Re: [dns-privacy] Call For Adoption: draft-wing-dprive-dnsodtls

🔓Dan Wing <dwing@cisco.com> Fri, 22 May 2015 16:13 UTC

Return-Path: <dwing@cisco.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E120F1A6EE9 for <dns-privacy@ietfa.amsl.com>; Fri, 22 May 2015 09:13:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.21
X-Spam-Level:
X-Spam-Status: No, score=-14.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CJrznNiufT7X for <dns-privacy@ietfa.amsl.com>; Fri, 22 May 2015 09:13:26 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 004611A044F for <dns-privacy@ietf.org>; Fri, 22 May 2015 09:13:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5528; q=dns/txt; s=iport; t=1432311206; x=1433520806; h=mime-version:subject:from:in-reply-to:date:cc:message-id: references:to; bh=8TyNFv/8CBVpBCO5yjWKI61c0GtlkLF8sjDmeCInnEA=; b=ileYO+6Q2ty8VVdA0nqm9shH4yyzuGCjPvVGQtZw8ZfcRB7sBQNqKEj/ iJpWt8gW9SHrnq1a1+8WWb4wIyW67SBfP44PtjX6G4O5FYFec+m5duiG+ fCFZwKf6YEZ3ei2FNBlcEGpbvpepEkjFipoKzAGEC0R4xYZd7X/aZyPJB Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D7AwAsVV9V/4YNJK1cDoMCVF7DHAmBWYV3AoE5OBQBAQEBAQEBgQqEIwEBBA4PSBQQCw4KJwchJREGExuHfAMSDc5gDYRyAQEBAQEBAQEBAQEBAQEBAQEBAQEBEwSLOoJNgW1HBAeDF4EWBYw9inqEf4FYgSmDb4JeiC+DKINZI4M6Xh4xgkcBAQE
X-IronPort-AV: E=Sophos;i="5.13,476,1427760000"; d="scan'208,217";a="152572159"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by alln-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 22 May 2015 16:13:19 +0000
Received: from [10.24.104.33] ([10.24.104.33]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id t4MGDHuq011389 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 22 May 2015 16:13:18 GMT
Content-Type: multipart/alternative; boundary="Apple-Mail=_9ED7280B-EBAB-4597-A2B4-1A2A7A4E7311"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2098\))
From: 🔓Dan Wing <dwing@cisco.com>
In-Reply-To: <CA+nkc8DK8320KAq8xWRbm4B8BLqPSErzyHxYZ6EPk1Uz4Mc6Og@mail.gmail.com>
Date: Fri, 22 May 2015 09:13:15 -0700
Message-Id: <8F5C00A9-C218-4470-89C5-3A84DCBF1FA3@cisco.com>
References: <555C942F.2090007@gmail.com> <CA+nkc8DK8320KAq8xWRbm4B8BLqPSErzyHxYZ6EPk1Uz4Mc6Og@mail.gmail.com>
To: Bob Harold <rharolde@umich.edu>
X-Mailer: Apple Mail (2.2098)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dns-privacy/Hd94sj768-CW7wB2DxhDbuOl-y8>
Cc: Tim Wicinski <tjw.ietf@gmail.com>, "dns-privacy@ietf.org" <dns-privacy@ietf.org>
Subject: Re: [dns-privacy] Call For Adoption: draft-wing-dprive-dnsodtls
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 May 2015 16:13:28 -0000

On 20-May-2015 07:40 am, Bob Harold <rharolde@umich.edu> wrote: 
> 
> 
> On Wed, May 20, 2015 at 10:03 AM, Tim Wicinski <tjw.ietf@gmail.com <mailto:tjw.ietf@gmail.com>> wrote:
> During the previous Call for Adoption a number of participants expressed interest in adopting this work.  WG members felt it needed some improvements, but thought it had potential. The authors addressed the issues and feel it meets what the working group was seeking, and have requested that we initiate a call for adoption.
> 
> If the working group adopts this document, it only means it wishes to study this solution more carefully.  The working group may still determine to not move forward with it.
> 
> The draft is available here: https://datatracker.ietf.org/doc/draft-wing-dprive-dnsodtls/ <https://datatracker.ietf.org/doc/draft-wing-dprive-dnsodtls/>
> Please review this draft to see if you think it is suitable for adoption by , and comments to the list, clearly stating your view.
> 
> Please also indicate if you are willing to contribute text, review, etc.
> 
>  
> I support adoption, and I will review.
> 
> I am unclear on Page 5
> 6.  Demultiplexing, Polling, Port Usage, and Discovery
> 
> "After performing the above steps, the host should determine if the
>    DNS server supports DNSoD by sending a DTLS ClientHello message."
> 
> It is unclear to me what the "above steps" actually refers to.  Can you clarify?

Section 6 suggests how a DNSoDTLS client can determine that its connected network will work with DNSoDTLS.  The exact method and algorithm will require more discussion in the WG, especially to balance the needs for security and interoperability against implementation flexibility.

-d