Re: [Add] [Ext] Draft Posting: CNAME Discovery of Local DoH Resolvers

John Levine <johnl@taugh.com> Sat, 27 June 2020 18:59 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 156AF3A08CB for <add@ietfa.amsl.com>; Sat, 27 Jun 2020 11:59:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.451
X-Spam-Level:
X-Spam-Status: No, score=-1.451 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1536-bit key) reason="fail (message has been altered)" header.d=iecc.com header.b=a4Ikdrz7; dkim=fail (1536-bit key) reason="fail (message has been altered)" header.d=taugh.com header.b=RdEURrAZ
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zcNyiCcsJeFR for <add@ietfa.amsl.com>; Sat, 27 Jun 2020 11:59:02 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 09B643A08C9 for <add@ietf.org>; Sat, 27 Jun 2020 11:59:01 -0700 (PDT)
Received: (qmail 61923 invoked by uid 100); 27 Jun 2020 18:58:59 -0000
Date: Sat, 27 Jun 2020 18:58:59 -0000
Message-ID: <rd84tj$1psp$1@gal.iecc.com>
From: John Levine <johnl@taugh.com>
To: add@ietf.org
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:subject:references:in-reply-to:cleverness; s=f1d8.5ef796f3.k2006; i=news@user.iecc.com; bh=xI3GkWwj+R5gw0bkLpT2jM3l7CeTifxGcfGQKl+VIxs=; b=a4Ikdrz7RCtXCdywnMwgdI4fwBiKuxpYyON8qkPMTAVnXGnkptedravkSfT3PzMdgdUKhz0zSGzKMagJI4sx3sEW/xS0rfZivdjUYBJ6jDDSt5+bL1eFioKNkXckexViMiterCdzGKLIh15l9MHFtDOfX6/te0iSKzPZBSAID1UAphhKcUrLetBWcKscgUjaV9JyG5hvy0WDazSsJQ8+hztOcPTa9vIgVMilhFh7C7NuBNgw/vWDnHcS/leQaFwG
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:subject:references:in-reply-to:cleverness; s=f1d8.5ef796f3.k2006; olt=news@user.iecc.com; bh=xI3GkWwj+R5gw0bkLpT2jM3l7CeTifxGcfGQKl+VIxs=; b=RdEURrAZTa4QjBHLAd0ZlsMddXd4V/3yi0CtCzVVymY1d/2U4mJXtZ1dZX2rXHvpZpk4ywzo/aUkuWRQnrT5Ide5rGYY0U4y7lMt/4gF87xgXFbXV/g6g3dK1Q+lgGZHLZ3nCLI/N2tpCeN8vWH20/1rQTogPY4Y7eCh9eARMl6HB0vvF02196ViNag7vrt2OpknDJFyLZKWYLKZo5gyvHgceD6iU3TUShFO1BWDGfQXV/OTNKsNt82yS7/WsO9H
Organization: Taughannock Networks
References: <CABcZeBPTkWeB40wpTowKvEJ-gXA3AL2e-BE+C_FC7Js7-D0DZQ@mail.gmail.com> <CABcZeBPMrn_H8EQfw3ksLnsMJd21=BTZ3h29g-rMnKO2SUJOFw@mail.gmail.com> <8FC68464-A7B8-48C9-BDDC-333207C16FD4@icann.org> <CABcZeBNKHHO=n68tj2DMGQkRaZQzbZE=DxQBjhH-wzJueRykZw@mail.gmail.com>
In-Reply-To: <CABcZeBPTkWeB40wpTowKvEJ-gXA3AL2e-BE+C_FC7Js7-D0DZQ@mail.gmail.com> <CABcZeBPMrn_H8EQfw3ksLnsMJd21=BTZ3h29g-rMnKO2SUJOFw@mail.gmail.com> <8FC68464-A7B8-48C9-BDDC-333207C16FD4@icann.org> <CABcZeBNKHHO=n68tj2DMGQkRaZQzbZE=DxQBjhH-wzJueRykZw@mail.gmail.com>
Cleverness: some
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: johnl@iecc.com (John Levine)
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/v4gceekx1L0dkuRY_JGzNa-otZg>
Subject: Re: [Add] [Ext] Draft Posting: CNAME Discovery of Local DoH Resolvers
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 27 Jun 2020 18:59:04 -0000

In article <CABcZeBNKHHO=n68tj2DMGQkRaZQzbZE=DxQBjhH-wzJueRykZw@mail.gmail.com>,
Eric Rescorla  <ekr@rtfm.com> wrote:
>> If Firefox has the means of sending a constructed CNAME query and process
>> the response, shouldn't it also (ahem) clearly have the means of sending a
>> constructed TBD1 query and process the response?'''
>>
>
>We do not send a raw query.

Beyond that I gather there is still concern about SOHO routers with
poorly implemented DNS forwarders that only handle some kinds of
queries.

R's,
John

PS: It sure would be nice to have more up to date info about how common
they are. Maybe I can use some of my 64 million RIPE Atlas credits.
-- 
Regards,
John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly