[DNSOP] Re: New I-D: draft-barrett-dnsop-domain-set-00 - T he Domain Set Discovery Protocol (seeking dispatch guidance)
Ben Schwartz <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAOdQrVNMWwvaN4mnLmby-wqFrF2MW17BhSHQaqrHNsVAtDxbww@mail.gmail.com> |
I don't think this is really suitable for DNSOP. The big challenge with this category of proposals is semantic: what does it mean to be part of a set? There are many different kinds of relationships between domains and organizations, and so two domains might be "the same organization" for some purposes but not others. DNSOP is probably not the place to establish any kind of taxonomy like that. If applications (or whatever "relying party") can standardize how this information will be used, then we can certainly work on an encoding for it. Related prior work: * DBOUND (https://datatracker.ietf.org/wg/dbound/about/) * First Party Sets (https://privacysandbox.google.com/blog/related-website-sets) --Ben Schwartz On Fri, Aug 21, 2026 at 1:08 PM Tom Barrett <[email protected]> wrote: > > > > Hi dnsop, > > Chris Schaub, Andrew Barrett, Pawel Kowalik, and I just posted a new > individual draft and would like the WG's dispatch guidance: > > https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-barrett-dnsop-domain-set/__;!!Bt8RZUm9aw!51wt3Ve--R8On228vkdoZYPFrTkh2eWz6vzTA_573pplbHFO64GJ3hldFOAmp3XNH3gEy9xy24mNLQtqY8O76LYP994$ > > Organizations often operate multiple domains (primary site, legacy > names, defensive registrations, verified-TLD names), with no standard > way for an owner to declare which ones belong together. domain-set > defines a DNS TXT record, optionally pointing to an HTTPS manifest, to > do this. Validation requires mutual attestation: a link is only valid > when both domains name each other, authenticated via DNSSEC or the Web > PKI. > > Known gaps are listed in Section 1.7 - ABNF completion, a manifest > media type, CNAME handling, NXDOMAIN/NODATA and TTL guidance, and an > optional re-attestation mechanism for stale links. We've also bundled > the record, manifest, and index pieces together for this first review; > happy to split them out if the WG takes it on. > > It overlaps with draft-ietf-dnsop-domain-verification-techniques and > draft-ietf-dnsop-integration, so we think dnsop's the right home, but > we'd like the WG's take on scope and adoption-readiness. > > Thanks, Tom > > -- > Schedule a call with me. > https://urldefense.com/v3/__https://calendar.app.google/BrESmtfgCG4tutSu7__;!!Bt8RZUm9aw!51wt3Ve--R8On228vkdoZYPFrTkh2eWz6vzTA_573pplbHFO64GJ3hldFOAmp3XNH3gEy9xy24mNLQtqY8O7JQ3nN68$ > > Thomas Barrett > President > EnCirca, Inc > +1.781.942.9975 (office) > 400 W. Cummings Park, Suite 1725 > Woburn, MA 01801 USA > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]