Re: [dns-privacy] ODoH RFC SetupBaseS clarification

Ravi sankar MANTHA <r.mantha@f5.com> Wed, 10 August 2022 16:19 UTC

Return-Path: <prvs=2148de39d=r.mantha@f5.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14BDAC13CCD4 for <dns-privacy@ietfa.amsl.com>; Wed, 10 Aug 2022 09:19:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.685
X-Spam-Level:
X-Spam-Status: No, score=-2.685 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.582, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=f5.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5F5B-wpIVnOg for <dns-privacy@ietfa.amsl.com>; Wed, 10 Aug 2022 09:19:13 -0700 (PDT)
Received: from mail15.f5.com (mail15.f5.com [104.219.106.14]) (using TLSv1.2 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9BF30C13CCD8 for <dns-privacy@ietf.org>; Wed, 10 Aug 2022 09:19:13 -0700 (PDT)
Authentication-Results: eopmail15.f5.com; dkim=pass (signature verified) header.i=@f5.com
IronPort-SDR: px/oiH7RuVAmGmkxKnp54hB0SRq19k/q/HajfTKNa5Xj0nCy3wAbl5SYNxK3/da/AKXwviEUvC ufHaTl5U7WkP1J0CYVJHriSfMmn+LWzg2PqutCE6u5xwOvpzAmgnHQ8bgkecSk0xsEnMWnHhx/ ZTv57vjTcwsU8CueZU34GgMKbxPe5ZWOP8DgqLhozs83Eai05NogI1y0MhaB61+kqlPVrfZv5c Tp04fzUrl3thDtZMLU3T/7rPOnv3GJ7y1dplMrXNWE50pKTHCcd5/3t6ATCyXdXQ9X8t4gutHS l1Y=
IronPort-Data: A9a23:bEno5K/i4U4dm1XmgnAlDrUDi3+TJUtcMsCJ2f8bNWPcYEJGY0x3x 2oYWm6GOfnbY2PxLYx/PIXjoBhXupOEzYUyQQs5qC5gHilAwSbn6XZ1DW+rZn/PcZeTJK5Dx 59DAjXmBJ5oFie0SjCFa+C99iQUOZllytMQMcacUsxLbVYMpBwJ1FQywIbVvqYy2YLjW1PU4 YuoyyHiEATNNwBcYzt8B52r+EsHUMTa4Fv0j3RmDRx5lAa2e0o9UPrzEZqMw07QGeG4KMbhH rqek+vplo/u10xF5tuNyt4Xe6CRK1LYFVDmZnF+A8BOjvXez8CbP3tSCRYSVatXo23hc9FZ7 vxo7MT1ZSJ3e6rGlaIaTgVSFDx4Mete4rjbLHOjsMuViUrbb3/rxPYoB0YzVWEa0r8vXScSq rpFeHZUNk/ra+GemdpXTsF2wMEqKtXrNasR5zdryjSx4fMOG8iYGvuWtYEJtNs3rpsXRq2GP pBxhSBURB/JfDVPN14PCZQxlua0nT/5fiEwgEjToKMx/2jamVAp3uWrO93QUtCPTN9e2EeVu myA+H72ajkWMsfa0SCE7Hunl8fOkD/1HoUIG9WFGlRClAXGnSpOHERDDR3jtaPs0gjlB4kAP xdBomxzufdn3VKPZdzbdAGejH6gnxc6Ydp0KfYc0h+p9rLy3xy/OGkhWmcZPYRi7NteqScC0 1aIm5blAGJpubjMEXaFrO7M8nW1JDQfKnIEaWkcVwwZ7tL/oYY1yBXSUtJkF63zhdrwcQwcC gui9UAWr7tOy8UM0s2GEZrv32rESkThJuLt2jjqYw==
IronPort-HdrOrdr: A9a23:WhpKcqMZoM7lfMBcTi2jsMiBIKoaSvp037By7TEIdfRUGvb5qy ncpoVh6faUskduZJhOo6HlBEDtex3hHNtOkPAs1NSZLXjbUQmTXeZfBOLZqlWKdkGQygce79 YHT0EUMqySMbEOt7ee3ODOKadD/DDoysGVrNab4lpAbUVSUIdLwz1CJiveKWFNeCx6bKBJZK a0145rihaBPUkzVICGPFEqc4H4zeEj36iWGyLuTyRXlTVngV6TmcLH+jajr2gjbw8=
X-IronPort-AV: E=McAfee;i="6400,9594,10435"; a="203164869"
X-IronPort-AV: E=Sophos;i="5.93,227,1654585200"; d="scan'";a="203164869"
X-Amp-Result: SKIPPED(no attachment in message)
X-Amp-File-Uploaded: False
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=JbYeXzfLMVnxyvTCr+y5vNBodaEE6vI1h5S8i5uaR7I+qZYgPRk2EXujGQo9E1s4mR0M7j7d89HE/GKicS17LVIj/XaQ29mp0rS2UgpP/eMeN8DN9F6k2ZYaiuHu0X5v3N1aVR+YKBPgbSQ0W+yWgczP8UNjDRGCQ0yhbpYfeNUsa8VTS070HtRb+K2hnumOUQWb9+8UuxKRZ/8Q/UpJSU7YEMmmZxwQszFWWX9hMGb5gLmHogOKKOfu0m2nQKbXA7JujibqoNggLNYBpBZ6mQwwAFttdKVa0ACIt0uAv9OegOOeZLIZeExy4aTBe15IotbNn7/3aYFGyxcLoTc7dw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=v0U1qtgDZxHFG1HFy+hocJ0hH7I74akR5RswzNoz8H0=; b=aUfvjTMCS/4oPMVK2J9RC5WRrHXbkfKVXzXJnk5rIGvLTtdvjt86JtG6tbIS/1R/+lqGxe3TdCuPlmwufW8bQI2HO/HXYkJ5Qc0tVnLaHmE12XeiZ9VV6hjeBAr8tQdGi2yWAWAClvXoEXdlf+86EcvM0OlLPvBnh3TKoC+a+1uXbYRxd++wWcDh7gV36PYIkilQ5vfdG1nVjxuRmFs/CJLzqZ8TzWy/0AuoQWDw9JwrOCySGCeN9qr8Mt2pwXkOdTD0zfSCVblqwvuQSrI+Ur5UxQo8MAdXsII6hB7H+jrAbmcQW/J4lgZnSX8gtBxJp/D8D+8JzfVaLud44BELmQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=f5.com; dmarc=pass action=none header.from=f5.com; dkim=pass header.d=f5.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=f5.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=v0U1qtgDZxHFG1HFy+hocJ0hH7I74akR5RswzNoz8H0=; b=cTFl/i/aihsT+cU3SQ+nmiWo3uMkAzykv/9tvx9vjt5e1rawTgEGsg16S0ywGtgw+vDfiATYCsqpq3vG9GXWBU5Pz7Tw0aueSHODxW3eaXj5rVJFaqOBgegXFkT3WY4s2XXcPHmf0XCS6paRtYnbNZ8iGeRiPUiGWfGjW1AV77c=
Received: from BL0PR01MB4387.prod.exchangelabs.com (2603:10b6:208:8b::16) by SJ0PR01MB7267.prod.exchangelabs.com (2603:10b6:a03:3f1::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5504.16; Wed, 10 Aug 2022 16:18:52 +0000
Received: from BL0PR01MB4387.prod.exchangelabs.com ([fe80::3180:e5a2:772f:fc1a]) by BL0PR01MB4387.prod.exchangelabs.com ([fe80::3180:e5a2:772f:fc1a%2]) with mapi id 15.20.5525.010; Wed, 10 Aug 2022 16:18:51 +0000
From: Ravi sankar MANTHA <r.mantha@f5.com>
To: Christopher Wood <caw@heapingbits.net>, Ravi sankar MANTHA <r.mantha=40f5.com@dmarc.ietf.org>
CC: "dns-privacy@ietf.org" <dns-privacy@ietf.org>
Thread-Topic: [dns-privacy] ODoH RFC SetupBaseS clarification
Thread-Index: AQHYrJKf3wHdYhbZzkq4IsF2+xArWq2n2KaggABTUwCAACOh/g==
Date: Wed, 10 Aug 2022 16:18:51 +0000
Message-ID: <BL0PR01MB43872AFB1A8DAF0EF09D137CA5659@BL0PR01MB4387.prod.exchangelabs.com>
References: <BL0PR01MB438718D20FCC518DFEDA5BF1A5659@BL0PR01MB4387.prod.exchangelabs.com> <BL0PR01MB4387AFD8D7C2895F2392433EA5659@BL0PR01MB4387.prod.exchangelabs.com> <7894036A-5F08-4D28-961D-A3C98C8A080C@heapingbits.net>
In-Reply-To: <7894036A-5F08-4D28-961D-A3C98C8A080C@heapingbits.net>
Accept-Language: en-GB, en-US
Content-Language: en-IN
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d7009cd2-7b91-40f1-569a-08da7aec03ae
x-ms-traffictypediagnostic: SJ0PR01MB7267:EE_
x-outbound-auth: 1
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: EQoQrns9cS2tEWb9NLFPxIRHf9btcQcp5g6pBMJajYYTc6KoS+tm5duLe5oEM7T31k48nmVCSzt/yFN0TnMyzVR7jr5uNKtx1IvaWYXsvvIvy8dp+FukfhbxUurHIMAfIL0wFrSGbotU9z/bHP2zswHsqbYI5OongCr5ttFf8BTKLKVH5c2MQG72E4qM4Zj2e5l+7jh4Fe2MLq/TAMwlv1wGU0NqLoRIW4cnwfhhalnW25LOkrvw72dOBDXKrURkjaEz5JmtqFoP8Jbzh/3r/kD3zHRFM+fivxUaNSQdUDVufsryJX1I5mZcPmfuAN3nHiZqEnJQSUd0wUHEq8KM0fzPIjpQ9btoUSxRGUutaGy4QnWc1lRkNxaok2OFcg4fzE33bcetdigKo4Inoq/sVWJAnuud18V6B0Z9xBPr84LA8EMhOF32cppaENwEH2UWOt572+W43TTn2Tv0Yu3Gd2BoVUrwMOAFHnVeF4DmAS/dMVvkvi8KBaZI3F+0Lh8lSAcbFe05eUfiWnKnR1pkNrcst5VKre339g5XPbu8RbUCKUUnrDah56mg19YjGMaJ2/eCGMVzMGyFPq7PXQgb7ZFl8GlvT9p0muTDLuEKHFXGTSprr0iNYnhsXu1qMHy/NLs0qWKer9yUuSI9wBqejSeJp06ukTOGQM7zDA/VALY6jRFDAhadyXNkQp6/GmTQukLk+oaDyjU1McgM/L8j79T7pKRpTeiNRytGyX5QXGxxfC2ZmujkEieZ5//sy3gwaLvPxpFKr1g8FaOixEWCVgnttEJg4s/yYq6K0qMkOKJzZSKT1d8GcINJb/FgNgll43WEytCVIKuiSFiPoUfh/w==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL0PR01MB4387.prod.exchangelabs.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(39860400002)(376002)(366004)(396003)(346002)(136003)(966005)(83380400001)(52536014)(8676002)(86362001)(66476007)(8936002)(4326008)(66446008)(66556008)(66946007)(64756008)(71200400001)(122000001)(316002)(186003)(55016003)(91956017)(76116006)(110136005)(41300700001)(33656002)(9686003)(26005)(55236004)(53546011)(38070700005)(5660300002)(478600001)(166002)(7696005)(45080400002)(38100700002)(6506007)(2906002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: kDIibN8chNad1Pb96qLIWob0vYn4O8HZ6cPq4oq4UDqrhDtttBT5HlcvFrMCXogFjGX9esWkZ1fppedQATL2KNlBvNp07OKWlLGCG+NTzvf9/qqp1sKNg98wLcDh7MaarTlJ+g3uakqZdb6Y8uW3Fb7x0xk42z7WBfoIyxmfaPM5TifsKBeK3GG7W2VsWnjP7AwlN2IM24Sk2a1v8d8U2sthpHs71gedllTA0KGCQAdWJwUo/C8iudF73NOgTzRtfUvO5pvWEkdVyJaUuZ3Bfh4zTv76n2LjxMROTCZvQLiD6kVLgNSJ4AK+M1m1AuQKjXEWQ6z3xWbJIzznCJnnXck+0M6ts5fugnbh0aofx0bbwjwexH+AFOlT2SirzpgdmiPW08nxKTEUDEfOHZwYnfqQma8G6NsVmFbBg3Aq2i4bBupesAuMmx/vfGa36HGF3HH8pGjvjv6LTEzI58v4XcYJTd6xwdRsxUuUPmxDTwfLnjg9NqA1bfIZOV0YQJIzZI1DbAYrlHLvuNoGff5IuieG+ntYQSI9hHsvk436Y0wQ3EQgFO2gP8EBEaCkBy70zXUcEs6tsd7hdCQGssy+hPhwJmL0l3RDrn9ZCVAh74qMjol7z9citJ8r6RaMVrsuX75rcKPWN3fBXz7beSESmlWAzV3HcCDSM2QaqwkUo+yYiSShtCOIwL10fk2NTmCBM4zDMeJHnSbYoyuMRQakh4+75+GWR+if0GRk5+NqD/IkxJi07r9gb4mTwQ7m+go00lhuIVaG/g3GOMNdNj9Cil+cTo3OxTZwv9NmLH4GGAb841d3wdmTtnZBM3CDC12edYy2/thuhxomy7KPmcUYMFJ2zWbYOSpZJV72NDBB1Z9V9YqRbiUYR9vxQ9BEFiYSxDCi6lzDOqETt+cY/DIZrUI+gHX5OhP8lKGO+eZYrscJWkiE6Ow6z8vuRy8nYGPVX0ZSLSSaebaE2edSK8svZ1l+H6+tqM75MBjh4yYMrsiPgJy6o/oPJhssfVxDlJUn8/vz4bQrQbnxPZUzb5TQla3LrrrZK46HGRuogSImCKbu9Pm3ZZi2fjfhLBJOTyzVUPliySjEKPuPHzzaHdv3P0Tg84MQgkaXVbkpnBr3O5CK3OZjT0LN2QNpdnVujw3XcNJfsTp7tpnSX2OthlA2WV6GbbOqLHNOYigmvarzt6uh8ZQTSi6kimq9ojpekT1/Ym9uKq/AL7lUoGsgLZ1HAtV1R2yynJKCNcUZgSo6XOo5b+a/JPNXckXRaiDA/SGr3ffQ1JMqR2okFuMmc5V3f/tQsl7C/0DZap7Oc1CkGfa/nsY3ekGuvVajEqsmDWc2ggOGANir6fQAQtbb9QBbrsX9wvF5DWjU1yOTyXSgEcw0OgSOVUYKaCO0FmOpZnPWpnW5mUd+l3VWfopDNmPojtNevIo7mnfukbUBCOVvt+eLe7aRdp6D7ctO0tp7CZ7QwDczUC05HePFveokTquvxwIwPQWqWwy3VbI0j6CHSr6Os81Yv0HxRjygFtILDAMVcmaxxF9ocVWWFOPV6IxFOvcBMkdtEM8YGGfdcpE14kTGIE2CMREjb1mgrOX3t61g
Content-Type: multipart/alternative; boundary="_000_BL0PR01MB43872AFB1A8DAF0EF09D137CA5659BL0PR01MB4387prod_"
MIME-Version: 1.0
X-OriginatorOrg: f5.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL0PR01MB4387.prod.exchangelabs.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d7009cd2-7b91-40f1-569a-08da7aec03ae
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Aug 2022 16:18:51.8661 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: dd3dfd2f-6a3b-40d1-9be0-bf8327d81c50
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: nTtfALwhl+XIQ2tX57AFtNezFU/qEbsEUUXp6p0rvOVHW2gNM3E3EAm9xX1c8tAu
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR01MB7267
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/cYHzQ0dFuuorcTlM-JoHQucCBqc>
Subject: Re: [dns-privacy] ODoH RFC SetupBaseS clarification
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Addition of privacy to the DNS protocol <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Aug 2022 16:19:18 -0000

Hi chris,
Thanks. I see that HPKE RFC defines Encap to be a randomised algorithm to generate a ephemeral. Thats sufficient and rest as you said is upto implementation.

Thanks,
Ravi Mantha
________________________________
From: dns-privacy <dns-privacy-bounces@ietf.org> on behalf of Christopher Wood <caw@heapingbits.net>
Sent: Wednesday, August 10, 2022 7:37:44 PM
To: Ravi sankar MANTHA <r.mantha=40f5.com@dmarc.ietf.org>
Cc: dns-privacy@ietf.org <dns-privacy@ietf.org>
Subject: Re: [dns-privacy] ODoH RFC SetupBaseS clarification

EXTERNAL MAIL: dns-privacy-bounces@ietf.org

Hi Ravi,

Most implementations allow applications to provide a source of randomness (via, e.g., a rand.Reader-like interface) for the purposes of deriving the client’s ephemeral key share. As this is an implementation detail, neither the HPKE nor ODoH RFCs explicitly specify how randomness is provided, so I don’t any change is needed here. If an HPKE implementation is _not_ using randomness for generating an ephemeral key share, then it’s horribly broken.

Best,
Chris

> On Aug 10, 2022, at 5:09 AM, Ravi sankar MANTHA <r.mantha=40f5.com@dmarc.ietf.org> wrote:
>
>
> Hi,
>
> In Section 6.2 of RFC 9230, its mentioned that SetupBaseS takes only 2 parameters  (pkR, "odoh query")
>
> However, reference implementations are indeed using a randomiser from client side.
>
> enc, ctxI, err := hpke.SetupBaseS(suite, rand.Reader, pkR, []byte(ODOH_LABEL_QUERY))
> (https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fcloudflare%2Fodoh-go%2Fblob%2F7c6d9ff448c53e0e546f2afe915ad9608e11f7bd%2Fodoh.go%23L471&amp;data=05%7C01%7Cr.mantha%40f5.com%7Ce46a7d20f78b46d3903108da7ad9d08b%7Cdd3dfd2f6a3b40d19be0bf8327d81c50%7C0%7C0%7C637957373465832299%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=HlytaAnSlUzFAFxseZF5dxZlax1VZ1gQCgdY4shqu3w%3D&amp;reserved=0)
>
> This has an implication on target implementations,
>
> If Targets assume the randomizer is not present in shared secret derivation, then Context is unique for Target Public Key and they may choose not to store/derive it per message per Public Key.
>
> If random seed is present, then contexts are unique only per message (DSN Query).
>
> So, this has an interoperability impact as Encrypt/Decrypt fails for Query Responses if wrong shared key/Context is used on Target side.
>
>  IMHO, we might need to clarify this in RFC either by updating pseudocode for SetupBaseS or add a note that Target should derive shared secret/Context with every oblivious DNS query. Or its implicit somewhere in the RFC ?
>
> Regards,
>
> Ravi Mantha
>
>
>
>
> _______________________________________________
> dns-privacy mailing list
> dns-privacy@ietf.org
> https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fdns-privacy&amp;data=05%7C01%7Cr.mantha%40f5.com%7Ce46a7d20f78b46d3903108da7ad9d08b%7Cdd3dfd2f6a3b40d19be0bf8327d81c50%7C0%7C0%7C637957373465832299%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=lb%2Fh7id%2BLLZ5O18lD2nAyp8XpiytzbC1ak9WEupgEN0%3D&amp;reserved=0

_______________________________________________
dns-privacy mailing list
dns-privacy@ietf.org
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fdns-privacy&amp;data=05%7C01%7Cr.mantha%40f5.com%7Ce46a7d20f78b46d3903108da7ad9d08b%7Cdd3dfd2f6a3b40d19be0bf8327d81c50%7C0%7C0%7C637957373465832299%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&amp;sdata=lb%2Fh7id%2BLLZ5O18lD2nAyp8XpiytzbC1ak9WEupgEN0%3D&amp;reserved=0