[DNSOP] Secdir early review of draft-ietf-dnsop-domain-verification-techniques-05

2024-08-07 Thread Benjamin Kaduk via Datatracker
Reviewer: Benjamin Kaduk Review result: Has Issues # SecDir review of draft-ietf-dnsop-domain-verification-techniques-05 CC @kaduk Since the changes from the -01 that I previously reviewed are so substantial, this is mostly a de novo review. The main comment on the diff is on the weakening of th

[DNSOP] Re: Request Feedback: draft-sheth-dns-integration

2024-08-07 Thread Ben Schwartz
Section 5.7 of draft-ietf-dnsop-domain-verification-techniques-05 says Some Application Service Providers currently require the Validation Record to remain in the zone indefinitely for periodic revalidation purposes. This practice should be discouraged. Subsequent validation action