[DNSOP] Re: Disclosure of Negative Trust Anchors in DNS Resp onses (draft-farrokhi-dnsop-ede-nta-00)
Mukund Sivaraman <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <ajKDmrqF-JC5EBT3@p5> |
On Wed, Jun 17, 2026 at 07:18:40PM +0800, Mukund Sivaraman wrote:
> Hi Joe
>
> This is a good idea. Some minor review comments below.
>
> > 1. Introduction
>
> > A resolver with an NTA in effect might send a response that
> > ordinarily would have been suppressed because of validation failures.
> > This document defines a new EDE that can be sent with a response to
>
> Minor editorial nit: I suggest s/with/within/ or s/with/in/
>
> > indicate that the response was subject to an active NTA.
>
> > 3. Operational Considerations
>
> > A resolver with multiple NTAs in place simultaneously MAY include
> > multiple instances of this EDE in a single response, each
> > representing a different NTA.
>
> Is this so that the different EDE option instances may have different
> EXTRA-TEXT values?
>
> > The operator MAY use the EXTRA-TEXT field to add context about the
> > NTA, such as the name at which it was configured, the reason it was
> > put in place, a reference where more information can be found, or its
> > expected duration. As noted in Section 2 of [RFC8914], EXTRA-TEXT is
> > intended for human consumption; operators SHOULD keep it readable and
> > SHOULD NOT include private or sensitive information. Structured data
> > MAY be included in the EXTRA-TEXT field, as described in
> > [I-D.ietf-dnsop-structured-dns-error].
>
> I-D.ietf-dnsop-structured-dns-errors are only mean to be generated in
> EDE options with specific INFO-CODEs {Filtered, Censored, Blocked}, and
> they are further extended by the sub-codes in that draft (i.e., they
> depend on the INFO-CODEs being in {Filtered, Censored, Blocked}.
>
> Would it not be better or even more correct to seperate the
> I-D.ietf-dnsop-structured-dns-error into a different EDE option, i.e.,
> separate from the NTA EDE option?
>
> Overall, nice and succinct.
As NTA's are configured per domain-level, you may also want to consider
changing the design to use a new EDNS option other than EDE, to include
the domain of the NTA and perhaps a field for the time of expiration of
the NTA.
Mukund
_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE----- iQQzBAABCgAdFiEEqPyXNiYqnt+m+AGHd1TIVyxnymkFAmoyg5cACgkQd1TIVyxn ymn3ZSAAt19AJ9sVgkM1MLH/PFdcTg4Qz+NdpZEySk+PVKov73rN6KAatsguj42W FQ3ItGUBpwR2Hz+Q9DzHV3VqoQNKGV9OIsIXzu1l6oqZBffsmsGJ4JQCA2HdAYGi WLjtvAga4OFc/u4kPLsHSMco7Dlp4bb5nNbp3xJCsA4X483I3VpwRCOdCE+NpaAh 4KMhreABw4Sgi9d58Wo+SaXxY1HT9tnjLlgyAXYMGdoJ4swGbXDfDFWiqamI4xaE RwVYS8ba/0RC8S3nd4xh+y3pXssUH2+l+Jr9SguIJ4wVlmLmWeGPDonKg85bAwrw trH1doEn3fYa8dA5XtGU8nmbweGQcjRRYadA4U2OIKp2mQAZj8J6Cx9da2EikLr1 alkduJYd4D1+ghXN40spPt6iu+UFBlIr58FAY0/RalyKprTduO4cwzq47YXPbD4/ u17aR3g8STDlHnUttTPQWSebHrztJ3z30ZXXe0GrIDOkHcDWGS1R0NQYjfNOsVrP 8r40G1hm55CX6iBqDJAAPNVXX44MG78qV6yoNjwSu5SYZB9xq3BYRvSaWIkXu/E0 71mVGmGGA3LwPDvnxO6UT3afMeSJihea01EbWlkLSuKfL/seXb68/cMJ40aDg1Rj 4nAR2jR3mPpSCu9pWOJ8fK2fmYktQOvUujjGApJAIqa251yhUW43sC7AYQ+bg564 2GMcfzTRlPMbgo7Sq/PQmBtIjgUsENiKzMbwebduEyHgopEsY8Rj252wRXQ4CZAG 0EitbLRz2n6eWS85SaqSwkiiLZnn2qELACrabv2GGYytK933AYHQ/0/AFNRLfaSl YrnnuQuCqgDo9nnjh8Ww417CjsfYDEcsTXrtaHSIwJMbYWeJM66/Pli7gjngjQq0 7qryODEJbm8jbgAlRw18txn30neomAaGZndF70/SLJKEVq3slKLDQXlPHceVgPil KjDGrIr3b0uSX56kima96qT4R3EOLsZGE1NrCNSvD+7mo7JLCH1SeeCN5MLy7PUP 453qFpaTOd4WnqEuhSBFlED6AIhXxk6rJLwklzGwzihJrfZ4YJfLG+aXyBDAUcAl uXqB6xIMgb5Y9s4fiduDEAwG77TAAOMtkcgUpMZqAoxjH0edVT18dd/0MxnzGYFS yos3no1J+ELTBLfnNlOuEyFnrN+oy7Nq2t0Xg7pzG/g2hHFtkvpn4khjNqv6JMrw xmEjSpy8AirQMU2G0mfdiKIoW8n7XARgKVB1yb8Jz74orFCkzASL+0YbnrcTYz7x y2+Ml+/ZfAGAu5v46c3E3raFO3oYXmMm22y3+Z78e0PQklOpcJN+dIRhM+ZpdeyA oAKj1n+22s4PNXKtmCvUh/uIwNpaVg== =k+pU -----END PGP SIGNATURE-----