Markdown Version | Recording 1 | Recording 2

Session Date/Time: 11 Nov 2021 16:00

dnsop

Summary

The dnsop session covered updates from the chairs, including an adopt-a-doc initiative and progress on existing documents. Key technical discussions included NSEC3 iteration limits, DNSSEC automation, domain verification techniques, structured data for DNS error pages, and a suite of drafts on Authenticated DNS over TLS (ADoT). While no immediate adoption decisions were made for the newer drafts, chairs expressed support for important work and outlined next steps for consideration.

Key Discussion Points

Chairs' Notes and Document Status Updates

NSEC3 Iteration Guidance (Wes Hardaker, Victor Ducournau)

DNSSEC Automation: Multi-Signer DNSSEC (Ulrich Wisser, Shumon Huque)

Domain Verification Techniques using DNS (Shivani, Shumon Huque)

Structured Data for DNS Error Pages (Dan Wing)

Authenticated DNS over TLS (ADoT) (Brian Dickson)

Decisions and Action Items

Next Steps


Session Date/Time: 12 Nov 2021 14:30

dnsop

Summary

The dnsop session covered three main topics: hackathon results on Extended DNS Error responses, an update on DNS Catalog Zones, and a discussion on NSEC3 parameter guidance. A new draft on Automatic DNSSEC Bootstrapping was also presented. Key discussions revolved around the safety and utility of unsolicited EDNS errors, the readiness of Catalog Zones for Working Group Last Call, and the contentious details of NSEC3 iteration count recommendations, particularly regarding the use of specific dates and the "serve-fail" vs. "insecure" outcomes. The bootstrapping proposal received strong support for adoption, with an open point on hashing in the naming scheme.

Key Discussion Points

Decisions and Action Items

Next Steps