Re: OPENPGPKEY RRTYPE review - Comments period ends Aug 6th

Mark Andrews <[email protected]> Thu, 24 Jul 2014 13:56:48 +1000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
In message <[email protected]>, Jay Daley writes
:
>
> On 24/07/2014, at 3:02 pm, Mark Andrews <[email protected]> wrote:
>
> >
> > In message <[email protected]>, Joe Abley
> > writes:
> >> Hi Jay,
> >>
> >> On 23 July 2014 at 19:09:06, Jay Daley ([email protected]) wrote:
> >>
> >>> The text contains this specification element:
> >>>
> >>> 3. The string "_openpgpkey" becomes the second left-most label in
> >>> the prepared domain name.
> >>>
> >>> without any explanation (that I can see) of a) why it is needed and
> >>> b) why openpgpkey has been chosen.
> >>
> >> I have no skin in this game, but it seems to me that use of an
> >> underscore label is a reasonable way to avoid overloading a zone
> >> apex with yet another large RRType that would (if used) no doubt
> >> gleefully be abused by amplification monkeys.
> >
> > It also creates a distinct namespace for the mapped email addresses
> > for this purpose.  This is one thing the existing mbox encoding got
> > wrong.
>
> I understand that.  My questions should perhaps be better put as
>
> - why should there be a distinct namespace for mapped email addresses?
> I see Joe has provided one reason (which doesn't appear to make sense to
> me since a large RRType can't be 'hidden' lower down), but my point is
> that there isn't a reason in the draft.

Because it it is bad to mix foo.example.net the host with [email protected]
the email address as they are different entities.  mbox did this.
Both mapped to foo.example.net in the DNS.  This results in overloading
so you can't know which records at the name apply to which entity.  Does
a TXT record refer to foo.example.net or [email protected]?

> - why should that distinct namespace have a 1 to 1 link with the RR that
> it will contain?
> This I think is something quite novel and worth a lot more discussion.

Take CERT for example.  You may have may protocols that all use
[email protected] but each has a different CERT record.  By having
different namespace for each protocol you avoid stuffing too many
records at a node (we are still limited to 64k).  If you want to
use the same CERT for multiple services you can enter it multiple
times or use CNAME to refer to a single instance.

> cheers
> Jay
>
> >
> >> Joe
> >>
> >>
> >> _______________________________________________
> >> dnsext mailing list
> >> [email protected]
> >> https://www.ietf.org/mailman/listinfo/dnsext
> > --
> > Mark Andrews, ISC
> > 1 Seymour St., Dundas Valley, NSW 2117, Australia
> > PHONE: +61 2 9871 4742                 INTERNET: [email protected]
>
>
> --
> Jay Daley
> Chief Executive
> .nz Registry Services (New Zealand Domain Name Registry Limited)
> desk: +64 4 931 6977
> mobile: +64 21 678840
> linkedin: www.linkedin.com/in/jaydaley
>

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [email protected]

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext