Last Call Review of draft-ietf-dnsop-serve-stale-08
review-ietf-dnsop-serve-stale-08-secdir-lc-montville-2019-09-23-00
Request | Review of | draft-ietf-dnsop-serve-stale |
---|---|---|
Requested revision | No specific revision (document currently at 10) | |
Type | Last Call Review | |
Team | Security Area Directorate (secdir) | |
Deadline | 2019-09-25 | |
Requested | 2019-09-11 | |
Authors | David C Lawrence , Warren "Ace" Kumari , Puneet Sood | |
I-D last updated | 2019-09-23 | |
Completed reviews |
Secdir Last Call review of -08
by Adam W. Montville
(diff)
Genart Last Call review of -07 by Brian E. Carpenter (diff) |
|
Assignment | Reviewer | Adam W. Montville |
State | Completed | |
Request | Last Call review on draft-ietf-dnsop-serve-stale by Security Area Directorate Assigned | |
Posted at | https://mailarchive.ietf.org/arch/msg/secdir/ivoWu2ZXsvVmyb-mXSnM4GDTPp4 | |
Reviewed revision | 08 (document currently at 10) | |
Result | Ready | |
Completed | 2019-09-23 |
review-ietf-dnsop-serve-stale-08-secdir-lc-montville-2019-09-23-00
I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. At first I was confused about offering an option to allow use of stale DNS data, but after reading the draft and realizing that the decision is still left to the operator, this draft is OK. The draft brings up-to-date the definition of TTL and offers additional specification on interpreting specific TTL values. Perhaps some expansion as to the prevalence of bad actors using the caches and fraudulently issued, domain-validated certificates in the Security Considerations section is warranted. Nevertheless, it appears that implementations have been fielded and in use operationally for quite some time, presumably without a problem, and, as previously stated, operators don't have to enable this functionality unless they warrant availability of their services to be paramount.