Re: OPENPGPKEY RRTYPE review - Comments period ends Aug 6th

Olafur Gudmundsson <[email protected]> Thu, 24 Jul 2014 06:06:31 -0400
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
<hat dane co-chair> 
On Jul 23, 2014, at 11:10 PM, Jay Daley <[email protected]> wrote:

> 
> On 24/07/2014, at 3:02 pm, Mark Andrews <[email protected]> wrote:
> 
>> 
>> In message <[email protected]>, Joe Abley writes:
>>> Hi Jay,
>>> 
>>> On 23 July 2014 at 19:09:06, Jay Daley ([email protected]) wrote:
>>> 
>>>> The text contains this specification element:
>>>> 
>>>> 3. The string "_openpgpkey" becomes the second left-most label in
>>>> the prepared domain name.
>>>> 
>>>> without any explanation (that I can see) of a) why it is needed and b) why 
>>> openpgpkey has 
>>>> been chosen.
>>> 
>>> I have no skin in this game, but it seems to me that use of an underscore lab
>>> el is a reasonable way to avoid overloading a zone apex with yet another larg
>>> e RRType that would (if used) no doubt gleefully be abused by amplification m
>>> onkeys.
>> 
>> It also creates a distinct namespace for the mapped email addresses
>> for this purpose.  This is one thing the existing mbox encoding got
>> wrong.
> 
> I understand that.  My questions should perhaps be better put as 
> 
> - why should there be a distinct namespace for mapped email addresses?  
> I see Joe has provided one reason (which doesn't appear to make sense to me since a large RRType can't be 'hidden' lower down), but my point is that there isn't a reason in the draft.
> 

Few reasons, one not to collide with regular names (unlikely in the first place) 
Secondly this allows the namespace to be delegated to the E-mail department to maintain. 
Thirdly if you do not want to have this extra label then you can just do the following
	_openpgpkey.foo.example.  DNAME foo.example. 
or 
	_openpgpkey.foo.example. DNAME _email.foo.example. 

> - why should that distinct namespace have a 1 to 1 link with the RR that it will contain?  
> This I think is something quite novel and worth a lot more discussion.
> 


Good point, namespaces are cheap, but we should think about the big picture. 
Well we also have a Smime draft that has different namespace “_smimecert” 
maybe we should think about having only one namespace for email “certs”. 

This is a discussion that probably needs bigger review than dnsext.

	Olafur

> cheers
> Jay
> 
>> 
>>> Joe
>>> 
>>> 
>>> _______________________________________________
>>> dnsext mailing list
>>> [email protected]
>>> https://www.ietf.org/mailman/listinfo/dnsext
>> -- 
>> Mark Andrews, ISC
>> 1 Seymour St., Dundas Valley, NSW 2117, Australia
>> PHONE: +61 2 9871 4742                 INTERNET: [email protected]
> 
> 
> -- 
> Jay Daley
> Chief Executive
> .nz Registry Services (New Zealand Domain Name Registry Limited)
> desk: +64 4 931 6977
> mobile: +64 21 678840
> linkedin: www.linkedin.com/in/jaydaley
> 
> _______________________________________________
> dnsext mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/dnsext

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext