Re: [Editorial Errata Reported] RFC6672 (5297)
"Rose, Scott" <[email protected]> Fri, 23 Mar 2018 13:49:31 -0400
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
--===============6286002398591735409== Content-Type: multipart/alternative; boundary="=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_=" --=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_= Content-Type: text/plain; format=flowed I agree with Wouter. It is technically correct* this way. The same goes with the other errata (5298). They both should be approved, IMHO. Scott *The Best Kind of Correct On 23 Mar 2018, at 11:43, W.C.A. Wijngaards wrote: > Hi, > > Seems fine to me too. Also Pieter's (5298) which is also about > missing > out on the NSEC and RRSIG bits. They aren't actually the focus, which > is why no-one missed them I guess (together with all the omitted RRSIG > fields?), but adding NSEC and RRSIG bits is correct for a signed zone. > > Best regards, Wouter > > On 23/03/18 16:27, Warren Kumari wrote: >> [ - RFC Editor for clutter ] >> >> This *seems* correct to me, but my brain turned into jelly much >> earlier in the week -- anyone disagree with the errata? >> >> W >> >> On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System >> <[email protected]> wrote: >>> The following errata report has been submitted for RFC6672, >>> "DNAME Redirection in the DNS". >>> >>> -------------------------------------- >>> You may review the report below and at: >>> http://www.rfc-editor.org/errata/eid5297 >>> >>> -------------------------------------- >>> Type: Editorial >>> Reported by: Pieter Lexis <[email protected]> >>> >>> Section: 5.3.4.1 >>> >>> Original Text >>> ------------- >>> ;; Header: QR AA RCODE=3(NXDOMAIN) >>> ;; OPT PSEUDOSECTION: >>> ; EDNS: version: 0, flags: do; udp: 4096 >>> >>> ;; Question >>> foo.bar.example.com. IN A >>> ;; Authority >>> bar.example.com. NSEC dub.example.com. A DNAME >>> bar.example.com. RRSIG NSEC [valid signature] >>> >>> Corrected Text >>> -------------- >>> ;; Header: QR AA RCODE=3(NXDOMAIN) >>> ;; OPT PSEUDOSECTION: >>> ; EDNS: version: 0, flags: do; udp: 4096 >>> >>> ;; Question >>> foo.bar.example.com. IN A >>> ;; Authority >>> bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC >>> bar.example.com. RRSIG NSEC [valid signature] >>> >>> Notes >>> ----- >>> The NSEC record in the original text would in no case be valid as it >>> denies it's own existence and the existence of the RRSIG, while the >>> text indicates that " the validator can see that it is a BOGUS >>> reply from an attacker that collated existing records from the DNS >>> to create a confusing reply". This indicates that NSEC and RRSIG >>> should be set in the NSEC bitmap >>> >>> Instructions: >>> ------------- >>> This erratum is currently posted as "Reported". If necessary, please >>> use "Reply All" to discuss whether it should be verified or >>> rejected. When a decision is reached, the verifying party >>> can log in to change the status and edit the report, if necessary. >>> >>> -------------------------------------- >>> RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26) >>> -------------------------------------- >>> Title : DNAME Redirection in the DNS >>> Publication Date : June 2012 >>> Author(s) : S. Rose, W. Wijngaards >>> Category : PROPOSED STANDARD >>> Source : DNS Extensions >>> Area : Internet >>> Stream : IETF >>> Verifying Party : IESG >>> >>> _______________________________________________ >>> dnsext mailing list >>> [email protected] >>> https://www.ietf.org/mailman/listinfo/dnsext >> >> >> =================================== Scott Rose NIST ITL [email protected] +1-301-975-8439 GV: +1-571-249-3671 =================================== --=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_= Content-Type: text/html Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/xhtml; charset=3Dutf-8"= > </head> <body> <div><div style=3D"white-space:normal"><p dir=3D"auto">I agree with Woute= r. It is technically correct* this way. The same goes with the other er= rata (5298). They both should be approved, IMHO.</p> <br><p dir=3D"auto">Scott<br> *The Best Kind of Correct</p> <br><p dir=3D"auto">On 23 Mar 2018, at 11:43, W.C.A. Wijngaards wrote:</p= > <blockquote><p dir=3D"auto">Hi,<br> <br> Seems fine to me too. Also Pieter's (5298) which is also about missing<b= r> out on the NSEC and RRSIG bits. They aren't actually the focus, which<br= > is why no-one missed them I guess (together with all the omitted RRSIG<br= > fields?), but adding NSEC and RRSIG bits is correct for a signed zone.<br= > <br> Best regards, Wouter<br> <br> On 23/03/18 16:27, Warren Kumari wrote:</p> <blockquote><p dir=3D"auto">[ - RFC Editor for clutter ]<br> <br> This *seems* correct to me, but my brain turned into jelly much<br> earlier in the week -- anyone disagree with the errata?<br> <br> W<br> <br> On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System<br> <[email protected]> wrote:</p> <blockquote><p dir=3D"auto">The following errata report has been submitte= d for RFC6672,<br> "DNAME Redirection in the DNS".<br> <br> --------------------------------------<br> You may review the report below and at:<br> <a href=3D"http://www.rfc-editor.org/errata/eid5297">http://www.rfc-edito= r.org/errata/eid5297</a><br> <br> --------------------------------------<br> Type: Editorial<br> Reported by: Pieter Lexis <[email protected]><br> <br> Section: 5.3.4.1<br> <br> Original Text<br> -------------<br> ;; Header: QR AA RCODE=3D3(NXDOMAIN)<br> ;; OPT PSEUDOSECTION:<br> ; EDNS: version: 0, flags: do; udp: 4096<br> <br> ;; Question<br> foo.bar.example.com. IN A<br> ;; Authority<br> bar.example.com. NSEC dub.example.com. A DNAME<br> bar.example.com. RRSIG NSEC [valid signature]<br> <br> Corrected Text<br> --------------<br> ;; Header: QR AA RCODE=3D3(NXDOMAIN)<br> ;; OPT PSEUDOSECTION:<br> ; EDNS: version: 0, flags: do; udp: 4096<br> <br> ;; Question<br> foo.bar.example.com. IN A<br> ;; Authority<br> bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC<br> bar.example.com. RRSIG NSEC [valid signature]<br> <br> Notes<br> -----<br> The NSEC record in the original text would in no case be valid as it deni= es it's own existence and the existence of the RRSIG, while the text indi= cates that " the validator can see that it is a BOGUS reply from an atta= cker that collated existing records from the DNS to create a confusing re= ply". This indicates that NSEC and RRSIG should be set in the NSEC bitmap= <br> <br> Instructions:<br> -------------<br> This erratum is currently posted as "Reported". If necessary, please<br> use "Reply All" to discuss whether it should be verified or<br> rejected. When a decision is reached, the verifying party<br> can log in to change the status and edit the report, if necessary.<br> <br> --------------------------------------<br> RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26)<br> --------------------------------------<br> Title : DNAME Redirection in the DNS<br> Publication Date : June 2012<br> Author(s) : S. Rose, W. Wijngaards<br> Category : PROPOSED STANDARD<br> Source : DNS Extensions<br> Area : Internet<br> Stream : IETF<br> Verifying Party : IESG<br> <br> _______________________________________________<br> dnsext mailing list<br> [email protected]<br> <a href=3D"https://www.ietf.org/mailman/listinfo/dnsext">https://www.ietf= =2Eorg/mailman/listinfo/dnsext</a></p> </blockquote><br></blockquote></blockquote><br><p dir=3D"auto">=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D<br> Scott Rose<br> NIST ITL<br> [email protected]<br> +1-301-975-8439<br> GV: +1-571-249-3671<br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</p> </div> </div> </body> </html> --=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_=-- --===============6286002398591735409== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext --===============6286002398591735409==--