Re: [Add] Proposed charter and BoF request for IETF 106

Richard Barnes <rlb@ipv.sx> Wed, 09 October 2019 18:46 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B3A4120120 for <add@ietfa.amsl.com>; Wed, 9 Oct 2019 11:46:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tRkTvYTrVCyV for <add@ietfa.amsl.com>; Wed, 9 Oct 2019 11:46:43 -0700 (PDT)
Received: from mail-ot1-x332.google.com (mail-ot1-x332.google.com [IPv6:2607:f8b0:4864:20::332]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20D6512007C for <add@ietf.org>; Wed, 9 Oct 2019 11:46:43 -0700 (PDT)
Received: by mail-ot1-x332.google.com with SMTP id 67so2638393oto.3 for <add@ietf.org>; Wed, 09 Oct 2019 11:46:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Ijd+t6JyHYzshMt+AF0h5bU00bqGmIncnDAB3mnkx04=; b=BdO+NFM1MYGDZxWYOZhNeMFp/ydkchkCfJR4eP0fzMQlUaF5FR+VPuMJ5QT8n9xZJh Nmg51J4ZYi1mQqGAqbCBt0EWjTuo6GJahlEh5f8Hu3nSH1W3GyoWC5o/sE61RjzPQ5c+ 2d213x6ek3cYw2W6zoGEP0Z7eqLMVrccokJAgH3ov9jRbTD4pWuFVjtuX85o3V+KiKSg dRrpXW+8uGWEwa7pn/AKbbITtcpyuEDKOvLq0Kj7HbOcB2GVbdOYvkLsG3zQWFeR1HZe h8V4lxmX9/Q1x3Ogr3Iq5fGl5ChyLEKuCzJ/XSG0xB8UawVXAsBQkPuRnIC3wM69YqmW sAyQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Ijd+t6JyHYzshMt+AF0h5bU00bqGmIncnDAB3mnkx04=; b=N3bnNXD6W9g0bCqT6Z4zHoic2dRdZEwhNnCfJKczIWkkch6cfljt1nZdnWh3WXCMtD xPqBLC+WWDVwRKK2QwSXO/V55ROUzmv90Tp0bpyihVlyw7+MRoTMSvPfEIeSW6N1oF/g i1eBpdYX9mJTo9qynKr30s17GIp1j0wlArxdMlfBqSywslhCPFOHzwq2he5tAZ4ie1Jy CDx3Dk7W3SfQFL5GQFNsdfEyfeFEneh7Fw9z7EEgsuioXM1ATOFodEdlH0jWxzTYKQgy ABiLrP0mJEKYNPylY6wvNuiTmhOdWpG9hI5Cc9WH6GH6Pifz34faUe00QwMt7wchi3Q2 19gA==
X-Gm-Message-State: APjAAAWu9EyFPlEbbP3hx/QzyV283oHTsGtg6YqDJ+KEM+uFTSNZwlDK 15Wk6xwLn4HvtXSO6WKtYgS+E7DPzXXSydtzRLFDgA==
X-Google-Smtp-Source: APXvYqzjTmn6S/CoWnWqXWJ6qwUOo20MpnudTDUID/mKBgXBULEcX02KGCrWJBO4WcoCiEhkaoUOZJdGmGJHTrHAAcY=
X-Received: by 2002:a9d:6641:: with SMTP id q1mr4302902otm.241.1570646802017; Wed, 09 Oct 2019 11:46:42 -0700 (PDT)
MIME-Version: 1.0
References: <CALaySJLxXVuHQNfTnaeKZ_R9xtBYWfbta+A1bWcE-ZQZwd3VZg@mail.gmail.com> <CABcZeBMkAFZW9mWjw92v+OR0Fa8ed+P80yc78eY07hCpsCNY6Q@mail.gmail.com> <1556423899.28427.1570640191209@appsuite-gw2.open-xchange.com> <CABcZeBNyRDqnVL68aXny=Ht69NjahmS4zRsnYizO53M--rhM5g@mail.gmail.com> <alpine.LRH.2.21.1910091313590.2297@bofh.nohats.ca> <CAFpG3gch-mgJJMO1rEg61PhYNKeKYiJwz4NTQ3QDbEb=WNkyQw@mail.gmail.com> <CABcZeBM68EWDO3rTOCnWfmieAGzxwR9YUj4pyvDtECFEDoFiNw@mail.gmail.com>
In-Reply-To: <CABcZeBM68EWDO3rTOCnWfmieAGzxwR9YUj4pyvDtECFEDoFiNw@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 09 Oct 2019 14:46:29 -0400
Message-ID: <CAL02cgQOUDfk20COShfYbQHOhb-aVTBh0g0ahjWdWZAFWuzN6w@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Cc: tirumal reddy <kondtir@gmail.com>, Paul Wouters <paul@nohats.ca>, ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b3fd1705947eb454"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/DQjhje2GPSp1j-G9Ugsu7hCsz38>
Subject: Re: [Add] Proposed charter and BoF request for IETF 106
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Oct 2019 18:46:46 -0000

On Wed, Oct 9, 2019 at 2:32 PM Eric Rescorla <ekr@rtfm.com> wrote:

>
>
> On Wed, Oct 9, 2019 at 11:04 AM tirumal reddy <kondtir@gmail.com> wrote:
>
>> On Wed, 9 Oct 2019 at 18:15, Paul Wouters <paul@nohats.ca> wrote:
>>
>>> On Wed, 9 Oct 2019, Eric Rescorla wrote:
>>>
>>> > You're misunderstanding me. I'm not saying that we should not enable
>>> network operators to shift to encrypted transport.
>>> > As I said in the section of my message that you cut, I'm more than
>>> happy to have the IETF standardize a mechanism for
>>> > the network to tell endpoints that it supports encrypted transport.
>>> I'm merely observing that this does not address the
>>> > issue that Mozilla is trying to address with our DoH/TRR deployment.
>>>
>>> And it seems doing this at the DHCP / Captive Portal level is enough. I
>>> don't see the need for a WG to be spun up for this.
>>>
>>
>> DHCP is not a secure way to discover the local DoT/DoH server.
>>
>
> It would probably useful to start by defining what "secure" means in this
> context. For instance, I am in an airport and I see the name of the WiFi AP
> printed on the wall an join a network with that SSID. How would you define
> securely learning the DoH server?
>

I would probably be happy with the property that some random other host on
the LAN couldn't feed you bad information.

Not that this has much to do with DoH.  The impact of rogue DHCP servers is
just as catastrophic for Do53.

--Richard



> -Ekr
>
>
>> -Tiru
>>
>>
>>>
>>> Paul
>>>
>>> --
>>> Add mailing list
>>> Add@ietf.org
>>> https://www.ietf.org/mailman/listinfo/add
>>>
>> --
>> Add mailing list
>> Add@ietf.org
>> https://www.ietf.org/mailman/listinfo/add
>>
> --
> Add mailing list
> Add@ietf.org
> https://www.ietf.org/mailman/listinfo/add
>