Re: [secdir] secdir review of draft-ietf-dnsext-dns-tcp-requirements-03

Ray Bellis <> Mon, 14 June 2010 10:49 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 6D2733A6885; Mon, 14 Jun 2010 03:49:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -9.305
X-Spam-Status: No, score=-9.305 tagged_above=-999 required=5 tests=[AWL=1.293, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id Q1EXhAjczzF2; Mon, 14 Jun 2010 03:49:37 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 952093A688B; Mon, 14 Jun 2010 03:49:36 -0700 (PDT)
DomainKey-Signature:;; c=nofws; q=dns; h=X-IronPort-AV:Received:Received:From:To:CC:Subject: Thread-Topic:Thread-Index:Date:Message-ID:References: In-Reply-To:Accept-Language:Content-Language: X-MS-Has-Attach:X-MS-TNEF-Correlator:Content-Type: MIME-Version; b=krIgTIu8w7O2gl86O/+uzVVtZLlrFlcjMAqmlgxhZiZUIKY+7Q+rv1sZ aoZxsIQ3+rCuTW/MaRCaqdNDee158WOAbYLaF55vgqX4pOWLCF1bxtqVL doaZQpDdoAkcW4W;
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;;; q=dns/txt; s=main.dkim.nominet.selector; t=1276512581; x=1308048581; h=from:sender:reply-to:subject:date:message-id:to:cc: mime-version:content-transfer-encoding:content-id: content-description:resent-date:resent-from:resent-sender: resent-to:resent-cc:resent-message-id:in-reply-to: references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:list-owner:list-archive; z=From:=20Ray=20Bellis=20<> |Subject:=20Re:=20secdir=20review=20of=20draft-ietf-dnsex t-dns-tcp-requirements-03|Date:=20Mon,=2014=20Jun=202010 =2010:49:37=20+0000|Message-ID:=20<AA39C80F-2467-40BD-BF2>|To:=20"<barryleiba@compute>"=20<>|CC:=20"<secdir@ietf.o rg>"=20<>,=20"<>"=20<iesg@iet>,=0D=0A=09"<draft-ietf-dnsext-dns-tcp-requirements.>"=0D=0A=09<draft-ietf-dnsext-dns-tcp-r>|MIME-Version:=201.0 |In-Reply-To:=20<AANLkTim9z6L2tPiT-6gy_YUdMUr-U3AQeJe1YKW>|References:=20<AANLkTim9z6L2tPiT-6g>; bh=k7SlM6SE4tzTcXskgwG5RSHQVZcZldBnsucLOJT78BE=; b=q1JGzg5vTom9lkUahpc+jkF4x7adqb99FPrvttnikG/vOxK82Il4DiIX Y04kgwYxzx9UUxJ4X7ATuP4FJ3fcA4LiNOnuF2SXAv2FQVn3fOoiu7HMM VSAqdutDi5MCvY4;
X-IronPort-AV: E=Sophos; i="4.53,413,1272841200"; d="scan'208,217"; a="19289450"
Received: from ([]) by with ESMTP; 14 Jun 2010 11:49:39 +0100
Received: from ([fe80::1593:1394:a91f:8f5f]) by ([fe80::7577:eaca:5241:25d4%20]) with mapi; Mon, 14 Jun 2010 11:49:38 +0100
From: Ray Bellis <>
To: "<>" <>
Thread-Topic: secdir review of draft-ietf-dnsext-dns-tcp-requirements-03
Thread-Index: AQHLA1x1KY8lbbDqwkqxPSjehhszdJKBRxSA
Date: Mon, 14 Jun 2010 10:49:37 +0000
Message-ID: <>
References: <>
In-Reply-To: <>
Accept-Language: en-GB, en-US
Content-Language: en-US
Content-Type: multipart/alternative; boundary="_000_AA39C80F246740BDBF20AE7C31A82BC2nominetorguk_"
MIME-Version: 1.0
X-Mailman-Approved-At: Mon, 14 Jun 2010 08:03:01 -0700
Cc: "<>" <>, "<>" <>, "<>" <>
Subject: Re: [secdir] secdir review of draft-ietf-dnsext-dns-tcp-requirements-03
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 14 Jun 2010 10:49:38 -0000

I have only one minor comment, in the Security Considerations section:

  At the time of writing the vast majority of TLD authority servers and
  all of the root name servers support TCP and the author knows of no
  evidence to suggest that TCP-based DoS attacks against existing DNS
  infrastructure are commonplace.

Since this is a working group document, not an individual or
independent submission, I'd rather see "and the dnsext working group
knows of no evidence", to stress that the fact was reviewed by the
working group, and the statement has working group consensus.  This
is, of course, assuming that that's truly the case -- if it is not,
then I do have an issue with that.

Well, during the substantial WG review the working group didn't tell me of any TCP-based DoS attacks against DNS, so in that respect the author _still_ knows of no evidence... ;-)

Olafur - what would you recommend?