Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec-algo-signal-04.txt
Miek Gieben <miek@miek.nl> Fri, 09 March 2012 09:07 UTC
Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 798C421F85F1; Fri, 9 Mar 2012 01:07:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1331284074; bh=FP/1FjQGfznkHvPHg4HeJ+jwBm5r/rGle6twh4tTDq4=; h=Date:From:To:Message-ID:References:MIME-Version:In-Reply-To: Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:List-Help: List-Subscribe:Content-Type:Sender; b=Hex3Bi5J2YBDkjOswbGr2Vd/JattMJ+Pi01z9viIyV18ZuDugQ3ijya0QRLkD+/rE oo2Z3FEWUo1bgU2apbe6naUX7c7SrKzgZzJ1k4WqImUV3OBDAVyPARxLmfoG2UgEbM BAhPQfcwzL9R7v8lAayAj1WMvI2nlsVoww6yDsX4=
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D21CB21F85AE for <dnsext@ietfa.amsl.com>; Fri, 9 Mar 2012 01:07:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.073
X-Spam-Level:
X-Spam-Status: No, score=-2.073 tagged_above=-999 required=5 tests=[AWL=0.527, BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FDBf9uX6ZcyU for <dnsext@ietfa.amsl.com>; Fri, 9 Mar 2012 01:07:52 -0800 (PST)
Received: from elektron.atoom.net (cl-201.ede-01.nl.sixxs.net [IPv6:2001:7b8:2ff:c8::2]) by ietfa.amsl.com (Postfix) with ESMTP id 4127E21F85F1 for <dnsext@ietf.org>; Fri, 9 Mar 2012 01:07:51 -0800 (PST)
Received: by elektron.atoom.net (Postfix, from userid 1000) id 93A3540004; Fri, 9 Mar 2012 10:07:48 +0100 (CET)
Date: Fri, 09 Mar 2012 10:07:48 +0100
From: Miek Gieben <miek@miek.nl>
To: dnsext@ietf.org
Message-ID: <20120309090748.GA20102@miek.nl>
Mail-Followup-To: dnsext@ietf.org
References: <20120306162935.4172.91398.idtracker@ietfa.amsl.com>
MIME-Version: 1.0
In-Reply-To: <20120306162935.4172.91398.idtracker@ietfa.amsl.com>
User-Agent: Vim/Mutt/Linux
X-Home: http://www.miek.nl
Subject: Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec-algo-signal-04.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============2836241423611916510=="
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org
[ Quoting <internet-drafts@ietf.org> at 08:29 on Mar 6 in "[dnsext] I-D Action:..." ] > > A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the DNS Extensions Working Group of the IETF. > > Title : Signaling Cryptographic Algorithm Understanding in DNSSEC > Author(s) : Steve Crocker > Scott Rose > Filename : draft-ietf-dnsext-dnssec-algo-signal-04.txt > Pages : 8 > Date : 2012-03-06 > > The DNS Security Extensions (DNSSEC) were developed to provide origin > authentication and integrity protection for DNS data by using digital > signatures. These digital signatures can be generated using > different algorithms. This draft sets out to specify a way for > validating end-system resolvers to signal to a server which > cryptographic algorithms and hash algorithms they support. I read a comment in the draft that this option list can get very long, which indeed is true. How about the following scheme: A resolver indicates the highest algorithm number it understands and thus *also* all *previous* algorithms. This way the whole option can be shortened to 4 bytes: 0: OPTION-CODE 1: DAU byte value 2: DHU byte value 3: N3U byte value And maybe this option can be renamed to Crypto Understood. A drawback is that a number of current specified features aren't available with this scheme. Regards, Miek Gieben
_______________________________________________ dnsext mailing list dnsext@ietf.org https://www.ietf.org/mailman/listinfo/dnsext
- [dnsext] I-D Action: draft-ietf-dnsext-dnssec-alg… internet-drafts
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Marc Lampo
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Warren Kumari
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Patrik Fältström
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Scott Rose
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Scott Rose
- [dnsext] FW: I-D Action: draft-ietf-dnsext-dnssec… Marc Lampo
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Mark Andrews
- Re: [dnsext] I-D Action: draft-ietf-dnsext-dnssec… Miek Gieben
- Re: [dnsext] FW: I-D Action: draft-ietf-dnsext-dn… Scott Rose