Re: [dns-privacy] [Ext] ALPN protocol ID for DoT

"John Levine" <johnl@taugh.com> Fri, 13 December 2019 04:18 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 49E10120803 for <dns-privacy@ietfa.amsl.com>; Thu, 12 Dec 2019 20:18:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level:
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1536-bit key) header.d=iecc.com header.b=IWFR5is9; dkim=pass (1536-bit key) header.d=taugh.com header.b=jrEbFLxe
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pogk6ui9urN4 for <dns-privacy@ietfa.amsl.com>; Thu, 12 Dec 2019 20:18:26 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 39BCB1200F6 for <dns-privacy@ietf.org>; Thu, 12 Dec 2019 20:18:25 -0800 (PST)
Received: (qmail 98090 invoked from network); 13 Dec 2019 04:18:25 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=17f28.5df31111.k1912; i=printer-iecc.com@submit.iecc.com; bh=LvQ2SlCtX3pIMbNg1V6kJWSYjrsMJBQKzbJtaiadERo=; b=IWFR5is9l4lvvl8n6JTaTSWsBHGFXMvMQt5MHI0/FZJX11I+cSMhvVS0oUuhn5QxIHIxnHLL+5FT07kTG7Nn5UBNmND09+W3IJKpirTROrPm6+RrqyXLN5g7dbGfqpfbJR8Hl1FM/nVdXzxbr2JfnWgLM9HVB2t67wlcDDr8uvw14pQl0DZvA+Wj2k6dKsIPgGgmWs8MhrVWbGABOOy24agWzT4YTn3qNBriekf/kOkKbJmQPtngjFPYLQgZvyNB
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=17f28.5df31111.k1912; olt=printer-iecc.com@submit.iecc.com; bh=LvQ2SlCtX3pIMbNg1V6kJWSYjrsMJBQKzbJtaiadERo=; b=jrEbFLxeo79VcCB+Pd5O7OfW2PKalclFmk9FvCQKcvqGQUL5Ol7KE5GLAjogA0+3Wb8zX7ZxmpfnhL6NfrNiXiiYBbRkuP5wZ5HNXYareuHvIfOuT0GSkrSjV6Z9ovYsMsR9K4dJk9Mj6Azk6jqftAOEli2jN5Q4RQZI0Eb63flNR0+XgdNH8PezFghIVgstoclbAkSwKmzH+vdBvXHGeK78b4aRGzZvyshcm6XC1urbLWj0F8wD8eFkpsN98fOY
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPSA (TLS1.2 ECDHE-RSA AES-256-GCM AEAD, printer@iecc.com) via TCP6; 13 Dec 2019 04:18:24 -0000
Received: by ary.qy (Postfix, from userid 501) id 3F164114907C; Thu, 12 Dec 2019 23:18:23 -0500 (EST)
Date: Thu, 12 Dec 2019 23:18:23 -0500
Message-Id: <20191213041824.3F164114907C@ary.qy>
From: John Levine <johnl@taugh.com>
To: dns-privacy@ietf.org
Cc: paul.hoffman@icann.org
In-Reply-To: <7F87E623-3D21-4061-816B-1B18FAED36FB@icann.org>
Organization: Taughannock Networks
X-Headerized: yes
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/90722D5TncIJwlPPPpJTqv9pv9M>
Subject: Re: [dns-privacy] [Ext] ALPN protocol ID for DoT
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2019 04:18:27 -0000

In article <7F87E623-3D21-4061-816B-1B18FAED36FB@icann.org> you write:
>- It will cause confusion because there will be two ways to do DoT, so a client might have to test each way
>in order to know if the resolver supports DoT.

I have no objection to reserving an ALPN ID for DoT for use by private
agreement, but I'd be pretty unhappy if it became a de-facto
alternative to port 853.

We really need to figure out how to do DoWhatever discovery,
preferably better than probe ports on the same IP as the port 53
server.

R's,
John