Re: [dane] any statistics of deployment available?

Hosnieh Rafiee <hosnieh.rafiee@huawei.com> Fri, 08 January 2016 20:17 UTC

Return-Path: <hosnieh.rafiee@huawei.com>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8332F1B2B78 for <dane@ietfa.amsl.com>; Fri, 8 Jan 2016 12:17:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xg1L4IaHsVUD for <dane@ietfa.amsl.com>; Fri, 8 Jan 2016 12:17:51 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA1611B2B77 for <dane@ietf.org>; Fri, 8 Jan 2016 12:17:50 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml404-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id CGN80517; Fri, 08 Jan 2016 20:17:48 +0000 (GMT)
Received: from LHREML504-MBS.china.huawei.com ([10.125.30.107]) by lhreml404-hub.china.huawei.com ([::1]) with mapi id 14.03.0235.001; Fri, 8 Jan 2016 20:17:46 +0000
From: Hosnieh Rafiee <hosnieh.rafiee@huawei.com>
To: "dane@ietf.org" <dane@ietf.org>
Thread-Topic: [dane] any statistics of deployment available?
Thread-Index: AdFIeslBxynRdYetRzmHZNYubTMahgACOpAAAAyqfgAAZr4wMA==
Date: Fri, 08 Jan 2016 20:17:45 +0000
Message-ID: <814D0BFB77D95844A01CA29B44CBF8A715B0BB55@lhreml504-mbs>
References: <814D0BFB77D95844A01CA29B44CBF8A715B0AEC4@lhreml504-mbs> <20160106131105.GC14398@sys4.de> <20160106191346.GF18704@mournblade.imrryr.org>
In-Reply-To: <20160106191346.GF18704@mournblade.imrryr.org>
Accept-Language: en-US, zh-CN
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.200.217.64]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Reflected
X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020205.5690196C.01FF, ss=1, re=0.000, recu=0.000, reip=0.000, cl=1, cld=1, fgs=0, ip=0.0.0.0, so=2013-06-18 04:22:30, dmn=2013-03-21 17:37:32
X-Mirapoint-Loop-Id: c223e647c4a85613a34b1bdea05bba3a
Archived-At: <http://mailarchive.ietf.org/arch/msg/dane/8FwpaAYCwCLH8CEdzQOn01XyzBU>
Subject: Re: [dane] any statistics of deployment available?
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Jan 2016 20:17:55 -0000


-----Original Message-----
From: dane [mailto:dane-bounces@ietf.org] On Behalf Of Viktor Dukhovni
Sent: 06 January, 2016 8:14 PM
To: dane@ietf.org
Subject: Re: [dane] any statistics of deployment available?

On Wed, Jan 06, 2016 at 02:11:06PM +0100, Patrick Ben Koetter wrote:

> > Is there any statistics or a site that I can find regarding the deployment of DANE over the internet?
> 
> We did a complete IPv4 scan two weeks ago. AFAIK Viktor is about to 
> analyse the data. But I don't know when he will be able to present results.

I don't have the scan data yet, but I will look.  At present my survey has found just over 10400 domains with working DANE TLSA records for SMTP, a majority of these are from a three hosting
providers:

    5146 udmedia.de
    1199 mx.transip.email
     933 mx.nederhost.net

Based on email discussion with the top two, it seems I've captured around 10% of their actual deployed numbers, so the number of SMTP domains is around 100k, with over 95% of these hosted by the above providers.

The number of SMTP DANE domains that are "large enough" by whatever criteria Gmail uses to list a domain in its email transparency report stands at 30 (was 24 in early October).

We're still early in the deployment process, but DANE support in OpenSSL will be available soon, which I think will help.  Hard to adopt a standard with no "running code".

Two of the six DANE patches scheduled for review have been reviewed and are now part of OpenSSL 1.1.0-dev, the rest will join them soon I hope.

[Hosnieh] Thanks a lot Viktor. Is there any estimation on when this will be available?

Thanks,
Best,
Hosnieh