[DNSOP] Re: New I-D: draft-barrett-dnsop-domain-set-00 - T he Domain Set Discovery Protocol (seeking dispatch guidance)
"John Levine" <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Organization | Taughannock Networks |
| Message-ID | <[email protected]> |
It appears that Paul Wouters <[email protected]> said: >On Fri, 21 Aug 2026, Paul Vixie wrote: > >> i have not studied the proposed mechanism but i strongly support the goal. the PSL which underlies the whole TLS universe is still run >on a volunteer basis and we >> need to evolve the architecture to support what it does. > >The PSL should be a DNSKEY flag, similar to how I proposed draft-ietf-dnsop-delegation-only >a long time ago. Imagine telling people "you can get on the PSL, just enable DNSSEC with >this one flag set". Well, good luck with that. >As for draft-barrett-dnsop-domain-set, I also share concerns about what >it means to be on it to an application. And how without DNSSEC, this >signal cannot be trusted. It points to https web sites where you presumably trust the CA. But I think that's an implementation detail and we first need to decide whether this is a problem that people really want to solve. We have a decade's experience that says it isn't. >Why would Big Bank want to link bigbank.com to bigbank.ca to bigank.com >to bigbank100yearanniversary.com ? That is, what is the use case for >this protocol ? Why do agents needs to know these links? What can they >do with this, that they cannot do right now? All good questions. R's, John _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]