
From nobody Sat Jun 16 07:29:53 2018
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55DEA130EA0 for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 07:29:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5H8VHdIQYPs9 for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 07:29:49 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D7153130E23 for <dane@ietf.org>; Sat, 16 Jun 2018 07:29:49 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id 51588B810A8; Sat, 16 Jun 2018 07:29:46 -0700 (PDT)
To: ietf-dane@dukhovni.org, ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Cc: matt@mattmccutchen.net, dane@ietf.org, rfc-editor@rfc-editor.org
Content-Type: text/plain; charset=UTF-8
Message-Id: <20180616142946.51588B810A8@rfc-editor.org>
Date: Sat, 16 Jun 2018 07:29:46 -0700 (PDT)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/9DCWp9MA-R_bv-gh13MzsWhBNvw>
Subject: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 14:29:53 -0000

The following errata report has been submitted for RFC7672,
"SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata/eid5395

--------------------------------------
Type: Technical
Reported by: Matt McCutchen <matt@mattmccutchen.net>

Section: 2.1.1

Original Text
-------------
   DNS records that would be
   classified "indeterminate" in the sense of [RFC4035] are simply
   classified as "insecure".

Corrected Text
--------------
   DNS records that would be
   classified "indeterminate" in the sense of [RFC4033] are simply
   classified as "insecure".

Notes
-----


Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC7672 (draft-ietf-dane-smtp-with-dane-19)
--------------------------------------
Title               : SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)
Publication Date    : October 2015
Author(s)           : V. Dukhovni, W. Hardaker
Category            : PROPOSED STANDARD
Source              : DNS-based Authentication of Named Entities
Area                : Security
Stream              : IETF
Verifying Party     : IESG


From nobody Sat Jun 16 07:40:10 2018
Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8418130E23 for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 07:40:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lf5fmszBsgtH for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 07:40:06 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [108.5.242.66]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C46D1130E1C for <dane@ietf.org>; Sat, 16 Jun 2018 07:40:06 -0700 (PDT)
Received: from [192.168.1.161] (straasha.imrryr.org [100.2.39.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mournblade.imrryr.org (Postfix) with ESMTPSA id 65AAF7A330D; Sat, 16 Jun 2018 14:40:05 +0000 (UTC) (envelope-from ietf-dane@dukhovni.org)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
In-Reply-To: <20180616142946.51588B810A8@rfc-editor.org>
Date: Sat, 16 Jun 2018 10:40:04 -0400
Cc: ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <8AC6FE84-11F6-44C3-8440-05E93DFE828C@dukhovni.org>
References: <20180616142946.51588B810A8@rfc-editor.org>
To: RFC Errata System <rfc-editor@rfc-editor.org>
X-Mailer: Apple Mail (2.3445.8.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/ExBt17wy4OWWCNWTAxtMOJI3aek>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 14:40:10 -0000

The reported erratum is correct, the text should have been as =
"Corrected".

> On Jun 16, 2018, at 10:29 AM, RFC Errata System =
<rfc-editor@rfc-editor.org> wrote:
>=20
> The following errata report has been submitted for RFC7672,
> "SMTP Security via Opportunistic DNS-Based Authentication of Named =
Entities (DANE) Transport Layer Security (TLS)".
>=20
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata/eid5395
>=20
> --------------------------------------
> Type: Technical
> Reported by: Matt McCutchen <matt@mattmccutchen.net>
>=20
> Section: 2.1.1
>=20
> Original Text
> -------------
>   DNS records that would be
>   classified "indeterminate" in the sense of [RFC4035] are simply
>   classified as "insecure".
>=20
> Corrected Text
> --------------
>   DNS records that would be
>   classified "indeterminate" in the sense of [RFC4033] are simply
>   classified as "insecure".
>=20
> Notes
> -----
>=20
>=20
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party =20
> can log in to change the status and edit the report, if necessary.=20
>=20
> --------------------------------------
> RFC7672 (draft-ietf-dane-smtp-with-dane-19)
> --------------------------------------
> Title               : SMTP Security via Opportunistic DNS-Based =
Authentication of Named Entities (DANE) Transport Layer Security (TLS)
> Publication Date    : October 2015
> Author(s)           : V. Dukhovni, W. Hardaker
> Category            : PROPOSED STANDARD
> Source              : DNS-based Authentication of Named Entities
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG

--=20
	Viktor.


From nobody Sat Jun 16 11:03:04 2018
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 28E29130E66; Sat, 16 Jun 2018 11:02:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fFdDCBEIQdNm; Sat, 16 Jun 2018 11:02:55 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C4D3130E22; Sat, 16 Jun 2018 11:02:55 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id C52CBB81A5A; Sat, 16 Jun 2018 11:02:51 -0700 (PDT)
To: matt@mattmccutchen.net, ietf-dane@dukhovni.org, ietf@hardakers.net
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Cc: kaduk@mit.edu, iesg@ietf.org, dane@ietf.org, rfc-editor@rfc-editor.org
Content-Type: text/plain; charset=UTF-8
Message-Id: <20180616180251.C52CBB81A5A@rfc-editor.org>
Date: Sat, 16 Jun 2018 11:02:51 -0700 (PDT)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/4vn7IhcLcT0rt2meZ6mXx2UsSE4>
Subject: [dane] [Errata Verified] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 18:02:57 -0000

The following errata report has been verified for RFC7672,
"SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata/eid5395

--------------------------------------
Status: Verified
Type: Technical

Reported by: Matt McCutchen <matt@mattmccutchen.net>
Date Reported: 2018-06-16
Verified by: Benjamin Kaduk (IESG)

Section: 2.1.1

Original Text
-------------
   DNS records that would be
   classified "indeterminate" in the sense of [RFC4035] are simply
   classified as "insecure".

Corrected Text
--------------
   DNS records that would be
   classified "indeterminate" in the sense of [RFC4033] are simply
   classified as "insecure".

Notes
-----


--------------------------------------
RFC7672 (draft-ietf-dane-smtp-with-dane-19)
--------------------------------------
Title               : SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)
Publication Date    : October 2015
Author(s)           : V. Dukhovni, W. Hardaker
Category            : PROPOSED STANDARD
Source              : DNS-based Authentication of Named Entities
Area                : Security
Stream              : IETF
Verifying Party     : IESG


From nobody Sat Jun 16 16:10:56 2018
Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B00C130E27 for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:10:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 64yETLblwJ6X for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:10:52 -0700 (PDT)
Received: from mail.proper.com (Opus1.Proper.COM [207.182.41.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CB337130E79 for <dane@ietf.org>; Sat, 16 Jun 2018 16:10:52 -0700 (PDT)
Received: from [10.32.60.38] (50-1-51-141.dsl.dynamic.fusionbroadband.com [50.1.51.141]) (authenticated bits=0) by mail.proper.com (8.15.2/8.15.2) with ESMTPSA id w5GNASxQ024377 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Sat, 16 Jun 2018 16:10:31 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
X-Authentication-Warning: mail.proper.com: Host 50-1-51-141.dsl.dynamic.fusionbroadband.com [50.1.51.141] claimed to be [10.32.60.38]
From: "Paul Hoffman" <paul.hoffman@vpnc.org>
To: "RFC Errata System" <rfc-editor@rfc-editor.org>
Cc: ietf-dane@dukhovni.org, ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Date: Sat, 16 Jun 2018 16:10:28 -0700
X-Mailer: MailMate (1.11.2r5479)
Message-ID: <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org>
In-Reply-To: <20180616142946.51588B810A8@rfc-editor.org>
References: <20180616142946.51588B810A8@rfc-editor.org>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/1kljDeMRLMas0NgvK0do1ch88Gc>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 23:10:54 -0000

This erratum should be rejected. RFC 4035 defines "indeterminate" in 
Section 4.4.3. RFC 4035 and RFC 4033 define "indeterminate" differently.

--Paul Hoffman

On 16 Jun 2018, at 7:29, RFC Errata System wrote:

> The following errata report has been submitted for RFC7672,
> "SMTP Security via Opportunistic DNS-Based Authentication of Named 
> Entities (DANE) Transport Layer Security (TLS)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata/eid5395
>
> --------------------------------------
> Type: Technical
> Reported by: Matt McCutchen <matt@mattmccutchen.net>
>
> Section: 2.1.1
>
> Original Text
> -------------
>    DNS records that would be
>    classified "indeterminate" in the sense of [RFC4035] are simply
>    classified as "insecure".
>
> Corrected Text
> --------------
>    DNS records that would be
>    classified "indeterminate" in the sense of [RFC4033] are simply
>    classified as "insecure".
>
> Notes
> -----
>
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC7672 (draft-ietf-dane-smtp-with-dane-19)
> --------------------------------------
> Title               : SMTP Security via Opportunistic DNS-Based 
> Authentication of Named Entities (DANE) Transport Layer Security (TLS)
> Publication Date    : October 2015
> Author(s)           : V. Dukhovni, W. Hardaker
> Category            : PROPOSED STANDARD
> Source              : DNS-based Authentication of Named Entities
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG


From nobody Sat Jun 16 16:29:32 2018
Return-Path: <kaduk@mit.edu>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A78013110C for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:29:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level: 
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Si_6GyzE5RSs for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:29:27 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B3311130DF1 for <dane@ietf.org>; Sat, 16 Jun 2018 16:29:27 -0700 (PDT)
X-AuditID: 12074422-7edff700000046dc-67-5b259d56be98
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id 9B.6F.18140.65D952B5; Sat, 16 Jun 2018 19:29:26 -0400 (EDT)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id w5GNTO9B008978; Sat, 16 Jun 2018 19:29:25 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id w5GNTGcP010660 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Sat, 16 Jun 2018 19:29:19 -0400
Date: Sat, 16 Jun 2018 18:29:16 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Paul Hoffman <paul.hoffman@vpnc.org>
Cc: RFC Errata System <rfc-editor@rfc-editor.org>, ietf-dane@dukhovni.org, ietf@hardakers.net, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Message-ID: <20180616232916.GB64971@kduck.kaduk.org>
References: <20180616142946.51588B810A8@rfc-editor.org> <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrIKsWRmVeSWpSXmKPExsUixG6nrhs2VzXa4M59FYs9xyeyWqx4fY7d YuK9DWwWOx8uZLfo2NHEavG9bTmTxa31X1gtmvZ/ZbM4fOwykwOnx/YjC9k9bq+ZyuKxZMlP Jo/bN/6we0zs38HoMeHUbhaPhrZjrB6TH7cxe3yefZU5gDOKyyYlNSezLLVI3y6BK2PKyuvM BYdkKtrvTWRtYHwr2sXIySEhYCLRe3clexcjF4eQwGImiQsPb7GCJIQENjJKrJifAZG4yiSx sreFGSTBIqAq8WDhfDCbTUBFoqH7MpgtIqAB1LwDbBKzwDFGiXdtZ9lBEsICdhLLlq4Bm8oL tO72/pPMEBsyJU4t284GEReUODnzCQuIzSygJXHj30umLkYOIFtaYvk/DpAwp4CNxK65l8DG iAooS+ztO8Q+gVFgFpLuWUi6ZyF0L2BkXsUom5JbpZubmJlTnJqsW5ycmJeXWqRrqpebWaKX mlK6iREcMy5KOxgn/vM6xCjAwajEw6sRrhotxJpYVlyZe4hRkoNJSZT3e4tKtBBfUn5KZUZi cUZ8UWlOavEhRgkOZiUR3uYsoHLelMTKqtSifJiUNAeLkjhv7iLGaCGB9MSS1OzU1ILUIpis DAeHkgRv/hygRsGi1PTUirTMnBKENBMHJ8hwHqDh8iA1vMUFibnFmekQ+VOMilLivHUgCQGQ REZpHlwvKKVJZO+vecUoDvSKMO+d2UBVPMB0CNf9CmgwE9Dg/QtVQAaXJCKkpBoYeXfxH/vL UZ6+au6DCwaPj00xKXzw7KLNMyXR0t6yhSqdIgwM/g59DQ/Ora9j+O1i48d7Zeuy7I26u5Kf nj7CtXsiS9/CSxc+N0ZbipyXktZ+8u7Dg3q/04fU62pfhpozv/vgJWOc12ASueS4WP8d8zON shPlf8ws8lY5z250lrGDTzxhTdR9JZbijERDLeai4kQA4u1ITUQDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/T2YM-P4oO37kIMZHqzBZVatFIaM>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 23:29:30 -0000

On Sat, Jun 16, 2018 at 04:10:28PM -0700, Paul Hoffman wrote:
> This erratum should be rejected. RFC 4035 defines "indeterminate" in 
> Section 4.4.3. RFC 4035 and RFC 4033 define "indeterminate" differently.

This statement is in the context of resolving the discrepancy; the
full context is:

   A DNS lookup may signal an error or return a definitive answer.  A
   security-aware resolver MUST be used for this specification.
   Security-aware resolvers will indicate the security status of a DNS
   RRset with one of four possible values defined in Section 4.3 of
   [RFC4035]: "secure", "insecure", "bogus", and "indeterminate".  In
   [RFC4035], the meaning of the "indeterminate" security status is:

      An RRset for which the resolver is not able to determine whether
      the RRset should be signed, as the resolver is not able to obtain
      the necessary DNSSEC RRs.  This can occur when the security-aware
      resolver is not able to contact security-aware name servers for
      the relevant zones.

   Note that the "indeterminate" security status has a conflicting
   definition in Section 5 of [RFC4033]:

      There is no trust anchor that would indicate that a specific
      portion of the tree is secure.

   In this document, the term "indeterminate" will be used exclusively
   in the [RFC4035] sense.  Therefore, obtaining "indeterminate" lookup
   results is a (transient) failure condition, namely, the inability to
   locate the relevant DNS records.  DNS records that would be
   classified "indeterminate" in the sense of [RFC4035] are simply
   classified as "insecure".

It's clear that the last statement is intended to contrast the two
senses, so the 4033 reference is correct.

-Benjamin




> --Paul Hoffman
> 
> On 16 Jun 2018, at 7:29, RFC Errata System wrote:
> 
> > The following errata report has been submitted for RFC7672,
> > "SMTP Security via Opportunistic DNS-Based Authentication of Named 
> > Entities (DANE) Transport Layer Security (TLS)".
> >
> > --------------------------------------
> > You may review the report below and at:
> > http://www.rfc-editor.org/errata/eid5395
> >
> > --------------------------------------
> > Type: Technical
> > Reported by: Matt McCutchen <matt@mattmccutchen.net>
> >
> > Section: 2.1.1
> >
> > Original Text
> > -------------
> >    DNS records that would be
> >    classified "indeterminate" in the sense of [RFC4035] are simply
> >    classified as "insecure".
> >
> > Corrected Text
> > --------------
> >    DNS records that would be
> >    classified "indeterminate" in the sense of [RFC4033] are simply
> >    classified as "insecure".
> >
> > Notes
> > -----
> >
> >
> > Instructions:
> > -------------
> > This erratum is currently posted as "Reported". If necessary, please
> > use "Reply All" to discuss whether it should be verified or
> > rejected. When a decision is reached, the verifying party
> > can log in to change the status and edit the report, if necessary.
> >
> > --------------------------------------
> > RFC7672 (draft-ietf-dane-smtp-with-dane-19)
> > --------------------------------------
> > Title               : SMTP Security via Opportunistic DNS-Based 
> > Authentication of Named Entities (DANE) Transport Layer Security (TLS)
> > Publication Date    : October 2015
> > Author(s)           : V. Dukhovni, W. Hardaker
> > Category            : PROPOSED STANDARD
> > Source              : DNS-based Authentication of Named Entities
> > Area                : Security
> > Stream              : IETF
> > Verifying Party     : IESG


From nobody Sat Jun 16 16:38:11 2018
Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AA78B13115F for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:38:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MopWGG8jipR1 for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 16:38:08 -0700 (PDT)
Received: from mail.proper.com (Opus1.Proper.COM [207.182.41.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 93254130DFC for <dane@ietf.org>; Sat, 16 Jun 2018 16:38:08 -0700 (PDT)
Received: from [10.32.60.38] (50-1-51-141.dsl.dynamic.fusionbroadband.com [50.1.51.141]) (authenticated bits=0) by mail.proper.com (8.15.2/8.15.2) with ESMTPSA id w5GNc3Pe033866 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Sat, 16 Jun 2018 16:38:04 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
X-Authentication-Warning: mail.proper.com: Host 50-1-51-141.dsl.dynamic.fusionbroadband.com [50.1.51.141] claimed to be [10.32.60.38]
From: "Paul Hoffman" <paul.hoffman@vpnc.org>
To: "Benjamin Kaduk" <kaduk@mit.edu>
Cc: "RFC Errata System" <rfc-editor@rfc-editor.org>, ietf-dane@dukhovni.org, ietf@hardakers.net, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Date: Sat, 16 Jun 2018 16:38:03 -0700
X-Mailer: MailMate (1.11.2r5479)
Message-ID: <FC1C09D7-77D7-4444-AF57-4FFB45E8605F@vpnc.org>
In-Reply-To: <20180616232916.GB64971@kduck.kaduk.org>
References: <20180616142946.51588B810A8@rfc-editor.org> <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org> <20180616232916.GB64971@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/2F3rLGuOcCM7jxk1Ha_M-Ev34Ss>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2018 23:38:10 -0000

My apologies: you are correct. The erratum is fine. I remembered the 
discussion leading to this text incorrectly.

--Paul Hoffman


From nobody Sat Jun 16 17:27:18 2018
Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A03C130E3B for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 17:27:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kFqqByd7tgun for <dane@ietfa.amsl.com>; Sat, 16 Jun 2018 17:27:14 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [108.5.242.66]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EF89130E12 for <dane@ietf.org>; Sat, 16 Jun 2018 17:27:14 -0700 (PDT)
Received: from [192.168.0.15] (209-122-241-179.s10917.c3-0.avec-cbr1.nyr-avec.ny.cable.rcncustomer.com [209.122.241.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mournblade.imrryr.org (Postfix) with ESMTPSA id E315B7A330D; Sun, 17 Jun 2018 00:27:11 +0000 (UTC) (envelope-from ietf-dane@dukhovni.org)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
In-Reply-To: <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org>
Date: Sat, 16 Jun 2018 20:26:11 -0400
Cc: RFC Errata System <rfc-editor@rfc-editor.org>, ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <3AF039B2-558A-41A8-9DBD-14D1CD935ED0@dukhovni.org>
References: <20180616142946.51588B810A8@rfc-editor.org> <FB36F471-DFF2-4302-892B-0FDC11DFCA9E@vpnc.org>
To: Paul Hoffman <paul.hoffman@vpnc.org>
X-Mailer: Apple Mail (2.3445.8.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/Jk7mEqBSGzRoXT7YocqY-V4r84I>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 17 Jun 2018 00:27:17 -0000

> On Jun 16, 2018, at 7:10 PM, Paul Hoffman <paul.hoffman@vpnc.org> =
wrote:
>=20
> This erratum should be rejected. RFC 4035 defines "indeterminate" in =
Section 4.4.3.

(That'd be section 4.3, for anyone reading along).

> RFC 4035 and RFC 4033 define "indeterminate" differently.

Actually, the erratum is correct.  RFC7672 uses the definition
from "RFC4035", and the intent was to make it clear that the
definition of "indeterminate" from RFC4033 is not used.  Rather,
what 4033 calls "indeterminate", "7672" considers (more aptly)
"insecure".  The original text erroneously distanced itself from
4035 instead of 4033.

--=20
	Viktor.


From nobody Sun Jun 17 20:15:01 2018
Return-Path: <paul@nohats.ca>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0BCE1130E1A for <dane@ietfa.amsl.com>; Sun, 17 Jun 2018 20:14:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pz2Q4ANGiXQa for <dane@ietfa.amsl.com>; Sun, 17 Jun 2018 20:14:56 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56D23124BE5 for <dane@ietf.org>; Sun, 17 Jun 2018 20:14:56 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 418GRb6Yg7z393; Mon, 18 Jun 2018 05:14:51 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1529291691; bh=uDKU/sods6m0hrhsOQ6poS4DygwWlvMVoqS6IUHMHYI=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=YCWzuCK7UYZQ2BcyZZlrMuPzZ/yilV+vDS4XEQ1an/98MQuO92fGjSY8s6pKiifgX OeWzg7XNZMkxF8gxx63QfQgaAZ37Pg3zAxYMTmHfU3uob4nC8CdnWL213oSno05FB1 ivmc/OvBmfLQtvQlP87fBN+7KnYDNFOa9WOW/Noo=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id qmJZ5A4vM-UJ; Mon, 18 Jun 2018 05:14:50 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Mon, 18 Jun 2018 05:14:48 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id F0F78B82C; Sun, 17 Jun 2018 23:14:47 -0400 (EDT)
DKIM-Filter: OpenDKIM Filter v2.11.0 bofh.nohats.ca F0F78B82C
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id E5D88402F27A; Sun, 17 Jun 2018 23:14:47 -0400 (EDT)
Date: Sun, 17 Jun 2018 23:14:47 -0400 (EDT)
From: Paul Wouters <paul@nohats.ca>
To: RFC Errata System <rfc-editor@rfc-editor.org>
cc: ietf-dane@dukhovni.org, ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com,  ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
In-Reply-To: <20180616142946.51588B810A8@rfc-editor.org>
Message-ID: <alpine.LRH.2.21.1806172308260.24664@bofh.nohats.ca>
References: <20180616142946.51588B810A8@rfc-editor.org>
User-Agent: Alpine 2.21 (LRH 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/pwafgWnWSw-515p_9squkM6phxE>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Jun 2018 03:14:59 -0000

On Sat, 16 Jun 2018, RFC Errata System wrote:

> Original Text
> -------------
>   DNS records that would be
>   classified "indeterminate" in the sense of [RFC4035] are simply
>   classified as "insecure".
>
> Corrected Text
> --------------
>   DNS records that would be
>   classified "indeterminate" in the sense of [RFC4033] are simply
>   classified as "insecure".

Whether original or corrected text, what it does here worried me more.

The RFC opens with:

 	Abstract

 	This memo describes a downgrade-resistant protocol [...]

Not really downgrade-resistant if I can just strip some RRSIGs from
the packets to make it fail open. So this text is confusing.

But it does make that clear in 2.1.2:

 	If any DNS queries used to locate
 	TLSA records fail (due to "bogus" or "indeterminate" records,
 	timeouts, malformed replies, SERVFAIL responses, etc.), then the SMTP
 	client MUST treat that server as unreachable and MUST NOT deliver the
 	message via that server.

I'm not sure if that's worth bringing into the errata. If we have the
errata as is, it might actually mislead developers into thiking they
must treet an indeterminate response as insecure and use it for TLSA.

Paul


From nobody Sun Jun 17 20:21:25 2018
Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54B4D1292F1 for <dane@ietfa.amsl.com>; Sun, 17 Jun 2018 20:21:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZZhtAPLkFqQD for <dane@ietfa.amsl.com>; Sun, 17 Jun 2018 20:21:21 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [108.5.242.66]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A43B9124D68 for <dane@ietf.org>; Sun, 17 Jun 2018 20:21:21 -0700 (PDT)
Received: from [192.168.1.161] (straasha.imrryr.org [100.2.39.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mournblade.imrryr.org (Postfix) with ESMTPSA id B53727A330D; Mon, 18 Jun 2018 03:21:20 +0000 (UTC) (envelope-from ietf-dane@dukhovni.org)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
In-Reply-To: <alpine.LRH.2.21.1806172308260.24664@bofh.nohats.ca>
Date: Sun, 17 Jun 2018 23:21:18 -0400
Cc: RFC Errata System <rfc-editor@rfc-editor.org>, ietf@hardakers.net, kaduk@mit.edu, ekr@rtfm.com, ogud@ogud.com, warren@kumari.net, matt@mattmccutchen.net, dane@ietf.org
Content-Transfer-Encoding: 7bit
Message-Id: <D8DDBDB8-9427-4E50-8AC9-8DC6D420A987@dukhovni.org>
References: <20180616142946.51588B810A8@rfc-editor.org> <alpine.LRH.2.21.1806172308260.24664@bofh.nohats.ca>
To: Paul Wouters <paul@nohats.ca>
X-Mailer: Apple Mail (2.3445.8.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dane/y7pfhPFI2weXtBP1UzkZL5FUOHE>
Subject: Re: [dane] [Technical Errata Reported] RFC7672 (5395)
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Jun 2018 03:21:24 -0000

> On Jun 17, 2018, at 11:14 PM, Paul Wouters <paul@nohats.ca> wrote:
> 
> I'm not sure if that's worth bringing into the errata. If we have the
> errata as is, it might actually mislead developers into thiking they
> must treet an indeterminate response as insecure and use it for TLSA.

I don't think that's a plausible risk.  That said, in the next
year or two, with soon 5 years of implementation experience behind
us, it may be time to publish an update the clarifies the murkier
corners of 7671/7672 or even a pair of bis rewrites.  Though it
might be tricky for lack of a working group in which to do so.
Perhaps UTA could work, though it too might be shut down by then.

-- 
	Viktor.

