Moving DNSSEC Lookaside Validation (DLV) to Historic Status
draft-ietf-dnsop-obsolete-dlv-02

Document Type Active Internet-Draft (dnsop WG)
Last updated 2019-11-05 (latest revision 2019-10-31)
Replaces draft-mekking-dnsop-obsolete-dlv
Stream IETF
Intended RFC status Proposed Standard
Formats plain text xml pdf htmlized bibtex
Reviews
Stream WG state Submitted to IESG for Publication
Document shepherd Tim Wicinski
Shepherd write-up Show (last changed 2019-09-03)
IESG IESG state RFC Ed Queue
Consensus Boilerplate Yes
Telechat date
Responsible AD Warren Kumari
Send notices to Tim Wicinski <tjw.ietf@gmail.com>
IANA IANA review state IANA OK - Actions Needed
IANA action state RFC-Ed-Ack
IANA expert review state Expert Reviews OK
IANA expert review comments I have reviewed the document and it is fine, after the RFC is published the line should read DLV 32769 DNSSEC Lookaside Validation (OBSOLETE) [RFCXYZZ] [RFC4431]
RFC Editor RFC Editor state EDIT
DNS Operations                                                W. Mekking
Internet-Draft                                                D. Mahoney
Updates: 6698, 6840 (if approved)                                    ISC
Intended status: Standards Track                        October 31, 2019
Expires: May 3, 2020

      Moving DNSSEC Lookaside Validation (DLV) to Historic Status
                    draft-ietf-dnsop-obsolete-dlv-02

Abstract

   This document obsoletes DNSSEC lookaside validation (DLV) and
   reclassifies RFCs 4431 and 5074 as Historic.  Furthermore, this
   document updates RFC 6698 by excluding the DLV resource record from
   certificates, and updates RFC 6840 by excluding the DLV registries
   from the trust anchor selection.

Status of This Memo

   This Internet-Draft is submitted in full conformance with the
   provisions of BCP 78 and BCP 79.

   Internet-Drafts are working documents of the Internet Engineering
   Task Force (IETF).  Note that other groups may also distribute
   working documents as Internet-Drafts.  The list of current Internet-
   Drafts is at https://datatracker.ietf.org/drafts/current/.

   Internet-Drafts are draft documents valid for a maximum of six months
   and may be updated, replaced, or obsoleted by other documents at any
   time.  It is inappropriate to use Internet-Drafts as reference
   material or to cite them other than as "work in progress."

   This Internet-Draft will expire on May 3, 2020.

Copyright Notice

   Copyright (c) 2019 IETF Trust and the persons identified as the
   document authors.  All rights reserved.

   This document is subject to BCP 78 and the IETF Trust's Legal
   Provisions Relating to IETF Documents
   (https://trustee.ietf.org/license-info) in effect on the date of
   publication of this document.  Please review these documents
   carefully, as they describe your rights and restrictions with respect
   to this document.  Code Components extracted from this document must
   include Simplified BSD License text as described in Section 4.e of

Mekking & Mahoney          Expires May 3, 2020                  [Page 1]
Internet-Draft                obsolete-dlv                  October 2019

   the Trust Legal Provisions and are provided without warranty as
   described in the Simplified BSD License.

Table of Contents

   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   2
   2.  Terminology . . . . . . . . . . . . . . . . . . . . . . . . .   2
   3.  Discussion  . . . . . . . . . . . . . . . . . . . . . . . . .   2
   4.  Moving DLV to Historic Status . . . . . . . . . . . . . . . .   3
     4.1.  Documents that reference the DLV RFCs . . . . . . . . . .   3
       4.1.1.  Documents that reference RFC 4431 . . . . . . . . . .   3
       4.1.2.  Documents that reference RFC 5074 . . . . . . . . . .   4
   5.  IANA Considerations . . . . . . . . . . . . . . . . . . . . .   4
   6.  Security considerations . . . . . . . . . . . . . . . . . . .   4
   7.  Acknowledgements  . . . . . . . . . . . . . . . . . . . . . .   5
   8.  Normative References  . . . . . . . . . . . . . . . . . . . .   5
   Authors' Addresses  . . . . . . . . . . . . . . . . . . . . . . .   6

1.  Introduction

   DNSSEC Lookaside Validation (DLV) was introduced to assist with the
   adoption of DNSSEC [RFC4033] [RFC4034] [RFC4035] in a time where the
   root zone and many top level domains (TLDs) were unsigned, to help
   entities with signed zones under an unsigned parent zone, or that
   have registrars that don't accept DS records.  The root zone is
   signed since July 2010 and as of May 2019, 1389 out of 1531 TLDs have
   a secure delegation from the root; thus DLV has served its purpose
   and can now retire.

2.  Terminology

   The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
   "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and
   "OPTIONAL" in this document are to be interpreted as described in
   [RFC2119] and [RFC8174].

3.  Discussion

   One could argue that DLV is still useful because there are still some
   unsigned TLDs and entities under those zones will not benefit from
   signing their zone.  However, keeping the DLV mechanism also has
   disadvantages:

   o  It reduces the pressure to get the parent zone signed.

   o  It reduces the pressure on registrars to accept DS records.

   o  It complicates validation code.

Mekking & Mahoney          Expires May 3, 2020                  [Page 2]
Internet-Draft                obsolete-dlv                  October 2019

   In addition, not every validator actually implemented DLV (only BIND
   9 and Unbound) so even if an entity can use DLV to set up an
   alternate path to its trust anchor, its effect is limited.
   Furthermore, there was one well-known DLV registry (dlv.isc.org) and
   that has been deprecated (replaced with a signed empty zone) on
   September 30, 2017.  With the absence of a well-known DLV registry
   service it is unlikely that there is a real benefit for the protocol
Show full document text