Re: [DNSOP] WG review of draft-ietf-homenet-dot-03

Ted Lemon <mellon@fugue.com> Tue, 21 March 2017 01:54 UTC

Return-Path: <mellon@fugue.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E781C1316C8 for <dnsop@ietfa.amsl.com>; Mon, 20 Mar 2017 18:54:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rr3FA_-wpXab for <dnsop@ietfa.amsl.com>; Mon, 20 Mar 2017 18:54:40 -0700 (PDT)
Received: from mail-qt0-x22f.google.com (mail-qt0-x22f.google.com [IPv6:2607:f8b0:400d:c0d::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3910A1316C5 for <dnsop@ietf.org>; Mon, 20 Mar 2017 18:54:40 -0700 (PDT)
Received: by mail-qt0-x22f.google.com with SMTP id i34so121533527qtc.0 for <dnsop@ietf.org>; Mon, 20 Mar 2017 18:54:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=4ZmYI2+jz+V3r2FIw47b9sAniycw5duuPMC0A+BQfjs=; b=KFZBVi2oL40Mp3gcwhKE0NAL4jnOPzTO5GwHYN90OsNiqlZ77Fo43IOyhXlEuupRPL af2TJxUc1T8Xj58qFmrRN0epy/HHmQqvDob8Wwtd8S1u94NTftnOLpz6eIbOKhEJjBGL +KANT4U64ZWM5G9oL9ga8M6rbuSJaWN+e/69Xy18kGet6T2q7JA2w9Jv0+Gq8d0mUOqI R74qlzMFBr/j0WzF45zO8p5bzn5XChRKsdlk/KoAYyWZ7MzHgc7pCp3i+XyeMnGrIgm5 tI2dz8g/kVeUZMCw8GA1B4QpN68YjJIJOvCC08hhhu2DgizH8COaJRkJtslVoFam+9Vz O6sA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=4ZmYI2+jz+V3r2FIw47b9sAniycw5duuPMC0A+BQfjs=; b=hu6RBkBmlseVVhBaGoWtYxFnClOmmtywDfaabD4UNxm5LdDxLsZA0l6xy/PWMaKrmt 7UU3QO8LDoYiuEpjBfxiGMkfB7W+G+yrM38oh9biVa0cGxAIObVnqMuL5hKbahplOAz3 9FG034QdCy2fz8yhiNh8sjaL4fDT8j91bKFjfkcNBsrMwlWOcgDIO7KN5KRq+9QJ/eti DrGD4ppVdlc5gvlCRC8qe4YkH8zmcUbzP0X8/BCYDRUK56vRd1+LCY+A6dA68ZHQ1oeV IlVVByI1YCcjsWNG9w3SqQ4hM5/HUXcG6n/DK51Xas4VYBRAWetatmw74f0OOGreqLhW NN5Q==
X-Gm-Message-State: AFeK/H1/9Hm2a7zjne6xWkW35m5Xm9RohiN29KJ8x9CDWjkamYJgeGyEtSUnPxlJb2dWzA==
X-Received: by 10.200.39.56 with SMTP id g53mr9868504qtg.134.1490061279448; Mon, 20 Mar 2017 18:54:39 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id d23sm13699671qta.32.2017.03.20.18.54.38 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 20 Mar 2017 18:54:38 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <18C28746-F113-4ABD-9896-29ECAC8C27DF@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_7C9ACE0B-A5DD-4CAC-8891-2325521DE2AC"
Mime-Version: 1.0 (Mac OS X Mail 10.2 \(3259\))
Date: Mon, 20 Mar 2017 21:54:37 -0400
In-Reply-To: <CAH1iCip8=KajuqXL6P72aMovsaXWPeWCAWHoXUJ+tZFY4FrG9g@mail.gmail.com>
Cc: "dnsop@ietf.org WG" <dnsop@ietf.org>
To: Brian Dickson <brian.peter.dickson@gmail.com>
References: <CAH1iCioEAfgS-Efj1OYsL1vG4STnwod=ARrtEKWsHYMCzRdq-Q@mail.gmail.com> <441D6008-B1B3-46D4-87C0-1BA8032B50DB@fugue.com> <CAH1iCip8=KajuqXL6P72aMovsaXWPeWCAWHoXUJ+tZFY4FrG9g@mail.gmail.com>
X-Mailer: Apple Mail (2.3259)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/v3AGu60fqQK7swosdHimYejLsu8>
Subject: Re: [DNSOP] WG review of draft-ietf-homenet-dot-03
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Mar 2017 01:54:42 -0000

On Mar 20, 2017, at 9:50 PM, Brian Dickson <brian.peter.dickson@gmail.com> wrote:
> This would require an update every time the KSK is rolled, or whenever the RRSIG needs to be refreshed. 68 years is an inconvenient interval, so maybe 50 or 20 years? This is still a lot better than 1 week or 1 month.

Isn't there some inconvenient process involved in using the KSK?   I suspect that in practice, this makes it harder, not easier.