Re: [DNSOP] Error handling in CAA

2017-11-18 Thread Mark Andrews
The only real way to determine if a lookup failure in internally or not is to query the authoritative servers for the zone directly. The simple fix is to charge $1000 extra if the CAA lookup fails due to the authoritative servers for the zone failing to support lookups for the CAA record or for th

Re: [DNSOP] Error handling in CAA

2017-11-18 Thread Viktor Dukhovni
On Fri, Nov 17, 2017 at 12:49:33PM -0800, Jacob Hoffman-Andrews wrote: > https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.5.4.pdf > > > CAs are permitted to treat a record lookup failure as permission to issue > > if: > > - the failure is outside the CA's infrastructure; > > - the lo

Re: [DNSOP] draft-ietf-dnsop-isp-ip6rdns

2017-11-18 Thread Paul Hoffman
On 16 Nov 2017, at 20:12, Lee Howard wrote: I updated this draft months ago, based on feedback from the previous WGLC, and it expired without comment. I’ve refreshed it, and would like to ask again for reviews (especially if anything has changed in the past year) and another WGLC. https://d