Re: [Add] Fwd: New Version Notification for draft-reddy-add-delegated-credentials-03.txt

tirumal reddy <kondtir@gmail.com> Mon, 11 December 2023 09:42 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6913BC14F5F7 for <add@ietfa.amsl.com>; Mon, 11 Dec 2023 01:42:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id upC8zB1QuQpz for <add@ietfa.amsl.com>; Mon, 11 Dec 2023 01:42:16 -0800 (PST)
Received: from mail-ej1-x62a.google.com (mail-ej1-x62a.google.com [IPv6:2a00:1450:4864:20::62a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7E09CC14F5E2 for <add@ietf.org>; Mon, 11 Dec 2023 01:42:16 -0800 (PST)
Received: by mail-ej1-x62a.google.com with SMTP id a640c23a62f3a-a1c6dad2dd0so133707466b.1 for <add@ietf.org>; Mon, 11 Dec 2023 01:42:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1702287734; x=1702892534; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=ipVXl7odghxVkrYbOMlC5j9dznTfMu57SNX6pRAT1Mc=; b=IMon/2WTB8svYQmHkXSkLGsFfAwM+fDZvoYV9LjyARGk2L5fLZr1EjB4ZNnuKDT0uQ yRYjlIjePQJMK0rE7iAKwPdnBFVszC47b2pjBQaGl2lav05awWuusqVD5nOchZ3g+8tH y/8vbvZv9UEy/5VYs9NwhVmQ+2fSg/EyqomAJ6ssfKLN2qqso4ZVAN6YtIMxF66KMC2T UTzm0aeOSDCywW8a79L5u1Ojc4GrGkKTHm8uOkWX3cOUyzyTA3iSGfm8FLHLd+QruLTq jA1iQBalBmBlq7LqCV6n7E6JDypVxYWkoOiEdqlhKci/K29z3kASThwqlrCjlSXdFKwm BzRg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1702287734; x=1702892534; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=ipVXl7odghxVkrYbOMlC5j9dznTfMu57SNX6pRAT1Mc=; b=ouGT4m+l4LC5EeuoM2smx5viIerAfDpQ+EuLiqHd5lQq7OCrXXyedGLdAdHPas+LUW rw7PiUuIqYIFRJbOVHGjXKJDOeIrB6Y4kTEyRlFA3pNljmlD/EJ/30QtxffVxyAM3tdR iCKNpfxfF3YJ0uvdxfr/zI1WYGscGZYodLIRaJnKYXb5jJzrlS+Md+HmWt/i7boP8ZXw M/KRXRaCSYU5pFkSLhJHMgFsWqbdU2sh6LsPif2oR7/8gfh05nCNeDcQtGgPKmVWOwVs 2j2Pk8OIc+RdQ6JKRoa5eYBXEa0dXdTAmV5/hkIBKb9uSf2yVtKDh76HP1dbeQwlPCjO Gnuw==
X-Gm-Message-State: AOJu0YyajiGJOzNzB2t0UDs2J9MYeu8XLugOwsGoggzVlAE/d6cECc1j 4LYxw3sILNJ/GcXSmzB5aaNsigYycohP41fWfZU=
X-Google-Smtp-Source: AGHT+IEaIOe9YaRxMzApUPwAQOpAf5FLMC3mrq7OW4Z/Hde+LCSh0YZAVe5E84xcXX6ODm1RO4B1N4noOsqt7jEX2AE=
X-Received: by 2002:a17:907:c705:b0:9cf:7c60:47b9 with SMTP id ty5-20020a170907c70500b009cf7c6047b9mr4190445ejc.1.1702287734142; Mon, 11 Dec 2023 01:42:14 -0800 (PST)
MIME-Version: 1.0
References: <170143520504.35318.12802754659981321130@ietfa.amsl.com> <CAFpG3geLWekOm3+ZHre282x03Cx6OE-rOkBw0kK01bLAuf4P4A@mail.gmail.com> <BN8PR15MB3281C55B67E34CF367B16484B38AA@BN8PR15MB3281.namprd15.prod.outlook.com>
In-Reply-To: <BN8PR15MB3281C55B67E34CF367B16484B38AA@BN8PR15MB3281.namprd15.prod.outlook.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Mon, 11 Dec 2023 15:11:38 +0530
Message-ID: <CAFpG3gcjCHPjRrkYbWRC5Etv0wo000nRh2w5dwO8UQkKbR5jqg@mail.gmail.com>
To: Ben Schwartz <bemasc@meta.com>
Cc: ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b2f99b060c38bf4f"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/9KzTv1_CQI811Kt_M4C88VAfkZc>
Subject: Re: [Add] Fwd: New Version Notification for draft-reddy-add-delegated-credentials-03.txt
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Dec 2023 09:42:20 -0000

On Sat, 9 Dec 2023 at 03:03, Ben Schwartz <bemasc@meta.com> wrote:

> The normative content of this specification (i.e. the SVCB parameter)
> looks good to me (although I wish for a better name than "tlsdelegation",
> perhaps "tls-dc" or "delegated-credentials").
>

"tls-dc" sounds good to me.


> Editorially, I think some improvements will be needed.  This SVCB
> parameter is generally applicable to any TLS-based protocol (not just in
> the context of DNS), but the draft is largely an argument for why this is a
> good idea in the DNS home CPE context.  It seems to me that this is
> backward: the document should present a technical element, and then an
> example of how it can be used.  Lengthy discussion about why it's useful
> might be more appropriate on the mailing list than in RFC text.
>

The detailed description was added to convince the WG members about
the necessity of the proposal, it can be removed from the document or moved
to Appendix after the draft is adopted.

-Tiru


>
> --Ben Schwartz
> ------------------------------
> *From:* Add <add-bounces@ietf.org> on behalf of tirumal reddy <
> kondtir@gmail.com>
> *Sent:* Monday, December 4, 2023 12:30 AM
> *To:* ADD Mailing list <add@ietf.org>
> *Subject:* [Add] Fwd: New Version Notification for
> draft-reddy-add-delegated-credentials-03.txt
>
> This revision of the draft https: //datatracker. ietf.
> org/doc/html/draft-reddy-add-delegated-credentials has been updated to
> address comments during the presentation at IETF-118. -Tiru ----------
> Forwarded message --------- From: <internet-drafts@ ietf. org>Date:
> ZjQcmQRYFpfptBannerStart
> This Message Is From an External Sender
>
> ZjQcmQRYFpfptBannerEnd
> This revision of the draft
> https://datatracker.ietf.org/doc/html/draft-reddy-add-delegated-credentials
> has been updated to address comments during the presentation at IETF-118.
>
> -Tiru
>
> ---------- Forwarded message ---------
> From: <internet-drafts@ietf.org>
> Date: Fri, 1 Dec 2023 at 18:23
> Subject: New Version Notification for
> draft-reddy-add-delegated-credentials-03.txt
> To: Tirumaleswar Reddy.K <kondtir@gmail.com>, Dan Wing <
> dwing-ietf@fuggles.com>, Mohamed Boucadair <mohamed.boucadair@orange.com>,
> Shashank Jain <Shashank_Jain@mcafee.com>, Shashank Jain <
> shashank_jain@mcafee.com>
>
>
> A new version of Internet-Draft
> draft-reddy-add-delegated-credentials-03.txt
> has been successfully submitted by Tirumaleswar Reddy and posted to the
> IETF repository.
>
> Name:     draft-reddy-add-delegated-credentials
> Revision: 03
> Title:    Delegated Credentials to Host Encrypted DNS Forwarders on CPEs
> Date:     2023-12-01
> Group:    Individual Submission
> Pages:    15
> URL:
> https://www.ietf.org/archive/id/draft-reddy-add-delegated-credentials-03.txt
> Status:
> https://datatracker.ietf.org/doc/draft-reddy-add-delegated-credentials/
> HTMLized:
> https://datatracker.ietf.org/doc/html/draft-reddy-add-delegated-credentials
> Diff:
> https://author-tools.ietf.org/iddiff?url2=draft-reddy-add-delegated-credentials-03
>
> Abstract:
>
>    An encrypted DNS server is authenticated by a certificate signed by a
>    Certificate Authority (CA).  However, for typical encrypted DNS
>    server deployments on Customer Premise Equipment (CPEs), the
>    signature cannot be obtained or requires excessive interactions with
>    a Certificate Authority.
>
>    This document explores the use of TLS delegated credentials for a DNS
>    server deployed on a CPE.  This approach is meant to ease operating
>    DNS forwarders in CPEs while allowing to make use of encrypted DNS
>    capabilities.
>
>
>
> The IETF Secretariat
>
>
>