Re: [DNSOP] Fwd: New Version Notification for draft-pusateri-dnsop-update-timeout-01.txt
Dick Franks <rwfranks@acm.org> Wed, 20 February 2019 14:50 UTC
Return-Path: <rwfranks@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4969C129741 for <dnsop@ietfa.amsl.com>; Wed, 20 Feb 2019 06:50:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.88
X-Spam-Level:
X-Spam-Status: No, score=-1.88 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.018, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2YFPr23R7yJQ for <dnsop@ietfa.amsl.com>; Wed, 20 Feb 2019 06:50:51 -0800 (PST)
Received: from mail-it1-f171.google.com (mail-it1-f171.google.com [209.85.166.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEBE8127AC2 for <dnsop@ietf.org>; Wed, 20 Feb 2019 06:50:50 -0800 (PST)
Received: by mail-it1-f171.google.com with SMTP id l15so16024619iti.4 for <dnsop@ietf.org>; Wed, 20 Feb 2019 06:50:50 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=E7NofsVaKkhgwWKLkHTW4UkI+ylWIJVRWlMG2ecyU1Y=; b=nCzUrpfhtAvM6ZIH9TqpyDuf2jqtRE5xngmfWZWSGbIBgoy0OibQoe2a8S21jINS4X KrKfa8MLfOafrr0/zMUpWsScZ0Ko5mZYH9UpQp08nT952qiNTVmCj7MwuKgnGpzREwk0 3sURZulbxnaZIr2ORKbvwAcFPh34r0lWuNknJxPMrie+ZQ93hKmiRemNM60/y4D/bqoY OWx5I6qwLwPDe55Jhb5o0QgNOdCUmHdw6Fj+VSZjTBlChO5PYA123oO9Q+A8UAbhs7WP vef2vlQs+S2pp3cTC9u4sphYTd8zLuDpKQeISNx4i5lIbzSolDMfRS7Fm6bqm0zD/LfQ wRtg==
X-Gm-Message-State: AHQUAuYDye+/lma7mbsQz8UH35teX+/oQEE4Guwn3iyCOReNsMEzbs69 lm85EvSsLaN8k/loYrVxkTfL8jriJEgsjn6bSeEbMOByQ4A=
X-Google-Smtp-Source: AHgI3IZC9wfjkJ3gGCDSlhMZnAptHF7/UxKiArVNBwf0QsW1yNGPASkJRMSvYweHcwBQjG5ovMVGDWdUyIMOf1bipQ0=
X-Received: by 2002:a5d:97c8:: with SMTP id k8mr21814165ios.267.1550674249979; Wed, 20 Feb 2019 06:50:49 -0800 (PST)
MIME-Version: 1.0
References: <155053239541.25848.12960190085730298684.idtracker@ietfa.amsl.com> <969D8BA1-6ED3-47E8-AFFD-2BEE8EA3E66B@bangj.com> <alpine.DEB.2.20.1902191219070.766@grey.csi.cam.ac.uk> <0DE33073-93B1-4CF5-B12D-B7266E21E8B2@timwattenberg.de> <CAKW6Ri51B6zLeBuL7dgLd-GLcqFJCHHJ37Fe7hvK+M_ATs9jAw@mail.gmail.com> <alpine.DEB.2.20.1902201234280.19193@grey.csi.cam.ac.uk>
In-Reply-To: <alpine.DEB.2.20.1902201234280.19193@grey.csi.cam.ac.uk>
From: Dick Franks <rwfranks@acm.org>
Date: Wed, 20 Feb 2019 14:50:12 +0000
Message-ID: <CAKW6Ri49=cFCSccYdc+8XJNHYGnM+joowMRD4Oub84UqoVQSSg@mail.gmail.com>
To: Tony Finch <dot@dotat.at>
Cc: Tim Wattenberg <mail@timwattenberg.de>, dnsop WG <dnsop@ietf.org>, Tom Pusateri <pusateri@bangj.com>
Content-Type: multipart/alternative; boundary="000000000000d51b8a0582547b38"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/v6rqGLLxuwV_9WCGng_0cJm_8O4>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-pusateri-dnsop-update-timeout-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Feb 2019 14:50:53 -0000
On Wed, 20 Feb 2019 at 12:36, Tony Finch <dot@dotat.at> wrote: > Dick Franks <rwfranks@acm.org> wrote: > > > > Unsigned 32 bit RRSIG time is good for travel until 7th February 2106. > > No, it lasts indefinitely. It covers +/- 68 years relative to current > POSIX time using serial number arithmetic. > The value is ( t - Jan1970 ) mod 2**32, for any integer t, which is certainly not relative to current time, always positive, and I agree lasts indefinitely. The point I was trying to make was that the wrapping occurs in 2106, not 2038 as some have claimed. RFC1982 serial number arithmetic is mandated for comparison of these values, not for defining the values themselves. [RFC4034] 3.1.5. Signature Expiration and Inception Fields The Signature Expiration and Inception fields specify a validity period for the signature. The RRSIG record MUST NOT be used for authentication prior to the inception date and MUST NOT be used for authentication after the expiration date. The Signature Expiration and Inception field values specify a date and time in the form of a 32-bit unsigned number of seconds elapsed since 1 January 1970 00:00:00 UTC, ignoring leap seconds, in network byte order. The longest interval that can be expressed by this format without wrapping is approximately 136 years. An RRSIG RR can have an Expiration field value that is numerically smaller than the Inception field value if the expiration field value is near the 32-bit wrap-around point or if the signature is long lived. Because of this, all comparisons involving these fields MUST use "Serial number arithmetic", as defined in [RFC1982]. As a direct consequence, the values contained in these fields cannot refer to dates more than 68 years in either the past or the future.
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Tom Pusateri
- [DNSOP] Fwd: New Version Notification for draft-p… Tom Pusateri
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Tony Finch
- Re: [DNSOP] Fwd: New Version Notification for dra… Robert Story
- Re: [DNSOP] Fwd: New Version Notification for dra… Tim Wattenberg
- Re: [DNSOP] Fwd: New Version Notification for dra… Paul Wouters
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Dick Franks
- Re: [DNSOP] Fwd: New Version Notification for dra… Paul Wouters
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Tony Finch
- Re: [DNSOP] Fwd: New Version Notification for dra… Tim Wattenberg
- Re: [DNSOP] Fwd: New Version Notification for dra… Joe Abley
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… Dick Franks
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Tony Finch
- Re: [DNSOP] Fwd: New Version Notification for dra… Paul Vixie
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Tony Finch
- Re: [DNSOP] Fwd: New Version Notification for dra… Dick Franks
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… 神明達哉
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Joe Abley
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri