Re: [DNSOP] Deprecating the status opcode

2019-05-15 Thread Chris Thompson
y reserved. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop

Re: [DNSOP] RFC 2136 pre-requisite checks before client authorization checks

2018-12-07 Thread Chris Thompson
specific RRs with guessed rdata, within it. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop

Re: [DNSOP] Review of draft-ietf-dnsop-terminology-bis-08

2017-12-22 Thread Chris Thompson
own parent. They can't both be true. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop

Re: [DNSOP] Order of CNAME and A in Authoritative Reply.

2015-08-12 Thread Chris Thompson
suggested by the use of together, though. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop

Re: [DNSOP] comments on draft-ietf-dnsop-dns-terminology-03

2015-07-14 Thread Chris Thompson
for any of its ancestors ? Also, as such a response is undoubtedly still legal, maybe this ought to mention what the common(er) practice now is - presumably REFUSED. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https

Re: [DNSOP] Review of draft-ietf-dnsop-resolver-priming-04

2014-09-15 Thread Chris Thompson
-octet minimum overhead is rather well known) -- Chris Thompson University of Cambridge Information Services, Email: c...@uis.cam.ac.ukRoger Needham Building, 7 JJ Thomson Avenue, Phone: +44 1223 334715 Cambridge CB3 0RB, United Kingdom

Re: [DNSOP] Anycast and DNS questions

2014-09-03 Thread Chris Thompson
than 27 (and a lot more detailed) although it still predates widespread use of anycast in the DNS context. Nothing has officially superceded RFC2182 and it remains a Best Common Practice document (BCP0016). -- Chris Thompson University of Cambridge Information Services, Email: c

[DNSOP] Insecure delegations from 239.in-addr.arpa needed? [was: draft-ietf-dnsop-rfc6598-rfc6303-01]

2014-08-20 Thread Chris Thompson
, but it doesn't contain any sort of delegation for these address ranges. What would be the right way to officially request IANA to do for 239.192.0.0/10 what Mark Andrews is proposing for 100.64.0,0/10? At least in this case ARIN is not involved: 239.in-addr.arpa is all IANA's own work! -- Chris

Re: [DNSOP] draft-ietf-dnsop-rfc6598-rfc6303-01

2014-08-20 Thread Chris Thompson
to EMPTY.AS112.ARPA once that is available. Would this last actually work to break the chain of trust (provided that EMPTY.AS112.NET was itself unsigned)? I am having difficulty working out exactly what a validator would do in this situation. -- Chris Thompson University of Cambridge

Re: [DNSOP] AS112 document question

2014-05-22 Thread Chris Thompson
and blackhole-2.iana.org have no records? Is the idea to introduce new names, or to add records to the existing names once there are enough AS112 nodes advertising the IPv6 prefix? -- Chris Thompson University of Cambridge Information Services, Email: c...@uis.cam.ac.uk

Re: [DNSOP] Extended CNAME (ENAME)

2014-05-20 Thread Chris Thompson
as the _http._srv.[name] one. (The idea of https overriding the port number(s) in the _http._srv.[name] records with 443 seems too horrible to contemplate.) -- Chris Thompson University of Cambridge Information Services, Email: c...@uis.cam.ac.ukRoger Needham Building, 7 JJ Thomson Avenue

Re: [DNSOP] search for normative reference

2013-12-18 Thread Chris Thompson
. (Well, they do as long as its official slaves are doing what we asked them to...) All this is not because we are particularly concerned to keep the zone contents secret. It's because they would be misleading. -- Chris Thompson University of Cambridge Computing Service, Email: c

[DNSOP] DNAMEs in the root zone? [was: Re: draft-grothoff-iesg-special-use-p2p-names-00.txt]

2013-12-09 Thread Chris Thompson
On Dec 7 2013, Joe Abley wrote: On 2013-12-05, at 07:15, Chris Thompson c...@cam.ac.uk wrote: [...] How would such DNAMEs interact with use of BIND's root-delegation-only (or equivalents, if any, in other software)? Do we have any idea how widespread use of that option is? I don't recall

Re: [DNSOP] [internet-dra...@ietf.org: I-D Action: draft-grothoff-iesg-special-use-p2p-names-00.txt]

2013-12-05 Thread Chris Thompson
of that option is? When ipv4only.arpa appeared as a delegation in October, I did wonder why it wasn't just an A rrset in the arpa zone, until I thought of that issue. Although maybe the reasoning was actually different. -- Chris Thompson University of Cambridge Computing Service, Email: c

[DNSOP] Root zone KSK rollover

2013-11-27 Thread Chris Thompson
, the IAB suggests the rollover of the Root Zone KSK before the end of the year, with significant prior notice to all involved parties, including vendors, implementors, TLD operators, and end-users. I think we can be fairly confident *that* isn't going to happen... :-) -- Chris Thompson

Re: [DNSOP] Fwd: New Version Notification for draft-jabley-dnsop-as112-dname-00.txt

2013-06-29 Thread Chris Thompson
)? Of course if the scheme goes ahead, EMPTY.AS112.ARPA itself becomes an obvious candidate for such a local definition as well. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United

Re: [DNSOP] Thoughts on CDS

2013-04-22 Thread Chris Thompson
be ignored. That is, the chain of trust used by the parent to validate a CDS is restricted to be of length 1. That is all it knows on earth, and all it needs to know (with apologies to John Keats). -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.uk

Re: [DNSOP] General comments on draft-kumari-ogud-dnsop-cds-01

2013-03-05 Thread Chris Thompson
contain RRs of the same class. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom. ___ DNSOP mailing list DNSOP

Re: [DNSOP] Adoption of draft-wkumari-dnsop-omniscient-as112-01.txt as a WG work item?

2013-02-27 Thread Chris Thompson
is to generate a negative answer to a reverse lookup. More to the current point is that (unfortunately) few DNS registries support putting DNAMEs in parent zones in place of delegations. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site

Re: [DNSOP] Adoption of draft-wkumari-dnsop-omniscient-as112-01.txt as a WG work item?

2013-02-22 Thread Chris Thompson
, and BIND gives me a NODATA response from its automatic empty zones that cover just those specific addresses and no others, then it is being unsafe? -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44

Re: [DNSOP] draft-wouters-dnsop-secure-update-use-cases-00

2012-07-24 Thread Chris Thompson
case if I could be sure that the updating of the delegation could always be done in a timely fashion. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom

Re: [DNSOP] draft-wouters-dnsop-secure-update-use-cases-00

2012-07-11 Thread Chris Thompson
in the delegation that points to a server that is not in fact authoritative for the zone at all. Is the above actually common usage? [That's not to say that any differences between the two NS RRsets is ever desirable, except as may be necessary or expedient during a change.] -- Chris Thompson

Re: [DNSOP] A good chance to get all riled up - draft-wkumari-dnsop-omniscient-as112-00

2012-06-12 Thread Chris Thompson
, the zones listed above will need to be delegated as * insecure delegations, or be within insecure zones. This will allow * DNSSEC validation to succeed for queries in these spaces despite not * being answered from the delegated servers. -- Chris Thompson University of Cambridge Computing

Re: [DNSOP] Sanity check

2011-10-27 Thread Chris Thompson
? -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom. ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo

Re: [DNSOP] CDS RRtype - automated KSK rollover

2011-07-06 Thread Chris Thompson
to worry about how to update the DS records in the parent zone :-) -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom

Re: [DNSOP] CDS RRtype - automated KSK rollover

2011-07-05 Thread Chris Thompson
and child, but there could be problems with automatically updating glue. The authoritative value of required glue may come from a grandchild zone which is not signed, even if the child is, and sibling glue could similarly involve unsigned zones. -- Chris Thompson University

Re: [DNSOP] CDS RRtype - automated KSK rollover

2011-07-05 Thread Chris Thompson
with a key for which the parent already holds a DS record would be the appropriate modification. But is this really necessary? -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United

Re: [DNSOP] WGLC: draft-ietf-dnsop-dnssec-dps-framework-04.txt

2011-06-23 Thread Chris Thompson
of uk managed by Nominet, are more recent examples. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom. ___ DNSOP mailing

Re: [DNSOP] draft-ietf-dnsop-default-local-zones-13

2010-06-15 Thread Chris Thompson
. ... PTR 8.e.f.ip6.arpa. PTR 9.e.f.ip6.arpa. ... Not that this would stop some implementors fetching the current value and fixing it in their code... One would want local.zones.arpa (or whatever) to be signed, of course! -- Chris Thompson

Re: [DNSOP] KSK rollover

2010-05-22 Thread Chris Thompson
? Why shouldn't a chain of trust through (say) a KSK and a ZSK be enough? Insisting on a one-step chain seems contrary to the spirit, at least, of RFC 4034 section 2.1.1. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site

Re: [DNSOP] RFC4641bis Editing Status Report.

2010-03-20 Thread Chris Thompson
imply NSEC3 support? If not, should we? I suppose it is still open to DNSEXT to submit new algorithms which imply NSEC only, but of course that is not expected to happen. (Anyway, 253 254 are 5 and there it's a matter for private agreement.) -- Chris Thompson University of Cambridge

Re: [DNSOP] Should root-servers.net be signed

2010-03-07 Thread Chris Thompson
does sign it's name servers. And indeed ns.se is in the se zone (no zone cut). But the consequence is that a DO=1 priming query for se returns 2706 bytes while one for . from the (DURZ-signed) root servers returns only 801 bytes. -- Chris Thompson University of Cambridge Computing

Re: [DNSOP] new draft about idn tld variants implementation

2009-10-16 Thread Chris Thompson
On Oct 16 2009, Alfred Hönes wrote: On Oct 16 2009, Chris Thompson wrote: On Oct 16 2009, Alfred Hönes wrote: Another point: The draft is speaking abut DNAME _in_ the root. According to my surficial knowledge, DNAME RRs 'live' at the _apex_ of the zone that shall be redirected

Re: [DNSOP] Why ZSK rollover is a Bad Idea (tm)

2009-10-07 Thread Chris Thompson
with KSKs rather than (the parent's) ZSKs? -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom. ___ DNSOP mailing list

Re: [DNSOP] Key Management and Provisioningl was Re: .PR ...

2009-09-09 Thread Chris Thompson
: of course. But incremental policy improvements would help meanwhile. -- Chris Thompson University of Cambridge Computing Service, Email: c...@ucs.cam.ac.ukNew Museums Site, Cambridge CB2 3QH, Phone: +44 1223 334715 United Kingdom

Re: [DNSOP] Key sizes was Re: I-D Action:draft-ietf-dnsop-rfc4641bis-01.txt

2009-04-22 Thread Chris Thompson
how much do we have to charge Black Hat, Inc. per key we crack for them, to make a decent profit?. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop

Re: [DNSOP] MX 0 . standard way of saying we don't do email ?

2009-04-15 Thread Chris Thompson
sure is why Philip Hazel implemented the option in the first place. Exim also provides the ability to use different retry rules in the case when the target was found via an A or record, and these are quite often used to give up (much) sooner on such deliveries. -- Chris Thompson Email: c

Re: [DNSOP] Updates to AS 112 WG drafts

2009-03-12 Thread Chris Thompson
of browser guesswork (there is no address record for as112.net). Not that I can get any response out of www.as112.net = 204.152.184.180 at the moment, either ... :-( -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https

Re: [DNSOP] Truncation discussion in draft-ietf-dnsop-dnssec-trust-anchor-02

2009-03-10 Thread Chris Thompson
long. On that basis, the trust anchor for the root zone ought to be the DS record from Trantor. -- Chris Thompson Email: c...@cam.ac.uk ___ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop