Re: [DNSOP] Fwd: New Version Notification for draft-wessels-dns-zone-digest-00.txt

神明達哉 <jinmei@wide.ad.jp> Fri, 06 April 2018 18:16 UTC

Return-Path: <jinmei.tatuya@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC3B1127137 for <dnsop@ietfa.amsl.com>; Fri, 6 Apr 2018 11:16:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JRNSw4GlkynO for <dnsop@ietfa.amsl.com>; Fri, 6 Apr 2018 11:16:40 -0700 (PDT)
Received: from mail-wm0-x22c.google.com (mail-wm0-x22c.google.com [IPv6:2a00:1450:400c:c09::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C53D0127342 for <dnsop@ietf.org>; Fri, 6 Apr 2018 11:16:27 -0700 (PDT)
Received: by mail-wm0-x22c.google.com with SMTP id x4so4834248wmh.5 for <dnsop@ietf.org>; Fri, 06 Apr 2018 11:16:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=HbQqcmnpewELUOA3QXn4Dlc+WqBlf2UJ8eSftP/GhLw=; b=iqUCvV3NCp61gM21VLdhSrRl3+tNacrByibKcOXz102QJEJJMwxiX+9lpfB1jDh6U1 kgAeB0YtxdXMXfOoIVs+6GIq5Mu8Zqbz66vdEzaMNZf+BVJIRusx/ljXn9kAZ6laOAyp IC2Ocdf9R11jscQUEZHzaRHzpTfp47F6VbUvCjCzdLN1vRqoIx8RFLAezyf0XxqG1CdV /urAncpVYWc1x7PpqnyOZkjXMQw1XuSLZt3dQyh5nERcAqWTUbfI9/hWT97rusJqynq5 X6Y0/KfS6xNkz8j0lECyJvGmBb14XIo/UMwn9rBm3SbQyUHSX03MSoPaWm1maLOS9205 KcKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=HbQqcmnpewELUOA3QXn4Dlc+WqBlf2UJ8eSftP/GhLw=; b=tPr/fx6dRFc+psOHeAtpSFGJn2pat2dsTghPyEy9wR4mVuHBtPE4PcRUgIeRRZnx4t q0rukiF8q2+ylWj0Sx1Lp2zUZ3hZ2bLGphQ3qhF+84GwsZM5ZCtggMFCXKlPXDAdQzOL gg8uU7o8jubcPtlqInxi3mVK81fwmTIs7Mp/aY5lLvMi8p06d/mksc8EofcimZspFHn4 te1aJk72ANxc6icmLdUWQLK6wvvUnx1MEAaYa4YfVmFUT31kAOgCRD0sWqC5cJ5jXmiH JgvzFpFRXNgJh0Xo/L7wLJxp9DOt1TVXW9ww1ch+EfW+6K1RdV2H5I9VpvfmMpQSZXqc zjJA==
X-Gm-Message-State: AElRT7FqjqQDITg+8VqjzdH6xPGlbP9pjPoljgqCa1QKDRAQgxjeoHC0 dulLAjikI358DYQTiVKy5FnKXfE6WI2o0q4vITOiYvI0
X-Google-Smtp-Source: AIpwx49qmgdlKoe9GJxxwbF24mfiksCkUr4rpDZwTo48aPwFSaXdAdgnsLxkMhuMG5CDYmiK85G5QSLshv+9tPw0mdM=
X-Received: by 10.28.125.84 with SMTP id y81mr14281644wmc.66.1523038586037; Fri, 06 Apr 2018 11:16:26 -0700 (PDT)
MIME-Version: 1.0
Sender: jinmei.tatuya@gmail.com
Received: by 10.223.151.19 with HTTP; Fri, 6 Apr 2018 11:16:25 -0700 (PDT)
In-Reply-To: <88E182D8-64C4-4FFE-961C-AA3571F8A86B@verisign.com>
References: <152277670738.22791.3511791082557717517.idtracker@ietfa.amsl.com> <88E182D8-64C4-4FFE-961C-AA3571F8A86B@verisign.com>
From: 神明達哉 <jinmei@wide.ad.jp>
Date: Fri, 06 Apr 2018 11:16:25 -0700
X-Google-Sender-Auth: FgTdisYQp25uG6T5QYtnzxPZPio
Message-ID: <CAJE_bqdumBhp0k0DsWb4Zrz4W1-Bn4PkpYn9rnZ_EE8cCNY3tQ@mail.gmail.com>
To: "Wessels, Duane" <dwessels@verisign.com>
Cc: dnsop <dnsop@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/tWkVmJI5cSOsEuTck-smRzrWtGg>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-wessels-dns-zone-digest-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Apr 2018 18:16:42 -0000

At Tue, 3 Apr 2018 21:32:04 +0000,
"Wessels, Duane" <dwessels@verisign.com> wrote:

> This draft proposes a technique and new RR type for calculating and
> verifying a message digest over the contents of a zone file.  Using
> this technique, the recipient of a zone containing the new RR type
> can verify it for completeness and correctness, especially so when
> the zone is signed.  We welcome your feedback on this document.

FWIW, I came up with a similar idea and implemented a patch to ISC
BIND 9 as a kind of hobby project.  It's available at:
https://github.com/jinmei/bind9-zonecksum/tree/zonesum
although it doesn't have a way to publish the digest in the form of RR.

And so, obviously, I like the basic idea of the draft:-)

--
JINMEI, Tatuya