From: "p...@redbarn.org" <p...@redbarn.org>
Date: Tuesday, April 11, 2023 at 11:11 AM
To: "dns-operati...@dns-oarc.net" <dns-operati...@dns-oarc.net>, Edward Lewis 
<edward.le...@icann.org>
Subject: Re: [dns-operations] [Ext] Re: Cloudflare TYPE65283

>Well, we are overdue for starting over on dnssec, which we used to do every 
>two years or so. But does the next generation have the will to do so?

Good point – and something that I keep in mind all the time…

At some point the operational burden (pain) might justify some re-engineering.

The important word there is “might”.

<Soapboxing:>

I make this statement upon hearing more and more discussions about how to dance 
around the DNSSEC definition, with the background that DNSSEC was designed in 
an era prior to the current DNS operational environment.  It’s simple to say 
that operational assumptions made about the DNS were incorrect in the early 
days of DNSSEC, more accurately, the field of operations as we know it today 
hadn’t begun.

One of my smoldering interests is “why aren’t new technologies adopted?”  It’s 
been 25 years since the first meeting to motivate DNSSEC adoption (April 1, 
1998, at a lunch during IETF 41, involving DARPA, ISC, and TISlabs).  I’ve seen 
the approaches of “more free tools”, “more education of operators”, “build a 
business case” all fail to achieve their mark.  My concern now, especially 
after hearing Shumon Huque’s DNS-OARC 40 presentation, along with some 1:1’s 
with operators in recent years, that the obstacles to deployment lie in the 
nature of how DNSSEC came to be.

I think there’s an overall desire to see DNSSEC succeed (omitting what 
‘success’ is for the moment) but there remain technical impediments in the way, 
some only identified as the field of DNS operations evolves.  There are things 
that can be fixed, but there needs to be a will to take on the ‘capital 
investment’ to do the work.  We do know more now that we did a quarter of a 
century ago.

And, for what it matters, I have some specific ideas I hope to have time to 
document and propose, this isn’t just a purely philosophical rant.  Well, it 
could be just a rant, if there’s no will to change.


_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to