[DNSOP] Re: New Version Notification for draft-muks-dns-nta- feed-zones-00.txt

Ondřej Surý <[email protected]> Sun, 19 Jul 2026 14:35:46 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi,

[sorry for duplicate, I forgot to cc dnsop@ the first time]

I briefly looked at the I-D and I think this is a wrong solution to a wrong problem.

If the need for NTA is so ubiquitous that it requires automated solution than we
are doing something wrong with DNSSEC that it became so unreliable that we
need to punch holes in it.

I would rather support Johan in his efforts to make the rollover more automated
and smooth than develop yet another horrible band-aid that we will have to deal
for eternity. This community has really bad habit of panicking over singular
incidents and we are still hurting badly from serve-stale because of single provider
had an outage. This time there was a different outage and I would rather focus
on preventing large scale outages than adding more ducttape around the camel
to hold its burden.

Ondrej
--
Ondřej Surý (He/Him)
[email protected]

A gentle nudge is always appreciated if I take a little longer to reply.

> On 19. 7. 2026, at 00:12, [email protected] wrote:
> 
> A new version of Internet-Draft draft-muks-dns-nta-feed-zones-00.txt has been
> successfully submitted by Mukund Sivaraman and posted to the
> IETF repository.
> 
> Name:     draft-muks-dns-nta-feed-zones
> Revision: 00
> Title:    DNS NTA feed zones
> Date:     2026-07-18
> Group:    Individual Submission
> Pages:    8
> URL:      https://www.ietf.org/archive/id/draft-muks-dns-nta-feed-zones-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-muks-dns-nta-feed-zones/
> HTML:     https://www.ietf.org/archive/id/draft-muks-dns-nta-feed-zones-00.html
> HTMLized: https://datatracker.ietf.org/doc/html/draft-muks-dns-nta-feed-zones
> 
> 
> Abstract:
> 
>  This memo documents a method for expressing a list of DNS negative
>  trust anchors [RFC7646] inside a specially constructed DNS zone, that
>  validating recursive name servers and other DNSSEC validators may
>  configure negative trust anchors from.
> 
> 
> 
> The IETF Secretariat
> 
> 
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]