Re: [DNSOP] 5011-security-considerations and the safetyMargin

Michael StJohns <msj@nthpermutation.com> Mon, 20 November 2017 16:29 UTC

Return-Path: <msj@nthpermutation.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F076129BD1 for <dnsop@ietfa.amsl.com>; Mon, 20 Nov 2017 08:29:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nthpermutation-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jSd6PZSt6f_o for <dnsop@ietfa.amsl.com>; Mon, 20 Nov 2017 08:29:12 -0800 (PST)
Received: from mail-wm0-x22c.google.com (mail-wm0-x22c.google.com [IPv6:2a00:1450:400c:c09::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6BED2129B73 for <dnsop@ietf.org>; Mon, 20 Nov 2017 08:29:12 -0800 (PST)
Received: by mail-wm0-x22c.google.com with SMTP id x63so7296395wmf.4 for <dnsop@ietf.org>; Mon, 20 Nov 2017 08:29:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nthpermutation-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=zw+njDr+O5DqlVtlWLN900Ez/FeIXEi2ToacHFxorrw=; b=j+YPnw7aZf+W4IGAiEI9vaZoxVCAB4vxIF/gR0y58GvUN2jkvvt0v61i2pn+gPBVB/ UOjBCfxNW1G9IKn72kBQ98zPnNf+COPJTgjPj6Mrc76Y+IS1lRW2OoHlaweYSoYLenKk yPslCq8/fm4kmgMmu+ZlAMYpv5QfXUItBO7lnM/Pu37T/cLuwgCSOzf6X3O3QrPWIHPL NjaZOtBDR9J/sObH1pqGvnuNB1rr+oIF3Y4dLbkooCSMOzu0KDWo8XvoZLf1vlUiunX8 WSBk4DPQ4pVczqz2NEZIqbVWYzKY1IY6N1UdPOvP9lRH7VLDlSwj1o6jY6+Wo2GbqyxL L0uQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=zw+njDr+O5DqlVtlWLN900Ez/FeIXEi2ToacHFxorrw=; b=KNEpN6A6sd3/8S8BNkKbdosrHFH6U49bizAZ912Tz00iaFj/4sB3lrqsHFKvQQOIxy tY2wLZqaAA3ToozMVc/4jPi9HlKmaynjc8Ha66DIRYTKKt0POhx7MO6dReD7WMFH+Mgf R8VMTqx0SFJDSt3YqlSZpMvGSGdJlU9IPnYHejmKdmZue+j5qdK6rKVUkRJ+ly0RGhWv jT+SX0Y/TgzTuh+zc8Nz0ja9fB/8Ka+XSco1nxuLB24urJqxK8rpO8xIBl8MB6bnA7iH vt1Zw+XYzNgdWR4YYkmjpzfTyH3V6dJKifbtYoJbAByXMcweyVArOlkEVhWvBfzWPdcn VFdg==
X-Gm-Message-State: AJaThX6y1DOv2EtlJrYaSUsh3a7eSY0xRqGW/JaIK9S+gB8NZpwq1TCV 9so8aZHG6KQA9sVGDo3i2uBCB+kpNSgfIY7IqjzWig==
X-Google-Smtp-Source: AGs4zMb6QWqMo6poJ8oQnAGxUzNVTzHjg14/iSzj35RgQE4JKZWgwS8m4/P8nEblc+gW7S94hJFmeGZcIo/WPKNi1II=
X-Received: by 10.28.155.200 with SMTP id d191mr12080244wme.31.1511195350926; Mon, 20 Nov 2017 08:29:10 -0800 (PST)
MIME-Version: 1.0
References: <ybld14kpaz4.fsf@wu.hardakers.net> <df6bee9d-c140-995b-e45d-fa12f76103f5@pletterpet.nl> <CA+nkc8A=Z2rB7iByow09zFeL45sf6NZcj36KRqDQZ7Cw1kNtUQ@mail.gmail.com> <CANeU+ZC7fVrodoRC60CJ3z9MSsoPxbNRJPPaQFNphPeGzPd=Qw@mail.gmail.com> <yblwp2kgblr.fsf@w7.hardakers.net>
In-Reply-To: <yblwp2kgblr.fsf@w7.hardakers.net>
From: Michael StJohns <msj@nthpermutation.com>
Date: Mon, 20 Nov 2017 16:29:00 +0000
Message-ID: <CANeU+ZBbPAqxwXHbE+9ZtL_0qo_sffaFRpwSpHfV05JT4UMTVw@mail.gmail.com>
To: Wes Hardaker <wjhns1@hardakers.net>
Cc: Bob Harold <rharolde@umich.edu>, IETF DNSOP WG <dnsop@ietf.org>, Matthijs Mekking <matthijs@pletterpet.nl>
Content-Type: multipart/alternative; boundary="001a1144f650143200055e6c9629"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/z2sQMi8ICaknSTeZBa6gVoiFdQY>
Subject: Re: [DNSOP] 5011-security-considerations and the safetyMargin
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Nov 2017 16:29:14 -0000

I’m running the math right now to see what works.  Give me a few days.
Mike

On Mon, Nov 20, 2017 at 11:26 Wes Hardaker <wjhns1@hardakers.net> wrote:

> Michael StJohns <msj@nthpermutation.com> writes:
>
> > 1 something.
>
> I think that the consensus is clearly something like that.  Are you
> (MSJ) interested in supplying a suggested final equation for it?
>
> --
> Wes Hardaker
> USC/ISI
>