[DNSOP] Roman Danyliw's No Objection on draft-ietf-dnsop-str uctured-dns-error-26: (with COMMENT)

Roman Danyliw via Datatracker <[email protected]> Thu, 23 Jul 2026 01:40:01 -0700
Newsgroups gmane.ietf.dnsop
Message-ID <178479600139.513802.13497309153421383301@dt-datatracker-d4d6ff9d9-fsx7d>
Roman Danyliw has entered the following ballot position for
draft-ietf-dnsop-structured-dns-error-26: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dnsop-structured-dns-error/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thank you to Stewart Bryant for the GENART review.

Thank you for addressing my DISCUSS feedback and part of my COMMENT feedback.

=== Prior COMMENT feedback

** Section 3

-- Bullet #1:
         Frustrated, the end user may switch to an
         alternate network that offers no DNS filtering against malware
         and phishing, potentially compromising both security and
         privacy.
-- Bullet #2:
     Frustrated, the end
      user may resort to using insecure methods to reach the domain,
      potentially compromising both security and privacy.

Can this threat be more precisely articulated?  What is being described in
bullet #1 and #2 seems like how web browsing looks in the real world.  For
example, I am a student on a mobile device using the school’s Wi-Fi network but
it blocks the social media site I want to use, so I switch to the cellular
network.  I am employee on a restricted enterprise Wi-Fi network with a BYOD
situation, but it blocks the shopping site where I want to make a purchase
while  having lunch in the cafeteria, so I switch to the cellular network.  I
try to access a web-site but it blocks me due to geofencing policies so I use a
VPN to exit in a different geography.  This speaks nothing of users in places
with censoring regimes implemented by carriers which regularly resort to
alternative means of access.

** Section 4
   j: (justification)  'UTF-8'-encoded [RFC5198] human-readable
      explanation for the DNS filtering decision.
…
      Returning non-UTF-8 data, syntactically invalid content, or
      deliberately meaningless values (including empty strings)
      indicates that a DNS server is misbehaving.

If this is human readable explanation not meant for automated processing, what
is a “deliberately meaningless value”?



_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]