[DNSOP] Re: New I-D: draft-barrett-dnsop-domain-set-00 - T he Domain Set Discovery Protocol (seeking dispatch guidance)

"John Levine" <[email protected]>
Newsgroups gmane.ietf.dnsop
Organization Taughannock Networks
Message-ID <[email protected]>
It appears that Paul Wouters  <[email protected]> said:
>On Fri, 21 Aug 2026, Paul Vixie wrote:
>
>> i have not studied the proposed mechanism but i strongly support the goal. the PSL which underlies the whole TLS universe is still run
>on a volunteer basis and we
>> need to evolve the architecture to support what it does.
>
>The PSL should be a DNSKEY flag, similar to how I proposed draft-ietf-dnsop-delegation-only
>a long time ago. Imagine telling people "you can get on the PSL, just enable DNSSEC with
>this one flag set".

Well, good luck with that.

>As for draft-barrett-dnsop-domain-set, I also share concerns about what
>it means to be on it to an application. And how without DNSSEC, this
>signal cannot be trusted.

It points to https web sites where you presumably trust the CA.  But I think that's
an implementation detail and we first need to decide whether this is a problem that
people really want to solve.  We have a decade's experience that says it isn't.

>Why would Big Bank want to link bigbank.com to bigbank.ca to bigank.com
>to bigbank100yearanniversary.com ? That is, what is the use case for
>this protocol ? Why do agents needs to know these links? What can they
>do with this, that they cannot do right now?

All good questions.

R's,
John

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.