[DNSOP] Re: WG Last Call: draft-ietf-dnsop-delegation-mgmt -via-ddns-02 (Ends 2026-09-07)

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
I've read draft-ietf-dnsop-delegation-mgmt-via-ddns-02, and it looks good to
me.  I could write code from what I read.

I am curious about how well RFC9859 (just NOTIFY to kick CDS scanning) has
been received so far.   The protocol described is certainly lower cost.
I think that a registrar or zone operator who has 9859-only (or for which the
KEYs are not yet authorized) could even take this as akin to an RFC9859 kick.

You mention that you've implemented; client and server I guess.
I guess you can't go "live" until you get IANA allocations.

I was surprised at the informative reference to I-D.leon-dnsop-signaling-zone-owner-intent.
I am not so sure it's informative; I think that many implementers might have
to read that document, at least to decide that they didn't need to read it.

I think you will get quantum-safe questions from reviewers and IESG.
It is certainly the case that we (DNSOP) do not have a ready answer yet.
I don't think that HMS-LMS is supported DNSSEC, I could be wrong.
I think it would be useful to support it for KEY RR: the use case here calls
for relatively few signatures/year, and re-onboarding and key updates is well
supported, so it would be a good quantum-safe story.

The *KEY* RR is used, not the DNSKEY RR, and maybe one sentence reminding
people of that SIG(0) user wasn't deprecated by the 20-year-old
type-key-rollover.

I would consider if a visual state machine diagram and/or decision tree is
worth the time doing the ascii art.   There are tools to help; but _asciio_
is also pretty good.
I think that might would help with section 9.4.1 and 9.4.2.
If I were writing code, I'd be drawing the diagram on a whiteboard first.

--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

**       My working hours and your working hours may be different.         **
** Please do not feel obligated to reply outside your normal working hours **

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmqMnlAACgkQgItw+93Q
3WX5WggAumlvXpexnfjqyLAlEhbVO4Cmc6FxLnb6S4QmgPBpe/NjeQ7xXq+IYWed
cpFa77yyQx9DABSRWlRSQWtqzqmP39mpkOWa0a/uicriJZ8fWBdFdYDBQydiu8Yh
r1UY2rbXEPljo/oRiOiernUYJSjiBPIpwonp+hCNb9bQFy36H2cjEFyA7vdTANYm
YVTDYNy8l7cNRWR8ssyI3j9sNop/Irs219diFTjryqiK/hgsC7ozBMolQ4LHj5Su
vYfdsHUCsvRrzlQRpFeDpfOZLiLapoXlfMaygrXEUFygEz8At8sRZrbwkPvK4/Oh
p+R7qwuxjZImA2Av2AVfh5ZwNyrQZw==
=JIku
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.