[DNSOP] Re: Disclosure of Negative Trust Anchors in DNS Resp onses (draft-farrokhi-dnsop-ede-nta-00)

Ralf Weber <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Moin!

On 17 Jun 2026, at 13:23, Mukund Sivaraman wrote:

> On Wed, Jun 17, 2026 at 07:18:40PM +0800, Mukund Sivaraman wrote:
>> I-D.ietf-dnsop-structured-dns-errors are only mean to be generated in
>> EDE options with specific INFO-CODEs {Filtered, Censored, Blocked}, and
>> they are further extended by the sub-codes in that draft (i.e., they
>> depend on the INFO-CODEs being in {Filtered, Censored, Blocked}.
>>
>> Would it not be better or even more correct to seperate the
>> I-D.ietf-dnsop-structured-dns-error into a different EDE option, i.e.,
>> separate from the NTA EDE option?
>>
>> Overall, nice and succinct.
>
> As NTA's are configured per domain-level, you may also want to consider
> changing the design to use a new EDNS option other than EDE, to include
> the domain of the NTA and perhaps a field for the time of expiration of
> the NTA.

I agree with you that  I-D.ietf-dnsop-structured-dns-error is not
applicable for this draft as it also applies to regular responses, but I
disagree that we should use another EDNS option for it. This is a classic
use case for EDE and the EXTRA-TEXT field should be absolutely what is
used to carry the additional information.

It could be a good idea to also put a structure around it so that the
NTA domain and expiry are shown there, which could be done in this draft
or a separate one.

So long
-Ralf
———
Ralf Weber

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.