[dns-privacy] draft-hoffman-dns-tls-stub-02, now with https:

Paul Hoffman <paul.hoffman@vpnc.org> Sun, 31 August 2014 00:50 UTC

Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E627C1A6F0F for <dns-privacy@ietfa.amsl.com>; Sat, 30 Aug 2014 17:50:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.647
X-Spam-Level:
X-Spam-Status: No, score=-3.647 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_MISMATCH_COM=0.553, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3tRpPQAtvxG6 for <dns-privacy@ietfa.amsl.com>; Sat, 30 Aug 2014 17:50:44 -0700 (PDT)
Received: from proper.com (Hoffman.Proper.COM [207.182.41.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A2B951A6F14 for <dns-privacy@ietf.org>; Sat, 30 Aug 2014 17:50:44 -0700 (PDT)
Received: from [10.20.30.90] (50-0-66-181.dsl.dynamic.sonic.net [50.0.66.181]) (authenticated bits=0) by proper.com (8.14.9/8.14.7) with ESMTP id s7V0ogYX001014 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO) for <dns-privacy@ietf.org>; Sat, 30 Aug 2014 17:50:43 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
X-Authentication-Warning: proper.com: Host 50-0-66-181.dsl.dynamic.sonic.net [50.0.66.181] claimed to be [10.20.30.90]
From: Paul Hoffman <paul.hoffman@vpnc.org>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Sat, 30 Aug 2014 17:50:40 -0700
References: <20140831004442.24801.83501.idtracker@ietfa.amsl.com>
To: dns-privacy@ietf.org
Message-Id: <A1CEA13B-35AA-4B3B-BC43-241C4016A613@vpnc.org>
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/dns-privacy/UT0mEgD8UMeBSZ76-4HRZS3unIQ
Subject: [dns-privacy] draft-hoffman-dns-tls-stub-02, now with https:
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 31 Aug 2014 00:50:46 -0000

Greetings again. It was pointed out to me this week that the earlier draft, while useful in stubs that are in part of an OS, was not useful to stubs that are part of a Javascript program that is in a browser. There is a desire for such programs to be able to get DNS responses. This goes back to the "use TLS, but do it as a URL idea" discussed in the meeting in London. I re-read RFC 3205 and realized that this proposal doesn't go against its recommendations.

So, this draft has both the original proposal (run over TLS, negotiated with ALPN) and the new one. Both have disadvantages. I'm interested to hear what people think, hopefully after they have read the draft.

--Paul Hoffman

Begin forwarded message:

> From: internet-drafts@ietf.org
> Subject: New Version Notification for draft-hoffman-dns-tls-stub-02.txt
> Date: August 30, 2014 at 5:44:42 PM PDT
> To: "Paul E. Hoffman" <paul.hoffman@vpnc.org>, Paul Hoffman <paul.hoffman@vpnc.org>
> 
> 
> A new version of I-D, draft-hoffman-dns-tls-stub-02.txt
> has been successfully submitted by Paul Hoffman and posted to the
> IETF repository.
> 
> Name:		draft-hoffman-dns-tls-stub
> Revision:	02
> Title:		Using TLS for Privacy Between DNS Stub and Recursive Resolvers
> Document date:	2014-08-30
> Group:		Individual Submission
> Pages:		10
> URL:            http://www.ietf.org/internet-drafts/draft-hoffman-dns-tls-stub-02.txt
> Status:         https://datatracker.ietf.org/doc/draft-hoffman-dns-tls-stub/
> Htmlized:       http://tools.ietf.org/html/draft-hoffman-dns-tls-stub-02
> Diff:           http://www.ietf.org/rfcdiff?url2=draft-hoffman-dns-tls-stub-02