Re: [IPsec] Alexey Melnikov's Discuss on draft-ietf-ipsecme-split-dns-14: (with DISCUSS)

Alexey Melnikov <aamelnikov@fastmail.fm> Mon, 19 November 2018 13:58 UTC

Return-Path: <aamelnikov@fastmail.fm>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E616C130DC7; Mon, 19 Nov 2018 05:58:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fastmail.fm header.b=BnB+C4v9; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=PTFsRhim
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hzh3cY4lR8Xv; Mon, 19 Nov 2018 05:58:11 -0800 (PST)
Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1F2D9130DCC; Mon, 19 Nov 2018 05:58:11 -0800 (PST)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id 9D80F2208B; Mon, 19 Nov 2018 08:58:09 -0500 (EST)
Received: from web5 ([10.202.2.215]) by compute7.internal (MEProxy); Mon, 19 Nov 2018 08:58:09 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fastmail.fm; h= message-id:from:to:cc:mime-version:content-transfer-encoding :content-type:references:subject:in-reply-to:date; s=fm1; bh=QHu 0cW7/HoeDBS4EAuyMvpkddRJJbgKfxh4ofYsLQ/U=; b=BnB+C4v9UsV8wE7ctYS ukSgzhKsGK68RdPq+ivmGcWSoEkzhYJyeSpIf7YthM1oly2g71ieEDLpTke7kaEP YT/Oze61ed69Rfly7fdsfAfBX3V5eHG5Jh/UnFx1xsbEogApZ79mhEtqxJ2obQ+f PDK7A3w9IKHZZ+Ls5l9SJj0YhvDVeP54wc7lUtgtVaqFChalmvG4LgFcX9sFXRlk W17cflRx7jd0EWbdEc0sbo++cscx1F8vG0tG9S7qhL+7K2mrfRHwtTWFBYXOsQk5 qs7QQVxDiK2fcHT7krXTEEykPVYBbBxiVj2QEoFgwQgjIbBkyaPhqYG12tHrouuj iHw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; bh=QHu0cW7/HoeDBS4EAuyMvpkddRJJbgKfxh4ofYsLQ /U=; b=PTFsRhimH4M+T1abraf/+f5s5A5wT1DicSDiDF05+zFstHfusQqJ962oH K3bVS2DlwaCIGXr99E3V4rYeYk29I6uzJ6rpwmYNY949TfRes8u614K+TDHPSRG+ CSEPhLmbvPrJ3RXPZ2pi0blLi7nQJn/ug7Q6EBQwHqKVi2puCHQ7l7ja9W2qRnSu 33zRhCgO3hGtLttW0Yt06Se/QbZoCYPJFYQOlFqDcVM7BDs6FBwUrtONED78FUwM mEuP4hp8GlAp1MUMUjPory0w4MYnXEEqgSS/mhFnRfN++kp/VHPRrITGeWZADF2s No50ztjKcRtA2bESldcFcHFfZWDLw==
X-ME-Sender: <xms:ccHyW-jA4u0yJoi-2Iafs3RkGoCWDVxlEMj1JsXxljcn5QmEE9-tZg>
X-ME-Proxy: <xmx:ccHyW02dAbxYnSVUwjhPFHkivtShrhNiwHRGH-k5X0EY__h72jrs_w> <xmx:ccHyW_QdSH38EjSORjPdDxjaIG3vi5nUtdIfR-gVWCyGvG5E7oM9wQ> <xmx:ccHyW-tBaH8_CKAogsUBNmYD05hEL6waisbTIkpmQyR12mUhZMMlLg> <xmx:ccHyW8awB2N1th1tmsWS1iR-4IlimBGeAlmCjDeH7bQh9DYdixSvew> <xmx:ccHyW7sTOFtQU3wtgZWwvuHRgzUa_VHJGgaOdVDIX0tOCSUCGq78rw> <xmx:ccHyWyMiD-81RGbKpcXgHMpoZ9lx1vzruFRbOfp8gDQbHpNfx3HhWw>
Received: by mailuser.nyi.internal (Postfix, from userid 99) id 2516A9E1EC; Mon, 19 Nov 2018 08:58:09 -0500 (EST)
Message-Id: <1542635889.4088149.1581869784.6FFDF4B4@webmail.messagingengine.com>
From: Alexey Melnikov <aamelnikov@fastmail.fm>
To: Paul Wouters <pwouters@redhat.com>, The IESG <iesg@ietf.org>
Cc: draft-ietf-ipsecme-split-dns@ietf.org, David Waltermire <david.waltermire@nist.gov>, ipsecme-chairs@ietf.org, ipsec@ietf.org
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="utf-8"
X-Mailer: MessagingEngine.com Webmail Interface - ajax-3449945b
References: <154247645671.15969.2304550137908278124.idtracker@ietfa.amsl.com> <559e3d1d-ad44-ccd5-e3ed-2f2ac88facb9@redhat.com>
In-Reply-To: <559e3d1d-ad44-ccd5-e3ed-2f2ac88facb9@redhat.com>
Date: Mon, 19 Nov 2018 13:58:09 +0000
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/IoKsBgmQyjOKuO5sOP-1qBnVRlA>
Subject: Re: [IPsec] Alexey Melnikov's Discuss on draft-ietf-ipsecme-split-dns-14: (with DISCUSS)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Nov 2018 13:58:13 -0000

Hi Paul,

On Mon, Nov 19, 2018, at 4:50 AM, Paul Wouters wrote:
> On 2018-11-18 12:40 a.m., Alexey Melnikov wrote:
> > ----------------------------------------------------------------------
> > DISCUSS:
> > ----------------------------------------------------------------------
> >
> > This is a well written document, so thank you for that.
> > I've noticed that Benjamin already found typos that I found and raised one of
> > the same questions, but I think this is important enough to be addressed before
> > I recommend approval of this document. Specifically:
> >
> > In Section 3.1:
> >
> >     o  Domain Name (0 or more octets) - A Fully Qualified Domain Name
> >        used for Split DNS rules, such as "example.com", in DNS
> >        presentation format and optionally using IDNA [RFC5890] for
> >        Internationalized Domain Names.
> >
> > Do you mean A-label or U-label form here?
> 
> 
> I thought it was obvious that we meant A-label. Why else refer to IDN if 
> you would just put in U-label, but I'll add the A-label term.

There are documents which allow either, so being clear on this point is important.

Thank you,
Alexey