Re: [Editorial Errata Reported] RFC6672 (5297)

"Rose, Scott" <[email protected]> Fri, 23 Mar 2018 13:49:31 -0400
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
--===============6286002398591735409==
Content-Type: multipart/alternative;
 boundary="=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_="

--=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_=
Content-Type: text/plain; format=flowed

I agree with Wouter.  It is technically correct* this way.  The same 
goes with the other errata (5298).  They both should be approved, IMHO.


Scott
*The Best Kind of Correct


On 23 Mar 2018, at 11:43, W.C.A. Wijngaards wrote:

> Hi,
>
> Seems fine to me too.  Also Pieter's (5298) which is also about 
> missing
> out on the NSEC and RRSIG bits.  They aren't actually the focus, which
> is why no-one missed them I guess (together with all the omitted RRSIG
> fields?), but adding NSEC and RRSIG bits is correct for a signed zone.
>
> Best regards, Wouter
>
> On 23/03/18 16:27, Warren Kumari wrote:
>> [ - RFC Editor for clutter ]
>>
>> This *seems* correct to me, but my brain turned into jelly much
>> earlier in the week -- anyone disagree with the errata?
>>
>> W
>>
>> On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System
>> <[email protected]> wrote:
>>> The following errata report has been submitted for RFC6672,
>>> "DNAME Redirection in the DNS".
>>>
>>> --------------------------------------
>>> You may review the report below and at:
>>> http://www.rfc-editor.org/errata/eid5297
>>>
>>> --------------------------------------
>>> Type: Editorial
>>> Reported by: Pieter Lexis <[email protected]>
>>>
>>> Section: 5.3.4.1
>>>
>>> Original Text
>>> -------------
>>>    ;; Header: QR AA RCODE=3(NXDOMAIN)
>>>    ;; OPT PSEUDOSECTION:
>>>    ; EDNS: version: 0, flags: do; udp: 4096
>>>
>>>    ;; Question
>>>    foo.bar.example.com. IN A
>>>    ;; Authority
>>>    bar.example.com. NSEC dub.example.com. A DNAME
>>>    bar.example.com. RRSIG NSEC [valid signature]
>>>
>>> Corrected Text
>>> --------------
>>>    ;; Header: QR AA RCODE=3(NXDOMAIN)
>>>    ;; OPT PSEUDOSECTION:
>>>    ; EDNS: version: 0, flags: do; udp: 4096
>>>
>>>    ;; Question
>>>    foo.bar.example.com. IN A
>>>    ;; Authority
>>>    bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC
>>>    bar.example.com. RRSIG NSEC [valid signature]
>>>
>>> Notes
>>> -----
>>> The NSEC record in the original text would in no case be valid as it 
>>> denies it's own existence and the existence of the RRSIG, while the 
>>> text indicates that " the validator can see that it is a  BOGUS 
>>> reply from an attacker that collated existing records from the DNS 
>>> to create a confusing reply". This indicates that NSEC and RRSIG 
>>> should be set in the NSEC bitmap
>>>
>>> Instructions:
>>> -------------
>>> This erratum is currently posted as "Reported". If necessary, please
>>> use "Reply All" to discuss whether it should be verified or
>>> rejected. When a decision is reached, the verifying party
>>> can log in to change the status and edit the report, if necessary.
>>>
>>> --------------------------------------
>>> RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26)
>>> --------------------------------------
>>> Title               : DNAME Redirection in the DNS
>>> Publication Date    : June 2012
>>> Author(s)           : S. Rose, W. Wijngaards
>>> Category            : PROPOSED STANDARD
>>> Source              : DNS Extensions
>>> Area                : Internet
>>> Stream              : IETF
>>> Verifying Party     : IESG
>>>
>>> _______________________________________________
>>> dnsext mailing list
>>> [email protected]
>>> https://www.ietf.org/mailman/listinfo/dnsext
>>
>>
>>


===================================
Scott Rose
NIST ITL
[email protected]
+1-301-975-8439
GV: +1-571-249-3671
===================================

--=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_=
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/xhtml; charset=3Dutf-8"=
>
</head>
<body>
<div><div style=3D"white-space:normal"><p dir=3D"auto">I agree with Woute=
r.  It is technically correct* this way.  The same goes with the other er=
rata (5298).  They both should be approved, IMHO.</p>
<br><p dir=3D"auto">Scott<br>
*The Best Kind of Correct</p>
<br><p dir=3D"auto">On 23 Mar 2018, at 11:43, W.C.A. Wijngaards wrote:</p=
>
<blockquote><p dir=3D"auto">Hi,<br>
<br>
Seems fine to me too.  Also Pieter's (5298) which is also about missing<b=
r>
out on the NSEC and RRSIG bits.  They aren't actually the focus, which<br=
>
is why no-one missed them I guess (together with all the omitted RRSIG<br=
>
fields?), but adding NSEC and RRSIG bits is correct for a signed zone.<br=
>
<br>
Best regards, Wouter<br>
<br>
On 23/03/18 16:27, Warren Kumari wrote:</p>
<blockquote><p dir=3D"auto">[ - RFC Editor for clutter ]<br>
<br>
This *seems* correct to me, but my brain turned into jelly much<br>
earlier in the week -- anyone disagree with the errata?<br>
<br>
W<br>
<br>
On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System<br>
&lt;[email protected]&gt; wrote:</p>
<blockquote><p dir=3D"auto">The following errata report has been submitte=
d for RFC6672,<br>
"DNAME Redirection in the DNS".<br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href=3D"http://www.rfc-editor.org/errata/eid5297">http://www.rfc-edito=
r.org/errata/eid5297</a><br>
<br>
--------------------------------------<br>
Type: Editorial<br>
Reported by: Pieter Lexis &lt;[email protected]&gt;<br>
<br>
Section: 5.3.4.1<br>
<br>
Original Text<br>
-------------<br>
   ;; Header: QR AA RCODE=3D3(NXDOMAIN)<br>
   ;; OPT PSEUDOSECTION:<br>
   ; EDNS: version: 0, flags: do; udp: 4096<br>
<br>
   ;; Question<br>
   foo.bar.example.com. IN A<br>
   ;; Authority<br>
   bar.example.com. NSEC dub.example.com. A DNAME<br>
   bar.example.com. RRSIG NSEC [valid signature]<br>
<br>
Corrected Text<br>
--------------<br>
   ;; Header: QR AA RCODE=3D3(NXDOMAIN)<br>
   ;; OPT PSEUDOSECTION:<br>
   ; EDNS: version: 0, flags: do; udp: 4096<br>
<br>
   ;; Question<br>
   foo.bar.example.com. IN A<br>
   ;; Authority<br>
   bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC<br>
   bar.example.com. RRSIG NSEC [valid signature]<br>
<br>
Notes<br>
-----<br>
The NSEC record in the original text would in no case be valid as it deni=
es it's own existence and the existence of the RRSIG, while the text indi=
cates that " the validator can see that it is a  BOGUS reply from an atta=
cker that collated existing records from the DNS to create a confusing re=
ply". This indicates that NSEC and RRSIG should be set in the NSEC bitmap=
<br>
<br>
Instructions:<br>
-------------<br>
This erratum is currently posted as "Reported". If necessary, please<br>
use "Reply All" to discuss whether it should be verified or<br>
rejected. When a decision is reached, the verifying party<br>
can log in to change the status and edit the report, if necessary.<br>
<br>
--------------------------------------<br>
RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26)<br>
--------------------------------------<br>
Title               : DNAME Redirection in the DNS<br>
Publication Date    : June 2012<br>
Author(s)           : S. Rose, W. Wijngaards<br>
Category            : PROPOSED STANDARD<br>
Source              : DNS Extensions<br>
Area                : Internet<br>
Stream              : IETF<br>
Verifying Party     : IESG<br>
<br>
_______________________________________________<br>
dnsext mailing list<br>
[email protected]<br>
<a href=3D"https://www.ietf.org/mailman/listinfo/dnsext">https://www.ietf=
=2Eorg/mailman/listinfo/dnsext</a></p>
</blockquote><br></blockquote></blockquote><br><p dir=3D"auto">=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D<br>
Scott Rose<br>
NIST ITL<br>
[email protected]<br>
+1-301-975-8439<br>
GV: +1-571-249-3671<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</p>
</div>
</div>
</body>
</html>

--=_MailMate_0FAC90A0-2DFB-4A6B-9D8E-779E8AD7E971_=--


--===============6286002398591735409==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext

--===============6286002398591735409==--