Re: [Add] My single use case

Eric Rescorla <ekr@rtfm.com> Fri, 11 September 2020 12:23 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 458673A0F9F for <add@ietfa.amsl.com>; Fri, 11 Sep 2020 05:23:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l0kc4K8-oJNg for <add@ietfa.amsl.com>; Fri, 11 Sep 2020 05:23:53 -0700 (PDT)
Received: from mail-lf1-x12b.google.com (mail-lf1-x12b.google.com [IPv6:2a00:1450:4864:20::12b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7AD003A0F9C for <add@ietf.org>; Fri, 11 Sep 2020 05:23:53 -0700 (PDT)
Received: by mail-lf1-x12b.google.com with SMTP id m5so5628323lfp.7 for <add@ietf.org>; Fri, 11 Sep 2020 05:23:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=XLx+nsjmDFQ6ZNm0+IGzOpbk0/glL3dUbpLxEx51Hvc=; b=mCF36xdX8hW538mHYQW4AL/FR69/iw4L7xbBk63a9+8PeQ1rWWM0YQ1CrVFIQFiT/M hu9cBGCIeo5vBDiuZNtLSl57JIVr9YpmlG88rm0F2+b+s2yP/8rkubDn/15DE9E9BLn/ YWZe6kyzJyn9ij5Ypsa9dF/6kvURKLcLVh8aDWSY6a5rWx43AOaKmG1B3WkA70zTjNKH efN6xFitizLjUrFUNvEnJCnhw8vZgLPd8EsjaafCMmktO9XYzUp6HiTNuegAbwQAZ6a3 SvTrLW0phEgW0dBZZBuw1G9dlKSfGyWzPiyShM2J0m1oCc0ZbFpL1jZ9WrXTu+gMA5JJ 4gGw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=XLx+nsjmDFQ6ZNm0+IGzOpbk0/glL3dUbpLxEx51Hvc=; b=Y/SAs3V2A/8KkZSkGEnppTaOGuaniDgbRbLJFmn4OQ4vVjz7lDkV0S9zX37BfnFx3O 5cLBrILKhRPo84HRsiRU3IsoMnFYl+vQn6HGnfCJ2ev/8cJ+Qgt5P1G0LGUHA8VzNozj gvBnUk41rRRE2LDGXkD23tcFZJlUvTvrlT9HihSc3pcFDlaok2DXyAQLhGDFwRJ0t8pk ieyMs7XQg/hbaIy7ztnnF4Ad5aZK0H0EC7u4sgqVpNb/koPgUYbtT0ClvwgZDI/31Ib0 N/bciNw/0RPLVIV1L3rW90lFAgI502pJMsCR6MJZnaKoeJATZVVR2UxrpHZ2FdiJYIsw csgA==
X-Gm-Message-State: AOAM5309czVJco2KvQgolU2KnCZCVeTWVQ1S/tgO1fF1bLuoSXRS+NpF oj6kHiTBNfUxvGIeaLWDhBoWigsPiBJNy0cKQ8OksQ==
X-Google-Smtp-Source: ABdhPJx384XVBj5l1AuXyYOSUqT2uglOl9jz7PgWmQ9oTuCU6ilkgsej0s4cO4mGjKY2N3wE1PLpL6qwZNfk7VCW+1A=
X-Received: by 2002:a19:c07:: with SMTP id 7mr192657lfm.516.1599827031623; Fri, 11 Sep 2020 05:23:51 -0700 (PDT)
MIME-Version: 1.0
References: <d4bd287a-d2ce-40cd-b635-4f74efbc77f6@www.fastmail.com> <CAFpG3ge=fyBOKsjZr+uK+kdmUsp0U1+osJjHSiwB9V59ctq=RA@mail.gmail.com> <CABcZeBPOjAor0js5RYkpzm0-6-Awx8Px06ycwu_W5XWakxYt2w@mail.gmail.com> <CAFpG3gfUr86haKDrMGTt7YjEG4uufdwF=16SbGb+5xs8JrLteg@mail.gmail.com>
In-Reply-To: <CAFpG3gfUr86haKDrMGTt7YjEG4uufdwF=16SbGb+5xs8JrLteg@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 11 Sep 2020 05:23:15 -0700
Message-ID: <CABcZeBMm9xaONrvBy5QWx=_2keaOw=QW0SexNwjAJCO4nbRyxw@mail.gmail.com>
To: tirumal reddy <kondtir@gmail.com>
Cc: Martin Thomson <mt@lowentropy.net>, ADD Mailing list <add@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000ec1dcf05af08c124"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/TlIMyul_yuNB4QMPw3m2Q_O6eb8>
Subject: Re: [Add] My single use case
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Sep 2020 12:23:55 -0000

On Fri, Sep 11, 2020 at 5:06 AM tirumal reddy <kondtir@gmail.com> wrote:

> On Fri, 11 Sep 2020 at 16:45, Eric Rescorla <ekr@rtfm.com> wrote:
>
>>
>>
>> On Thu, Sep 10, 2020 at 10:59 PM tirumal reddy <kondtir@gmail.com> wrote:
>>
>>> The use case looks incomplete, it does not explain how the new device is
>>> on-boarded into the network.
>>>
>>
>> For wired network you plug into the wall.
>> For a wireless network, someone gives you an SSID and a (common) password.
>>
>
> You seem to be referring to home/coffee shop use cases and not relevant to
> on-boarding devices in an enterprise network.
>

Sure. Well, if you like add "network certificate + SSO" I don't think it
materially changes the situation.

-Ekr


> -Tiru
>
>
>> For mobile, via the usual mechanisms.
>>
>> -Ekr
>>
>> -Tiru
>>>
>>> On Thu, 10 Sep 2020 at 20:38, Martin Thomson <mt@lowentropy.net> wrote:
>>>
>>>> My preference is to tackle just this:
>>>>
>>>> As a new device or application, when I join a network that I have no
>>>> prior relationship with or configuration for, I want to discover the DoT or
>>>> DoH resolver that corresponds to the Do53 resolver offered by that network.
>>>>
>>>> This might need the full matrix of DoT/DoH, v4/v6, with/without a
>>>> forwarder, but this is fundamentally just a single use case.
>>>>
>>>> Specifically, I want to NOT learn about whether the resolver does qname
>>>> minimization or DoT to the authoritative or whether it does the eDNS client
>>>> subnet or different policies with respect to what is answered or anything
>>>> else that might make a decision to use this alternative complicated.
>>>> Existing methods don't provide this information.  I don't want a protocol
>>>> that does anything fancy because that makes the decision complex.
>>>>
>>>> --
>>>> Add mailing list
>>>> Add@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/add
>>>>
>>> --
>>> Add mailing list
>>> Add@ietf.org
>>> https://www.ietf.org/mailman/listinfo/add
>>>
>>