[DNSOP] Re: Disclosure of Negative Trust Anchors in DNS Resp onses (draft-farrokhi-dnsop-ede-nta-00)

Mukund Sivaraman <[email protected]> Tue, 14 Jul 2026 02:41:30 +0800
Newsgroups gmane.ietf.dnsop
Message-ID <alUxWmQUBCaS-LqH@p5>
Hi Petr

On Mon, Jul 13, 2026 at 04:20:27PM +0200, Petr Špaček wrote:
> On 17. 06. 26 12:47, Joe Abley wrote:
> > Babak, Sebastiaan and I put pen to paper and came up with the following:
> > 
> > https://datatracker.ietf.org/doc/draft-farrokhi-dnsop-ede-nta/
> > 
> > https://github.com/farrokhi/id-ede-nta (working copy)
> 
> Good idea!
> 
> In section 2:
> > This EDE is intended for use in DNS responses sent by a DNS resolver with a configured NTA and SHOULD NOT be included in other responses. For example, a DNS response sent by an authoritative-only DNS server, which does not perform validation and hence has no obvious use for an NTA, SHOULD NOT include this EDE.
> 
> Why not MUST NOT?
> 
> I think an occurrence of SHOULD NOT should (see what I did there) have an
> explanation under what conditions it can be violated, and I can't think of
> any.
> 
> 
> Personally I think machine parseable EXTRA-TEXT would be a good idea.
> Something like
> {"d": "example.com", "e": "2026-07-30T00:00:00Z"}
> or so.

If the data is going to be structured, use of a separate EDNS option
with name and expiry timestamp fields would be better.

		Mukund

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE-----

iQQzBAABCgAdFiEEqPyXNiYqnt+m+AGHd1TIVyxnymkFAmpVMVcACgkQd1TIVyxn
ymmDViAApvrORGMl0YsKHSK5UvZaWgzmkoJ+KrgA/CAGUU5n74nMdJk84L4A6F++
OzvAPACzWUsln4cCGd94EEFoWJ/sFjvOq4dDx+GE3cdPnA1P+DXcLi7fjJ2UrhDa
XI7vLRmFzjgifCnp9habuDR1F4JwCa0HdNh3ZkHLwa8KoXK1J9WB+DFFzRp/WB64
/wfIQ3REQGySkZ3Mb2SB7MUK704fTv9XlaiLkQCDs6BRbYVutvX7Z/ECp6v6i89G
vgMmwA9BamUSJFx7a7DtGjqCbtD/av7p8ggwPWaDfmzBG2AOEuw7f7bxw+OXeO+x
ytbaupJDqXf+f1y9lvG959RB0dnI2rcR7Keg//PuSHTOXwd7dvzt9cBdlHsaTUlJ
6iYaX4h0NMHRyz9w3KMKOjelgK71p7FqxsxQJuJ1BmY9A5+o4IxFH7Tsdg7B8KPW
Mncc3h0qylf69XygUNQ3uMxiiiANCiUtjZTCWnet2Y+6xFQxVcYBjn7L2C32LXp9
qBWaUwPFhOx1DYw9yXgJDul1hDshvXkImPqQ/PD52Q3zOo5GOIEhjo+KWakQ4ZFF
WAG3x2nft7eJ+wYrzEn+HRZ5fRXufUAnViXIlpXcEnlITN5Y5S26QccjxnELvrft
HdmxlGIGPfTiLCNbWiRXJ5WZ/RHASU7YY/NbASodA5/x9aa7k3NBWgSSY9gpIM/t
t78NCMCkizR9vq69rwJ+J0TQQh4V+ldTDdMlJeabhnSgtv9mokv6pyrw7eiBWcxT
N2JD7qWuXZpq5om5g/6B7xIKHWtjB3VMsn4PyiF7bkOQ20MrG4Dq+cMvprVfM2Zd
Q8w+OWB27HJ+Wi3xeo/1Pnl3DzvrNHr+3BBe2gb2AHeahqHO/Q3NdbAqgIHwoMnI
ZecHJsE/gXCaeilBzPOzcJ9Yb6SonVDCGyRQ9U0ixHivoXh1YpzHxuvWyFKxD8WI
W5US4xHGMach1pK4zaknN8oVeLQgHCpaqsEn7+0UVrPTedFhNJ2Kqg15tcQv77zA
XLPiWkvMAzFheEx/6kveSASnteN5hPfGBTY3utzJjTCq6M4DoSOQximDUaIJhL7Q
f09hSVB5B9ytignGrm/95+evqsO8xNLX+nYkkcA8pH6oaoriYZ3XNKuUYGiYOPyz
r0U0B/dciupkAx8gx6QomQkv65oI67Jsvc78R/c53m6Oycmd2H9ala3PHbZFdc3E
bGxBcO8dGTKOs4hwV9Gft/2qQ8m2YTw+ILjvHpGms6tzW9WrlslTsAYqBOA1xTYx
dwkOW8Pr8sXPhZZjDQ9rMW1GceirTpxTpdml9TqG0quzQ4PCBZYECaXiQqequ5Fc
veP1jmM/UP31TF3lwILhcgyg49gAFw==
=M/+j
-----END PGP SIGNATURE-----