Re: [Editorial Errata Reported] RFC6672 (5297)

"W.C.A. Wijngaards" <[email protected]> Fri, 23 Mar 2018 16:43:35 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8830934889813968946==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="MKkIdRvDlItXlbOj5IZYATwWROvSP2bLw"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--MKkIdRvDlItXlbOj5IZYATwWROvSP2bLw
Content-Type: multipart/mixed; boundary="7AjaXvMsofuM93hLMCzVsTZbmyOBav1rB";
 protected-headers="v1"
From: "W.C.A. Wijngaards" <[email protected]>
To: Warren Kumari <[email protected]>
Cc: "Rose, Scott" <[email protected]>, Suresh Krishnan <[email protected]>,
 Terry Manderson <[email protected]>,
 Olafur Gudmundsson <[email protected]>, Andrew Sullivan
 <[email protected]>, [email protected],
 Pieter Lexis <[email protected]>
Message-ID: <[email protected]>
Subject: Re: [dnsext] [Editorial Errata Reported] RFC6672 (5297)
References: <[email protected]>
 <CAHw9_iJ1nJ2QJPQPtOPOzN7K+8Hx12Y=t0BQwcbp8KwjJc4+bA@mail.gmail.com>
In-Reply-To: <CAHw9_iJ1nJ2QJPQPtOPOzN7K+8Hx12Y=t0BQwcbp8KwjJc4+bA@mail.gmail.com>

--7AjaXvMsofuM93hLMCzVsTZbmyOBav1rB
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Hi,

Seems fine to me too.  Also Pieter's (5298) which is also about missing
out on the NSEC and RRSIG bits.  They aren't actually the focus, which
is why no-one missed them I guess (together with all the omitted RRSIG
fields?), but adding NSEC and RRSIG bits is correct for a signed zone.

Best regards, Wouter

On 23/03/18 16:27, Warren Kumari wrote:
> [ - RFC Editor for clutter ]
>=20
> This *seems* correct to me, but my brain turned into jelly much
> earlier in the week -- anyone disagree with the errata?
>=20
> W
>=20
> On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System
> <[email protected]> wrote:
>> The following errata report has been submitted for RFC6672,
>> "DNAME Redirection in the DNS".
>>
>> --------------------------------------
>> You may review the report below and at:
>> http://www.rfc-editor.org/errata/eid5297
>>
>> --------------------------------------
>> Type: Editorial
>> Reported by: Pieter Lexis <[email protected]>
>>
>> Section: 5.3.4.1
>>
>> Original Text
>> -------------
>>    ;; Header: QR AA RCODE=3D3(NXDOMAIN)
>>    ;; OPT PSEUDOSECTION:
>>    ; EDNS: version: 0, flags: do; udp: 4096
>>
>>    ;; Question
>>    foo.bar.example.com. IN A
>>    ;; Authority
>>    bar.example.com. NSEC dub.example.com. A DNAME
>>    bar.example.com. RRSIG NSEC [valid signature]
>>
>> Corrected Text
>> --------------
>>    ;; Header: QR AA RCODE=3D3(NXDOMAIN)
>>    ;; OPT PSEUDOSECTION:
>>    ; EDNS: version: 0, flags: do; udp: 4096
>>
>>    ;; Question
>>    foo.bar.example.com. IN A
>>    ;; Authority
>>    bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC
>>    bar.example.com. RRSIG NSEC [valid signature]
>>
>> Notes
>> -----
>> The NSEC record in the original text would in no case be valid as it d=
enies it's own existence and the existence of the RRSIG, while the text i=
ndicates that " the validator can see that it is a  BOGUS reply from an a=
ttacker that collated existing records from the DNS to create a confusing=
 reply". This indicates that NSEC and RRSIG should be set in the NSEC bit=
map
>>
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". If necessary, please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party
>> can log in to change the status and edit the report, if necessary.
>>
>> --------------------------------------
>> RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26)
>> --------------------------------------
>> Title               : DNAME Redirection in the DNS
>> Publication Date    : June 2012
>> Author(s)           : S. Rose, W. Wijngaards
>> Category            : PROPOSED STANDARD
>> Source              : DNS Extensions
>> Area                : Internet
>> Stream              : IETF
>> Verifying Party     : IESG
>>
>> _______________________________________________
>> dnsext mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/dnsext
>=20
>=20
>=20



--7AjaXvMsofuM93hLMCzVsTZbmyOBav1rB--

--MKkIdRvDlItXlbOj5IZYATwWROvSP2bLw
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE7fqj8spObrBWga+On28cLX4EX40FAlq1IKcACgkQn28cLX4E
X41yIQ//Q4dX4zqJqGP2JaEXF2YIzbydM/73vympWPTqjTeo0RtlwFXKAT+cDoPA
hmbWIhOwWTv3PiAOv5DN6zpxvo9v7TkaW1QJdjV6ozjVCsdyi6W3BeBjt7zDRIXe
+98DEG6wlq5wEmLE9KOM9N9EPcFiu/ng2jQsy6/OA30PV24Ymq4st3+ESbY/2yIU
xjudony2BpePPmqoIwfXMELRAoBZeS+APoCA3ZXZ7sLVUNyvFWp4zc4N/MMxsK4j
4jFnaElcd6Hzkv0lI5d/0t0YSo3IYGJoH4yxRNZROsIkO3kdefzavwidzZI1hnLz
R7NeZqaviq+zbuOOoKrNNiYZhBf3Vc3krD6nL8Z7zZXhvOt6rODh7tvNF6JhAYDU
hpS6EaxCMy9ntwJlajaMENqxYPSrBx+NTeKSec5v9k6EqVBVfIznd9mArJpGv8bD
SAbsCyu/r57QeUtPF6hi8YKFmX/eT495hMVYRb+8io2ZhXfk9sgoIvKOE1hzILIb
O5WwYO/AtOYgT07LDoWaNLOf3sj5SYhzjkxdv9+AvF4NXZ0rl0TF809UJac+/R+B
T/3VGk8mtOytISJdlu6oV7TE3qEX1AzruLOyK49YQL8MNEl+d9ejw1G8W0gqZHLm
20jX2CaO8ZbWF56LAg3n9tamF+7X/9s6BijRd7jUlKy8RRZcA8o=
=ZhKn
-----END PGP SIGNATURE-----

--MKkIdRvDlItXlbOj5IZYATwWROvSP2bLw--


--===============8830934889813968946==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext

--===============8830934889813968946==--