Re: [DNSOP] `localhost` and DNS.

Ted Lemon <mellon@fugue.com> Wed, 15 November 2017 21:05 UTC

Return-Path: <mellon@fugue.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C3CFE1273E2 for <dnsop@ietfa.amsl.com>; Wed, 15 Nov 2017 13:05:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 72tVW0tvZK2U for <dnsop@ietfa.amsl.com>; Wed, 15 Nov 2017 13:05:14 -0800 (PST)
Received: from mail-pf0-x232.google.com (mail-pf0-x232.google.com [IPv6:2607:f8b0:400e:c00::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 178ED1271FD for <dnsop@ietf.org>; Wed, 15 Nov 2017 13:05:14 -0800 (PST)
Received: by mail-pf0-x232.google.com with SMTP id 17so17880969pfn.12 for <dnsop@ietf.org>; Wed, 15 Nov 2017 13:05:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=woEQ7eL6N1MohiQ5zpguu5sGGGyK+c3YfngIPYmGXw0=; b=M2R52IxLD1QuvdyTJ6uVrewgQkLUyJBfXW1Le11/vGmv9qhZ9Cngw9+c6jsCSSQXOu 7cu68sX9pmPqKa2AjEklFGC2n+49TOIxXqDrABcE4zTRVqxhvn63jYljYS8/TqllWRVx 1ElZ0J+KAoLlcVk2VLDREMbGxpBUz4Q6Onz62Es7UPgjVjnBCz+Ah/kwx1EdXBRLQ3TU c4sOhxsXbHS3RCIxVk1hSDhdh259NeFb/N0iZt5bLZgGnchCQ/vF0KKv3iOP4rhtXYSs GQ5vi7+1j5QLspUw5M/GU+qTNhF6XAnh89Gu9YLTEq1e+fE/VGg+ARiK+4TKD7u/DFMY p0sA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=woEQ7eL6N1MohiQ5zpguu5sGGGyK+c3YfngIPYmGXw0=; b=AbECa4vcGV94mbUqxrEgpTHicltrYLi6FqGF3bq/clZocNMu4XpQrSKgxZHHbolSPp ee29mxJ24uuJf0ZmE10FtEaTbZ1L12XOrWBqBwlYWMwjDDWvCKIx/N/Xx/jt/bTH6KCp Jx1W/nUzS8duSDcrvzhKuYH/3VCq0COMFdzeheyKOeI/Wtw9LWLBmtFlz7UR9NlFJP/+ q8YmBufu8thcTy162f1m5l13SboPh4SzD8yt+uBUxpZSoPc5udgyBLs+2YZ3qc/8ykEE 54C+1k37yigwfm/frM4htuB/KeXbdvF+xkuKGB9Fb7uDMFzWpWekDUtohB0BGzmmwwVd E6KQ==
X-Gm-Message-State: AJaThX5gpnl0TtpvR9FLrwGfHfUroFdnL07OyriDk6OtlRViOKfiLxIq WcKsYt7yzv2RQlqPbtSE4i6/OfilMY8=
X-Google-Smtp-Source: AGs4zMZencPza4l+0AOjj0yogu/SnJWBn/kQvEbo873JRCd8vOMTnRwQdSLF7YiN9jvDXg4ZOXoatA==
X-Received: by 10.84.247.148 with SMTP id o20mr7103006pll.137.1510779913599; Wed, 15 Nov 2017 13:05:13 -0800 (PST)
Received: from [192.168.43.27] ([111.65.61.187]) by smtp.gmail.com with ESMTPSA id 62sm21036268pgh.31.2017.11.15.13.05.08 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 15 Nov 2017 13:05:13 -0800 (PST)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <57BD04DF-B473-41B8-9ECD-D197232365FB@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_DF6B7816-67BF-419C-85BC-2AA6D3CA79BF"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Thu, 16 Nov 2017 05:05:05 +0800
In-Reply-To: <CAKXHy=dgQmAgsTaNWpj3dYPN2nv7UnZLbe58A9vmya3JNdmHeQ@mail.gmail.com>
Cc: dnsop WG <dnsop@ietf.org>
To: Mike West <mkwst@google.com>
References: <CAKXHy=dgQmAgsTaNWpj3dYPN2nv7UnZLbe58A9vmya3JNdmHeQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/rKCi_7LYInpJlgV3682YswxWl5U>
Subject: Re: [DNSOP] `localhost` and DNS.
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 21:05:16 -0000

On Nov 15, 2017, at 10:51 PM, Mike West <mkwst@google.com> wrote:
> Skimming through the recording of Monday's meeting <https://play.conf.meetecho.com/Playout/?session=IETF100-DNSOP-20171113-0930> (starting at around 53:56), it sounds to me as though there's at least loose agreement that signing a response for `localhost` is not what we'd like to recommend: all the folks who commented explicitly took that position for similar reasons. The current text in https://tools.ietf.org/html/draft-ietf-dnsop-let-localhost-be-localhost-01#section-4.2 <https://tools.ietf.org/html/draft-ietf-dnsop-let-localhost-be-localhost-01#section-4.2> reflects this position, and IMO it's what we should run with.

Yes, the current text appears to me to be correct.