[DNSOP] Re: Disclosure of Negative Trust Anchors in DNS Resp onses (draft-farrokhi-dnsop-ede-nta-00)
Mukund Sivaraman <[email protected]> Tue, 14 Jul 2026 02:41:30 +0800
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <alUxWmQUBCaS-LqH@p5> |
Hi Petr
On Mon, Jul 13, 2026 at 04:20:27PM +0200, Petr Špaček wrote:
> On 17. 06. 26 12:47, Joe Abley wrote:
> > Babak, Sebastiaan and I put pen to paper and came up with the following:
> >
> > https://datatracker.ietf.org/doc/draft-farrokhi-dnsop-ede-nta/
> >
> > https://github.com/farrokhi/id-ede-nta (working copy)
>
> Good idea!
>
> In section 2:
> > This EDE is intended for use in DNS responses sent by a DNS resolver with a configured NTA and SHOULD NOT be included in other responses. For example, a DNS response sent by an authoritative-only DNS server, which does not perform validation and hence has no obvious use for an NTA, SHOULD NOT include this EDE.
>
> Why not MUST NOT?
>
> I think an occurrence of SHOULD NOT should (see what I did there) have an
> explanation under what conditions it can be violated, and I can't think of
> any.
>
>
> Personally I think machine parseable EXTRA-TEXT would be a good idea.
> Something like
> {"d": "example.com", "e": "2026-07-30T00:00:00Z"}
> or so.
If the data is going to be structured, use of a separate EDNS option
with name and expiry timestamp fields would be better.
Mukund
_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 1.5 KB)
-----BEGIN PGP SIGNATURE----- iQQzBAABCgAdFiEEqPyXNiYqnt+m+AGHd1TIVyxnymkFAmpVMVcACgkQd1TIVyxn ymmDViAApvrORGMl0YsKHSK5UvZaWgzmkoJ+KrgA/CAGUU5n74nMdJk84L4A6F++ OzvAPACzWUsln4cCGd94EEFoWJ/sFjvOq4dDx+GE3cdPnA1P+DXcLi7fjJ2UrhDa XI7vLRmFzjgifCnp9habuDR1F4JwCa0HdNh3ZkHLwa8KoXK1J9WB+DFFzRp/WB64 /wfIQ3REQGySkZ3Mb2SB7MUK704fTv9XlaiLkQCDs6BRbYVutvX7Z/ECp6v6i89G vgMmwA9BamUSJFx7a7DtGjqCbtD/av7p8ggwPWaDfmzBG2AOEuw7f7bxw+OXeO+x ytbaupJDqXf+f1y9lvG959RB0dnI2rcR7Keg//PuSHTOXwd7dvzt9cBdlHsaTUlJ 6iYaX4h0NMHRyz9w3KMKOjelgK71p7FqxsxQJuJ1BmY9A5+o4IxFH7Tsdg7B8KPW Mncc3h0qylf69XygUNQ3uMxiiiANCiUtjZTCWnet2Y+6xFQxVcYBjn7L2C32LXp9 qBWaUwPFhOx1DYw9yXgJDul1hDshvXkImPqQ/PD52Q3zOo5GOIEhjo+KWakQ4ZFF WAG3x2nft7eJ+wYrzEn+HRZ5fRXufUAnViXIlpXcEnlITN5Y5S26QccjxnELvrft HdmxlGIGPfTiLCNbWiRXJ5WZ/RHASU7YY/NbASodA5/x9aa7k3NBWgSSY9gpIM/t t78NCMCkizR9vq69rwJ+J0TQQh4V+ldTDdMlJeabhnSgtv9mokv6pyrw7eiBWcxT N2JD7qWuXZpq5om5g/6B7xIKHWtjB3VMsn4PyiF7bkOQ20MrG4Dq+cMvprVfM2Zd Q8w+OWB27HJ+Wi3xeo/1Pnl3DzvrNHr+3BBe2gb2AHeahqHO/Q3NdbAqgIHwoMnI ZecHJsE/gXCaeilBzPOzcJ9Yb6SonVDCGyRQ9U0ixHivoXh1YpzHxuvWyFKxD8WI W5US4xHGMach1pK4zaknN8oVeLQgHCpaqsEn7+0UVrPTedFhNJ2Kqg15tcQv77zA XLPiWkvMAzFheEx/6kveSASnteN5hPfGBTY3utzJjTCq6M4DoSOQximDUaIJhL7Q f09hSVB5B9ytignGrm/95+evqsO8xNLX+nYkkcA8pH6oaoriYZ3XNKuUYGiYOPyz r0U0B/dciupkAx8gx6QomQkv65oI67Jsvc78R/c53m6Oycmd2H9ala3PHbZFdc3E bGxBcO8dGTKOs4hwV9Gft/2qQ8m2YTw+ILjvHpGms6tzW9WrlslTsAYqBOA1xTYx dwkOW8Pr8sXPhZZjDQ9rMW1GceirTpxTpdml9TqG0quzQ4PCBZYECaXiQqequ5Fc veP1jmM/UP31TF3lwILhcgyg49gAFw== =M/+j -----END PGP SIGNATURE-----