[DNSOP] Evaluation of NSEC3-encloser attack

2024-03-25 Thread Haya Shulman
Dear researchers, operators and developers, Recently two attack vectors exploiting vulnerabilities in DNSSEC to launch Denial of Service (DoS) against DNS resolvers were publicly disclosed: KeyTrap and NSEC3-encloser attack. Both issues were assigned a CVE ID by MITRE: KeyTrap CVE-2023-50387 and

[DNSOP] [Editorial Errata Reported] RFC9460 (7871)

2024-03-25 Thread RFC Errata System
The following errata report has been submitted for RFC9460, "Service Binding and Parameter Specification via the DNS (SVCB and HTTPS Resource Records)". -- You may review the report below and at: https://www.rfc-editor.org/errata/eid7871 --

Re: [DNSOP] [Editorial Errata Reported] RFC9460 (7871)

2024-03-25 Thread Ben Schwartz
\DDD escaping in RFC 1035 is decimal, not octal [1]. --Ben P.S. I agree that this is unusual and surprising. [1] https://datatracker.ietf.org/doc/html/rfc1035#:~:text=%5CDDD%20%20%20%20%20%20%20%20%20%20%20%20where%20each%20D%20is%20a%20digit%20is%20the%20octet%20corresponding%20to%0A%20%20%20%

Re: [DNSOP] [Editorial Errata Reported] RFC9460 (7871)

2024-03-25 Thread Rebecca VanRheenen
Hi Warren, We are unable to verify this erratum that the submitter marked as editorial, so we changed the Type to “Technical”. As Stream Approver, please review and set the Status and Type accordingly (see the definitions at https://www.rfc-editor.org/errata-definitions/). You may review the r