[secdir] SECDIR review of draft-ietf-dnsop-svcb-dane-01
Donald Eastlake <d3e3e3@gmail.com> Wed, 12 July 2023 21:28 UTC
Return-Path: <d3e3e3@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D02FC14068D; Wed, 12 Jul 2023 14:28:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.847
X-Spam-Level:
X-Spam-Status: No, score=-1.847 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s5t5L_-mCStB; Wed, 12 Jul 2023 14:28:19 -0700 (PDT)
Received: from mail-ed1-x52e.google.com (mail-ed1-x52e.google.com [IPv6:2a00:1450:4864:20::52e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 85B55C157902; Wed, 12 Jul 2023 14:28:16 -0700 (PDT)
Received: by mail-ed1-x52e.google.com with SMTP id 4fb4d7f45d1cf-51e2a6a3768so9308038a12.0; Wed, 12 Jul 2023 14:28:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1689197294; x=1691789294; h=cc:to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=wHHIgOQ2ELXUizxZv5UWDq3fsDxcmPQb6mZeIo7jSaA=; b=fNFKxJbcjIwe056kxss68Gk/vkDEFEWROC3YNjFfKslMqMTsrm8+NP1g4q/Y/7Cfow pClfoOGy7KQ9mZ8XyAjODPg9dQ80iiAFSymVyjbRUX42cWRWtGo5UQ7x+KQKA/BKCrP7 uheS17oGFHLz6kFLj88tQuoGwL1xdBvYIvOEcaeJktfO4CEqpleFmvtw5k8N1DjgToqs i8Tj7QKHlWX7B+qrDlPUdBYSCOrRUe1O63SKty3REiKo+LGd5HfANsJ03kgss+DgMznJ NoIvu9ep6DO4hyScjqBeVC67xOl1fRLH0La1sIAFhBB9AXPRY3vlqcgqNZXjD5T9yPgH 31KA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1689197294; x=1691789294; h=cc:to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=wHHIgOQ2ELXUizxZv5UWDq3fsDxcmPQb6mZeIo7jSaA=; b=VdfUxF8oJ72oaIwUtFXzjg5MJQUIn3zSQSBYU7q+UoH1z3A751vZG+TsdZDMb6IKE1 yixnDwtfBukuVQ6DicASJIc4bAnKQG3oY5q+WopZWBEKevTg1EtTLMbWprgToyPiLbJ9 HtkmERJWFZqDE7CzaJ4Pa5JEiaLXjmwMShJ4R7vhw1NnUznxnA7y5cX7+160MKTcg1k2 gpXqf8MCDGWcaMamX/FSLVA8CXvq175VeUJfCKqiReqYnAG6OobyPSxIb3tK2dMAjox4 t4emh3CxjEX7IQoEZh733KA5IqeRW8lUfQWxBK//VYDoCFdyrrvMhzUn3TbN8bzwd65C hQZQ==
X-Gm-Message-State: ABy/qLYGJWHPA0bM/2YK5YohLyYRkQUUHw+CZxHKtDmv7evPNGsk295L uu6R+zaZzevY7j+OkoSkHL+XfaY2pa4pKDrI7DgxyojxcDg=
X-Google-Smtp-Source: APBJJlF5ay7gWh3xYwNir3HH2c3X1j3sJvfUKKlL969Vm2i7LcIO76S8Vg38QIa2TPsUaEXfGhTdmYiT994FDQITCxk=
X-Received: by 2002:aa7:dbd2:0:b0:51e:5ec8:d2f7 with SMTP id v18-20020aa7dbd2000000b0051e5ec8d2f7mr7579058edt.30.1689197293874; Wed, 12 Jul 2023 14:28:13 -0700 (PDT)
MIME-Version: 1.0
From: Donald Eastlake <d3e3e3@gmail.com>
Date: Wed, 12 Jul 2023 17:28:02 -0400
Message-ID: <CAF4+nEFjzZDXyD1=Vc5b2ZdcqFk2BJz4s4OZOn19w5QTbLCe=g@mail.gmail.com>
To: draft-ietf-dnsop-svcb-dane.all@ietf.org
Cc: secdir <secdir@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a8346b060050e48e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/q3RNK2e-XR-rG0F4OWlJG_NZpq0>
Subject: [secdir] SECDIR review of draft-ietf-dnsop-svcb-dane-01
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Jul 2023 21:28:20 -0000
I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents. Document editors and WG chairs should
treat these comments just like any other comments.
The summary of the review is Ready with nits.
This document specifies the interaction of DANE (DNS-Based Authentication
of Named Entities) and DNS Service Bindings (SVCB). It also adds "_quic" to
the IANA Underscored and Globally Scoped DNS Node Names registry for use
with the TLSA Resource Record (RR).
This is an early review. The document appears to be adequate from a
security perspective. The heavy lifting occurs through the use of DNSSEC
and TLS/DTLS specified elsewhere. This document is mostly about how things
fit together and what various RRs would look like. It includes the TLV 1.3
RFC in the References section and should probably also include DNSSEC
references which should be referred to at an appropriate place in the text.
I provide some comments below, most of which are just wording suggestions.
First page headings: "Updates" should just have the RFC number "6698" not
"rfc6698" (See in the xml source where it says 'updates="rfc6698" '.)
Title: I suggest expanding a bit to something like the following, which
the RFC Editor may want you to do anyway:
"Using DNS Service Bindings (SVCB) with DNS-Based Authentication of
Named Entities (DANE)"
Abstract: I think it should mention "_quic". I suggest something like
DNS Service Binding (SVCB) resource records (RRs) add a new form of name
indirection to the DNS. This document specifies DNS-Based Authentication of
Named Entities (DANE) interaction with Service Bindings to secure
endpoints, including the use of ports and transports discovered via Service
Parameters. It also specifies the _quic underscored DNS node name to
designate the QUIC transport.
Section 1, last word of first paragraph: maybe "TLS" -> "TLS/DTLS".
This document would benefit from some additional terminology definitions in
Section 2 for such things as SvcParam and SNI. Perhaps there should be a
reference to the DNS terminology draft-ietf-dnsop-rfc8499bis-08.
Section 3, 2nd paragraph: "was entirely secure" -> "was entirely secured by
DNSSEC".
Section 5.2: Is "Accidental" the right word in the Section name? Would
"Erroneous" or some other word be better?
- It isn't clear from the text what a "third-party consumer" is. Maybe a
figure with boxes would help. "third-party" is hyphenated in one place but
not in another.
- In the last sentence, "take caution" sounds a little odd to me; suggest
either "take care" or "be cautious".
Section 6, first line: suggest "property" -> "part"
Section 8: Seems more polite to say "requested" rather than "instructed".
Thanks,
Donald
===============================
Donald E. Eastlake 3rd +1-508-333-2270 (cell)
2386 Panoramic Circle, Apopka, FL 32703 USA
d3e3e3@gmail.com
- [secdir] SECDIR review of draft-ietf-dnsop-svcb-d… Donald Eastlake
- Re: [secdir] SECDIR review of draft-ietf-dnsop-sv… Ben Schwartz