[{"author": "Tim Wicinski", "text": "<p>Good evening all - even IQUERY Roy</p>", "time": "2024-07-26T01:31:03Z"}, {"author": "Roy Arends", "text": "<p>:-)</p>", "time": "2024-07-26T01:31:27Z"}, {"author": "Tim Wicinski", "text": "<p>Also - from last time 2931 <em>could</em> use a refresh if it's not been put in the bin</p>", "time": "2024-07-26T01:33:41Z"}, {"author": "Donald Eastlake", "text": "<p>MACSEC = 802.1AE</p>", "time": "2024-07-26T01:39:00Z"}, {"author": "Shane Kerr", "text": "<p>Am I in the wrong room? I feel like I ended up in v6ops... <span aria-label=\"yum\" class=\"emoji emoji-1f60b\" role=\"img\" title=\"yum\">:yum:</span></p>", "time": "2024-07-26T01:44:17Z"}, {"author": "Tim Wicinski", "text": "<p>your DNS Load Balancer sent you to the wrong room Shane</p>", "time": "2024-07-26T01:44:50Z"}, {"author": "Lorenzo Colitti", "text": "<p>you don't need to deprecate dns64 to deprecate 7050</p>", "time": "2024-07-26T01:49:10Z"}, {"author": "David Schinazi", "text": "<p>The fun part is we can just remove <a href=\"http://ipv4only.arpa\">ipv4only.arpa</a>. from .arpa and break all 7050 implementations worldwide</p>", "time": "2024-07-26T01:49:59Z"}, {"author": "Jim Reid", "text": "<p>What?? All 2 of them? :-)</p>", "time": "2024-07-26T01:50:29Z"}, {"author": "Tim Wicinski", "text": "<p>Let's do that on a Friday Dave</p>", "time": "2024-07-26T01:50:35Z"}, {"author": "Erik Nygren", "text": "<p>+1 to what Lorenzo --- that may be the thing to be clear about is that this is deprecating 7050 not DNS64, as lots of large mobile networks rely heavily on DNS64 and handsets out there have a long lifetime.</p>", "time": "2024-07-26T01:50:52Z"}, {"author": "David Schinazi", "text": "<p>Sounds good. we can blame it on Crowdstrike</p>", "time": "2024-07-26T01:50:56Z"}, {"author": "Q Misell", "text": "<p>taking bets now on who would even notice</p>", "time": "2024-07-26T01:51:22Z"}, {"author": "Peter DeVries", "text": "<p>Was the remote room for this discussion available?  I couldn't connect using the link on side meetings.  Is there a recording?</p>", "time": "2024-07-26T01:51:27Z"}, {"author": "Jessica Krynitsky", "text": "<p>too soon, David :')</p>", "time": "2024-07-26T01:51:50Z"}, {"author": "Benno Overeinder", "text": "<p>This is the link to the full client <a href=\"https://meetings.conf.meetecho.com/ietf120/?session=33061\">https://meetings.conf.meetecho.com/ietf120/?session=33061</a></p>", "time": "2024-07-26T01:52:13Z"}, {"author": "Jim Reid", "text": "<p>let's call this list stupiddnstricks@...</p>", "time": "2024-07-26T01:52:58Z"}, {"author": "Peter DeVries", "text": "<p>I meant the side meeting yesterday</p>", "time": "2024-07-26T01:52:59Z"}, {"author": "Benno Overeinder", "text": "<p>Peter, ack.</p>", "time": "2024-07-26T01:53:24Z"}, {"author": "Jessica Krynitsky", "text": "<p>I like it Jim</p>", "time": "2024-07-26T01:53:29Z"}, {"author": "Tommy Jensen", "text": "<p>STUpid Dns trickS (STUDS)</p>", "time": "2024-07-26T01:54:16Z"}, {"author": "Tim Wicinski", "text": "<p>there are so many stupiddnstricks, I won;t know where to start</p>", "time": "2024-07-26T01:54:33Z"}, {"author": "Shane Kerr", "text": "<p>There was a typo in the link for the webex for the side meeting yesterday. <span aria-label=\"disappointed\" class=\"emoji emoji-1f61e\" role=\"img\" title=\"disappointed\">:disappointed:</span></p>", "time": "2024-07-26T01:54:52Z"}, {"author": "Jim Reid", "text": "<p>@Tim, we generally start in the DNS with a mailing list. :-)</p>", "time": "2024-07-26T01:55:38Z"}, {"author": "Jim Reid", "text": "<p>whoops s/DNS/IETF/</p>", "time": "2024-07-26T01:55:53Z"}, {"author": "Tim Wicinski", "text": "<p>I want to thank Tommy for this talk, as DNS folks are so welcoming and happy to help</p>", "time": "2024-07-26T02:01:56Z"}, {"author": "Kazunori Fujiwara", "text": "<p>A research paper  proposes a DNS system that can flexible access control with TSIG key mechanism<br>\nfor each DNS updates.</p>", "time": "2024-07-26T02:03:29Z"}, {"author": "Kazunori Fujiwara", "text": "<p><a href=\"https://www.jstage.jst.go.jp/article/jssst/28/4/28_4_4_97/_pdf/-char/ja\">https://www.jstage.jst.go.jp/article/jssst/28/4/28_4_4_97/_pdf/-char/ja</a></p>", "time": "2024-07-26T02:03:54Z"}, {"author": "Kazunori Fujiwara", "text": "<p>(Sorry, Japanese language)</p>", "time": "2024-07-26T02:04:04Z"}, {"author": "Andrew Campling", "text": "<p>It sounds like Ben is suggesting it should be a BCP?</p>", "time": "2024-07-26T02:04:51Z"}, {"author": "Roy Arends", "text": "<p>I was trying to say the same. Looks more like suggesting a good practice.</p>", "time": "2024-07-26T02:05:38Z"}, {"author": "Tom Hill", "text": "<p>The hat definitely gives Tom Bombadil vibes</p>", "time": "2024-07-26T02:13:05Z"}, {"author": "Evan Hunt", "text": "<p>i'm a \"no opinion\" because I haven't had time to consider the alternative working groups and whether they'd be a better fit than dnsop</p>", "time": "2024-07-26T02:14:17Z"}, {"author": "Jessica Krynitsky", "text": "<p>This is meant to be informational/best practice, not normative</p>", "time": "2024-07-26T02:14:35Z"}, {"author": "Erik Nygren", "text": "<p>It may be the same set of people if it is here or ADD, so getting it done somewhere is what might matter.</p>", "time": "2024-07-26T02:15:45Z"}, {"author": "Tommy Jensen", "text": "<blockquote>\n<p>I want to thank Tommy for this talk, as DNS folks are so welcoming and happy to help</p>\n</blockquote>\n<p>Thanks, and seriously, this was a super productive room for talks that included auth in DNS and DNS64. go dnsop!</p>", "time": "2024-07-26T02:16:33Z"}, {"author": "Matthew Pounsett", "text": "<p>ADD feels less right than DNSOP. My instinct is DNSOP or something new.</p>", "time": "2024-07-26T02:16:54Z"}, {"author": "Benjamin Schwartz", "text": "<p>I think the mTLS thing should go to ADD</p>", "time": "2024-07-26T02:16:58Z"}, {"author": "Shane Kerr", "text": "<p>Zone walking as a \"problem\". <span aria-label=\"neutral\" class=\"emoji emoji-1f610\" role=\"img\" title=\"neutral\">:neutral:</span></p>", "time": "2024-07-26T02:17:45Z"}, {"author": "Jim Reid", "text": "<p>+1 Matt. Ben, if the mTLS stuff gets watered down, would you prefer the ID to be adopted in dnsop or add?</p>", "time": "2024-07-26T02:17:57Z"}, {"author": "Tobias Fiebig", "text": "<p>@matthew for some reason '... or something new' feels surprisingly common for tommy's drafts</p>", "time": "2024-07-26T02:18:01Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention silent\" data-user-id=\"645\">Jim Reid</span> <a href=\"#narrow/stream/114-dnsop/topic/ietf-120/near/130822\">said</a>:</p>\n<blockquote>\n<p>+1 Matt. Ben, if the mTLS stuff gets watered down, would you prefer the ID to be adopted in dnsop or add?</p>\n</blockquote>\n<p>I would prefer ADD.</p>", "time": "2024-07-26T02:18:36Z"}, {"author": "Jim Reid", "text": "<p>Thanks Ben. I prefer dnsop. So there! :-)</p>", "time": "2024-07-26T02:19:35Z"}, {"author": "Tommy Jensen", "text": "<blockquote>\n<p>for some reason '... or something new' feels surprisingly common for tommy's drafts</p>\n</blockquote>\n<p>m'bad...</p>", "time": "2024-07-26T02:19:54Z"}, {"author": "Shane Kerr", "text": "<p>And IBM NS1!!! We do <del>black lies</del> compact denial of existence!!!</p>", "time": "2024-07-26T02:20:00Z"}, {"author": "Tobias Fiebig", "text": "<p>maybe we just need a TJDNS-WG ;-)</p>", "time": "2024-07-26T02:20:15Z"}, {"author": "Jessica Krynitsky", "text": "<p>^ supportive of this</p>", "time": "2024-07-26T02:20:38Z"}, {"author": "Jessica Krynitsky", "text": "<p><span aria-label=\"laughing\" class=\"emoji emoji-1f606\" role=\"img\" title=\"laughing\">:laughing:</span></p>", "time": "2024-07-26T02:20:50Z"}, {"author": "Shane Kerr", "text": "<p>With a curve-based algorithm signing is not expensive on the fly.</p>", "time": "2024-07-26T02:21:52Z"}, {"author": "Tommy Jensen", "text": "<p>I don't like a trade-off of not having DNSSEC confirmation of negative answers...</p>", "time": "2024-07-26T02:23:14Z"}, {"author": "Jim Reid", "text": "<p>depends on how many on the fly signatures are needed...</p>", "time": "2024-07-26T02:23:19Z"}, {"author": "Paul Hoffman", "text": "<p>Maybe call this \"rainbow lies\"</p>", "time": "2024-07-26T02:23:29Z"}, {"author": "Jim Reid", "text": "<p>Too many negatives in your comment Tommy at this time of the IETF day.</p>", "time": "2024-07-26T02:24:16Z"}, {"author": "Benjamin Schwartz", "text": "<p>This will fail hard when it runs into RFC 8198, as has already been noted and is about to be noted half a dozen times.</p>", "time": "2024-07-26T02:24:25Z"}, {"author": "Rahel Fainchtein", "text": "<p>Re: Done Hopping: Wouldn't the lack of authenticated negative answers allow for injection of negative responses?</p>", "time": "2024-07-26T02:24:27Z"}, {"author": "Rahel Fainchtein", "text": "<p>*zone hopping</p>", "time": "2024-07-26T02:24:39Z"}, {"author": "Tommy Jensen", "text": "<blockquote>\n<p>Too many negatives in your comment Tommy at this time of the IETF day.</p>\n</blockquote>\n<p>Sorry, I was busy writing a charter for Tobias -- let's try \"I do not like this approach of only signing positive answers\"</p>", "time": "2024-07-26T02:25:25Z"}, {"author": "Tobias Fiebig", "text": "<p>Charter for TJDNS, you mean? ;-P</p>", "time": "2024-07-26T02:25:58Z"}, {"author": "Tommy Jensen", "text": "<p>what else? :P</p>", "time": "2024-07-26T02:26:15Z"}, {"author": "Benjamin Schwartz", "text": "<p><span class=\"user-mention silent\" data-user-id=\"4705\">Rahel Fainchtein</span> <a href=\"#narrow/stream/114-dnsop/topic/ietf-120/near/130838\">said</a>:</p>\n<blockquote>\n<p>Re: Done Hopping: Wouldn't the lack of authenticated negative answers allow for injection of negative responses?</p>\n</blockquote>\n<p>True!</p>", "time": "2024-07-26T02:26:16Z"}, {"author": "Shumon Huque", "text": "<p>online signing &amp; nsec3 is probably good enough today. If we want something better for precomputed signatures, NSEC5 anyone? I'll duck now :(</p>", "time": "2024-07-26T02:26:53Z"}, {"author": "Tommy Jensen", "text": "<p>To be clear to the presenter (thank you for sharing!), addressing this problem is a good use of time, but I would expect to maintain signing of both positive and negative answers.</p>", "time": "2024-07-26T02:28:29Z"}, {"author": "Jim Reid", "text": "<p>Zone walking isn't a problem IMO. I'll duck  and run away too.</p>", "time": "2024-07-26T02:29:03Z"}, {"author": "Tobias Fiebig", "text": "<p>@jim I would agree. DNS is public data.</p>", "time": "2024-07-26T02:29:19Z"}, {"author": "Tommy Jensen", "text": "<p>Lots of ducking going on, hope everyone is ok.</p>", "time": "2024-07-26T02:29:38Z"}, {"author": "Roy Arends", "text": "<p>I removed my hand, since all my points have been made.</p>", "time": "2024-07-26T02:30:14Z"}, {"author": "Tom Hill", "text": "<p>Evan mentioned NSEC5, so I'm outta the queue</p>", "time": "2024-07-26T02:30:21Z"}, {"author": "Tobias Fiebig", "text": "<p>i think the current presenter just made the same point as everyone in the queue wanted to make.</p>", "time": "2024-07-26T02:30:29Z"}, {"author": "Benno Overeinder", "text": "<p>Thanks Roy and Tom.</p>", "time": "2024-07-26T02:30:33Z"}, {"author": "Benjamin Schwartz", "text": "<p>Secrets that can't be rotated aren't secrets.</p>", "time": "2024-07-26T02:30:41Z"}, {"author": "Tobias Fiebig", "text": "<p>Working with passive DNS, I can note that you find _a lot_</p>", "time": "2024-07-26T02:30:51Z"}, {"author": "Roy Arends", "text": "<p>I can compile any zone by looking at DITL data.</p>", "time": "2024-07-26T02:31:13Z"}, {"author": "Jim Reid", "text": "<p>Access to DITL data is restricted to DNS-OARC</p>", "time": "2024-07-26T02:31:54Z"}, {"author": "Tobias Fiebig", "text": "<p>and it is not deterministic which names do (not) show up in passive DNS</p>", "time": "2024-07-26T02:32:04Z"}, {"author": "Tobias Fiebig", "text": "<p>@jim and farsight sells it.</p>", "time": "2024-07-26T02:32:19Z"}, {"author": "Shane Kerr", "text": "<p>To be fair, there is a difference between knowing one person's e-mail address and knowing the e-mail of everyone at an organization. A given DNS name being published is not exactly the same as knowing _all_ DNS names in a zone.</p>", "time": "2024-07-26T02:32:40Z"}]