Re: [dns-privacy] [Ext] Intermediate proposal (what I was saying at the mic)

Robert Evans <evansr@google.com> Fri, 30 July 2021 18:43 UTC

Return-Path: <evansr@google.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F3BB03A0A3E for <dns-privacy@ietfa.amsl.com>; Fri, 30 Jul 2021 11:43:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -18.097
X-Spam-Level:
X-Spam-Status: No, score=-18.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.499, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NIr9Wny8YY5U for <dns-privacy@ietfa.amsl.com>; Fri, 30 Jul 2021 11:43:08 -0700 (PDT)
Received: from mail-il1-x135.google.com (mail-il1-x135.google.com [IPv6:2607:f8b0:4864:20::135]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 919F13A0A39 for <dprive@ietf.org>; Fri, 30 Jul 2021 11:43:08 -0700 (PDT)
Received: by mail-il1-x135.google.com with SMTP id h18so10404610ilc.5 for <dprive@ietf.org>; Fri, 30 Jul 2021 11:43:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=5Xrnn1xBjSTeuNn5gIr1qI+zfICmpdS+d1t5OPIULCo=; b=RpcG/Z6YHuyES3qBa2Sw+73tsJj81p7nUkmndUMLEK6fCSEAIf9sFIe8kKkc7HkVF6 r3vOJL967VhTm8++64HMoxSKutPnEBxs/034Q1oKHwY7yUqMsP6qUPQK0+hvp6GO3as+ YsspsYPe7DlnLA0KfDOmxABKN/J7kTf0fsOIYisndqwizL86Vq4zelYYKziSYwsLuyZz ytA4pymMJEWAo9/6ogTaTZfxHUUKQC//FxtmljbxBWrXjUBEHKJ9ljoH8q3em7tXGnVX DkjOKc17VTppfV2xHqsve5mXUDbU3/7N3OgQac+JVThxwpkS0bVm6NvcfgR6nHF+3Omz 408w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=5Xrnn1xBjSTeuNn5gIr1qI+zfICmpdS+d1t5OPIULCo=; b=OlPZGL5Y4NBcgBWsNiufZyjrwSaLJTdzJm8Mt8+SnXYbHfE8IhsYsUDgpj/Wge7dk6 OtvWWPetjxs1WGCP4hrZ7Eb9PUZ5X2/3bmrLVtr9rccdTEBV4soCULdt4ynB8IxN/Ia6 9bE46BrjzJ4VfrmCjluykGMrDwNhlD1NAfHfnuktBYKp+tUx4Wr10i92Hb2hiqRwGE8b 5kE3LFZC2J8bQj+PvlOB+hJu2zpzV1kia8TNnReT6fPY7GpU020mX5l/9rdx6OehIJXg j0qvQPHhnuZ7qYQV/UQqopJDONYKeo5vVr654yqhkfeoo3VhT9UxHFi23W38/Yi1fLxs t5Fw==
X-Gm-Message-State: AOAM5330YiDD74ShZXznBVfzxfzSfjptwTxQ4nOzEUrhFwteGeoJrRPO /EqwGfzo38PAAnsUpAlOQNFvrNLpka00VS+AfAc1tO82+3VulQ==
X-Google-Smtp-Source: ABdhPJw5YWzI6l3S13W+2ZahGWRLk9+RY9r3LG5Nq6ImIwvzTMmMqVKDYkhU4+EYptT3cReGNwdcSLwpj+/WOkuTpg0=
X-Received: by 2002:a05:6e02:1e06:: with SMTP id g6mr2830188ila.41.1627670586770; Fri, 30 Jul 2021 11:43:06 -0700 (PDT)
MIME-Version: 1.0
References: <CABcZeBNRZsyjd-M_hKOwxdqY=Y7oZs5-d4waqPHb9gO-GJNV+Q@mail.gmail.com> <7514B406-2907-4059-AB59-6F3BAC05B839@icann.org>
In-Reply-To: <7514B406-2907-4059-AB59-6F3BAC05B839@icann.org>
From: Robert Evans <evansr@google.com>
Date: Fri, 30 Jul 2021 14:42:55 -0400
Message-ID: <CAPp9mx+5YagTBnZsvqtAGUvu+si29WQ15ENePNgD6N-SQ15PuA@mail.gmail.com>
To: Paul Hoffman <paul.hoffman@icann.org>
Cc: Eric Rescorla <ekr@rtfm.com>, "dprive@ietf.org" <dprive@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000232c1e05c85b97dd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/DF0hxbOH5nU3z9t967GRI9Ik6ZQ>
Subject: Re: [dns-privacy] [Ext] Intermediate proposal (what I was saying at the mic)
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Addition of privacy to the DNS protocol <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Jul 2021 18:43:14 -0000

On Thu, Jul 29, 2021 at 6:43 PM Paul Hoffman <paul.hoffman@icann.org> wrote:

> Having a differentiated signal for "I don't expect to be authenticated"
> would be good for draft-ietf-dprive-unauth-to-authoritative. I also agree
> with the reasoning of the recursive and auth operators who spoke at the mic.
>

Suppose ADoX specifies that SVCB with alpn=dot but without any
authentication params implies the same thing. Would that be good enough?