Skip to main content

Telechat Review of draft-ietf-dnsop-must-not-sha1-06
review-ietf-dnsop-must-not-sha1-06-dnsdir-telechat-van-dijk-2025-05-01-00

Request Review of draft-ietf-dnsop-must-not-sha1
Requested revision No specific revision (document currently at 10)
Type Telechat Review
Team DNS Directorate (dnsdir)
Deadline 2025-05-20
Requested 2025-03-31
Authors Wes Hardaker , Warren Kumari
I-D last updated 2025-11-30 (Latest revision 2025-09-10)
Completed reviews Dnsdir IETF Last Call review of -03 by Florian Obser (diff)
Artart IETF Last Call review of -03 by Barry Leiba (diff)
Secdir IETF Last Call review of -03 by Yoav Nir (diff)
Genart IETF Last Call review of -03 by Behcet Sarikaya (diff)
Dnsdir Telechat review of -05 by Florian Obser (diff)
Opsdir Telechat review of -06 by Thomas Graf (diff)
Secdir Telechat review of -06 by Yoav Nir (diff)
Dnsdir Telechat review of -06 by Peter van Dijk (diff)
Assignment Reviewer Peter van Dijk
State Completed
Request Telechat review on draft-ietf-dnsop-must-not-sha1 by DNS Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/dnsdir/RW9aRcpNHL61L3_iCQTHNf-3B7A
Reviewed revision 06 (document currently at 10)
Result Almost ready
Completed 2025-05-01
review-ietf-dnsop-must-not-sha1-06-dnsdir-telechat-van-dijk-2025-05-01-00
Hello SHA1-fighting friends,

this is a DNSDIR review for draft-ietf-dnsop-must-not-sha1.

This document appears to be mostly ready, but should perhaps (as also noted on
the mailing list) gain some visible relation to 8624(-bis) - unless the
argument is that the table in 8624 and its predecessors now lives at IANA and
history is tracked there, which would also make sense to me.

Like the OPSDIR review flagged a problem in the DS update for IANA, the request
to change [DNSKEY-IANA] requests "MUST NOT" while the table just has Y/N.
However, this appears to be covered by 8624-bis. This document should perhaps
also say Updating: 8624 (or -bis) as it updates the tables in there?

Nits:

> Since then, multiple other algorithms with stronger cryptographic strength
are now widely available for DS records and for DNSKEY and RRSIG records.

"Since" and "are now"' feels incongruent. Perhaps "have become widely
available"?