[DNSOP] Possible breaking inconsistencies in draft-ietf-dnsop-rfc8624-bis-01

2024-10-12 Thread Paul Hoffman
Earlier, Wes said "I believe the 8624bis document is functionally "done" and should be published." However, there has been too little discussion on what the new columns actually mean, and someone reading the new IANA registries would not know what to do. In specific, "Use for DNSSSEC Signing" a

[DNSOP] Re: draft-crocker-dnsop-dnssec-algorithm-lifecycle-01

2024-10-12 Thread Steve Crocker
Thanks for your comments. Regarding the lack of mention of the Red Hat incident, it seemed to me that an RFC proposing an organized way to manage the lifecycle of algorithms should not include mention of a particular incident. If someone feels it's necessary to document the triggering event, perh

[DNSOP] Re: DNSOPDNSOPdraft-crocker-dnsop-dnssec-algorithm-lifecycle-01

2024-10-12 Thread Steve Crocker
As I said in my immediately previous email, thanks for the support and I'm in complete agreement. Steve On Fri, Oct 11, 2024 at 6:22 PM Wes Hardaker wrote: > Wes Hardaker writes: > > > I believe we must allow for this possibility in the 4 columns even > > when we may wish it won't be used. >

[DNSOP] Re: Possible breaking inconsistencies in draft-ietf-dnsop-rfc8624-bis-01

2024-10-12 Thread Steve Crocker
Paul, You wrote, "You cannot use two algorithms to sign or delegate at the same time." If there are two or more independent signers for a zone -- see RFC 8901 -- then multiple algorithms might be in use at the same time. I think there is some wording that says the algorithms must be the same, I

[DNSOP] Re: [Ext] Possible breaking inconsistencies in draft-ietf-dnsop-rfc8624-bis-01

2024-10-12 Thread Paul Hoffman
On Oct 12, 2024, at 09:20, Steve Crocker wrote: > You wrote, "You cannot use two algorithms to sign or delegate at the same > time." If there are two or more independent signers for a zone -- see RFC > 8901 -- then multiple algorithms might be in use at the same time. > > I think there is some

[DNSOP] Re: DNSOPdraft-crocker-dnsop-dnssec-algorithm-lifecycle-01

2024-10-12 Thread Steve Crocker
Wes, Thanks for your comments and support. I'm in complete agreement. See inline for an additional comment. Steve On Fri, Oct 11, 2024 at 6:16 PM Wes Hardaker wrote: > Tim Wicinski writes: > > > I do believe the 8624bis authors and the WG are open to updating > the values for the table > >