[dns-privacy] Ben Campbell's No Objection on draft-ietf-dprive-dnsodtls-13: (with COMMENT)

"Ben Campbell" <ben@nostrum.com> Wed, 14 December 2016 21:26 UTC

Return-Path: <ben@nostrum.com>
X-Original-To: dns-privacy@ietf.org
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id A444212944B; Wed, 14 Dec 2016 13:26:23 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Ben Campbell <ben@nostrum.com>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.39.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148175078366.16848.15860504963811965232.idtracker@ietfa.amsl.com>
Date: Wed, 14 Dec 2016 13:26:23 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/AWWMQhwAoQvyE5_KjVkgsRrTgSg>
Cc: tjw.ietf@gmail.com, dns-privacy@ietf.org, draft-ietf-dprive-dnsodtls@ietf.org, dprive-chairs@ietf.org
Subject: [dns-privacy] Ben Campbell's No Objection on draft-ietf-dprive-dnsodtls-13: (with COMMENT)
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.17
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Dec 2016 21:26:23 -0000

Ben Campbell has entered the following ballot position for
draft-ietf-dprive-dnsodtls-13: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dprive-dnsodtls/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Update: Looks like the address for Dan Wing needs to be updated.

-1: Is TCP head of line blocking considered a problem between the client
and cacheing resolver? Otherwise, between that and the potential to use
TCP fast open, the motivation for not just using TLS seems weak (which
may not be a problem for an experimental RFC.)

- 3.1: "DNS clients and servers MUST NOT use port 853 to transport
cleartext
   DNS messages. "
Am I correct to assume that this requirement is really about clients and
servers that do not implement this spec? While I see the point, how would
such a client or server even know about the restriction?