Re: [dns-privacy] [Ext] next steps for draft-opportunistic-adotq

Ben Schwartz <bemasc@google.com> Tue, 23 March 2021 21:20 UTC

Return-Path: <bemasc@google.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D9EF13A16D3 for <dns-privacy@ietfa.amsl.com>; Tue, 23 Mar 2021 14:20:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.599
X-Spam-Level:
X-Spam-Status: No, score=-17.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nOyD1tzeiw99 for <dns-privacy@ietfa.amsl.com>; Tue, 23 Mar 2021 14:20:46 -0700 (PDT)
Received: from mail-wm1-x32f.google.com (mail-wm1-x32f.google.com [IPv6:2a00:1450:4864:20::32f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A8BB33A16E8 for <dns-privacy@ietf.org>; Tue, 23 Mar 2021 14:20:35 -0700 (PDT)
Received: by mail-wm1-x32f.google.com with SMTP id n11-20020a05600c4f8bb029010e5cf86347so1798540wmq.1 for <dns-privacy@ietf.org>; Tue, 23 Mar 2021 14:20:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=slfjHbLbVs6HFFEe8SEJI24Skd+9jj5aUAPrOQmvxUk=; b=NJ4fAsbaViPkY+Y5hQ3Uovz+l/t/63KqAugWusnY8BXwFxNiaKMOym+nwkEIxNT3Oj SODDs/2+WiCTl5yIwgAT5N8xrMFSxw1+yjnZoHfYWBzM+/294heb1kMrDS2sbog5dhO2 5b9i0TLi0o3mvw/MSSh3beW5oSaK58wNt0rJWqxT7/SuRnI20Cu/lcttwGOMGgc4tPsE 8uKRCNhWHzWZ4PRFbtW2+GmyuQrbH2q+0VHPUd9vT3zccYyU+FMGcFLX+lV3YWjhy0Kp JM5wPK9WPiYMNfqjftJP8lshlk6I8nqiSup2xwBcDK1cWMu18/78TTronw89OZA5R7BF fSmQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=slfjHbLbVs6HFFEe8SEJI24Skd+9jj5aUAPrOQmvxUk=; b=HrYw1e/10TOOkBD7lDM5y8KGyE+MvrmnpCNJkiZvI0Q7dmgAYEcZbb5kxi2VsRwr2/ GX7gE+MibwBYbEkHDCtzONLvL/NAINBMavw67JF3vR0WgBs6d1Y61FoUUc4xlYkG7aad F1O9HMhVszg1qQqOOi8xcD6QBMwuHBk3AI90aN8IBCyFAc1eRY+AMkGvNdBt0G6fCWM5 Ghav92R+gpHdg6I8hrjd0OhUVykRh6+c0ackn+rJlgTvsd+4TQojttHeX38jY1f3BP5z sAotDw0iUBQfDoj1r5eUAwOe0sCjmdPPF0DjuazPw+bcfrVln8C0AL1lbY865Q1b8EPR FzLg==
X-Gm-Message-State: AOAM532JmJaqhSlboHpqA+xRgt3CMFcT1hdWqN4Kg5HxeZLZt2kLEMTc kWj0xwJZCR5hAPPgg2CuJVaojRUKfsHnXqcE5lIZjxpj/6k=
X-Google-Smtp-Source: ABdhPJzNl5hPuTNlTqIcjEfI0cf/9L5TEfGMjaF8E1RX6kpreY3fvgYmddjwTanKv5WgcFipzBnxm9qP2rd+DGAFX8w=
X-Received: by 2002:a1c:7209:: with SMTP id n9mr13302wmc.132.1616534432614; Tue, 23 Mar 2021 14:20:32 -0700 (PDT)
MIME-Version: 1.0
References: <2ba5ac12c24eaee4c51de2cd2c1693e9bd1fd8b2.camel@powerdns.com> <4bc96140-454e-0746-83b3-bb1331cf7cce@cs.tcd.ie> <ADB00FD5-A6EA-4D05-84E8-A44A2E40BE7C@icann.org> <8363070a-8fc5-2d20-a9aa-45673d1515ac@innovationslab.net> <5861CBBC-4C76-4455-90FF-B127171CF054@rfc1035.com> <1bed6998-49fe-3620-e3a2-b51942c795cc@nohats.ca> <C09A688F-A8BD-4AD0-B02A-7A476D26AFE8@rfc1035.com>
In-Reply-To: <C09A688F-A8BD-4AD0-B02A-7A476D26AFE8@rfc1035.com>
From: Ben Schwartz <bemasc@google.com>
Date: Tue, 23 Mar 2021 17:20:21 -0400
Message-ID: <CAHbrMsCRdF6+RKq857tZFO_eTPtiCcQ3LMqhG6LG1=GEkmbk7Q@mail.gmail.com>
To: Jim Reid <jim@rfc1035.com>
Cc: Paul Wouters <paul@nohats.ca>, DNS Privacy Working Group <dns-privacy@ietf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="000000000000a657c105be3ac006"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/S68ITZJyVhA_62NgKQCM52Go-c8>
Subject: Re: [dns-privacy] [Ext] next steps for draft-opportunistic-adotq
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Mar 2021 21:20:51 -0000

On Tue, Mar 23, 2021 at 12:23 PM Jim Reid <jim@rfc1035.com> wrote:

> It doesn’t seem right to allow a TLD operator to tell someone what DoH
> server(s) to use/not use to resolve $tld's names.


I think there's a miscommunication here.  The proposals here are about
how a TLD operator can tell a **recursive resolver** what encrypted DNS
server to use, exactly like an NS record.  This is not suggesting any
change to stub resolver behavior.