[DNSOP] Re: WG Last Call: draft-ietf-dnsop-delegation-mgmt -via-ddns-02 (Ends 2026-09-07)
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
I've read draft-ietf-dnsop-delegation-mgmt-via-ddns-02, and it looks good to me. I could write code from what I read. I am curious about how well RFC9859 (just NOTIFY to kick CDS scanning) has been received so far. The protocol described is certainly lower cost. I think that a registrar or zone operator who has 9859-only (or for which the KEYs are not yet authorized) could even take this as akin to an RFC9859 kick. You mention that you've implemented; client and server I guess. I guess you can't go "live" until you get IANA allocations. I was surprised at the informative reference to I-D.leon-dnsop-signaling-zone-owner-intent. I am not so sure it's informative; I think that many implementers might have to read that document, at least to decide that they didn't need to read it. I think you will get quantum-safe questions from reviewers and IESG. It is certainly the case that we (DNSOP) do not have a ready answer yet. I don't think that HMS-LMS is supported DNSSEC, I could be wrong. I think it would be useful to support it for KEY RR: the use case here calls for relatively few signatures/year, and re-onboarding and key updates is well supported, so it would be a good quantum-safe story. The *KEY* RR is used, not the DNSKEY RR, and maybe one sentence reminding people of that SIG(0) user wasn't deprecated by the 20-year-old type-key-rollover. I would consider if a visual state machine diagram and/or decision tree is worth the time doing the ascii art. There are tools to help; but _asciio_ is also pretty good. I think that might would help with section 9.4.1 and 9.4.2. If I were writing code, I'd be drawing the diagram on a whiteboard first. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide ** My working hours and your working hours may be different. ** ** Please do not feel obligated to reply outside your normal working hours ** _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmqMnlAACgkQgItw+93Q 3WX5WggAumlvXpexnfjqyLAlEhbVO4Cmc6FxLnb6S4QmgPBpe/NjeQ7xXq+IYWed cpFa77yyQx9DABSRWlRSQWtqzqmP39mpkOWa0a/uicriJZ8fWBdFdYDBQydiu8Yh r1UY2rbXEPljo/oRiOiernUYJSjiBPIpwonp+hCNb9bQFy36H2cjEFyA7vdTANYm YVTDYNy8l7cNRWR8ssyI3j9sNop/Irs219diFTjryqiK/hgsC7ozBMolQ4LHj5Su vYfdsHUCsvRrzlQRpFeDpfOZLiLapoXlfMaygrXEUFygEz8At8sRZrbwkPvK4/Oh p+R7qwuxjZImA2Av2AVfh5ZwNyrQZw== =JIku -----END PGP SIGNATURE-----