[DNSOP] Re: WG Last Call: draft-ietf-dnsop-integration-04 (Ends 2026-09-07)

Paul Wouters <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
On Mon, 24 Aug 2026, Ondřej Surý via Datatracker wrote:

> This message starts a WG Last Call for:
> draft-ietf-dnsop-integration-04

I find the document both verbose in words yet not containing much
information. While I don't object to it, I would also not object
to not moving forward with it.


I miss most technical advise to application developers on the common
security issues that come up when integrating DNS into an application. For
example:

- Comparison checks with and without trailing dot (see recent curl CVE)
- Comparison forgetting DNS is not case sensitive
- U-label / A-label comparisons
- Repeated DNS checks not working due to cache and especially negative cache
- Dangling CNAMEs
- CNAMEs / DNAMEs processing should not change origin name (QNAME)
- Dangling A records at hyperscalers / cloud providers
- DNS fields in protocols are unlikely to be NULL terminated strings,
   but TLV data structures.

Case sensitivity is mentioned but more in an 'off the cuff' way,
decreasing the importance it really deserves. I say that as having
recently paid out a bounty at $dayjob because we forgot it somewhere.


Paul

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.