Re: [Add] Encrypted DNS support in iOS and macOS

"Vinny Parla (vparla)" <vparla@cisco.com> Mon, 29 June 2020 15:49 UTC

Return-Path: <vparla@cisco.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B3D3A3A0121 for <add@ietfa.amsl.com>; Mon, 29 Jun 2020 08:49:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.599
X-Spam-Level:
X-Spam-Status: No, score=-14.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=H1VRaBPg; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=LlH+68Vs
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UmZrzbiFMuVZ for <add@ietfa.amsl.com>; Mon, 29 Jun 2020 08:49:01 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3696B3A011B for <add@ietf.org>; Mon, 29 Jun 2020 08:49:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6565; q=dns/txt; s=iport; t=1593445741; x=1594655341; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=gdRC1H75H6C85huHZy9v38T+8aeUJ8gcNrVQ0vcUYGE=; b=H1VRaBPgEyjxkOx3LEnv+0jhZM+S3vvOTMlIDakZBStkHN81TXII4JUn xf368CNfJDMu7SejnAa52w/Z9BBqshEvmPNeTQhgJAChqEsGq5DH4HWuJ ECle+Y/TxNpRXUjcI6MmjEtgtYXPDpJnXgSF/j6IemWAwmQY8/4d8KFhO o=;
X-Files: smime.p7s : 3980
IronPort-PHdr: =?us-ascii?q?9a23=3ATrEq/RYzQFg6298JFa61s1L/LSx94ef9IxIV55?= =?us-ascii?q?w7irlHbqWk+dH4MVfC4el21QWVD4ne4uhPzevbr66mXnYPst6Ns3EHJZpLUR?= =?us-ascii?q?JNycAbhBcpD8PND0rnZOXrYCo3EIUnNhdl8ni3PFITFJP4YFvf8XG35CQZXB?= =?us-ascii?q?TyKQQzIf76Scbeis2t3LW0/JveKwxDmDu6Z+Z0KxO75QXcv8Ubm81sMKE0nx?= =?us-ascii?q?DIuXBPPe9RwDBl?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0AaCACZDPpe/5NdJa1gglOBUlEHbys?= =?us-ascii?q?tLywKhCeDRgOmJIEugSQDVQQHAQEBCQMBASUIAgQBAYQCRQKCKgIkNgcOAgM?= =?us-ascii?q?BAQsBAQUBAQECAQYEbYVbDIVvAgEDEhEdAQE3AQ8CAQhCAgICMCUCBA4NBhS?= =?us-ascii?q?DBYF+TQMfDwEOoXUCgTmIYXaBMoMBAQEFgUZBgygYggcHAwaBOIESQYEUiWI?= =?us-ascii?q?dGoFBP4FUgh8uPoJcAoFhgxQzgi2SNId6mk4KglyEK4JWgUaRFZ8Um2eDSJB?= =?us-ascii?q?0AgQCBAUCDgEBBYFaAy8pgS1wFYMkUBcCDY4uEoNOilZ0NwIGCAEBAwl8jnU?= =?us-ascii?q?BgRABAQ?=
X-IronPort-AV: E=Sophos;i="5.75,295,1589241600"; d="p7s'?scan'208";a="504800752"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 29 Jun 2020 15:49:00 +0000
Received: from XCH-ALN-005.cisco.com (xch-aln-005.cisco.com [173.36.7.15]) by rcdn-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id 05TFn0kB032280 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 29 Jun 2020 15:49:00 GMT
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by XCH-ALN-005.cisco.com (173.36.7.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 29 Jun 2020 10:48:59 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 29 Jun 2020 10:48:59 -0500
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 29 Jun 2020 10:48:59 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Y5krwYsuDBA3IDHgamsHkx3MVkQbhr07jIOdyG8h15QOSPlHU/8rigGCaZUuSrqUZMJr9Bvmq6mj3d0Kz8CPOWiXJpoutVDlZODOH/1+A22jLA3Mj0f9juMFjn1ydYTh1ePkuydy9ncgD1LboMWhn7Iobv3/yJGY8hAqkMod8TERrDhOHpSpl5bv/3zlNycjsyQK93WP2hd6F9+s8SczwpirUFzBOkUEYSM4AJU7dFfzFXeNRs3bygqB/Lj5FmaOn3NTejoE1pEWB5HMnCbimU7VG8cfFFR+o29jxIXk+CioUdmQH1AgdxierTeukWS1Hw1+2aGMBup6ztyTmmUnSA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=a/pVZiywVhuRZjcBR7/n5KzWZbhxlvaDo085MGT4Nlg=; b=n4YRSLOqBE+svl0M/g7vTob6xJ+mKC308A5so0Ln0w+KDkvB1wVhzz+ecJnoJhPIOeRTj950d11lc0deO+ZvxnfXjGzDbqmBVsfwXrHx5ORJMOJJzoPyFuMbIl/6lhEcdwzf2NSojO78I70rWLYkPqTSmgjNG8LRGOUaH/RDWyg1UYSvS3hnabhRAYKTEDCUKJRk72APpbS2Vk+tBkJ5G7lQwZp9Q7UOOCLjW3xWCOa8FAJfKwvALKH6Zk7JVDyjhdrWIIJUhzPcAVsFMPq36avzwrA8YGaSpfKp5elwJ2JlcIBViM8yfXjf+s0l1j7x/OKeKWsc5MSUfZGam89ZKQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=a/pVZiywVhuRZjcBR7/n5KzWZbhxlvaDo085MGT4Nlg=; b=LlH+68VsDIbq+/1RVtZqL43DT4L6+W5c8dMfpTFpDVutpX+xHeAamUHlb1KYiF6dl0zjtRpDnpvwTUfssRjrJKELjkKnXxzvDGVmdWBlmuCW/7zycs7DEhb91j7/xB+eTEgL/dOT4/wGIpx7k4Oxk+z54gCV1uOs/QFrwrbVfBo=
Received: from SA0PR11MB4768.namprd11.prod.outlook.com (2603:10b6:806:71::7) by SA0PR11MB4590.namprd11.prod.outlook.com (2603:10b6:806:96::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3131.23; Mon, 29 Jun 2020 15:48:59 +0000
Received: from SA0PR11MB4768.namprd11.prod.outlook.com ([fe80::4517:e44a:590a:8967]) by SA0PR11MB4768.namprd11.prod.outlook.com ([fe80::4517:e44a:590a:8967%3]) with mapi id 15.20.3131.027; Mon, 29 Jun 2020 15:48:58 +0000
From: "Vinny Parla (vparla)" <vparla@cisco.com>
To: Tommy Pauly <tpauly=40apple.com@dmarc.ietf.org>
CC: ADD Mailing list <add@ietf.org>
Thread-Topic: [Add] Encrypted DNS support in iOS and macOS
Thread-Index: AQHWTADYBlaAS56gmEed6GBF9KU+1qjr+06AgACd+YCAAfNb8A==
Date: Mon, 29 Jun 2020 15:48:58 +0000
Message-ID: <SA0PR11MB47681A2BC6EA0796664C61ABD86E0@SA0PR11MB4768.namprd11.prod.outlook.com>
References: <CAArYzrLmkpgjgn_HRCSVH4a5w68Wzu=QcyQyiK7HTjcNbKyxWA@mail.gmail.com> <B2CF15E9-0D5E-4D8E-A3F3-05A0CADFFEF2@apple.com>
In-Reply-To: <B2CF15E9-0D5E-4D8E-A3F3-05A0CADFFEF2@apple.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: dmarc.ietf.org; dkim=none (message not signed) header.d=none;dmarc.ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [173.38.117.71]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9227fcbd-4725-4656-f8b0-08d81c43f01f
x-ms-traffictypediagnostic: SA0PR11MB4590:
x-microsoft-antispam-prvs: <SA0PR11MB45902593BE19A073397F91F1D86E0@SA0PR11MB4590.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 044968D9E1
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: b4pN+RAT3styWlRplZxOxU/gQLAA1O+dskj/gxW80IQiAaMV/l0iAJHVHn9gIFJHW2s5fG6EZoT8X4Ag3Xj4wU0Y8aJkXyO3s7GYkZBoP8dvOHFcozqhrBwLohcSNa70tIPsajcxLsiQ9dUAJi+wfAJ2ReJ5uet7/AeJl+clU383G3qH9w3v/vkRDwYqupLF5O7uyVZ13TWTtF8uf+MEpk4lGZnS6cx2vH79A2zRCWGOJcK5ubGKDqSi1TLoplnd6YDy7e9ypgd+/JbWcmVpLPv2tztcp8FgGsc46LTHIzittq3rAtb7Pd0GFoD6j984LWyXcNh0dQT8YIkVCiwnwWJRkxKQeFGOzTt8cOKT25dQdCMpBu1iDl08rzS/Ij/nvZQZV7jhBc5+HoI0lS2ZyQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA0PR11MB4768.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(366004)(346002)(376002)(136003)(39860400002)(396003)(33656002)(6506007)(186003)(26005)(7696005)(9686003)(52536014)(966005)(86362001)(55016002)(76116006)(66446008)(64756008)(66556008)(66476007)(66616009)(66946007)(71200400001)(316002)(2906002)(8676002)(4326008)(4744005)(478600001)(8936002)(5660300002)(99936003); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: iUOPr0LtJkw8AdKcYG4ldBcYHl+aMtxxaNDO4S31/OMP50eWIc0WWx4/PThymf19Yq/NZ4RzI082Sb9EidVfR20pd1mSS0J2LkA7MCayWHcpZM2kpE7F5o0Iz6MW44KDgvGvav9MvFJbnt1e8MVZhdEY51XWgO4MmpC/8W6mtSIdAGErx9s7vAfovKsrELJPyZdmcKfiigZBMznOnw1X9+daBOJnLJE8odvGiEa7Esm1gpPhyZvRJ+M0ih8MRAm4ztrFqpzsis2TUz9AGSAKjmwQ1bN8wVBY/buZyxIztCzEXtm7B0RGXgIdLdDwpFz1aOdcKzl2GOBIBy4pEkp80nOKCOGFiuQvtd0EY/i8qNt5GaZQ26xvqEb/Pu5XQJ2UNkZgc7eddPbjHmSYc+4C88Lfm22GF0qdNXmq5DliAZTKJvxEokRfh3xPY2tjXOIw/IY1CAXw6rmUydUk9GPjrrloF6kh0rIGLGhTbpU1EZIRUhkNqezThmS06YQXy+aF
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=SHA1; boundary="----=_NextPart_000_017C_01D64E0B.4469CEC0"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA0PR11MB4768.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9227fcbd-4725-4656-f8b0-08d81c43f01f
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jun 2020 15:48:58.8475 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: x7LiPv0fj8ps4xeUfVhpFLpVwJSclZ3u7psOdOez31AyuPPooYnoAoKuLXXJulPj795LrHxZsshZF7MjbLhIUQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR11MB4590
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.15, xch-aln-005.cisco.com
X-Outbound-Node: rcdn-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/3ltCKtQVHzfiChIFnWBni3ZMHxg>
Subject: Re: [Add] Encrypted DNS support in iOS and macOS
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Jun 2020 15:49:03 -0000

Hi,

Thanks for the excellent video explaining the new capabilities.

One thing that was unclear -
I understand that VPN and Captive Portal settings take precedence.

Does this mean that if VPN intentionally sets Do53 configuration for the 
tunnel DNS-settings that legacy DNS will be used over that interface in all 
cases?
Will per-app secure-DNS settings be used in that case or not?

I looked at various documentation, but was not clear to me what the behavior 
was.
https://developer.apple.com/documentation/devicemanagement/dnssettings/dnssettings
https://developer.apple.com/documentation/networkextension/nednssettingsmanager
https://developer.apple.com/documentation/networkextension/nednssettings


Thx
-Vinny