[DNSOP] draft-ferro-dnsop-apertoid: _apertoid TXT records for AI agent identity, TXT overloading vs new RRTYPE?
Andrea Ferro <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Hi dnsop, I have an individual draft I would like to put in front of the group, with one specific design question I expect this list will have strong views on. AI agents increasingly act on behalf of domains, but there is no standard way for a domain to declare which agents it authorizes, or for a relying party to verify that an agent legitimately represents the domain it claims. This is roughly the gap SPF, DKIM and DMARC closed for email, applied to AI agents rather than mail. Approach: draft-ferro-dnsop-apertoid publishes a domain policy record and per-agent declaration records (an agent endpoint bound to an Ed25519 public key, with mandatory expiry) as DNS TXT records under an _apertoid underscore-scoped name. A companion HTTP-signing draft (draft-ferro-httpbis-apertoid-sig) handles per-request proof; I am raising the DNS layer here. https://datatracker.ietf.org/doc/draft-ferro-dnsop-apertoid The design question I most want the group’s view on: I have used underscore-scoped TXT records, following the SPF/DKIM/DMARC precedent. I am aware of the long-standing tension around overloading TXT for structured data versus defining a dedicated RRTYPE, and that the history there is not encouraging on either side. For a greenfield application like this, does the group consider _apertoid TXT records the right call, or would a new RRTYPE be the more defensible foundation? Two further points I would value feedback on: the include= delegation model and its lookup and loop bounds, and whether any of this overlaps existing work I should be building on instead. There is a reference implementation with a conformance harness that checks the draft’s examples byte for byte; writing it surfaced several under-specified points I have since fixed. https://github.com/ApertoID/apertoid Thank you, Andrea Ferro _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 2.1 KB) - not displayed