Re: [DNSOP] Insecure delegations from 239.in-addr.arpa needed? [was: draft-ietf-dnsop-rfc6598-rfc6303-01]

Mark Andrews <marka@isc.org> Thu, 21 August 2014 05:30 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 179081A702B for <dnsop@ietfa.amsl.com>; Wed, 20 Aug 2014 22:30:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.569
X-Spam-Level:
X-Spam-Status: No, score=-2.569 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.668, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qlY4ilWOfPeW for <dnsop@ietfa.amsl.com>; Wed, 20 Aug 2014 22:30:08 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0ACDB1A7013 for <dnsop@ietf.org>; Wed, 20 Aug 2014 22:30:08 -0700 (PDT)
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) by mx.pao1.isc.org (Postfix) with ESMTP id C96443493A2; Thu, 21 Aug 2014 05:30:05 +0000 (UTC)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id 0D70416005B; Thu, 21 Aug 2014 05:41:25 +0000 (UTC)
Received: from rock.dv.isc.org (c211-30-183-50.carlnfd1.nsw.optusnet.com.au [211.30.183.50]) by zmx1.isc.org (Postfix) with ESMTPSA id CF79F160059; Thu, 21 Aug 2014 05:41:24 +0000 (UTC)
Received: from rock.dv.isc.org (localhost [IPv6:::1]) by rock.dv.isc.org (Postfix) with ESMTP id 0E2BF1D1C8EB; Thu, 21 Aug 2014 13:23:58 +1000 (EST)
To: Chris Thompson <cet1@cam.ac.uk>
From: Mark Andrews <marka@isc.org>
References: <20140814001610.3124D1CC688D@rock.dv.isc.org> <86AC48C0-4DFF-4286-A9B1-2A6BE3D14BDC@hopcount.ca> <20140814160453.1C7931CCE03D@rock.dv.isc.org> <7EA38D42-3915-403E-AFE3-C0A8E4A391BF@hopcount.ca> <20140814233627.457201CCFF9F@rock.dv.isc.org> <Prayer.1.3.5.1408201724000.12368@hermes-1.csi.cam.ac.uk>
In-reply-to: Your message of "20 Aug 2014 17:24:00 +0100." <Prayer.1.3.5.1408201724000.12368@hermes-1.csi.cam.ac.uk>
Date: Thu, 21 Aug 2014 13:23:58 +1000
Message-Id: <20140821032358.0E2BF1D1C8EB@rock.dv.isc.org>
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/u0tSinmFtD4dgzYdWybPgNCkdfw
Cc: dnsop@ietf.org, Joe Abley <jabley@hopcount.ca>
Subject: Re: [DNSOP] Insecure delegations from 239.in-addr.arpa needed? [was: draft-ietf-dnsop-rfc6598-rfc6303-01]
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Aug 2014 05:30:10 -0000

In message <Prayer.1.3.5.1408201724000.12368@hermes-1.csi.cam.ac.uk>, Chris Thompson w
rites:
> On Aug 15 2014, Mark Andrews wrote:
> 
> [...]
> >The last delegation in the current chain is a secure delegation from
> >IN-ADDR.ARPA to 100.IN-ADDR.ARPA so there is a problem currently.
> >No one can safely setup their own reverse zones validation is now
> >starting to be done in stub resolvers and to do so would result in
> >validation failures.
> >
> >> Are you reacting to some other suggestion that one or both of ARIN and
> >> IANA are keen to insert a secure delegation for each of those 64 zones?
> >
> >I'm saying that there needs to be a delegation and that the delegation
> >needs to be insecure.  There currently isn't a delegation at this level.
> 
> This thread reminds me that the same problem arises if one wants to
> locally define reverse zones for the IPv4 multicast addresses described
> in sections 6.1 and 6.2 of RFC 2365, i.e. parts of 239.192.0.0/10.
> 239.in-addr.arpa is signed with a chain of trust from the root, but
> it doesn't contain any sort of delegation for these address ranges.
> 
> What would be the right way to officially request IANA to do for
> 239.192.0.0/10 what Mark Andrews is proposing for 100.64.0,0/10?
> At least in this case ARIN is not involved: 239.in-addr.arpa is
> all IANA's own work!

Write up a draft for this range requesting that the DNSSEC chain
of trust gets broken for reverse range as per the method described
in RFC 6303.  

> -- 
> Chris Thompson               University of Cambridge Information Services,
> Email: cet1@uis.cam.ac.uk    Roger Needham Building, 7 JJ Thomson Avenue,
> Phone: +44 1223 334715       Cambridge CB3 0RB, United Kingdom.
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka@isc.org