Re: [Add] Paul Wouters' Discuss on draft-ietf-add-resolver-info-12: (with DISCUSS)

mohamed.boucadair@orange.com Tue, 02 April 2024 06:47 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1543EC14F61A; Mon, 1 Apr 2024 23:47:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.094
X-Spam-Level:
X-Spam-Status: No, score=-7.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2ccCEO0falBD; Mon, 1 Apr 2024 23:47:42 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.126.239]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 74AF3C14F60F; Mon, 1 Apr 2024 23:47:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1712040462; x=1743576462; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:from; bh=taINqjy8WWMCgyQ7Qjn8R8yYzWdaGr1k/yYdp+FTQwA=; b=hAFNRsq4HADMo89yvarhWiLDOSx06W4w1kEw3QYoWap1fgM/nYjjbVBo xakL+lxqHm74CkEc8ii4szm8J60jLhADLu92uiFD35mJDliyuVWbcCrVE FE0o5IopIh0qtxqrbPEJgAOXcTPV1oJVkIFSzSLcme5hIjF9zMmZICmrD 3GFinthLB2Ol9B/j3CSns5Oq3UI4kQnsKDVxeuWZlvwSEGfFdMvgWmAXi 2kkS1FJVzWpmU6Z7Oz6z/YT66m1vI36TicXUvHqvRP9DhhVr7THtOeW/F PooCiHKX564V7xn697rKbzLENduiFk2E+4PTu69vKFbnAmnuK2yUGArqI A==;
Received: from unknown (HELO opfedv3rlp0b.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 02 Apr 2024 08:47:39 +0200
Received: from unknown (HELO opzinddimail2.si.francetelecom.fr) ([x.x.x.x]) by opfedv3rlp0b.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 02 Apr 2024 08:47:39 +0200
Received: from opzinddimail2.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with SMTP id 43E8BD2DF2FB; Tue, 2 Apr 2024 08:47:39 +0200 (CEST)
Received: from opzinddimail2.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id AE609D2DF2F8; Tue, 2 Apr 2024 08:47:12 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail2.si.francetelecom.fr (Postfix) with ESMTPS; Tue, 2 Apr 2024 08:47:12 +0200 (CEST)
Received: from mail-db8eur05lp2105.outbound.protection.outlook.com (HELO EUR05-DB8-obe.outbound.protection.outlook.com) ([104.47.17.105]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 02 Apr 2024 08:47:12 +0200
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by GV2PR02MB8507.eurprd02.prod.outlook.com (2603:10a6:150:af::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.46; Tue, 2 Apr 2024 06:47:06 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::18a0:3679:a134:1d02]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::18a0:3679:a134:1d02%6]) with mapi id 15.20.7409.042; Tue, 2 Apr 2024 06:47:06 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.106.160.156-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=Pass smtp.helo=postmaster@EUR05-DB8-obe.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 104.47.17.105 as permitted sender) identity=mailfrom; client-ip=104.47.17.105; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: Pass (smtp-in365b.orange.com: domain of postmaster@EUR05-DB8-obe.outbound.protection.outlook.com designates 104.47.17.105 as permitted sender) identity=helo; client-ip=104.47.17.105; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@EUR05-DB8-obe.outbound.protection.outlook.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all"
IronPort-Data: A9a23:to96cqOliwYLEM/vrR1tkMFynXyQoLVcMsEvi/4bfWQNrUoh0WcAn WMaC2nXM/yDa2r3LtAkOoqx8UwH6sTVy4RnGQZtpSBmQkwRpJueD7x1DKtR0wB+jCHnZBg6h ynLQoCYdKjYdleF+lH3dOGJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 YyaT/H3Ygf/h2YoajhMsspvlTs01BjMkGJB1rABTaAT1LPuvyF9JI4SI6i3M0z5TuF8dgJtb 7+epF0R1jqxEyYFUrtJoJ6iGqE5aue60Ty1t5Zjc/PKbi6uBMAF+v1T2PI0MS+7gtgS9jx74 I0lWZeYEW/FMkBQ8QgQe0EwLs1wAUFJ0LabJ3qSn9Gt9lSFSmXAm691HmI9BaRNr46bAUkWn RAZAB0wVEjews6ckPe8QOQqgdk/Js72Oo9Zomtn0TzSEfchR9bEXrnO4thbmjw3g6iiH96HP 5ZfNWUpNUuGOkUSUrsUIMpWcOOAg37/ejhVpBSforc86mTazRZZ16LkNtXYPNeNQK25m27D/ zmYpj2hXHn2MvSi7gPfozGs1tbutn2lG5tJDIOW/ONT1Qj7Kms7U0ZMCQTTTeOCok25Xd5DK lY89S8nrKx0/0uuJvHlVgC85mGDowIRQcF4Guwk5QfLy628yweUHWcsTzNdZpohrsBebTAw3 1GV2tLkGTIqubGZDGiQ7bCQsz6ofCkTI2gqZCIYQ00C+daLiIg/glfETt9iCrWdj9DpF3f32 T/ihCEyi50SgNIFkaKh8jjvnzWuq57SZgs07R/QRWWr8kVyY4vNWmCzwV3S7PIFIIzJQ0Sb5 CUAg5LHtL1ICoyRniuQRulLBKuu+/uOLDzbhxhoAoUl8DOuvXWkeOi8/Q2SOm9gbsAGVBH0X nbK+jpPyMcJJ2mJZpdeNtfZ59sR8YDsEtHsV/bxZ9VIY4RseALvwM2ITR7Bt4wKuBh9+ZzTK aumndCQ4WEyKIkP8dZbb+IU0LtuyipuyH7JHc3/107+iefYY2OJQ7AYNlfIdvo+8K6PvATS9 ZBYKteOzBJcFub5Z0E7ELL/z3hbcBDX5riv8KS7k9JvxCI4RQnN7NePnNscl3RNxfg9qwsx1 ijVtrVk4FT+n2bbDg6Bd2pubrjiNb4m8itibH1yZwj1giR6CWpK0Ev5X8pvFVXA3L07pcOYs 9FZI5vaahiyYmiZpGhGPcGtxGCcXE3y1FvSYkJJnwTTj7Y7HFaVpbcIjyPq9SIUCTGwu9d2q Lq6zmvmrWkrFmxf4DLtQKv3lTuZ5CBD8MorBhegCocJJC3ErtMxQwSv1aBfHi35AU6frtds/ 13LWUtwSCiki9NdzeQlcojf893wTLAhQxIHd4QZhJ7vXRTnEqOY6dcoeI61kfr1DQsYJI3Ki SRpI/DA3DkvsWtw69c5P5w7iKU06p3ouqNQyRliEDPTdVO3B7h8I36Am85SqqlKwbwfsgyzM q5K0scPIq2HYasJD3ZITDfJrMzbvR3XptUWxfMvKUP16Wl8+7/vvYB6IUyXkCIERFdqGN9N/ NrNYPIr1jE=
IronPort-HdrOrdr: A9a23:hf8C3qM8Beg06MBcT17155DYdb4zR+YMi2TDiHoddfUFSKalfp 6V98jzjSWE8Ar4WBkb+exoS5PwOk80lKQFl7X5Uo3SODUO1FHHEGgm1/qa/9SCIVy2ygc+79 YGT0EWMrSZYTdHZITBkW+F+r0bsbq6GdWT9ILjJgBWPGNXgs9bjjtRO0K+KAlbVQNGDZ02GN 63/cxcvQetfnwRc4CSGmQFd/KrnayBqLvWJTo9QzI34giHij2lrJTgFQKD4xsYWzRThZ8/7G n+lRDj7KnLiYDw9vac7R6f031loqqv9jJxPr3DtiHTEESstu+cXvUsZ1RFhkF0nAjg0idorD CGmWZbAy060QKtQojym2qk5+HtvQxel0PK2BuWh2Durtf+Qy9/A81dhZhBeh+c8EY4uspguZ g7ql5xmqAnfi8oph6NleTgRlVvjA65sHAimekcgzhWVpYfcqZYqcga8FlOGJkNESrm4MR/ed Mee/309bJTaxeXfnrZtm5gzJilWWkyBA6PRgwHttaO2zZbkXhlxw8TxdAZnH0H6JUhIqM0k9 jsI+BtjvVDX8UWZaVyCKMIRta2EHXERVbWPGebMT3cZdE60rL22u/KCe8OlZ6XkbQzveUPpK g=
X-Talos-CUID: 9a23:Z6l57msOX+ohPraDJqjMMBC76IssLnvf4VnNHXahSl93ZOXPUk2z85tNxp8=
X-Talos-MUID: 9a23:SkXvCgrcnKP+kPxpAqkezwxFDZ05oKT+MWEmz8tFopKcCwJ6Jg7I2Q==
X-IronPort-AV: E=Sophos;i="6.07,174,1708383600"; d="scan'208,217";a="31361106"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BwjbmIUkGafqnC4yy5ohPgTyLS+8H7xl6y8IZajuMQRZrwTdLF/HTgp+dJ1VvErkPjnb89k7t8/A0pjUIIeT54gOEAd+0ulD94lrHIUtai3gXCOdMHc2b6RfOWeuZyfY0zj3/laEhartktIJE8ULftN39znba5QdkPkVjYkOJfUBJkZtE6xAQJbC783hvcNXlnhlrlEBqouc/DZOAzVW5mrtjKEdAA2caUk2N/TK+cLnUr4eP2/dG8j99s32RjKeSSoRu+wGLivns+SSmwklu71MISrcTT0mfrYxMprLPGSqRHL2Od7BG4j/WYWv6uH2gsIsAu8ay9D74YjXhRGoww==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=mIMQR1+loQTw2PZ9ASBk0kX9G9PR2Rlb7tu5KA2te6Y=; b=m2b2mFe9ygyNv5Lzph6yUhoXQs7rlW16h5D0qC/QI/h9dDm0HSOuy3BCqOefWxkX/1Yxsk+qaotSSC8qgkJ/CJPvDqzlG+Q3bRG/drbGD6iFPUjY9G4N9ILEPSXLKu/hbh6nrfHz+nRvPDfSCKgIZs3QapDbLlMSCkZI4/zt3Ix1DfxnNjaSvCj2Xp4DBog6sCL4NnrnLm1T42laJsKpq+MCRGoz+viPOMYD1RoNkv1aMNNXjHgluDD1tcgC63jaHpQDE6PC+1h7r7nlDKAIZ2kBWFNLT29j1VdvD0nGMNirH5cOsBCfsr0ZoMjS+lKTEiKwMO6CfzCLmOMjIUKCFw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: tirumal reddy <kondtir@gmail.com>, Paul Wouters <paul.wouters@aiven.io>
CC: The IESG <iesg@ietf.org>, "draft-ietf-add-resolver-info@ietf.org" <draft-ietf-add-resolver-info@ietf.org>, "add-chairs@ietf.org" <add-chairs@ietf.org>, "add@ietf.org" <add@ietf.org>, "tojens@microsoft.com" <tojens@microsoft.com>
Thread-Topic: Paul Wouters' Discuss on draft-ietf-add-resolver-info-12: (with DISCUSS)
Thread-Index: AQHahDB0NehYs3C36kCEZPl96OI/tLFUiFiw
Date: Tue, 02 Apr 2024 06:47:06 +0000
Message-ID: <DU2PR02MB1016011E1C399D5EC90BD1FFE883E2@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <171184989711.29383.9811877433419506782@ietfa.amsl.com> <CAFpG3gdGMgv6H=CkVLvwk=EBXQBFWXfwSbbC-M1z0P_kqukF2w@mail.gmail.com>
In-Reply-To: <CAFpG3gdGMgv6H=CkVLvwk=EBXQBFWXfwSbbC-M1z0P_kqukF2w@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=4c668c86-b995-4b19-a101-d551a8977b73; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-04-02T06:46:32Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=0; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|GV2PR02MB8507:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: nDJToMDqKy6dPmIAetB1OyY/aqX9ne77owvNMG+9+OSMeUS/Gzc4+qwoCzfjVnltanVdTJTmt4+1C8Uj8hP9mZujJujXjop8+kvzLgOlc4xQefLWwDuwX2ptDZc7xobJV9nfuliV5pOctkwe5CcJ+b+ZAefthiXpZ2bOVkSiJ7KLFdNsaGPdocWjC6Gmi2n9nyUYcLIKxiq13F33W36BzAoIzkFwTYiGYbIuG6OPMBXxyhq8hqQLxkx69j+kxcmMrkSpAXXW3SOvXR0uvkR9hw51v/GpJpt4bJ1FDxEU5kByCbv5PC0ESNkp11eLbCXNJGbT1sdrX2bh+eU9Ofl2CWdjR7CPsE2WrYbAa0Tl0ZvBL8b89Xq8dsHh2sHbWiyGoBdz9S244R5XEdNcZtyl/v2upNTca8v7wlNi6KQEx2YqwyJwUlaet2k4e+M24yDES4h7vohdSMRmNBK+7IQKx/iB9rFPo73+HdGwGwu9IbUEENV/q1+QLhpqZi8buKSQhaHX4gUEBsR8JkfH/Bblax8MId1hC1gQRX1ejUirwDpWw6TazzvnXyPi+f/qHrAgYQqtbewTMeM+94Gn3KUYZThBEE/SIBlOFWVsvFx0J2OSgh7J/ZmfpvYiMg+O8mE/
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR02MB10160.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015)(366007); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: L+bCtHIfaHxFldfo0vMjHYZzSaYIa4bynxxGPFtF8K19q4zaHTQwarCreBe+A7nHsJGi7swYRLFSuDjNcaBlycAID2F6XV1/ReqXXYKpE3ZDKhH7JeVlUYrcOf0iqPQH92nc8nqatfNpV0frN5bPZ7xFabplIRC7qi1xvQBHqhS8MKowl5lrJ62TJfZOBv+D2UMtDtq5b4KdX3g7ZoXFIqRRdzbWzDGNLO6omhCYx9WEBJjDmP9Bx/pJojXozdjki+1RokI7JUYRJZF58E+U4P1Mx2WutxnOZyi8HeGIpPEdrSJ6os4ZOGIhlO9AyUcNn5mfwvz8EFOXtwiTxlGrKYcaPkYbBXeX3Jii1yHLKthM4SmIApHW68zgVCNX8BX13UydJ0ZIXVUnob3b9LLSfwbm5POjvV6qTemO8vSddNItZmNV/MbZ3gwQO9k/h5f0koZPVyb0EgpI1/QVn3lXdSG2jThUYZpd0fFNrjt6N59rvVHd/RUm34P2mWGnIWeqG8V+E1HPCzQOfzc2KzsVntzSqwx83zLpSF0icGABz3ax7u5wS3PSDKDA9VgRsD+SpE/Jx8eDTvGoYYV83YmX7sDq80A2ADhl4s+YrUcqmv+6IZsBLCDJ0J/5sMRp4OuAbqKAnqVo0ESaIzvrVUUY+M93bxRX9auan39xRBJV8xVY7Bc6GdTW1JDRIawkGsLnYS+EXPlIBC0KgDL88B9QeQ8fBFkS3ZaQIm4RCC1N8Z7MQ7lp4mGqtrvbaxQd7SOB6vrUgc7yEZOOcgjINxnlYT6+qvIU+4on4C/+dgrfyMWRORFJjRsW2zOlYUKseSSd12aQUWhFRR9xebwKLJ2irQdCs697l1k5tQphEWts22Xshkgc0dDiLiGGM8l7aKybUU3LmW3gUF5R/A4HNBmGUVgkwZYlwOsVtwhVavVujvj9bczWbfAmF4vKrH9JYJIvkDqLHWLBd4zvdcBmEChCLL6fOg1Fd/VrZW6HHi5aFfi5yzK80OztVWdgVna079rHuN5los53TRRoB6q2uXMNLkyDH4oxzfTPg26923ntFILcefo0RSkf4RWgl62zEaZwzkai+UeOTjj/9YmdlYcDO6ECzk6XtC/+KGiJRlpqtByGfWUmuyZ6b+gfp1swZdlItUs6neqLbD0QGmxf53DEt03ZcgA5w3vUqGd2D1kiBcc1wweprb9mKRxDxxkE+A8XZLKU58vWR2AlJ0hd8jboeJJTfM19OypSfd5qw1Uyg0FLckbYWyxnbZvkvO7CnHoLj+26/K9LW97lMStMXHS3jOKSgas6FjlZvKhvrepxyhkYjoei5Xk3eF50sdOB8GxHDLQFr3SZULIv+Rjy5729R/1NQ0DIqK+NmM/Syt9wzqZV7ndao1Zj78GURFqbDtw2Pw6X3JQnPp/Xsjj7msTuw5o1zdvCSEVbuvRLQNT+gdtaMmOuPqHCXGctb3UuAz9MgcVE6mkO+1z5mPWVAi2KPTD5cHCiuSSLooVvSrxp1itUGESRGy9MJt70K3l9sq1KvWh6M+rPV1fqybiq58RPPlf9Fu/NSXEhOvtyUrBrOwV/yJw7SWmIJR4HI3evc5gCjlSx8wtlVj6Ac+ad9mqoCw==
Content-Type: multipart/alternative; boundary="_000_DU2PR02MB1016011E1C399D5EC90BD1FFE883E2DU2PR02MB10160eu_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 48d96bb9-abbb-414e-9a97-08dc52e0b64d
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Apr 2024 06:47:06.4238 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: CNdplZYe9vD2EmlP7zR05Pf04a8Jaqac2+r6svkZlVmvQ3RxD1a13FK9v9XF8Lj53vnlFa28Mpprll5VMTmdbMV9js0kS2ZW1kXAZfzC/uM=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2PR02MB8507
X-TM-AS-ERS: 10.106.160.156-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.0.1002-28292.005
X-TMASE-Result: 10--39.000700-10.000000
X-TMASE-MatchedRID: OoEa6u7Uk5/uYusHgJkgyumA9mU59vyjDO+DX+rUwfbfaldUczBqFy77 4nlxVOXqPvl4Qvnzd50Uh606rb6lUG/6CCblACLhPsmmct6fmyLPlmI4N1s8ird2BlHAIizFZrC hzCJ9VmyqoYavcamf/KnL54M5CzEQzfqlpbtmcWj4qCLIu0mtIEukIs3g1Hjeve7lipYRMOIqqt DuUtwyfDuIoG1s2/QqkU34HyglnlpswYo64ufkVaVjgXyvS9c/8ECtMBmVuLSsHQKvmWegTT+Ok 6f9gUlFkLnXdtbjjFBp0H4s0viYcOXYI0z4MDj0A4U/HawwP4p4m2Pup/NT5D9BBAgMnMgeg5or tHq/YwyvECmMzxONBi/aTczbsnfWwyZ3/yP11spNLPQl0QAltMKQwZEtTDYaRkG71CUUxH1FFrj TpX9jDIxucsDcm7ws23lEaQw/5rKVOwZbcOalS0i2QXVfwItREi1yhIAhxwmSWSLVUEh6rZEnW4 9GUt83iONMOkcrBiZwOv+MoMUU73RS3qnEC5At9v33UW8WNYA6FHRWx2FGsCjEINafKEeOKJwGD RM+ng8SyqLFkpowsNpGxB3OAtwH2OhBkd5P7oq/d317BwwdByIqpZjtBYB7J8xrsPNKOE3Vs/In f2JOLoraMTvTS9Adwi/qej7ZmtMJslazArifUrSUy1jsufgzOfqhGDhC7z3r76lSVRWjbVQ4v/y 8XPEr93msvGF1E0z0hqgkYn/Qi9ZfgYyzPJbKhIsxwoHavWVZm1p1VXPd7EonRFIZ1F+fUPB9C8 jdfmPOARc7rRfejG8Ii4OrQL/Flc0nk7YwHdzSW4PuR8yqFZsoi2XrUn/JJ51KgEwAGdm6rRx26 7m9tpWD5DDAqPadHRcIXG0b6Kg/3GZ+dHsx6tEe7ATC7LiF6T/LTDsmJmg=
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: cd4592dc-bf95-4693-9d1f-6d2e7e41b6d9-0-0-200-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/nJER2x8jiMett4g3hzAajMOn8MQ>
Subject: Re: [Add] Paul Wouters' Discuss on draft-ietf-add-resolver-info-12: (with DISCUSS)
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Apr 2024 06:47:47 -0000

Hi all,

Please see inline.

Cheers,
Med

De : tirumal reddy <kondtir@gmail.com>
Envoyé : lundi 1 avril 2024 14:30
À : Paul Wouters <paul.wouters@aiven.io>
Cc : The IESG <iesg@ietf.org>; draft-ietf-add-resolver-info@ietf.org; add-chairs@ietf.org; add@ietf.org; tojens@microsoft.com
Objet : Re: Paul Wouters' Discuss on draft-ietf-add-resolver-info-12: (with DISCUSS)


Hi Paul,

Thanks for the review. Please see inline

On Sun, 31 Mar 2024 at 07:21, Paul Wouters via Datatracker <noreply@ietf.org<mailto:noreply@ietf.org>> wrote:
Paul Wouters has entered the following ballot position for
draft-ietf-add-resolver-info-12: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-add-resolver-info/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------


In general, I am not sure what this document wants to achieve.

It states:

        DNS clients can use the resolver information to identify the
        capabilities of DNS resolvers.

It then defines qnamein, exterr and infourl. The latter should not be used
by the DNS client. So what should a DNS client do with the information
that QNAME Minimalization is used, or that the DNS resolver code base
supports EDE (but EDE might not be in use anyway). What behavioral
change is expected from "DNS Clients" that are targeted by this document?
If no change in behavior is expected, why should a DNS client support and
perform this query?

The specific policy on how the client will use the discovered resolver information is outside the scope of ADD WG charter. Hence, the behavior change expected from DNS clients is not explicitly defined. For instance, the client may give higher precedence to a resolver that offers QNAME minimization versus a resolver that does not support it. Another example, could be the client could notify the end-user that the resolver will perform filtering (e.g., EDE codes 4 and 16). This notification can help to inform the end-user and client about the resolver's error handling capability.

[Med] ACK. The WG charter has the following:

"Making any recommendations about specific policies for clients
or servers is out of scope."



Furthermore, none of the answers can be trusted without some form of
enterprise provisioning.

No, browsers can be pre-configured with trusted recursive resolvers offered by ISPs.


Why inform the resolver is using qname minimalization? What makes this
optional special, compared to other things like 0x20 support, the infra-rr
hardering support, DNSSEC support? Why is it not providing keywords for
DoH or DoT or DoQ support? Why not show what normally would be in the
CHAOS version.bind data like dns implementation name and version?

The WG has agreed on the three attributes and a registry is added with specification required as the registry procedure to add new
attributes in future specifications.
[Med] Added a new sentence to clarify the rationale for selecting this **initial** set of information:

NEW:
   That information is selected because it
   provides benefits to the security and privacy of DNS data.  Other
   information can be registered in the future per the guidance in
   Section 8.2.


If the DNS client would behave differently based on the setting of
qnamein, what would it be and how would it determine the security of
the returned value (eg why wouldn't the target DNS resolver just lie to
cause the DNS Client to do whatever behavior it does differently when
it sees qnamein?). If this is meant only for administrators doing DNS
diagnostics, why not ONLY return an infourl and have qnamein and exterr
contained in infourl, or even more keywords based on a DNS yang model
list of keywords?

What is the DNS Client expected to do with the exterr values returned?
What does "supported" mean, eg versus "configured".

It means the DNS server is configured to return the exterr values. we will replace "supported" with "configured" for clarity.
[Med] Please see: Paul's review by boucadair · Pull Request #29 · boucadair/add-resolver-information (github.com)<https://github.com/boucadair/add-resolver-information/pull/29/files>

What different
DNS Client behavior is expected based on this value?

The "infourl" seems a bit risky. While the documents tries to limit
the impact, I don't understand its approach.

The "infourl" is typically meant for IT staff for troubleshooting purposes.


Why insist on "https" ? It's a public API that anyone that can query
the nameserver can presumably retrieve anyway? That is, I assume such
a infourl would not require HTTP level authentication. I don't see why
it should be forced over https.

Yes, HTTP level authentication is not required. HTTPS was explicitly mentioned to avoid providing the information over insecure HTTP.


Why is the information presented a text/html and not plaintext ? Or
json? Or yang? This would avoid various risks of exposure to the enduser
which are not meant to consume this anyway according to the document.

        The URL SHOULD be treated only as diagnostic

Why is that not the case for qnamein and exterr?
Why is that not a MUST?

[Med] because this can be relaxed by the condition in the MAY right after.


        A DNS client MAY choose to display the URL to the end user

Why is this not a MUST NOT ?
[Med] Because a user can have a policy to trust a specific resolver.


        if and only if the encrypted resolver has sufficient reputation

This is not something an implementer can write code for reading the RFC.
It further more pushes centralization towards "reputable DNS resolvers".
How does the DNS client get updates about the reputable status of a DNS
resolver?

DNS clients, such as web browsers, typically update their trusted recursive resolvers (TRR). The process of updating the TRR can happen through software updates or other automated mechanisms.

-Tiru


I feel just like "captive portals", that this can/will be misused and be used
for advertisement or other non-DNS purposes. Forcing this to be text/plain
or json/yang would make this "less consumable" to endusers and thus make them
more safe against abuse.

In Section 7 it states:

        1. Establish an authenticated secure connection to the DNS resolver.

        [...]

        It is important to note that, of these two measures, only the
        first one can apply to queries for 'resolver.arpa'

How can anyone establish a secure authenticated connection to
"resolver.arpa"?

No, the above text is referring to DNR (and not DDR).

Cheers,
-Tiru


If they do, either the client has to authenticate it is the real
"resolver.arpa" but then its contents cannot apply (it's something on
the internet, not local) or it authenticates to "something else", in
which case how can that be secure, or if it is secure but populated with
information that validates "starbucks", how meaningful is "authentication"
in this context?

The section contains another set of "weasel wording" on determining
reputation of the resolver that is not really implementable in code.




____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.