On Wed, 2021-10-20 at 11:24 -0700, Wes Hardaker wrote:
> So, the question: what's the right FINAL value to put in the draft
> before LC?

I don't know what the -right- value is, but I know what I want: 0 iterations, 
empty salt, otherwise the NSEC3 gets ignored, presumably leading to SERVFAIL. 
This removes the 'insecure' window completely.

So, I'll support any push to lower the numbers.

Editorial nit, already hinted at above: the text currently has "Validating 
resolvers MAY return SERVFAIL when processing NSEC3 records with iterations 
larger than 500." - I suggest changing this to "validating resolvers MAY ignore 
NSEC3 records with iterations larger than 500". That way, zones in the middle 
of a transition from 1000 to 0 iterations do not get punished. Zones at 1000, 
not in a transition, will still get SERVFAIL by virtue of the NSEC3 proof 
missing (because it is ignored).

Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to