13 pm, Brian Dickson <brian.peter.dickson@gmail.com> wrote:
> 
> For example, in evaluating the break-points when partitioning the labels to limit the total number of queries, the sequence COULD treat any contiguous sequence of underscore labels as if it were a single label, and then do its partitioning of labels using the same relative logic.

FWIW, my take is that treating consecutive special-use labels as a single label
only to resume minimisation at some subsequent non-special-use label sounds too
complex to me.  Intermediate special-use labels are just as likely to be ENTs
and to not be privacy-relevant zone cuts even when some labels below are not
special-use.

So whether it is MAY or SHOULD, my sense is that if an implementation chooses
to implement the proposed strategy it should just make the final query at
that point.

-- 
	Viktor.