Re: [DNSOP] Working Group Last Call for draft-ietf-dnsop-qdcount-is-one

2024-03-18 Thread Joe Abley
Hi Chris, Thanks for the review! On 19 Mar 2024, at 03:28, Chris Box wrote: > It is a little cart-before-horse in having the reasoning occur after the > conclusion. But I can see the benefit in having a very clear statement up > front in the document. Some people only read the beginning. The

Re: [DNSOP] Working Group Last Call for draft-ietf-dnsop-qdcount-is-one

2024-03-18 Thread Chris Box
DNSOP, I've reviewed draft-ietf-dnsop-qdcount-is-one-02. I find it generally very clear. It is a little cart-before-horse in having the reasoning occur after the conclusion. But I can see the benefit in having a very clear statement up front in the document. Some people only read the beginning. S

Re: [DNSOP] I-D Action: draft-ietf-dnsop-ns-revalidation-06.txt

2024-03-18 Thread Willem Toorop
Op 18-03-2024 om 17:01 schreef Florian Obser: On 2024-03-17 20:12 -07,internet-dra...@ietf.org wrote: Internet-Draft draft-ietf-dnsop-ns-revalidation-06.txt is now available. It is | 7. Security Considerations | [...] | In case of non DNSSEC validating | resolvers, an attacker controlling a

Re: [DNSOP] Dnsdir early review of draft-ietf-dnsop-dnssec-automation-02

2024-03-18 Thread Jim Reid
> On 18 Mar 2024, at 12:50, David Lawrence via Datatracker > wrote: > > Reviewer: David Lawrence > Review result: On the Right Track > > Early review of draft-ietf-dnsop-dnssec-automation. Thanks *very* much for such a detailed review Tale. I’m sure the authors will appreciate your comments

[DNSOP] Dnsdir early review of draft-ietf-dnsop-dnssec-automation-02

2024-03-18 Thread David Lawrence via Datatracker
Reviewer: David Lawrence Review result: On the Right Track Early review of draft-ietf-dnsop-dnssec-automation. The process itself seems to be reasonably described. I don't have any suggestions as to the basic steps proposed. Questions: Section 2 is titled "Use Cases" but 2.1 isn't a use case a

Re: [DNSOP] I-D Action: draft-ietf-dnsop-ns-revalidation-06.txt

2024-03-18 Thread Florian Obser
On 2024-03-18 10:33 +01, Philip Homburg wrote: > In your letter dated Mon, 18 Mar 2024 08:01:38 +0100 you wrote: >>On 2024-03-17 20:12 -07, internet-dra...@ietf.org wrote: >>> Internet-Draft draft-ietf-dnsop-ns-revalidation-06.txt is now available. It >>is >> >>| 7. Security Considerations >>| [

Re: [DNSOP] I-D Action: draft-ietf-dnsop-compact-denial-of-existence-03.txt

2024-03-18 Thread Geoff Huston
> On 18 Mar 2024, at 9:32 AM, Dave Lawrence wrote: > > Shumon Huque writes: >> The draft allows (but does not proscribe) NXDOMAIN to be inserted >> into the Rcode for non DNSSEC enabled responses. I guess the main >> reason for not being proscriptive was what I mentioned - there were >> deploym

Re: [DNSOP] I-D Action: draft-ietf-dnsop-ns-revalidation-06.txt

2024-03-18 Thread Philip Homburg
In your letter dated Mon, 18 Mar 2024 08:01:38 +0100 you wrote: >On 2024-03-17 20:12 -07, internet-dra...@ietf.org wrote: >> Internet-Draft draft-ietf-dnsop-ns-revalidation-06.txt is now available. It >is > >| 7. Security Considerations >| [...] >| In case of non DNSSEC validating >| resolvers, a

Re: [DNSOP] I-D Action: draft-ietf-dnsop-ns-revalidation-06.txt

2024-03-18 Thread Florian Obser
On 2024-03-17 20:12 -07, internet-dra...@ietf.org wrote: > Internet-Draft draft-ietf-dnsop-ns-revalidation-06.txt is now available. It is | 7. Security Considerations | [...] | In case of non DNSSEC validating | resolvers, an attacker controlling a rogue name server for the root | has potentially