[DNSOP] New I-D: draft-barrett-dnsop-domain-set-00 - The Dom ain Set Discovery Protocol (seeking dispatch guidance)
Tom Barrett <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAAhn4w_zdDmkzXT=uYdy66ji4H7yCHcBKdjjYJv1GMbE2dfGPg@mail.gmail.com> |
Hi dnsop, Chris Schaub, Andrew Barrett, Pawel Kowalik, and I just posted a new individual draft and would like the WG's dispatch guidance: https://datatracker.ietf.org/doc/draft-barrett-dnsop-domain-set/ Organizations often operate multiple domains (primary site, legacy names, defensive registrations, verified-TLD names), with no standard way for an owner to declare which ones belong together. domain-set defines a DNS TXT record, optionally pointing to an HTTPS manifest, to do this. Validation requires mutual attestation: a link is only valid when both domains name each other, authenticated via DNSSEC or the Web PKI. Known gaps are listed in Section 1.7 - ABNF completion, a manifest media type, CNAME handling, NXDOMAIN/NODATA and TTL guidance, and an optional re-attestation mechanism for stale links. We've also bundled the record, manifest, and index pieces together for this first review; happy to split them out if the WG takes it on. It overlaps with draft-ietf-dnsop-domain-verification-techniques and draft-ietf-dnsop-integration, so we think dnsop's the right home, but we'd like the WG's take on scope and adoption-readiness. Thanks, Tom -- Schedule a call with me. https://calendar.app.google/BrESmtfgCG4tutSu7 Thomas Barrett President EnCirca, Inc +1.781.942.9975 (office) 400 W. Cummings Park, Suite 1725 Woburn, MA 01801 USA _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]