• Revised I-D Needed - Issue raised by WG
  • Awaiting Expert Review/Resolution of Issues Raised
  • Awaiting External Review/Resolution of Issues Raised
  • Awaiting Merge with Other Document
  • Author or Editor Needed
  • Waiting for Referenced Document
  • Waiting for Referencing Document
  • Revised I-D Needed - Issue raised by WGLC
  • Revised I-D Needed - Issue raised by AD
  • Revised I-D Needed - Issue raised by IESG
  • Doc Shepherd Follow-up Underway
  • Other - see Comment Log

IETF :: dnsop

Current state: Submitted to IESG for Publication

Viewing the last 20 entries. Show full log.

(System)

RFC published

Cindy Morgan

State changed to RFC Ed Queue from Approved-announcement sent

(System)

IANA Action state changed to No IC

Cindy Morgan

State changed to Approved-announcement sent from Approved-announcement to be sent

Cindy Morgan

IESG has approved the document

Cindy Morgan

Closed "Approve" ballot

Cindy Morgan

Ballot approval text was generated

Cindy Morgan

Ballot writeup was changed

Ron Bonica

State changed to Approved-announcement to be sent from Approved-announcement to be sent::Point Raised - writeup needed

Matthijs Mekking

New revision available

Cindy Morgan

State changed to Approved-announcement to be sent::Point Raised - writeup needed from Waiting for AD Go-Ahead

Stewart Bryant

[Ballot comment]
I have not read this draft, but from the reviews of my IESG colleagues, it is clear that I would have no objection to it's publication.

Stewart Bryant

[Ballot Position Update] New position, No Objection, has been recorded for Stewart Bryant

Pete Resnick

[Ballot Position Update] New position, No Objection, has been recorded for Pete Resnick

Barry Leiba

[Ballot comment]
Another vote for "A fine document." And another vote for "Turn Appendix E into a retained summary of changes from 4641."

Barry Leiba

[Ballot Position Update] New position, Yes, has been recorded for Barry Leiba

Sean Turner

[Ballot comment]
This was a pleasure to read - nicely done.

One shameless plug for security considerations of MD5 and SHA-1: RFC 6151 (MD5 Security Considerations) and RFC 6194 (SHA-1 security considerations).

Sean Turner

[Ballot Position Update] New position, Yes, has been recorded for Sean Turner

Stephen Farrell

[Ballot comment]

Excellent document, thanks.

I found the diff from RFC 4641 to be too big to be much use
(with the time available for review) so feel free to tell me
where to go if I make a comment on existing 4641 text and
you don't wanna think about the comment.

- 3.4.1 - I think its fair to say now that rsa-sha256 is
widely supported in libraries at least. I've no idea about
how well its supported in validators, but the lack of sha256
in libraries was previously the cause of delay elsewhere.

- 3.4.4 - Maybe worth a reference to the Lenstra paper [1]
as a warning to use good RNGs. They found a non-negligible
percentage of keys that were badly generated due
(presumably) to a lack of good randomness when e.g. devices
were first powered on.

[1] http://eprint.iacr.org/2012/064

- 4.4.1 - "to be a fraction of your signature validity
period" is unclear. 1/100000 is a fraction as is 9/10 but so
is 100000/1. In another reading of that text you might also
be asking that the signature validity period be a multiple
of the TTL. I think that needs to be made more clear.

- 4.4.2.2 - Is "Inception time" well (enough) defined? It is
mentioned in 1.2 but I'd forgotten that by the time I got
here and 1.2 doesn't have a reference. Might be no harm to
say a bit more about what that is in both places. (In
particular since here, you also have the inception offset
which is not defined in this doc.) Maybe do that in
appendix A?

typos:

- p8, last sentence of 3rd para has a typo, maybe
s/are based/that are based/

- p10, typo, s/it's not much point/there's not much
point/

Stephen Farrell

[Ballot Position Update] New position, Yes, has been recorded for Stephen Farrell

Viewing the last 20 entries. Show full log.