[DNSOP] Re: DNSOPDNSOP4 documents for consideration about the future of LocalRoot behavior.

Wes Hardaker <wjhns1@hardakers.net> Mon, 26 January 2026 21:41 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 50DF4AD6FEF9 for <dnsop@mail2.ietf.org>; Mon, 26 Jan 2026 13:41:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.2
X-Spam-Level:
X-Spam-Status: No, score=-0.2 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=hardakers.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id neItb9jNmNVq for <dnsop@mail2.ietf.org>; Mon, 26 Jan 2026 13:41:31 -0800 (PST)
Received: from mail.hardakers.net (mail.hardakers.net [107.220.113.177]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 97791AD6FEEB for <dnsop@ietf.org>; Mon, 26 Jan 2026 13:41:31 -0800 (PST)
Received: from localhost (unknown [10.1.0.5]) by mail.hardakers.net (Postfix) with ESMTPA id 3672D21B62; Mon, 26 Jan 2026 13:41:24 -0800 (PST)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.hardakers.net 3672D21B62
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardakers.net; s=default; t=1769463684; bh=SydpW6cs0+cDltVG4sI69U3DaMPEDPhsc8N13uQWab4=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=Msb1SxZ/0RcJqLJx9B4+RHawSN6NAdjE+glcDJSxrM+LDjKq/YUcm6KLamqJ0dxTn pMUOl4vKtxwRCfPChgOsIwn8dwIcOLf+KhCp/ul7lKBB7SDQqtGP15JYma55OGYNUJ 2af6bj+8YWgiu3clsAPrY/ROiE53BphK/Wy4j/zQ=
From: Wes Hardaker <wjhns1@hardakers.net>
To: Ben Schwartz <bemasc=40meta.com@dmarc.ietf.org>
In-Reply-To: <DS0PR15MB5674E9944F3090E1D48F62CFB393A@DS0PR15MB5674.namprd15.prod.outlook.com> (Ben Schwartz's message of "Mon, 26 Jan 2026 16:57:30 +0000")
References: <ybla4y6lwjf.fsf@wx.hardakers.net> <CAKr6gn0yUL1X87+BavA569LGMaWe2VY4a6-iqTAmzwdrZVPx_g@mail.gmail.com> <ybla4y6ia6t.fsf@wx.hardakers.net> <CAKr6gn1L=hHOj2he0Rs_38B5n3pnNZw3xFMx36QLcjthJfUosQ@mail.gmail.com> <yblwm1agppa.fsf@wx.hardakers.net> <25556.1769124242@obiwan.sandelman.ca> <DS0PR15MB567499ECC061876A8A244F35B394A@DS0PR15MB5674.namprd15.prod.outlook.com> <ybl8qdng7r4.fsf@wx.hardakers.net> <20260124030638.D7CFBF2E6F2E@ary.qy> <ybly0lneka7.fsf@wx.hardakers.net> <CAKr6gn2nV+B0mjdCixKG+2UpdmtHFxp_1ZqzK5WFuK4Hxd9GGg@mail.gmail.com> <DS0PR15MB5674E9944F3090E1D48F62CFB393A@DS0PR15MB5674.namprd15.prod.outlook.com>
Date: Mon, 26 Jan 2026 13:41:23 -0800
Message-ID: <ybl1pjc8324.fsf@wx.hardakers.net>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain
Message-ID-Hash: B7B4FUEDEIMXFRU46GQZ4XPOWDLL56WB
X-Message-ID-Hash: B7B4FUEDEIMXFRU46GQZ4XPOWDLL56WB
X-MailFrom: wjhns1@hardakers.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: George Michaelson <ggm@algebras.org>, dnsop WG <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: DNSOPDNSOP4 documents for consideration about the future of LocalRoot behavior.
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/qrfF_AIEPWnw_21Smybr3uebvmU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Ben Schwartz <bemasc=40meta.com@dmarc.ietf.org> writes:

> Suggesting that LocalRoot resolvers use HTTP, on the other hand, seems like a dangerous
> shortcut.

We could remove the suggestion, but please do note that the documents
really say implementations should use what is best for them.  It
suggests that HTTP has some advantages, and you're right we should
probably add some text describing why DNS does too.  IMHO, we should be
providing options not mandates for what to use.

> (IXFR seems well-suited to LocalRoot, but we could pretty easily layer
> on ZSTD or something if needed.)

IXFR actually isn't useful for signed zones, as the IXFR content ends up
being about the same size after every zone signing.  But do note that
it's an option for URLs in the option list too.

> The proposed "root zone publication points" system effectively
> introduces a hard dependency on HTTP, to accomplish the equivalent of
> what DNS Priming does in-band.

No, it says that both AXFR and HTTP records should be available for use.
That's an option not a dependency.

-- 
Wes Hardaker
Google