[DNSOP] Re: Disclosure of Negative Trust Anchors in DNS Resp onses (draft-farrokhi-dnsop-ede-nta-00)

Petr Špaček <[email protected]> Mon, 13 Jul 2026 16:20:27 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On 17. 06. 26 12:47, Joe Abley wrote:
> Babak, Sebastiaan and I put pen to paper and came up with the following:
> 
> https://datatracker.ietf.org/doc/draft-farrokhi-dnsop-ede-nta/
> 
> https://github.com/farrokhi/id-ede-nta (working copy)

Good idea!

In section 2:
> This EDE is intended for use in DNS responses sent by a DNS resolver with a configured NTA and SHOULD NOT be included in other responses. For example, a DNS response sent by an authoritative-only DNS server, which does not perform validation and hence has no obvious use for an NTA, SHOULD NOT include this EDE.

Why not MUST NOT?

I think an occurrence of SHOULD NOT should (see what I did there) have 
an explanation under what conditions it can be violated, and I can't 
think of any.


Personally I think machine parseable EXTRA-TEXT would be a good idea. 
Something like
{"d": "example.com", "e": "2026-07-30T00:00:00Z"}
or so.

-- 
Petr Špaček

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]