Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD

Geoff Huston <gih@apnic.net> Wed, 04 April 2018 05:12 UTC

Return-Path: <gih@apnic.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A6C3126DD9 for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 22:12:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=apnic.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PpizQS0BM-ks for <dnsop@ietfa.amsl.com>; Tue, 3 Apr 2018 22:12:45 -0700 (PDT)
Received: from APC01-PU1-obe.outbound.protection.outlook.com (mail-pu1apc01on0085.outbound.protection.outlook.com [104.47.126.85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F50B1200FC for <dnsop@ietf.org>; Tue, 3 Apr 2018 22:12:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apnic.onmicrosoft.com; s=selector1-apnic-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=6oBEGg7GMS6BkQW9VBTI8+HpaKmjB5vc97WdPVwWeco=; b=YVwuxFsFniSvKX5AaG5uONy4tcH+kIwEyPbpF1m/FpoIX947dvhquC6oasyEagVSSRVXCutKNjQpXVwdDnlZYku740r2D/dQa7akaTUWsOzAtfYRMaN0SDZ28ezBlhwbRX7i2pK0BBNfFHJeKXTFY18eGr+rYVu0/rWR9h7zTXM=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=gih@apnic.net;
Received: from [IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c] (2001:388:1000:110:68a8:aacd:ca4f:a91c) by SIXPR04MB0698.apcprd04.prod.outlook.com (2a01:111:e400:51ee::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.631.10; Wed, 4 Apr 2018 05:12:40 +0000
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.3 \(3445.6.18\))
From: Geoff Huston <gih@apnic.net>
In-Reply-To: <B83C8945-C7CC-44D3-BB0B-E036DF05EED0@isc.org>
Date: Wed, 04 Apr 2018 15:12:29 +1000
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsop <dnsop@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <59D24D95-0A54-4F89-9F0C-4FDE68486049@apnic.net>
References: <039408B0-89EE-4038-B9C9-CBCC35EC24EC@isc.org> <64816369-700A-4413-B1F0-160FB145EE6C@gmail.com> <BF3E4F4D-027C-4A2B-8026-14AF3FBA4603@isc.org> <2F103A8E-72F6-4159-900D-B7006D0AC647@gmail.com> <6D617FAC-D981-4AE1-8943-4F0D12C46397@vpnc.org> <0B0775D9-B5E6-4778-A199-FE4D09A0BE17@apnic.net> <D19F6299-922A-4DCE-8E95-85CA72E63129@vpnc.org> <A4AA3F56-12A5-4951-B01A-450B493E0E4A@apnic.net> <412D2533-2332-4F38-BAC6-4C5AF391C124@isc.org> <756BFAD3-2867-4646-B028-7D93C05BA8F3@apnic.net> <167E8357-FE53-43DC-84C6-B720BD8069E4@isc.org> <E7EFB44E-09C8-492D-AF9A-7EAAECD729D5@apnic.net> <3282A858-194C-4E28-AA2B-28F0881B9BAA@isc.org> <50B1B4C2-29EC-4CF1-946F-95D823A15860@apnic.net> <B83C8945-C7CC-44D3-BB0B-E036DF05EED0@isc.org>
To: Mark Andrews <marka@isc.org>
X-Mailer: Apple Mail (2.3445.6.18)
X-Originating-IP: [2001:388:1000:110:68a8:aacd:ca4f:a91c]
X-ClientProxiedBy: HK0PR03CA0040.apcprd03.prod.outlook.com (2603:1096:203:2f::28) To SIXPR04MB0698.apcprd04.prod.outlook.com (2a01:111:e400:51ee::21)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 042ecac2-064c-487a-cf42-08d599eab0b0
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(5600026)(4604075)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:SIXPR04MB0698;
X-Microsoft-Exchange-Diagnostics: 1; SIXPR04MB0698; 3:+bLIl4WgITGCylX5C2oSF+XOVUdktvO8l+rqj02/Em53TfQMd8wiAOwMQF0hfHJPH9NQ4j7NUJ8WV4ATkGGM69WplLJJGvqUHUoRrdpLHrC/+8YddQNMo8c1XJVYCKGNrY/vnZjbscSAYu23udZk2NSS0grqgzUgFYRq88ZAcPM4nz/gCdfAXWTZF5SlJWrthitamcsisROAc8C65fm8dnv0ssXJJxVkVdmTPBChUi6p8d5RKc1U6mgRwPwi/9mt; 25:UHSLgfshQW5yoPeGvDmMYTl9Vhg6Az0k+pA4B7b5w6i077IUoqZTfiXLMC63yh887o6SF5J+yoAuUvMWkEOKoKCJK00O+3FVZ64QSAFMzZkNh6yqjAoi/efBFhr0O6sNtEn9A2HPCCJTudNhcF1tFIgAnus4U5+/jtdYdJRxwh1Ui3fKfggg+HCcxGW27oZiTvNqwoDMnPNH0ZgUs6gLRnzWQF9nzPQKxmzkzRoknU/8xcG0TYYidV/L6wbw6XdlvYwDlKPn4pXBoj2NiTlVAQDrd17Pf5uBfgAr3xkViemyvft8awm6kk6NPkMJP1V1/Z770je3utba/I33vRI4JQ==; 31:fDrEeF8RrJrsTpnCcLOO4D5k5ixanBRV0TZEnQIh4hQ4Yi+fjQC/nV+TC5LT8XJNAx8iqg5AKwI6KriL2OQc9j+04w7Ei6hdOslLhtugvkXAxn73NIqjq3n/zzNwNj3prM85w/gNRfx9zqKsnio4w7HcYWie39LTjWlZPBNoY2UqK4bdzET2pP+Ei/C6Ks0SRpAhg18I9V2d2SllD1lYQvAHAxvkiUSix6YPTK8+3cE=
X-MS-TrafficTypeDiagnostic: SIXPR04MB0698:
X-Microsoft-Exchange-Diagnostics: 1; SIXPR04MB0698; 20:QxukKVahAoYWA+duHz/Cbq8gTnFEEdZnk5ZJf85ETvSf9TJo8izxio5i6lKfAfarIkYl0rsVy1whjmWkBKP16LmwIm9+PvTo4IjG02RKDTrWDyi5ZSMsYbrcOdT4y5pEKy5LjdqUwlQNGOC2vgC3f8AfnZc+UQJvisLctaASgCR+DU28s4dgfH9bS3sNyTfPaiYxsZm0bGpiXEE6T76TMap6RcU/p+SOoIHajUgUSSdhjFW8q6f9MtD/1Fr+2NUL; 4:jqD675IfcncFxVVo0Zc/LehBrYEdLlI0r9SQMXD3/PFzfEIpKT+5g/pXpnWb53zLOBihP2Fal01CLeNabPwhl7aJB6TbrRSe3/dxN7510qDM+6dd5f3yFf7P1x2IRorxPJ8WdeCx5bVsoARvZGSrPdflfFw+k5ykIenJnmoj2t/0SaEBFx+F9KkarZivlRPatIkvleFrhB6jeduVBtwHmvsYs7L483ftJdDMN7q/FlUq+p3nUMQaqOs2GuA/ZWOti5ggGl/5w3iLBagzbQpgwMZWiIkQ6f601Ez19kskltpy6hHcwEp97QY3ELlYtDvP
X-Microsoft-Antispam-PRVS: <SIXPR04MB0698725FBEB9733872F4A6B6B8A40@SIXPR04MB0698.apcprd04.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(17755550239193);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(8121501046)(5005006)(93006095)(93001095)(10201501046)(3002001)(3231221)(944501327)(52105095)(6041310)(20161123558120)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123562045)(6072148)(201708071742011); SRVR:SIXPR04MB0698; BCL:0; PCL:0; RULEID:; SRVR:SIXPR04MB0698;
X-Forefront-PRVS: 0632519F33
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(366004)(39380400002)(396003)(39850400004)(376002)(346002)(51444003)(189003)(199004)(68736007)(105586002)(81166006)(81156014)(33656002)(8676002)(1706002)(52116002)(23676004)(106356001)(36756003)(52396003)(6916009)(86362001)(2486003)(52146003)(82746002)(93886005)(50226002)(83716003)(316002)(2906002)(2616005)(6666003)(305945005)(8936002)(7736002)(229853002)(8746002)(446003)(11346002)(25786009)(476003)(186003)(47776003)(478600001)(59450400001)(53936002)(386003)(46003)(54906003)(5660300001)(50466002)(76176011)(6486002)(97736004)(6116002)(4326008)(57306001)(6246003)(486006)(16526019)(42262002); DIR:OUT; SFP:1101; SCL:1; SRVR:SIXPR04MB0698; H:[IPv6:2001:388:1000:110:68a8:aacd:ca4f:a91c]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
Received-SPF: None (protection.outlook.com: apnic.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;SIXPR04MB0698;23:8flbuh4G0V8XlFlmZA0Ij7fEMSoRrEKghAPxXXSRyNzx8O67SppclMjQsG7KzBljIANH0askiMJrWyAj8rhpCGOiDWwPU6/4XL39Dz6Jb0tsePnrUlySbuiD1FVyCqFJV6nyfG0Gypy49DaG/Dye+hfSGmw+JbVDK365Z9ZaUreFKQfNMlhAwSFlrJSXWUDQer6SxlQoo1eLe/4m8+UIF31pK2FB0NCAIvlyWWt3SlG1vCnrqcBiuUYy/n+VXd+zNWfVXsknpN9tpBLh9d950mKl/pwky6MyWOLINIBT8gONHlMZkM21AGhV6GIZyzJELhVtjcd/Ke/IV723Wo8vcl1b9fVXCgqks8b3EiJvGaGLOks94kO32HvxI5IKrY0LDeRIqKS4qMi4+rshAfyyeAlSeYNrTOG8oVHd8Y7ScB55oFa6e++x8IF1zJyPkLK6aQ4pszQ14wGK38J8lE/R2ZD85Vy3uSDuacTo2UjbSQYsbuGm7gHup98zxV7s8kSHnz/P96SKOP66Dk1MDZWw95RL2uwGVCUm1dy4YjPHCi+Fj5qD3C0iNBA6wgwO2HIH0AY2YeioAarmjUep+gCdm94pPxxnyTXJ4rIySuOP00JZ1YalLa6aa1j920O4SykU/Hn+DQE+felCqZzk/VMKqNrLEF5rpMlVaywazvXH13nQaJhdmDnWYh/YFATDABMuSs1NlsIq47z9CiY8Bvr0Eeqlx7QSGB0J6yA7RfnxWcTVFZyRYK+k6oDDzHcyX8H0UjqGKZYjH4/hvRJI93Dt6ZcFEd7QfuPlH6UBKSvF3Nm8Fe71/9GRjx6DROLPQhW97g7OQLejCJlztZy1gndi1JXwHO5yF72q4o9H53YOL7be986ZVOmG8zqNLD7mW48FCAWH4S0omkH7+hDWyS6AJyO+QNHQFClittCB+zkWPdMFxZULEP1N4C9lMmH3UYhMH31+8E4urM+v2SpPAeNVEpy9qsNJFqV50aMxl6W3N22Z3rukUS3njKHSBA/n3BuGVyry+8izd6vTRtwL+pdLA59Zp3185159TiIpLieki1SV+RypdJn3ORD0lvym2+t7nzAiThG3olzEw3Mct0Cshu8MM7wqj/O/k+o1tNEjHEcZjXockPpGZemPOGFFOLbOXiF0hK7hOS9nqHRRnPTJ3zkpTl+CcUK09dWfEC2GSRV2nMIYLaV0OLUBRYcvoTKBqjpwHSEl4k4lsI/DjBX9OkgV/CsUH2QT8osXhuSTjBYDF416tR0/McCIUm/zI6+EQX6X06fsSqogMW4/te8rZewFzGGGqAY8QuN3sYg3hOlBRbvPRBfuACtI5wRe67F/6kZtx18OJ4vYZ0vkkfNdk52cnszBu5iStfuC8LujSwI=
X-Microsoft-Antispam-Message-Info: VgmXy0tnHcDB7GUquPQI/4HuUhU9Jyv5XO21ow3FXrIVmRcKlc9xjYnbhwcYGxpjaT1/iP6Y6gwpyF5xCgb35mnSsd+iIaRY+jjwHmVoSVx/VafVb4jS3qApZrjm3TF1YQYqVhXDHKaPFHOuSXoPInlqNm2M7WMC9n6SFaAhfSkOU1n1cj110j7xw/4GuzQ1
X-Microsoft-Exchange-Diagnostics: 1; SIXPR04MB0698; 6:6BQnGO1CGy6U+bLY8KmHUt5BXt9jCC1ge/9ykpkKPkGeWXkr0smfVKTRz/GIqZ1hHha4MIL+1XF/qworolflSnwu/ZmW4TdE1WWw6wjf2lxxZbus/cAzEgf+6HMfCn127nLphVure+4F7PUYGroCW5dxzHX7Vqxk+bd41y3q7sYwkZBlbF5MxewcDCAD878AgZcU1t7iJ2vTkspJYEwo+DnQkcdHnak5b8DsmNmL4zfhbFV4rWRXFeOmAiK5236wMx2ZF39Wy4lvgJcmAVt88ByCciyFXeakNrIyUbygtGk0WqAvJTCDlg6PUAvYN/RrfR8n44W19kd1FWsuAjXuMMWQ3sQK2XVwPhekw6CYpzqdfCEcUAsBHPnL/atth7rkAExhhHJ8i9n+zZcXHt/lJRrBQkr2sAkE+j7HtA3OSey4kjR08cDxMDsmFBGUGVDy2g1/2kPMpmYZX3Pt+NHuOg==; 5:sCUdtLVMb2/DxAG3e+o4fqon/fMpPdoIwETe6fgTmeNuQ/SbYf32dU5xwsmnMw/IB84UwCsPfstTCM+K9jsKxoyaeU0W9DTIyO3SEAUNsFhLKCY33RrX9aZ0uN7aRRpzvRU7Apc+IKHeSqvyii1I2BragvruZpyHlTKGu1M5NiM=; 24:cUVAf7Fuh6/UWB3IdmaGXJMH4ao+2oPlqfCJPCcUaMnlXRN2cPjt/90qZpzxIU2+KkhBgSzIpH40MPdT4QJHuttFTDiNLwhXwre3W6Ztv8g=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SIXPR04MB0698; 7:gluTZlhBdT7F4OoNcm7bgiPVrGNAym3PweKzoeaXePK7Mv7m5ra9Hoh/vIMf2zUSkavKwJ3x3CJe3OT2geC/Ts+w1y3BeRgl76rOuoO4+agTNAW0vMLAuXmI7S/3vBPRfGNNahVZUj8n0t6L9Tu98V9+bveSmKKMam5bg5kHdbepMsEEUC6W/XRBVXSEmNl+3LuTSZbNgeiO5zhAZa18c6MrJ3apai7FZjbxeou48GWH4C3b+0E2gkkwa/G9IKAa
X-OriginatorOrg: apnic.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Apr 2018 05:12:40.0442 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 042ecac2-064c-487a-cf42-08d599eab0b0
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 127d8d0d-7ccf-473d-ab09-6e44ad752ded
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SIXPR04MB0698
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/urxNc74R3BS1mPJYzaEzL_x42Vc>
Subject: Re: [DNSOP] draft-ietf-dnsop-kskroll-sentinel-10 and AD
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Apr 2018 05:12:47 -0000

>> 
>> 
>> All of the following conditions must be met to trigger special
>> processing inside resolver code:
>> 
>> o  The DNS response is DNSSEC validated
>> 
>> o  The result of validation is “Secure”.
>> 
>> o  The Checking Disabled (CD) bit in the query is not set.
>> 
>> o  The QTYPE is either A or AAAA (Query Type value 1 or 28).
>> 
>> o  The OPCODE is QUERY.
>> 
>> o  The leftmost label of the original QNAME (the name sent in the
>>   Question Section in the original query) is either "root-key-
>>   sentinel-is-ta-<key-tag>" or "root-key-sentinel-not-ta-<key-tag>”.
>> 
>> 
>> Geoff
> 
> I think that is the way to go.
> 

Mark, thanks for your patience with my evident cluelessness!


Geoff