Re: [Add] Food for thought?

tirumal reddy <kondtir@gmail.com> Wed, 22 January 2020 15:45 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 37AAB1200F5 for <add@ietfa.amsl.com>; Wed, 22 Jan 2020 07:45:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZSMcN3Y7jRgg for <add@ietfa.amsl.com>; Wed, 22 Jan 2020 07:45:14 -0800 (PST)
Received: from mail-il1-x12b.google.com (mail-il1-x12b.google.com [IPv6:2607:f8b0:4864:20::12b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 435CE1200F7 for <add@ietf.org>; Wed, 22 Jan 2020 07:45:14 -0800 (PST)
Received: by mail-il1-x12b.google.com with SMTP id c4so5479142ilo.7 for <add@ietf.org>; Wed, 22 Jan 2020 07:45:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=EcXis8lPitLhHsM3lvnRVrJbqdnAydqT6vQbY3l7GnA=; b=rtkKw7Xmth1ZiJIP1v/eJgdRY+MMHn5Db3uuek1BF+uO232TLbm9fTfpK4USLYhA2p 8RV31TDozdd/puOQsP+Nb23XMzMsgOLJLtmCnFtBsy+ClDgVEJLSh7L2lFDWfRgneSVs wNmUyBlkTXGWkTtqlhJXkEUxgvTSVQQYEvU66TrK5bQtGRTe4girG+EbVHAYXNLupW4V c+kVQl0BWHz22s9UMfC5effeKCr3qoXz6jo7CO7psUEyO9u5N70Z2HS1tjD3fTlYg31Y mPAThz0Y6Xwjwdt8AVON650jh4RTEm3A+kk+LGLiWIGTOZLhLWH8EOIzuq+inyk0anER Obsw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=EcXis8lPitLhHsM3lvnRVrJbqdnAydqT6vQbY3l7GnA=; b=UJdMzNZH2lRrBQxz0zXPEFc6QxkvNkK5GI6rRk6YxcfrP32Xezu2NE0j2XGXLv0Dwr RPyZCCkIvmwvqMSxLJ9ogNaz3OVU/D5AhVqFoirKBOZAwboiSDJlI+z49BNgM5kpVntG 6ucybYEHCLNSyiWuLvm3yAtMzHLA0K4XBZdng2v0+3/7v7SkVg2RuUDFzvSDE4kqKfR7 B+5+oDQeaV5e1ggd0fKle8F2muhqY2k4VtSysonFgOpguaHfixaesRK3HdADVYunpRTx PCdUbg1Ps3wFqhVM1xCLQVm4zIkaN7NqCTukc9gHZPhJm9HZN4UpIfqltFONkZ5Cly9L L8Zg==
X-Gm-Message-State: APjAAAUEI5TGNhhqTZKal54Q4Y1cTyVd9PhmPU3yaL37YodMdnNmHWGu 4FyouKafCP2w3zt+ijJtfYoxcO4LvEAgnVoZFo4=
X-Google-Smtp-Source: APXvYqxTW/Nwew9eJuKwgf7admFFPqFe71LWxGVeFzW0JPrLL24+n5AuzTyx3TpIhVb6YzhOHDaRA67DyimZlwNXseo=
X-Received: by 2002:a05:6e02:f0f:: with SMTP id x15mr8386228ilj.298.1579707913557; Wed, 22 Jan 2020 07:45:13 -0800 (PST)
MIME-Version: 1.0
References: <CAChr6SwZMid9ruggYAu5bqBEcujhczp34mJ=TZPAjSXw50ZBKQ@mail.gmail.com> <C70ECC76-7431-4FC2-B555-0E1D8D82B449@nbcuni.com> <CAChr6SwYtJh84CLE9n+fuqjdFAaSzNP=aFKqa70KY=Mx+F76MQ@mail.gmail.com> <CWXP265MB0566FDF1030771C6916BE37AC2360@CWXP265MB0566.GBRP265.PROD.OUTLOOK.COM> <F82221F8-35B8-497F-8AA9-F2405000650F@fugue.com> <CAOdDvNqyJhu_q8ALpBeg=zcjyUpHW=fpTxSsoCV0_c=oiXg=pA@mail.gmail.com> <7B424818-0F38-44E7-8EDE-165E96A6221A@icann.org> <CAChr6SyUKmvAQ8niPYjQmL4EREY7c6dqqsjp-M2bt4a_i-L40A@mail.gmail.com> <9c261636-a030-6116-098d-ac89b1227bad@ericsson.com> <03037960-e9a7-3dd5-7009-3c79e589fd08@ericsson.com> <97C1A1AA-D146-4B07-8489-9658385F3DF1@fugue.com>
In-Reply-To: <97C1A1AA-D146-4B07-8489-9658385F3DF1@fugue.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 22 Jan 2020 21:15:01 +0530
Message-ID: <CAFpG3gcK0gervdWc5w+1vBJ4MT04gR-J+GmHFoXdzS9BnzW18Q@mail.gmail.com>
To: Ted Lemon <mellon@fugue.com>
Cc: Mohit Sethi M <mohit.m.sethi=40ericsson.com@dmarc.ietf.org>, "add@ietf.org" <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000095ab8059cbc69e3"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/RM8_RNnSgfeC5gmjfxi3FQ1jTnU>
Subject: Re: [Add] Food for thought?
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jan 2020 15:45:17 -0000

On Wed, 22 Jan 2020 at 19:53, Ted Lemon <mellon@fugue.com> wrote:

> On Jan 22, 2020, at 8:50 AM, Mohit Sethi M <
> mohit.m.sethi=40ericsson.com@dmarc.ietf.org> wrote:
>
> Rather than distinguishing between private/local networks vs. Internet, it
> could distinguish home/enterprise networks or whether infrastructure is
> available to aid the discovery or not. For example, some enterprise
> networks may have servers (such as a Windows Active Directory Domain
> Service) to help assist in the discovery of DNS resolvers. This would not
> be possible in many home networks on the other hand.
>
>
> Practically speaking, it might help to think of this in terms of scenarios
> rather than types of networks.   It’s true e.g. that a corporate network
> may have WADDS, but it may also not.  What matters is whether it has it,
> not whether it is a corporate network.   It might help with clarity if we
> think about it this way, although I agree with your basic point.
>
> And then what is it about WADDS that makes it able to help the client to
> find a secure resolver, as compared to unauthenticated DHCP?
>

Policies can be configured on both the OS and browsers in the endpoint via
Active directory, Discovery of DoH/DoT servers is not required. For
instance, see
https://support.mozilla.org/en-US/kb/customizing-firefox-using-group-policy-windows,
the policy can specify the Enterprise DoT/DoH server the browser should use.

The challenge is with BYOD devices or Enterprise networks that have
limited/no configuration control on endpoints.

Cheers,
-Tiru


> Is it a property that is unique to WADDS, or is WADDS implementing an
> example of some property that other services might also be able to
> implement?
>
> --
> Add mailing list
> Add@ietf.org
> https://www.ietf.org/mailman/listinfo/add
>