[DNSOP] Re: AD review of draft-ietf-dnsop-structured-dns-error

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Sun, 13 April 2025 12:28 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0B3CF1B5EDA5 for <dnsop@mail2.ietf.org>; Sun, 13 Apr 2025 05:28:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -11.888
X-Spam-Level:
X-Spam-Status: No, score=-11.888 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cisco.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CJyiq7zyXLPQ for <dnsop@mail2.ietf.org>; Sun, 13 Apr 2025 05:28:14 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id ACF161B5ED88 for <dnsop@ietf.org>; Sun, 13 Apr 2025 05:28:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=47366; q=dns/txt; s=iport01; t=1744547294; x=1745756894; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=EBJphSh+i9Ogw5k2vtvatvznoWng2R6nTBlPzsVHipA=; b=e5jfM//BM7JbrAyukZdCFxkYJ0T9k0PlGH0AcqA4ckGs75tRDzDIEcof P2CHtazILiPzWhEjWaackc1Eieu38eK7Sh8C8w8+UN24kUmfHGUlTPooC MB61y25+WR8cuSde+9PawKaIhM1dGZCF8uOooAlHMfWJXBqPDa25dITMX W5jGhfCHm6I3LLTClqtFu/+4QOW/y/pFPAZeilYhPH8xmYnpaAgJKOebW cOChmKgY/zaffsl8IJY5CFvhh76/ixZ7XAFWoRLzJfA8xd4JK7s4vTUzM me2a75nwcqNCAWMrOZB0EY7FsjjQstcyHFh51Z0yqoUPW7FE+P8yzHfvk g==;
X-CSE-ConnectionGUID: PxI2XImiRuOyzAdJkQU6Mw==
X-CSE-MsgGUID: usltpLBFQeKZ/lO9Z1HS+g==
X-IPAS-Result: A0ADAADyrPtn/5QQJK1aGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQFAJYEaBAEBAQEBCwGBQAEwUgd2gRxIiCADhE5fiHYDi2OFZIYzgTqEXxSBEQNWDwEBAQ0COwkEAQGFBwKLKAImNAkOAQIEAQEBAQMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOFew2GWgEBAQEDDAZZCAYQAgEIEQMBAQEhAQYHIBEUCQgCBA4FCAwOglwFghwUAzEDARAGolABgUACiit4gTSBATuDMUHZDg2CVAaBSAGIMR4BKoEzggaCJIIpgjMnG4FJRIEVQoJoPoIfQgEBAQEBgSMFARIBBwIaHQEHD4Nfgi8EgRCBBhc+AwQ+FB9IgkiBJYJ+hD+BI4M3V4JvgXuCFXxVhxlSdSIDJjMsAVUTFwsHBYEpQwOBDyNOBTAdgXyDdIU2ghGBXAMDI4MVdRyEbIRXLU+DM4FBHUADC209FCMUGwUEgTUFljcTCyIag0ctGQYrOQQUDgURAwgIBgEBFwkCdggtHwcPAg8DFhELAgQsgRCRMDiDGAGMG0eOFJQhcQqEG4wZjziGLheEA40Jj1OJEmaYfoUdiGiEB5EjAkoIhQYCBAIEBQIPAQEGgWc8DVxwcBU7gmcfMxkPi0iCZRaDWIQ9VsMPeAI6AgcBCgEBAwmGSIkiLXFdAQE
IronPort-PHdr: A9a23:FN+qnxJkdbG4LU01a9mcuVQyDhhOgF28FhQe5pxijKpBbeH6uZ/jJ 0fYo/5qiQyBUYba7qdcgvHN++D7WGMG6Iqcqn1KbpFWVhEEhMlX1wwtCcKIEwv6edbhbjcxG 4JJU1oNwg==
IronPort-Data: A9a23:BoL/x6k5NhX9fjtaNYNt2UTo5gzGJ0RdPkR7XQ2eYbSJt1+Wr1Gzt xIWXTyFO6vcYDH9KIpxaIXn/B8BvJSEm99jQFBkqSsxEVtH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaC4E/rav658CEUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+pC31GONgWYubzpIsvnb8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSb /rD1ryw4lTC9B4rDN6/+p6jGqHdauePVeQmoiM+t5mK2nCulARrukoIHKZ0hXNsttm8t4sZJ OOhGnCHYVxB0qXkwIzxWvTDes10FfUuFLTveRBTvSEPpqHLWyOE/hlgMK05FbUI27xHIGRPz +E/OSIkYjKAvt/o5a3uH4GAhux7RCXqFIobvnclyXTSCuwrBMmaBa7L/tRfmjw3g6iiH96HO JFfMmQpNUqGOkEfUrsUIMpWcOOAi2fudTZbpXqepLE85C7YywkZPL3FbIeLIobXG5sL9qqej n/d+3jhJjs0DdG8+32B1SOe38/03iyuDer+E5X9rJaGmma7ymoIDwU+VFanr7++kEHWZj5EA 0UQ/ixrqe0581amC4CkGRa5u3WD+BUbXrK8DtEH1e1E8YKNiy6xDWkfRTkHY9sj3PLajxRzv rNVt7sF3QBSjYA=
IronPort-HdrOrdr: A9a23:W+TSD6G0fCnFEMtspLqFlZLXdLJyesId70hD6qkvc203TiXIra CTdaogtCMc0AxhJk3I+ertBEGBKUmsk6KdkrNhTItKPTOW91dAQ7sSl7cKrweQfxEWs9Qtqp uIEJIORuEYb2IK8PoSiTPQe71Psbv3lZxAx92us0uFJjsaEp2Imj0JcTpzZXcGPDWua6BJc6 a0145snRblU3IRaciwG3kCWMb+h/CjrvjbSC9DLSQKrC2Vgx2VyJOSKXWlNxElPA9n8PMHyy zoggb57qKsv7WQ0RnHzVLe6JxQhZ/I1sZDLNbksLlUFhzcziKTIKhxUbyLuz445Mu17kwxrd XKqxA8e+xu9nLqeH2vqxeF4Xii7N9u0Q6h9baruwqmnSXLfkN8NyOHv/MeTvLt0TtkgDi76t MT44vWjesOMfqKplWM2zGBbWAYqqPzmwtirQbW5EYvC7f3r9Rq3Nci1VIQH5EaEC3g7oc7VO FoEcHH/f5TNUiXdnbDowBUsZaRt1kIb1+7q3I5y4eo+ikTmGo8w1oTxcQZkHtF/JUhS4Nc7+ CBNqhzjrlBQsIfcKo4XY46MIeKI32IRQiJPHOZIFzhGq1CM3XRq4Tv6LFw4O2xYpQHwJY7hZ yEWlJFsmw5fV7oFKS1rdB22wGIRH/4USXmy8lY6ZQ8srrgRKDzOSnGU1wqm9vImYRXPiQaYY fEBHt7OY6VEYK1I/c94yTuH51JbWITWMcJutA9QTu107D2w6XRx5jmTMo=
X-Talos-CUID: 9a23:6VZkZWtsmyNne2JQmv24lPpz6IsdYlyH/FbVInWlLnd7YbG3SmatpoZ7xp8=
X-Talos-MUID: 9a23:/QiZXw56y/XQxj3Pkif655Vrxox1+KCyEGQnv6wLmPvDMQshCW69t3e4F9o=
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-l-core-11.cisco.com ([173.36.16.148]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 13 Apr 2025 12:28:13 +0000
Received: from rcdn-opgw-1.cisco.com (rcdn-opgw-1.cisco.com [72.163.7.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-11.cisco.com (Postfix) with ESMTPS id CB4AA180001EE for <dnsop@ietf.org>; Sun, 13 Apr 2025 12:28:13 +0000 (GMT)
X-CSE-ConnectionGUID: qY7x3hwOTNK/oiafQXkZMg==
X-CSE-MsgGUID: 1HG8v1stS5qJjEkcBarzIw==
Authentication-Results: rcdn-opgw-1.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.15,210,1739836800"; d="scan'208,217";a="27117614"
Received: from mail-bn8nam12lp2171.outbound.protection.outlook.com (HELO NAM12-BN8-obe.outbound.protection.outlook.com) ([104.47.55.171]) by rcdn-opgw-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 13 Apr 2025 12:28:13 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=szcwp4XyNyFbKeL+lL9qoym/jvY+2uufxnm7+TpRTPUv/6smBMSQkzNEiduEqTrcQm8Jc/hVM2UQwghf4wX8fSqu2Cq9rhvsizIi5Hnj+jti6TYbRNHsmGM7CcJAi92WDQgBE0CarNC4HaI8U9ZG2pJGNurkWnYNhzPPMCxqsAWXrEBeHKn7w20rL9Q7csgQCeiRzWpXLmCXoXa4600AFMeGAQoZK+/AyEZbZFyzraRzcxsqmZ1p6Rk/SXrM0BobPw82mA3HpSz2WcxbQLHIijmbwoUVtgYUacqnjmIaF3aTiqTcoVi4sTlYa2VkeYt9MftMOq02oZJ77nQg9XpOKQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=EBJphSh+i9Ogw5k2vtvatvznoWng2R6nTBlPzsVHipA=; b=NwGdCx0EZKN+ozBGaMPG/I31E3a8IKghVJuo4Ud90aJm1NzWqkyBgKg/g+5Q1avvc8eG70Y7AAt0LDbbkf+s25Mj/D2KOl6KGwQqu0wEbzhqRdrbhU4B7VohLmlM3DKoL9OQMkKJzcM5YsketDDTIhnTaQ9M5ji0/4aCotge4/F6T6IZU9grL2z3UWUVTgYy4i91gqn8a/N1W8MQr1D7XcGHp5KwvArgkla/gl6fQLkTgIxTw7sfigyN9GPrBY9eyJmEPVj3gRznlbl9KTnSJzfgY9xYMUOdFDs9MhNh3njcbNLR+jFs57iyzZGqllINr/9aGDGkBP55Q5Uz4sh3/g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by IA0PR11MB7954.namprd11.prod.outlook.com (2603:10b6:208:40e::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8632.30; Sun, 13 Apr 2025 12:28:11 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::dad6:3d43:4561:3c11]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::dad6:3d43:4561:3c11%3]) with mapi id 15.20.8632.030; Sun, 13 Apr 2025 12:28:10 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: tirumal reddy <kondtir@gmail.com>
Thread-Topic: AD review of draft-ietf-dnsop-structured-dns-error
Thread-Index: AQHbpVBiuz5jGyb9gkS5MUAqEgmHlLOYRwMAgAdErhCAAdWLgIAAMxnQ
Date: Sun, 13 Apr 2025 12:28:10 +0000
Message-ID: <PH0PR11MB4966968764FA55E69F60AB59A9B02@PH0PR11MB4966.namprd11.prod.outlook.com>
References: <PH0PR11MB4966F72BAF1F83E3F80D7C0EA9A92@PH0PR11MB4966.namprd11.prod.outlook.com> <CAFpG3gc2sojMQb+joC82nLxjU-4daJzDoJgdyub8h0NXC6G7jg@mail.gmail.com> <PH0PR11MB49667337AF2C5A63D2080C40A9B12@PH0PR11MB4966.namprd11.prod.outlook.com> <CAFpG3gfqWKYs0w+2rVgF_iMNUcyA91rsdmtqjz8_GaT4GNHFrA@mail.gmail.com>
In-Reply-To: <CAFpG3gfqWKYs0w+2rVgF_iMNUcyA91rsdmtqjz8_GaT4GNHFrA@mail.gmail.com>
Accept-Language: fr-BE, en-US
Content-Language: fr-BE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR11MB4966:EE_|IA0PR11MB7954:EE_
x-ms-office365-filtering-correlation-id: 4645cf71-7adc-4cc2-2494-08dd7a86a749
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|376014|1800799024|38070700018|13003099007|8096899003|7053199007;
x-microsoft-antispam-message-info: NBXLR8ZWjIjKu2KO2uqvwbj6yO+vhqtWUmd1t0gOmkV9bOyF8GTjVGmA22mR+4aHgCfYDbNE97R0ey31WSvoUmGbjJixQFoGw9jdPTZSWvlOqKVwq1k6dY6rPDRVkkzZ6EWCZ8FC5j79V+6cNmdn4c1tARA5NEicN2CknEL1BxACQfZp/Qr1nllZTuL59jO9YeStdY1hAM8Mr0orZPzgYf6SMt2WHzmKejsKXpR1CRITuNof490GuKUbPv8VnuAy34o8bZRqudbE1Y212lwEJuVg2Jza/1T49mLVU9rOpOr9UNABC1c2CNl8A1MFR5hgU4Pl0Yh6WNvXgXb65hnEyLvsuJwiA9t6LALdsyILMCR/olszqGDuEnnw+rh5OXP2ulbZAhNWkL8EiVorfXYqSMx7JMaOqBd7nc4jGBpSB21+7tA3ym9923r8NTwlwQcBCnpHDAohopwz/DE0uvcd/hvnRVmmQVrXrCPx3Ieo/eYFLNsc20Iiw469jSfcQVENY0D2pZ+LLW7OmTWFlb7OH8xheHPnT2R9ShSkAdh/q0HM1sxshZJobO7U5b2z88XbBrPovYklHu21gtW4ebGq+GG1oRAwFRQI3zpH51wOZAE+zBLOtRmyMfInhTV8OQyubqZf9cAyUhhxrtxOpVqcerjQ/PnGOJUVWJO9a42X8gmeQ/8r06h/+3tmLYESsyqn4owheFwPdRC3/IErRiW/aIyoenL+zZS5AF9OhvYTV6IxUboHrjJ4Z46l1m6kmrowvqQ+u6M42lQWd+R92H3GG63KfehsT63cqeRf0YdAWvH7+pinNBGc4v7VzODkUFSMEhnTfR/IQiPHlOh/T7sbb7xwdSlR5U+GTyP6chh0Gb3MMaV1ke9ornKqW73CY7Gp+uCVcW7hR837uiqmMYCoYwDmSbj9kdIVCJ6XGFbwRc9ejaKsLtcVlF31ZAn/rR4gtt/J0SZBcJXfwRj5ug1Kyih8/oX5eo+otCoeWNHV3y69wC3UHhP+SJ8Lck5GtuFxHMkSUC1Wku9TP6pmwIzxKHX2JEUHONt5f5+OqtbkDyiS+Fz0UVqUaOoR4zqfkijQgV+W1flZQ7GR8x0TtM8rKuFLtHjGNaNQtVC+qYcQrg8loSzVIDbzqs5M4jHKsABADQrvIWx7oAxE4p7PlrA9NatVsv0D3a4pMDz/wiEcDFCMJzFxcUrXO0VFHXRHGM+mk1GCQOv9OFAeHCHbLro6RxmJp76FMzzvp7cLlXsEEc4zglvhZVp6rGUGf9u7VbRF9wkYTn6Df/xU87H761EaN9RbBuSbeFaXn1lhIZepIQod9f0nwGJrUf2ThvtT5tfbQCudvSNgiMg5xx51yq8zfQ2M/OIX351i94jOJT5rqC9ziNGa2G1MeTotQbl/lVwQCoAPw0OkjAG/FVRsQXZSw2bq0WNhv+bGBDXSldzhSp0=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PH0PR11MB4966.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(1800799024)(38070700018)(13003099007)(8096899003)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 9yae6PS/6QKJR1V3p9m6oXVUNz3OiY6+7+TVVlig9Bt2ASWTUjqN4ep93Vk6L+JuUkqd4roNzdJqbfMPYVqrlcXyOlX/B77gYfjW/nEXUch0uh5Z2M7giWBw8T2jyahBE6aJsV7pYbY7onWACKiSh0c/nfcbK8Ef1d0UOWZqIKlz4gY4corl7vCQnhMYhkCE7bICHsGmGco8VZRJqfSeAqWVoT9b9fesPAufsoiKWWx8tYqEdDspZCRjHnk+SjKv8SO3hTz+A0gFGLfjZaeloUKsspNplieB7W/Wg6DI/Pa1qD7AhhizdV2cJgaQKtQUl7Z6bsPnNGb2LrJjpd18+4ucKbC0oszMIZjVkp4aVjWFviBBteAqWBAGsIq0+jrFQFppTUGySvDFmGEMCUDY7jt4AHHhLezN1XdbYtNGRo8XSktoR95oXfxWK2iwh8Ax2eUsv8rOvs8k2sYDBj0vG57k2jhNtQdwPmrXUuxsfpKgVna+htTOwNS2UjJ9GcKpca2PYb5LEa3+6bA55CHi3qMbNPCTt5/Yz2SAVw3Fzp8ceLS4HoVtn9g0ey4mFgNpt8Nmiii+J806vQs2JlJH35D03YB9WfXoEu5MSsJOpn40Y3UeMiA/9JvOifvGEmTQtRXy1CDoQhBD+mblp46mgaPPQsjMKw9s45IQbdnvKUqXD7tUEARbIkfssHsDrxS9l6RaUccmepKM4/tCw67H/vQ+zr2XzxfxQsFiD5jE37NkA7Zs2keHQX1rRnkq2Yjt9YDk1k2WybnPkjS0gs3u2Vt/rvCN9e4ycRp/48ykWktpwHqFuC2AOz6HaBm5dsNJMO8JhSxWNZp9TCLda1ywlUyz4dP8zNz1VSEmh56qmir0uXRqpEPsPUDBm9KBsMuqDUkZSWFLbP2gOvTmOs/hDe08KJE7QpZDOPLAyB+pR3IvmuJx7In3QM0nGDKJWgoOgSoZQqY7Cmbsdz3g9D3RQ451X6qaBHuVTOij39uvmG0AdETdBV6vgATXLNCLmK7i4ae9I2eiRS2P4kjL9FrYJHxDlabJcA9Zz45dldciCDtSZ7rFjVUMscA5zmOr6O5cA3Dyv5I0EQSIwXesT+hPMNZHuAWv8JRd4uqP8veB7AoAKvG9b41IlT2jwqFV++s5Zn+NqqIvXuH7fSm7jOft+2geliqYiRW71IJx00kXa7dkkPcSejM35R+kHYrm4lJN04KwX5PtF4rZ2cSrFRzEU7QtarQC2DA3yJtEj80iXvCRMZ29TXrtb83TBhbh3swwg3JnHP35YYVoCTrEKPrNebv8sXt5IHtEGBPlQJeqXZBfCCpMHxZVQMvEVkuB/BhAR/AMqsg0Jc1r5DdvrH+h75cpKvqTAdVyZ0+Pb93jXxYy/DdW5HOLqxnkiza5mK4dellIbIzQxnKDTQaNDkvlMs7+uHzjw4vl6t+i5B/8EJcrhH1XY6pMVJi6eeVN7Jafpkz7ApcQ80V6hXHfPhCedFKVa91UrEaXdlXFYB+EOczheKfj2iyKTmijG+5g1OObCkmFprKbZSIxe0IE7U6LeaJTDQ/pXw8GCtIexT0aPUsgS4YQATZ8byy59ch/R757gngBSCp544crIDsP7Py/mg==
Content-Type: multipart/alternative; boundary="_000_PH0PR11MB4966968764FA55E69F60AB59A9B02PH0PR11MB4966namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4645cf71-7adc-4cc2-2494-08dd7a86a749
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Apr 2025 12:28:10.7178 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: RR8NI82HhAaN1Qp+ojunWNOxaaCQe54q/B+vSKm9O1fJmohko+7QwW1s9Zxh6+t2jNTAHApBnxNYjCDo4VPsAQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA0PR11MB7954
X-Outbound-SMTP-Client: 72.163.7.162, rcdn-opgw-1.cisco.com
X-Outbound-Node: alln-l-core-11.cisco.com
Message-ID-Hash: HG5Z7R2KDCAIQKTNJS22JICFXM45PRXE
X-Message-ID-Hash: HG5Z7R2KDCAIQKTNJS22JICFXM45PRXE
X-MailFrom: evyncke@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "dnsop@ietf.org" <dnsop@ietf.org>, "danwing@gmail.com" <danwing@gmail.com>, "neil.cook@noware.co.uk" <neil.cook@noware.co.uk>, Mohamed Boucadair <mohamed.boucadair@orange.com>, "benno@NLnetLabs.nl" <benno@nlnetlabs.nl>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: AD review of draft-ietf-dnsop-structured-dns-error
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/zWnUuh_r5PaPRlO0SIJrvebVzBc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Superb, thank you


Eric

Envoyé à partir de Outlook pour Android<https://aka.ms/AAb9ysg>
________________________________
From: tirumal reddy <kondtir@gmail.com>
Sent: Sunday, April 13, 2025 11:25:01 AM
To: Eric Vyncke (evyncke) <evyncke@cisco.com>
Cc: dnsop@ietf.org <dnsop@ietf.org>; danwing@gmail.com <danwing@gmail.com>; neil.cook@noware.co.uk <neil.cook@noware.co.uk>; Mohamed Boucadair <mohamed.boucadair@orange.com>; benno@NLnetLabs.nl <benno@nlnetlabs.nl>
Subject: Re: AD review of draft-ietf-dnsop-structured-dns-error

On Sat, 12 Apr 2025 at 11:04, Eric Vyncke (evyncke) <evyncke@cisco.com<mailto:evyncke@cisco.com>> wrote:

Tiru and other authors,



Thanks for your reply and for the revised I-D. As noted below, some points of the AD review were either not addressed at all or I still have suggestions.

We addressed the pending issues, please see https://www.ietf.org/archive/id/draft-ietf-dnsop-structured-dns-error-12.html

Best Regards,
-Tiru




Nevertheless, I am proceeding with the IETF Last Call, i.e., you may consider my AD review comments as a community review during the IETF Last Call.



Regards



-éric







From: tirumal reddy <kondtir@gmail.com<mailto:kondtir@gmail.com>>
Date: Monday, 7 April 2025 at 16:25
To: Eric Vyncke (evyncke) <evyncke@cisco.com<mailto:evyncke@cisco.com>>
Cc: dnsop@ietf.org<mailto:dnsop@ietf.org> <dnsop@ietf.org<mailto:dnsop@ietf.org>>, danwing@gmail.com<mailto:danwing@gmail.com> <danwing@gmail.com<mailto:danwing@gmail.com>>, neil.cook@noware.co.uk<mailto:neil.cook@noware.co.uk> <neil.cook@noware.co.uk<mailto:neil.cook@noware.co.uk>>, Mohamed Boucadair <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>>, benno@NLnetLabs.nl <benno@nlnetlabs.nl<mailto:benno@nlnetlabs.nl>>
Subject: Re: AD review of draft-ietf-dnsop-structured-dns-error

Hi Eric,



Thanks for the review. Please see inline



On Fri, 4 Apr 2025 at 17:27, Eric Vyncke (evyncke) <evyncke@cisco.com<mailto:evyncke@cisco.com>> wrote:

Dear authors, dear shepherd, DNSOP WG,



As Mohamed ‘Med’ Boucadair is now the responsible AD for DNSOP, he passed me the role of responsible AD for this I-D :-) Therefore, here is my own AD review. Before proceeding with the publication process (IETF Last Call and the IESG evaluation), I request to have all points below addressed, i.e., by changing the text, by replying by email wit explanations, ... (Feel free to reject my comments as long as you explain why).



Benno, the shepherd’s write-up needs to be revised:

1.     In point 1), there is an unfinished sentence “The status of Proposed Standard will”

2.     Change the responsible AD to a guy name “Éric Vyncke” ;-)



### Section 1



I am unsure whether firewalls and IPS do use DNS filtering rather than content inspection.



DNS filtering is also done by firewalls and IPS. For instance, by-pass content inspection for domains with low security risk score.





Is it worth defining “Users of DNS service”, is it the app or the user using the app ? The text also uses “end user”, is the same human being ?



Fixed text, please see https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/pull/59





` the DNS server`is a little ambiguous here, should it rather be “recursive DNS resolver“ ?



It could be either a DNS resolver or DNS forwarder.



EVY> suggest to explicitly write so in the I-D



### Section 3



` In order to return a block page over HTTPS, man in the middle (MITM)` should “without triggering an invalid TLS server authentication” be added ? Please refrain from using “MITM”, favor “on path attack” or simply “interception” in this case.



Fixed text, please see https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/pull/59





` The HTTPS server will have access` unsure which HTTPS server is referred to... is it the expected or the spoofed reply servers ?



The HTTP server hosted on the network security device, fixed text.





s/Enterprise networks do not assume/Enterprise networks do not always assume/



Should there be text in the DNSSEC bullet that if the filtering DNS server is also the DNSSEC validator, then all is good ?



Good point, updated text.





Should bullet (4) be merged in bullet (3) ?



Yes, merged.





### Section 4



Does this text add any value ` Note that [RFC7493<https://www.rfc-editor.org/rfc/rfc7493>] was based on [RFC7159<https://www.rfc-editor.org/rfc/rfc7159>] but [RFC7159<https://www.rfc-editor.org/rfc/rfc7159>] was replaced by [RFC8259<https://www.rfc-editor.org/rfc/rfc8259>].`?



Yes, it helps when going through RFC7493 to refer to RFC8259 instead of RFC7159 (RFC7493 refers to RFC7159) .





s/ This field is structured as an array of contact URIs, using/ This field is structured as an array of contact URIs that MUST use/ ?



Fixed.





Can the “l” name occur in the absence of “j” or “o” names ?



"j" is a mandatory field, so "l" cannot occur without it.



As I live in a country with 3 (+ English) languages, I sincerely regret that only one language can be used... IMHO, “j” should be an array of <language, text> especially when the end user is residential.



The idea is if the language is known, it could be translated by the client to the end-user's native language.

(My country has 22 national languages :))



EVY> Oh man... you beat me flat there ;-)

EVY> suggest adding some text around it even if I still would prefer an array of languages.



Did the WG consider using a single URI pointing to a possibly larger JSON file ?



Did the WG consider using CBOR for encoding ? It may be useful to justify in the I-D why JSON was preferred to CBOR.



JSON is already used by DNS (see RFC8427) and the spec mandates DoT, DoH or DoQ, fragmentation is not an issue over these transports.



EVY> OK, the justification is good



### Section 5.2



S/ A or AAAA record query/ A or AAAA resource record query/



Fixed.



EVY> actually not fixed...





The 2 seconds for TTL seems very short to me. I would avoid using this value even as an example.



Okay, replaced with 10 seconds.





### Section 5.3



As the I-D states `following ordered actions`, please use a numbered list.



Thanks, updated.





Also, I wonder about the actual order as the channel considerations should probably be first, before the JSON syntax.



#1 discusses implementations that both support and do not support this specification. If the input is not valid JSON, subsequent steps will be skipped.





In ` If the "c" field contains any URI scheme not registered in the Section 10.3<https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-structured-dns-error-10#IANA-Contact> registry, it MUST be discarded` it is unclear what the “it” refers to.



Fixed.





s/ In such a case, the content of the "c" attribute can be ignored/ In such a case, the content of the "c" attribute MAY be ignored/



Fixed.





The last two bullets (DNS forwarder and app) are not really part of this list but should probably appear as stand alone.



Yes, added a new section (see https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/pull/62)





### Section 6



Is worth explaining why value = 0 is there and why there are no values for 1 to 4 ?



1 to 4 are reserved for other error codes, please see Section 10.4





### Section 7



It is unclear whether the original reply is forwarded as it is received, i.e., is the information specified in this document also forwarded ?



Yes, the EXTRA-TEXT field is forwarded to the DNS client. Updated text for clarity.





### Section 10.1



I am not an application expert, but is this registration required ?



Good catch, it is not required, removed the section.





### References



draft-ietf-add-ddr-10 is now RFC 9642



draft-ietf-add-resolver-info-13 is now RFC 9606 (the authors should know ;-) )



Yes, fixed all above :)





DNS terminology is no more RFC 8499 but RFC 9499



Fixed.



Cheers,

-Tiru