Re: [dns-privacy] Root Server Operators Statement on DNS Encryption
John Heidemann <johnh@isi.edu> Fri, 02 April 2021 04:23 UTC
Return-Path: <johnh@isi.edu>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 752613A30D6 for <dns-privacy@ietfa.amsl.com>; Thu, 1 Apr 2021 21:23:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8unO0eX4WXMW for <dns-privacy@ietfa.amsl.com>; Thu, 1 Apr 2021 21:23:50 -0700 (PDT)
Received: from ant.isi.edu (ant.isi.edu [IPv6:2001:1878:401::8009:1c09]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9CD083A30D5 for <dprive@ietf.org>; Thu, 1 Apr 2021 21:23:50 -0700 (PDT)
Received: from dash.ant.isi.edu (localhost [127.0.0.1]) by ant.isi.edu (Postfix) with ESMTP id 3AAD4A04B3; Thu, 1 Apr 2021 21:23:48 -0700 (PDT)
Received: from dash.ant.isi.edu (localhost6.localdomain6 [IPv6:::1]) by dash.ant.isi.edu (Postfix) with ESMTP id 7AA82440064; Thu, 1 Apr 2021 21:23:47 -0700 (PDT)
From: John Heidemann <johnh@isi.edu>
To: Tomas Krizek <tomas.krizek@nic.cz>
cc: Rob Sayre <sayrer@gmail.com>, Bill Woodcock <woody@pch.net>, "dprive@ietf.org" <dprive@ietf.org>
In-reply-to: <62d91128-6ef7-1a92-1ac8-f67e6af90583@nic.cz>
References: <c925da9089fa4b1e991ec74fc9c11e7f@verisign.com> <CAChr6Sxwao=FAcoeHMuOf0L=JCZ+wvhsr9BNZW_dbt+1=HWQwg@mail.gmail.com> <20210331091238.GA10597@nic.fr> <CAChr6SxPNVAZMYfZqF+K6Xf8FPGa9ZgHkL-uUvtKMEiJSPmp8Q@mail.gmail.com> <2607D274-936F-4A31-9E4D-EEBCF45BE838@pch.net> <CAChr6Szg+EbFqSpFPco8Gyb9pzNNnrSoQJcXTDVeg40_EXiPDg@mail.gmail.com> <4B1CCB51-C777-4434-B28E-76C22C12E4DA@pch.net> <CAChr6Sym=tm-vj-3FB-GbOG6U=U4CFsRE6yyWJk14waZQLbRiQ@mail.gmail.com> <62d91128-6ef7-1a92-1ac8-f67e6af90583@nic.cz>
X-url: http://www.isi.edu/~johnh/
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Date: Thu, 01 Apr 2021 21:23:47 -0700
Message-ID: <1462727.1617337427@dash.ant.isi.edu>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/dZbf3wZdPLrLkdznsWIcQqW2idw>
Subject: Re: [dns-privacy] Root Server Operators Statement on DNS Encryption
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Apr 2021 04:23:55 -0000
On Thu, 01 Apr 2021 11:59:26 +0200, Tomas Krizek wrote: >On 31/03/2021 23.28, Rob Sayre wrote: >> On Wed, Mar 31, 2021 at 2:16 PM Bill Woodcock <woody@pch.net> wrote: >> >>> >>> …and it’s measuring latency rather than server-side load. I just checked >>> with our engineers, and it sounds like the server load per-query is more >>> like 3x-5x higher for the encrypted queries. >>> >> >> Plenty of folks have evaluated the costs here. I'd prefer to discuss data >> rather than "checking with engineers". It's not really reasonable to >> measure "server load per-query" without a bunch of other data on how the >> TLS sessions are being created and maintained. >> >> So, if you have some data you'd like to share with the list, that would >be >> most welcome. > >We've done some measurements comparing the server-load overhead of DoT >and DoH and while the exact results vary greatly with the client >behaviour, connection management and other parameters, I think 3x-5x >server-load overhead (compared to UDP) is a reasonable expectation. [1] We've published results of server-side CPU and memory at Liang Zhu and John Heidemann. LDplayer: DNS Experimentation at Scale. In _Proceedings of the ACM Internet Measurement Conference_, Boston, Massachusetts, USA, ACM. October, 2018. <https://doi.org/10.1145/3278532.3278544>, <https://www.isi.edu/%7ejohnh/PAPERS/Zhu18b.html>. Including replay of root DNS traffic (DITL) with it's current mix of UDP and TCP and all-TLS. We found (DNS over) UDP and TLS took about the same CPU on our hardware, and pure TCP (without TLS) was actually lower CPU than UDP. See Figure 11 and section 5.2.3 in the paper. (Our code and data is available if you want to reproduce our experiments on your hardware.) IMHO, a bigger operational concern than CPU is actually memory---it's easy to burn through a lot of RAM with TCP and TLS state---see section 5.2.2 and figures 13 and 14 in the paper. It depends a lot on the TCP and TLS timeout you use. Fortunately it's less than 24GB at steady state, which is not a problem for today's hardware. (Although the server should be prepared to early-terminate connections if it's under memory pressure.) Our experiments assume well configured clients and servers. Although not so important for load, optimizations make a huge difference difference for latency. Options like TCP fast open and TLS connection resumption get some of the improvements in QUIC, but over TCP (see <http://dx.doi.org/10.1109/SP.2015.18>, <https://www.isi.edu/%7ejohnh/PAPERS/Zhu15b.html> for the details). I hope people evaluating DNS over QUIC compare against best-configured TCP and not just basic TCP without optimizations. -John Heidemann
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- [dns-privacy] Root Server Operators Statement on … Hollenbeck, Scott
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Erik Kline
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Jim Reid
- Re: [dns-privacy] Root Server Operators Statement… Eric Rescorla
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Erik Kline
- Re: [dns-privacy] Root Server Operators Statement… Eric Rescorla
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Vladimír Čunát
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Brian Haberman
- Re: [dns-privacy] Root Server Operators Statement… Frederico A C Neves
- Re: [dns-privacy] Root Server Operators Statement… Jim Reid
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Hollenbeck, Scott
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Jim Reid
- Re: [dns-privacy] Root Server Operators Statement… Vladimír Čunát
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Jim Reid
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Brian Haberman
- Re: [dns-privacy] Root Server Operators Statement… Brian Haberman
- Re: [dns-privacy] Root Server Operators Statement… Tomas Krizek
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Stephen Farrell
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Andrew Campling
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Andrew Campling
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Christian Huitema
- Re: [dns-privacy] Root Server Operators Statement… Rob Sayre
- Re: [dns-privacy] Root Server Operators Statement… Petr Špaček
- Re: [dns-privacy] Root Server Operators Statement… Brian Haberman
- Re: [dns-privacy] Root Server Operators Statement… Bill Woodcock
- Re: [dns-privacy] Root Server Operators Statement… Vittorio Bertola
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- Re: [dns-privacy] Root Server Operators Statement… Stephane Bortzmeyer
- [dns-privacy] DDoS resiliance & DNS-over-TCP (was… Shane Kerr
- Re: [dns-privacy] Root Server Operators Statement… Christian Huitema
- [dns-privacy] RFC7626 and risk/threat analysis Jim Reid
- Re: [dns-privacy] Root Server Operators Statement… John Heidemann
- Re: [dns-privacy] Root Server Operators Statement… Wes Hardaker
- Re: [dns-privacy] Root Server Operators Statement… Brian Haberman