[DNSOP] Re: draft-johani-dnsop-dnssec-alg-experimental-range

marka <[email protected]> Wed, 15 Jul 2026 15:11:19 +1000
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>

> On 14 Jul 2026, at 21:49, Petr Špaček <[email protected]> wrote:
> 
> Hi.
> 
> First, I support goal of this document - having both ranges allocated.
> 
> On 25. 06. 26 21:08, Johan Stenstam wrote:
>> The problem that the only “experimental use” DNSSEC algorithms are the multiplexed 253+254 code points that have unique constraints on how they can be used has been discussed repeatedly. And the problem simply doesn’t go away.
> Having said that, I disagree with most of the text in the document. Most of it is a very long description of laziness.
> 
> 253 and 254 code points require one-time cost to code the support for it. It is in the spec for 20+ years, so it is basically technical debt.
> 
> I agree 253 and 254 are ugly because DS and RRSIG do not have the identifier. If that is considered to be a significant problem we could also standardize say 249 PRIVATEDNSBETTER and 250 PRIVATEOIDBETTER which do add the identifier to both fields. That would be marginally more work, but significantly more future proof, and IMHO better design design.

One can provide an identifier by emitting a space in the base64 output at the point where the identifier ends.  Just choose OIDs and DNS names that are multiples of 3 bytes in length so the base64 encoding is a multiple of 4 octets.  One could even put ‘(‘ and ‘)’ around it to make it more visually prominent.  Also it’s not like we can’t just add a comment at the end of the record with the identifier in its normal text form.

One can skip unknown OID and DNS names relatively easily.  One doesn’t have to match every bytes of the identifier to do that.  Remember we are doing experimental algorithms.  Once we have selected the algorithms we are happy we can give them real code points.

> Having said all this, I recognize many people want to do their thing and are not interested in repaying technical debt (after all the draft says we don't care and number-squat already...).
> 
> For that sole reason I think it is better to get experimental and private ranges allocated now and legalize what folks are already doing.
> 
> -- 
> Petr Špaček
> 
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]