Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Wes Hardaker
Warren Kumari writes: > This reply might have been a bit hasty -- I don't actually know how > tightly this is specified, or who decided which DS algorithm should be > used. I'm not personally sure how the algorithms/other-properties are picked for the IANA zones. I can certainly ask the IAB to

Re: [DNSOP] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Viktor Dukhovni
On Thu, Sep 09, 2021 at 11:28:04AM -0400, Paul Wouters wrote: > Looks like for arpa., the DS records are: > > arpa. 27247 IN DS 42581 8 1 > 778606D9623F843F156E7D11ACBF815EB67AB516 > arpa. 27247 IN DS 42581 8 2 > F28391C1ED4DC0F151EDD251A3

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Warren Kumari
On Thu, Sep 9, 2021 at 1:39 PM Warren Kumari wrote: > > > On Thu, Sep 9, 2021 at 12:13 PM Joe Abley wrote: > >> Hi Paul (W), >> >> On Sep 9, 2021, at 12:05, Paul Wouters wrote: >> >> > On Thu, 9 Sep 2021, Paul Hoffman wrote: >> >> >> >> Did you first ask the administrators of the zone in quest

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Warren Kumari
On Thu, Sep 9, 2021 at 12:13 PM Joe Abley wrote: > Hi Paul (W), > > On Sep 9, 2021, at 12:05, Paul Wouters wrote: > > > On Thu, 9 Sep 2021, Paul Hoffman wrote: > >> > >> Did you first ask the administrators of the zone in question before > sending this message to a grooup that has no administra

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Suzanne Woolf
Hi, (Wes and Warren— cc’d as IAB and IESG members, do you guys have any further guidance?) > On Sep 9, 2021, at 12:12 PM, Joe Abley wrote > > The IETF (well, the IAB) has administrative control over the contents of the > ARPA zone. I do not know in practice whether this extends to the machine

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Joe Abley
Hi Paul (W), On Sep 9, 2021, at 12:05, Paul Wouters wrote: > On Thu, 9 Sep 2021, Paul Hoffman wrote: >> >> Did you first ask the administrators of the zone in question before sending >> this message to a grooup that has no administrative power over the zone? > > No, I used this group as the

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Paul Wouters
On Thu, 9 Sep 2021, Paul Hoffman wrote: On Sep 9, 2021, at 8:28 AM, Paul Wouters wrote: This is hinted strongly at in 2006: https://datatracker.ietf.org/doc/html/rfc4509#section-6.2 and even stronger via a MUST NOT in 2019's RFC 8624: https://datatracker.ietf.org/doc/html/rf

Re: [DNSOP] [Ext] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Paul Hoffman
On Sep 9, 2021, at 8:28 AM, Paul Wouters wrote: > This is hinted strongly at in 2006: > > https://datatracker.ietf.org/doc/html/rfc4509#section-6.2 > > and even stronger via a MUST NOT in 2019's RFC 8624: > > https://datatracker.ietf.org/doc/html/rfc8624#section-3.3 RFC 8624 is imp

[DNSOP] SHA-1 DS algo in arpa. :)

2021-09-09 Thread Paul Wouters
Looks like for arpa., the DS records are: arpa. 27247 IN DS 42581 8 1 778606D9623F843F156E7D11ACBF815EB67AB516 arpa. 27247 IN DS 42581 8 2 F28391C1ED4DC0F151EDD251A3103DCE0B9A5A251ACF6E24073771D7 1F3C40F9 Per our own recommendation

Re: [DNSOP] Genart last call review of draft-ietf-dnsop-dns-tcp-requirements-12

2021-09-09 Thread Petr Špaček
On 07. 09. 21 18:46, Wessels, Duane wrote: Dan, thanks for the review. Responses are inline. On Sep 1, 2021, at 3:12 AM, Dan Romascanu via Datatracker wrote: Minor issues: 1. In Section 4.1: DNS clients MAY also enable TFO when possible. Maybe I do not fully understand the intent he