2
0
mirror of https://github.com/ietf-wg-dnsop/wg-materials synced 2025-08-22 02:09:16 +00:00

Merge branch 'main' of github.com:ietf-wg-dnsop/wg-materials

This commit is contained in:
Benno Overeinder 2023-04-24 15:36:57 +02:00
commit eb587ef704
5 changed files with 138 additions and 21 deletions

View File

@ -1,19 +1,20 @@
# DNSOP Chairs Status
### Updated: 01 March 2023
### Updated: 28 March 2023
Official document list: https://datatracker.ietf.org/wg/dnsop/documents/
This Document: https://github.com/DNSOP/wg-materials/blob/master/dnsop-document-status.md
This Document: https://github.com/DNSOP/wg-materials/blob/main/dnsop-document-status.md
Questions, Concerns, etc: dnsop-chairs at ietf.org
## Done since Last Meeting
~~draft-ietf-dnsop-dnssec-bcp~~ **RFC9364**
### RFC Ed Queue
* ["Service binding and parameter specification via the DNS (DNS SVCB and HTTPS RRs)" - draft-ietf-dnsop-svcb-https](https://datatracker.ietf.org/doc/draft-ietf-dnsop-svcb-https/)
* ["DNS Security Extensions (DNSSEC)"](https://datatracker.ietf.org/doc/draft-ietf-dnsop-dnssec-bcp/)
- IETF LC until 2023-04-03
* ["DNS Catalog Zone" - draft-ietf-dnsop-dns-catalog-zones"](https://datatracker.ietf.org/doc/draft-ietf-dnsop-dns-catalog-zones/)
@ -23,21 +24,26 @@ Questions, Concerns, etc: dnsop-chairs at ietf.org
- AD Followup
* draft-ietf-dnsop-avoid-fragmentation
- No followup from implementors on appendix
* draft-ietf-dnsop-alt-tld
- IETF LC until 2023-04-10
## WGLC Approved
## In WG Last Call
* draft-ietf-dnsop-rfc8499bis
- Writeup after IETF
* draft-ietf-dnsop-glue-is-not-optional
- Writeup in next week.
* draft-ietf-dnsop-rfc8499bis
## In WG Last Call
* draft-ietf-dnsop-domain-verification-techniques
* draft-ietf-dnsop-dnssec-validator-requirements
- updated doc
- Another person doing editorial review
- Will take some time to clean up text
## Upcoming WG Last Calls
@ -46,20 +52,22 @@ Questions, Concerns, etc: dnsop-chairs at ietf.org
* draft-ietf-dnsop-dns-error-reporting
* draft-ietf-dnsop-caching-resolution-failures
- Authors feel ready
## Adopted by WG, Under Discussion (ranked)
* draft-ietf-dnsop-dnssec-bootstrapping
* draft-ietf-dnsop-ns-revalidation
- document has three TODO to address
- **Action**: Shumon working on adding an author to help
- Updated Document, resolved all outstanding TODOs
* draft-ietf-dnsop-dnssec-automation
- Still needs another agenda
* draft-ietf-dnsop-svcb-dane
* draft-ietf-dnsop-structured-dns-error-page
- Work In Progress
## Recently Expired Documents
@ -75,7 +83,6 @@ Questions, Concerns, etc: dnsop-chairs at ietf.org
* draft-klh-dnsop-rfc8109bis
## New Documents
* draft-huque-dnsop-compact-lies

View File

@ -1,31 +1,32 @@
# DNS Operations (DNSOP) Working Group
## IETF 116
* Date: Thursday, 30 March 2023
* Time: 09:30-11:30 JST (UTC+9 Tokyo)
* Room G403
* Time: 09:30-11:30 JST (00:30-02:30 UTC)
* Room: G403
* [MeetEcho](https://meetings.conf.meetecho.com/ietf116/?group=dnsop&short=&item=1)
* [Minutes](https://notes.ietf.org/notes-ietf-116-dnsop)
* [Zulip](https://zulip.ietf.org/#narrow/stream/dnsop)
* [Upload Slides](https://datatracker.ietf.org/meeting/116/session/dnsop)
### Chairs
* Benno Overeinder [benno@nlnetlabs.nl](benno@nlnetlabs.nl)
* Suzanne Woolf [suzworldwide@gmail.com](suzworldwide@gmail.com)
* Tim Wicinski [tjw.ietf@gmail.com](tjw.ietf@gmail.com)
### IESG Overlord
* Warren Kumari [warren@kumari.net](warren@kumari.net)
### Document Status
* [Github](https://github.com/ietf-wg-dnsop/wg-materials/blob/main/dnsop-document-status.md)
* [Datatracker](https://datatracker.ietf.org/wg/dnsop/documents/)
* [Upload Slides](https://datatracker.ietf.org/meeting/116/session/dnsop)
#
## Agenda
### Administrivia

View File

@ -0,0 +1,108 @@
DNSOP WG
IETF 116, Yokohama
Thursday moringing, March 30, 2023
Chairs: Benno Overeinder, Suzanne Woolf, Tim Wicinski (remote)
Minutes taken by Paul Hoffman
Only stuff said that happened at the mic is reported here
Administrivia and updates of old work
GNU Name System (Very Short Update), Christian Grothoff
https://datatracker.ietf.org/doc/draft-schanzen-gns/
Warren Kumari: Need to reply to authors
Did the IETF conflict review
Close to DNSOP, but doesn't prevent publication
Has a limited number of possible responses in the conflict review
Wes Hardaker: Thank you for using .alt
Lots of cool technology in the protocol
Christian: Knew that they had publish a RFC
Conflict with the RRtypes, prevents working with the DNS in the future
George Michaelson: Mostly philosophical comments
Implement a registry function for .alt
First occupant has some expectation of structure
Who has control of the registry?
Christian: Will do first come, first served in their own .alt
Has an issue with "reservers"
Should not be spinning an alternate registry
Christian: Didn't get an IANA, so they did their own
Eliot Lear: Thanks to the WG, authors and ADs
Has not made a publication decision yet
Invites people to still commment to the ISE
Structured Error Data for Filtered DNS - Document Update, Tirumal Reddy
https://datatracker.ietf.org/doc/draft-ietf-dnsop-structured-dns-error/
Ben Schwartz: Would like to see the registries tightly controlled: IETF review
Wants to prevent the designated expert from being pressured for odd states
Tommy Pauly: Agrees with Ben on reviews
Wants the text to not be browser-specific
Contact info marked as mandatory
There may be future cases which don't need contact info
Browser or OS may know better than the DNS about what to do because it has more context
Tiru: Agrees, didn't put specific URIs in
Should be a list of URIs, but may be too narrow
Structured Error Data for Filtered DNS - Implementation, Gianpaolo Scalone (remote) and Ralf Weber (local)
https://datatracker.ietf.org/doc/draft-ietf-dnsop-structured-dns-error/
Designed an extension for Chrome
Wes: Super happy to see the deployment
Ralf: No address redirection
Use NXDOMAIN with EDE
What is the UI when the main page is fine but are requesting sub-resource like JS or CSS
Tiru: Don't want a user to go to another page, so put it all on the main page
Gianpaolo: Sees some text to explain this
Tiru: Can address comments gotten here
Domain Verification Techniques using DNS, Shivan Kaul Sahib
https://datatracker.ietf.org/doc/draft-ietf-dnsop-domain-verification-techniques
Yasuhiro Morishita: Wants information for external DNS providers
Users cannot usually add underscore names
John Levine: Draft has considerbly improved
Wants more definition of what is machine-readable and what is human-readable
Give plausible argument about why CNAME is not a good idea
Wes: Encourage text that says if not using DNSSEC, must do other mechanisms
Compact Denial of Existence in DNSSEC, Shumon Huque
https://datatracker.ietf.org/doc/draft-huque-dnsop-compact-lies/
Lars-Johan Liman: Does the draft do things differently if the DO bit is set?
Shumon: Not currently, but is considering
But this has impact on resolver, please describe in document
Viktor Dukhovni: A lot of complexity depending on resolver setting DO bit
Someone might deliberately send known NXDOMAIN through resolvers
Shumon: Will document this
May take a while for current implementations to go away
Shumon: Optimistic that the current implementers can change quickly
Jim Reid: Skeptical of this
Rather ugly from protocol point of view
A lot of work for just to make responses shorter
Would want it to be informational
Shumon: Wants to implement what is already done
Christian Elmerot: Thinks that this simplifies things quite a bit
Already using in production, but are doing it differently
Wants to have one way to suggested
Jim: Happy to have this help coordination, not standard
Ralf: Thanks for doing this, need to document it
Should minimize impact on the rest of the ecosystem
Consistency for CDS/CDNSKEY and CSYNC is Mandatory, Peter Thomassen (remote)
https://datatracker.ietf.org/doc/draft-thomassen-dnsop-cds-consistency/
Viktor: Corner case: if someone is moving to a hoster that doesn't do DNSSEC
Peter: Could add a way to turn off DNSSEC on transfer
Johan Stenstram: Breaks the logic that "if it is signed, it is good"
Doesn't like "if this is really important"
Let's not go there
Authoritative servers are proxies for the registrant
Out of sync is reflection on the registrant: business issues
Wes: CSYNC was for keeping DNS up and running
CSYNC can't fix the business problems
Peter: Agrees that one signature should be OK
Other parts of the spec also suggest asking multiple places
Generalized DNS Notifications, Johan Stenstam
https://datatracker.ietf.org/doc/draft-thomassen-dnsop-generalized-dns-notify/
Viktor: Once it is a service, is the transport UDP?
DNS Out Of Protocol Signalling, Willem Toorop
https://datatracker.ietf.org/doc/draft-grubto-dnsop-dns-out-of-protocol-signalling/
Lars-Johan: Please do this

View File

@ -1,5 +1,6 @@
# DNS Operations (DNSOP) Working Group
## IETF %%MTG%%
* Date:
@ -9,23 +10,23 @@
* [MeetEcho](https://meetings.conf.meetecho.com/ietf%%MTG%%/?group=dnsop&short=&item=1)
* [Minutes](https://codimd.ietf.org/notes-ietf-%%MTG%%-dnsop)
* [Zulip](https://zulip.ietf.org/#narrow/stream/dnsop)
* [Upload Slides](https://datatracker.ietf.org/meeting/%%MTG%%/session/dnsop)
### Chairs
* Benno Overeinder [benno@nlnetlabs.nl](benno@nlnetlabs.nl)
* Suzanne Woolf [suzworldwide@gmail.com](suzworldwide@gmail.com)
* Tim Wicinski [tjw.ietf@gmail.com](tjw.ietf@gmail.com)
### IESG Overlord
* Warren Kumari [warren@kumari.net](warren@kumari.net)
### Document Status
* [Github](https://github.com/ietf-wg-dnsop/wg-materials/blob/main/dnsop-document-status.md)
* [Datatracker](https://datatracker.ietf.org/wg/dnsop/documents/)
* [Upload Slides](https://datatracker.ietf.org/meeting/%%MTG%%/session/dnsop)
#
## Agenda
### Administrivia

View File

@ -56,7 +56,7 @@ def printitem(docs):
for i in docs:
lines.append(f"* {i.get('title')}")
lines.append(f" - {i.get('url')}")
lines.append(f" - {i.get('email')}, {i.get('time')} min")
lines.append(f" - {i.get('email')}, {i.get('time')}")
lines.append(" - Chairs Action:")
lines.append("")
alltimes.append(f"{i.get('title')}\t{i.get('email')}\t{i.get('time')}\n")