Re: [Add] data integrity and DNSSEC or DoH/DoT

"Ralf Weber" <dns@fl1ger.de> Thu, 22 August 2019 11:28 UTC

Return-Path: <dns@fl1ger.de>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C98A1200FD for <add@ietfa.amsl.com>; Thu, 22 Aug 2019 04:28:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QK7Ia1vuJA3o for <add@ietfa.amsl.com>; Thu, 22 Aug 2019 04:28:35 -0700 (PDT)
Received: from smtp.guxx.net (nyx.guxx.net [85.10.208.173]) by ietfa.amsl.com (Postfix) with ESMTP id D8A7F120026 for <add@ietf.org>; Thu, 22 Aug 2019 04:28:34 -0700 (PDT)
Received: by nyx.guxx.net (Postfix, from userid 107) id C90085F42A11; Thu, 22 Aug 2019 13:28:33 +0200 (CEST)
Received: from [192.168.2.190] (p54B8ABDF.dip0.t-ipconnect.de [84.184.171.223]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by nyx.guxx.net (Postfix) with ESMTPSA id 3FDB65F41172; Thu, 22 Aug 2019 13:28:32 +0200 (CEST)
From: Ralf Weber <dns@fl1ger.de>
To: Rob Sayre <sayrer@gmail.com>
Cc: David Conrad <drc@virtualized.org>, Jim Reid <jim@rfc1035.com>, ADD Mailing list <add@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Date: Thu, 22 Aug 2019 13:28:31 +0200
X-Mailer: MailMate (1.12.5r5635)
Message-ID: <EACE25AB-B694-4E6B-BFF2-B06EBB6094FA@fl1ger.de>
In-Reply-To: <CAChr6SxuR20YD7idwniprB7C-4E1vxdhVzUSh4AVW=EeK6BHUA@mail.gmail.com>
References: <A1128702-1E19-4657-9740-E84AE09992F2@piuha.net> <CABcZeBMfOTjq-8hDDoKMtJvfHUA5nC8o60zuk-2Xe-ZhfwriJQ@mail.gmail.com> <766112E1-F532-4C6B-8CA8-A096671E02EE@piuha.net> <CA+9kkMAfuOwJu8_qJTuhAY4mUwR+tVUxr+k3QFHBk3byV672Ow@mail.gmail.com> <A7EA862E-8E80-40E3-834D-E628988C0A24@virtualized.org> <CAFWeb9KT=2JL0oHUgJ2WMcduR3na+hP2QncvRR4YurmqsAWxTA@mail.gmail.com> <59E0EC53-0E30-431C-8376-52C7BFC121A8@virtualized.org> <CAFWeb9+Z7RmXEr46qx5PaUcxh2R3+HXhrZeW-8QEMX4HLt7a-w@mail.gmail.com> <589DAFCB-1BDC-4156-A2CA-179C4559A6B2@virtualized.org> <cf2152d7-8618-7ad2-b8f9-7a259ab5df19@cs.tcd.ie> <683A176C-3CE6-4866-A736-F2A7465FA5B5@rfc1035.com> <ee8291ce-855f-a5d8-e9d8-74be9f58c321@cs.tcd.ie> <A73CCDC6-5AC4-4780-8B63-B9BD4A7ED70A@virtualized.org> <CAChr6SxuR20YD7idwniprB7C-4E1vxdhVzUSh4AVW=EeK6BHUA@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/L9r_lJ4t0-L0vukolJpSJ1kB6EM>
Subject: Re: [Add] data integrity and DNSSEC or DoH/DoT
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Aug 2019 11:28:37 -0000

Moin!

On 22 Aug 2019, at 0:18, Rob Sayre wrote:

> On Wed, Aug 21, 2019 at 3:15 PM David Conrad <drc@virtualized.org> 
> wrote:
>
>> My response to Ted that caused me to get sucked into this particular 
>> swamp
>> (something I already regret)
>>
>
> Is that the swamp where the only significant DNSSEC providers are 
> Google
> and Cloudflare?
I assume you are talking about validating recursive resolvers here. 
There are
way more, e.g Comcast, all the swedish ISP, a couple of ISPs in South 
America
and I know that there are more European ISPs that are planning to turn 
it on.

Plus even without validation in the recursive resolver you could have 
validation
on your end device if you want.

So long
-Ralf
---
Ralf Weber