From 2a540924f913c4a6cc4697c82b246acee1b9e52f Mon Sep 17 00:00:00 2001 From: Tim Wicinski Date: Fri, 17 Apr 2020 17:59:38 -0400 Subject: [PATCH] added dmitry; minutes --- .../dnsop-ietf107-agenda-requests.md | 6 + dnsop-ietf107/dnsop-ietf107-agenda.md | 4 + dnsop-ietf107/dnsop-ietf107-minutes.md | 227 ++++++++++++++++++ 3 files changed, 237 insertions(+) create mode 100644 dnsop-ietf107/dnsop-ietf107-minutes.md diff --git a/dnsop-ietf107/dnsop-ietf107-agenda-requests.md b/dnsop-ietf107/dnsop-ietf107-agenda-requests.md index c831a22..96a3a4f 100644 --- a/dnsop-ietf107/dnsop-ietf107-agenda-requests.md +++ b/dnsop-ietf107/dnsop-ietf107-agenda-requests.md @@ -75,3 +75,9 @@ - Requester Email: shuque@gmail.com - Time Requested: 15min - Chairs Action: + +* Draft name: Use of GOST 2012 Signature Algorithms + - Datatracker URL: https://datatracker.ietf.org/doc/draft-belyavskiy-rfc5933-bis/ + - Requester Email: beldmit@gmail.com + - Time Requested: 15min + - Chairs Action: diff --git a/dnsop-ietf107/dnsop-ietf107-agenda.md b/dnsop-ietf107/dnsop-ietf107-agenda.md index 2e8cb1c..f25a9a8 100644 --- a/dnsop-ietf107/dnsop-ietf107-agenda.md +++ b/dnsop-ietf107/dnsop-ietf107-agenda.md @@ -128,6 +128,10 @@ title: DNSOP-interim-2020-01/-02 - Shumon Huque, 15 min - Chairs Action: +### Use of GOST 2012 Signature Algorithms in DNSKEY and RRSIG Resource Records for DNSSEC + - https://datatracker.ietf.org/doc/draft-belyavskiy-rfc5933-bis/ + - Dmitry Belyavsky, 15min + - Chairs Action: # ## Reference diff --git a/dnsop-ietf107/dnsop-ietf107-minutes.md b/dnsop-ietf107/dnsop-ietf107-minutes.md new file mode 100644 index 0000000..b2de781 --- /dev/null +++ b/dnsop-ietf107/dnsop-ietf107-minutes.md @@ -0,0 +1,227 @@ + +# DNS Operations (DNSOP) Working Group +## interim-2020-dnsop-01 + +* Date: 14 April 2020 +* Time: 1400-1600 UTC +* Webex: https://ietf.webex.com/ietf/j.php?MTID=m706bba8b48e3db3db02d72f0941b2630 + +### +* Jabber: dnsop@jabber.ietf.org +* EtherPad: https://etherpad.ietf.org:9009/p/interim-2020-dnsop-01 + +### Chairs +* Tim Wicinski tjw.ietf@gmail.com +* Suzanne Woolf suzworldwide@gmail.com +* Benno Overeinder benno@nlnetlabs.nl + +### IESG Overlord +* Warren Kumari warren@kumari.net + +### Document Status +* https://github.com/DNSOP/wg-materials/blob/master/dnsop-document-status.md + +### Datatracker +* https://datatracker.ietf.org/wg/dnsop/documents/ + +# Agenda + +## Administrivia + * Agenda Bashing, Blue Sheets, etc, 10 min + * Updates of Old Work, Chairs, 10 min + +## Current Working Group Business + +### Service binding and parameter specification via the DNS + - https://datatracker.ietf.org/doc/draft-ietf-dnsop-svcb-httpssvc/ + - Ben Schwartz, 15 min + - Chairs Action: ? +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-svcb-httpssvc-slides/ + +Stephen Farrell: Keep the ALPN port; +Paul Vixie: I proposed removing port number. add a warning that operators should avoid using non-default ports for general Internet use. +Non-default ports may be firewalled in client networks, so may appear to work in testing but may not work for some clients/users. +Ben Schwartz: We can fix this with 1-2 sentences + +Chairs: Want to encourage Interop testing, and WGLC before 108 + +### DNS Query Name Minimisation to Improve Privacy (bis) + - https://datatracker.ietf.org/doc/draft-ietf-dnsop-rfc7816bis/ + - Ralph Dolmans, 15min + - Chairs Action: How close to WGLC? +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-draft-ietf-dnsop-rfc7816bis/ + +Ralf Weber: don't minimize forwarding; +Jim Reid: query limiting - wording on labels +Stehane Bortzmeyer: number of queries - SHOULD is reasonable (also, see section 7.1 of RFC 1035) +Paul Vixie: 1) auth misconfig hard to detect, mixed-mode authority and delegation disappeared. with NS, answer in answer section. +2) rate limiting have ddos implications. +Joe Abley: choice of qtype - use SOA as an option. +Ralph: small set of qtypes +Joe: any benefit to a small set? +Paul: Agree with Joe, SOA should be in the mix +Mark Andrews: Forwarders and qname +Warren Kumari: Why are we not using the original qtype +Ralph: Pick the most common qtype the upstream would use +Ralph: NS queries are sometimes blocked, but A are not. +Erik Nygren: A vs AAAA query. A may stick out more. + +Chairs Action: New Version, then working toward WGLC + +# +## New Working Group Business + +### Avoid IP fragmentation in DNS + - https://datatracker.ietf.org/doc/draft-fujiwara-dnsop-avoid-fragmentation/ + - Kazunori Fujiwara, 15 min + - Chairs Action: Adopt? +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-avoid-fragmentation-in-dns/ + +Joe Abley: this is useful +Ralf Weber: Useful + + +### The Delegation_Only DNSKEY flag + - https://tools.ietf.org/html/draft-pwouters-powerbind-03 + - Paul Wouters, 10 min + - Chairs Action: Adopt? +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-slides-interim-2020-dnsop-01-draft-pwouters-powerbind/ + +ben Schwartz: Why does it need to be machine readable? +Peter van Dijk: +Ralf Weber: +Joe Abley: adding complexity must have problem to solve +PW: Large outside subset to never trust DNSSEC. +Wes Hardaker: DNSSEC transparency because don't trust DNSSEC +Joe Abley: World is not as clean as it seems +Warren Kumari: +Matthijs Mekking: + +### Parameterized Nameserver Delegation with NS2 and NS2T + - https://datatracker.ietf.org/doc/draft-tapril-ns2/ + - Tim April, 15 min + - Chairs Action: +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-slides-draft-tapril-ns2/ + +Sam Weiler: Chil/Parent/both no restrictions. new record type that only appears on the parent is a can of worms. +Matt Pounsett: if redesigning NS, remove the current ambiquity. +Joe Abley: Can allow clients to never use old polocy +Peter van Dijk: Agree with Sam/Joe, as a resolver implementor, this is scary. +Alexander Dupuy: If done, present in parent, and in authority sections. +Paul Hoffman: Similiar to work done in ADD queue +Ralf Weber: Stub/resolver different than resolver/authorative +Ben Schwartz: Work like this is blocking current dprive work + +### DNS Catalog Zones & A Data Model for Configuring DNS Zone Provisioning + - https://datatracker.ietf.org/doc/draft-toorop-dnsop-dns-catalog-zones/ + - https://datatracker.ietf.org/doc/draft-toorop-dnsop-dns-zone-provisioning-yang/ + - Willem Toorop, 15 min + - Chairs Action: +https://datatracker.ietf.org/doc/slides-interim-2020-dnsop-01-sessa-cross-implementation-configuration-and-provisioning-management/ + +Vixie: Will drop metazone in favor of this + +# +## Reference + +### BlueSheets + +Attendees are asked to visit and enter your Name+Affiliation in the Blue-Sheet section of the DNSOP Etherpad. + +### Mic Line Queue + +The Mic Line will use the WebEx chat channel. To get in the queue type q+ to leave type q-. +Please don't type questions or other things into the WebEx chat channel as that will make +managing the queue very hard for the chairs. Please use the Jabber channel for side conversations. + +When you connect into WebEx you should start off as auto-muted so you'll +need to unmute yourself to speak when called. + +### Helpful Info & Prep + +The IETF has prepared a couple of documents to help get everyone ready. + + https://www.ietf.org/how/meetings/107/session-participant-guide/ + + https://www.ietf.org/how/meetings/107/session-presenter-guide/ + +Attendee List +========== +Warren Kumari, Google +Stephen Farell, Trinity College Dublin +Hugo Salgado, .CL +Ralph Dolmans, NLnet Labs +Donald Eastlake, Futurewei +Paul Ebersman, Neustar +Joe Abley, PIR +Joao Damas, APNIC +Willem Toorop, NLnet Labs +John Border, Hughes +Kazunori Fujiawra, JPRS +Mike Bishop, Akamai +Ted Hardie, Google +Murray Kucherawy, Facebook +Tim Wicinski, unaffialted +Stéphane Bortzmeyer, AFNIC +Sean Turner, sn3rd +Shumon Huque, Salesforce +Peter van Dijk, Open-Xchange PowerDNS +Keith Mitchell, DNS-OARC +Ben Schwartz, Google +Yoshiro YONEYA, JPRS +Sam Weiler, W3C/MIT +John Dickinson Sinodun IT +Vittorio Bertola, Open-Xchange +David Kinzel, Shaw Communications +Ralf Weber, Akamai Technologies +Scott Hollenbeck, Verisign +Michael Gibbs, Verisign +Ash Wilson, Valimail +Eric Orth, Google +Michael Hausding, SWITCH +Jerry Lundström, DNS-OARC +Witold Kręcicki, ISC +Puneet Sood, Google +Paul Vixie, Farsight +Jim Popovitch, DomainMail, LLC (just curious) +Shinta Sato, JPRS +Ladislav Lhotka, CZ.NIC +Joey Salazar, ARTICLE19 +Dick Franks, unaffiliated +Zaid AlBanna, Verisign +Tim April, Akamai Technologies +Mallory Knodel, CDT +Matthijs Mekking, ISC +Roland van Rijswijk-Deij, NLnet Labs +Fredereico Neves, Nic.br +Cathy Aronson, ARIN +Mark Andrews, ISC +Pieter Lexis, Open-Xchange PowerDNS +Jeff Osborn, ISC +Duane Wessels, Verisign +Shane Kerr, NS1 +Erik Nygren, Akamai +Matthew Pounsett, DNS-OARC +Bernie Innocenti, Google +Petr Špaček, CZ.NIC +James Gould, Verisign +Vladimir Cunat, cz.nic +Denesh Bhabuta, DNS-OARC +daniel migault +Jim Reid, RTFM llp +Alexander Dupuy, Google +David Blacka, Verisign +Robert Story, USC/ISI +Chi-Jiun Su, Hughes Network Systems +Mauricio Vergara Ereche, ICANN +Claire Pershan, unaffiliated +Michael Richardson, Sandelman Software Works +Wes Hardaker, ISI +Kaustubha Govind, Google Chrome +Marc Groeneweg, SIDN +Hugo Kobayashi, NIC.br +Paul Wouters, Red Hat +Paul Hoffman, ICANN +Benno Overeinder, NLNet Labs +Suzanne Woolf, PIR +Dan McArdle, Google/Chrome