Re: [DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-11-01 Thread A. Schulze
Am 01.11.18 um 00:03 schrieb Wessels, Duane: > I think you might be the first person to argue for supporting multiple ZONEMD > algorithms per zone. I actually expected more. I remember Stephen Farrell saying something like "while designing new protocols, algorithm agility is an important poin

Re: [DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-11-01 Thread Joe Abley
On Nov 1, 2018, at 09:08, Richard Gibson wrote: RFC 2181 section 5: "It is meaningless for two records to ever have label, class, type and data all equal - servers should suppress such duplicates if encountered." And RFC 7719 section 4 affirms the "different data" requirement. Excellent. Joe

Re: [DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-11-01 Thread Richard Gibson
On 10/31/18 19:50, Joe Abley wrote: It sounds wrong to me to say that identical instances of RRs would not be allowed in a zone. It's true though, right? It's not meaningful to include more than one resource record with the same (owner,type, class, TTL, RDATA) in the same RRSet, and hence al

Re: [DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-10-31 Thread Joe Abley
Hi Duane, On 31 Oct 2018, at 19:03, Wessels, Duane wrote: >> Section 1.2 >> >> I don't understand the benefits of suggesting that verification of a zone >> digest "would be implemented in name server software". The inference is that >> software that normally concerns itself with responding to

Re: [DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-10-31 Thread Wessels, Duane
Hi Joe, Thanks for the detailed review. > On Oct 29, 2018, at 2:45 PM, Joe Abley wrote: > > Hi all, > > I have read draft-wessels-dns-zone-digest-04. > > General Summary > > I find this document to be generally well-written, clear and unambiguous. > > ... > > Nits > > The document conta

[DNSOP] review: draft-wessels-dns-zone-digest-04.txt

2018-10-29 Thread Joe Abley
Hi all, I have read draft-wessels-dns-zone-digest-04. General Summary I find this document to be generally well-written, clear and unambiguous. I think being able to embed a checksum in a zone, which can be authenticated using DNSSEC, is generally useful. I think describing the construction an