[DNSOP] Re: draft-ietf-dnsop-delext-08 ietf last call Dnsdir review

Peter Thomassen <[email protected]> Tue, 21 Jul 2026 18:57:17 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Roy,

Minor nit:

On 7/20/26 16:28, Roy Arends wrote:
>> 3)
>> "To avoid a downgrade attack, where the Delegation Type RRsets and NSEC (or
>> NSEC3) records can be replaced by unsigned NS records, causing the resolver to
>> use unencrypted transport"
[...]
> 
> I will remove ", causing the resolver to use unencrypted transport” and add a reference to paragraph 8.2.1

When reading "the Delegation Type RRsets and NSEC (or NSEC3) records can be replaced", I was briefly confused regarding what about their RRSIGs.

Suggest adding "signed" before "Delegation Type RRsets", or "and their signatures" after "records".

Cheers,
Peter

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]