Re: [dns-privacy] Complete changes to the (no longer just) opportunistic ADoT draft

"Hollenbeck, Scott" <shollenbeck@verisign.com> Tue, 23 February 2021 18:52 UTC

Return-Path: <shollenbeck@verisign.com>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 454AA3A0E65 for <dns-privacy@ietfa.amsl.com>; Tue, 23 Feb 2021 10:52:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GzOLQJX8i39L for <dns-privacy@ietfa.amsl.com>; Tue, 23 Feb 2021 10:52:50 -0800 (PST)
Received: from mail2.verisign.com (mail2.verisign.com [72.13.63.31]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E99DF3A0E6A for <dprive@ietf.org>; Tue, 23 Feb 2021 10:52:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=1048; q=dns/txt; s=VRSN; t=1614106370; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=8hv0DdXFNtorlqeIHylYHYYO91HUMZ0RatglN3LDkUQ=; b=OdrLiXOpiGkcnC/1KRrTyeAzNcKXz2ENlzZ02/PqxZMdNguQ4hLnSvhI /P3cU2bVeOf9eyMsmJV+aLcA6eh+0YIMBy/2czNvjS5DQKDmqupTkFT3v HGz8Q6/3kAMgTdcWBwUSbm+kz9rbdC1UI8QUJt2jrma0OcvEWPDdRewi7 JHvCHohpB7DUB06nbnlUJSJQO96EmP5OqZ+IOALRLr3L+PmH88T5LP8ce 2zVee/n6GRdaDYEOY38w15ZKFnu1VgNYClRXxGWrle1VzJAlMWR8+ICzp PbOCKiRWMc/6+dyXkZKovf7V7BcpgvcAQV66XFBYgBdUHUG7FL2Gz7YPm w==;
IronPort-SDR: ouZ8NAvRZx4LaT512k6ZYGiQNOjTUw2KQ+Gt7Q3RSP+zlqZpJkj8er3SSHdSaGY9O0XrSDU/VO HlsASH8DdU1Tn4wAvjuNpqtBJAAWj4BiQY02RCWc0QHcDRsV+//g4gD7Ungkd/rwqAXGbyf2JG whXUP93mVFUNVq3fLIWoHBjnMQmkpywUO2aQbOwx8uQsoA8nFjIkPR5DVCx3HCyX4s6j9M2M4B Lk0ybW9cDRUvWt8WZVU156HGAUn23adrOWTkN1EZHxIaeYCPfIxZM5DZOhmCCva4D4tbW8ndEt zVU=
X-IronPort-AV: E=Sophos;i="5.81,200,1610409600"; d="scan'208";a="4929773"
Received: from BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) by BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2176.2; Tue, 23 Feb 2021 13:52:47 -0500
Received: from BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde]) by BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde%4]) with mapi id 15.01.2176.002; Tue, 23 Feb 2021 13:52:47 -0500
From: "Hollenbeck, Scott" <shollenbeck@verisign.com>
To: "paul.hoffman@icann.org" <paul.hoffman@icann.org>, "dprive@ietf.org" <dprive@ietf.org>
Thread-Topic: Complete changes to the (no longer just) opportunistic ADoT draft
Thread-Index: AQHXCWGIKOmpibYQCE+yDbc28QfoRqpmFfsw
Date: Tue, 23 Feb 2021 18:52:47 +0000
Message-ID: <c7270dfc9cac41b1b3eccfbe6a16a762@verisign.com>
References: <5478A187-BF50-4ACB-8A6C-BDE56233F4A7@icann.org>
In-Reply-To: <5478A187-BF50-4ACB-8A6C-BDE56233F4A7@icann.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/rtQVofpALs_4E_kdhTTSgPqaGMc>
Subject: Re: [dns-privacy] Complete changes to the (no longer just) opportunistic ADoT draft
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Feb 2021 18:52:51 -0000

> -----Original Message-----
> From: dns-privacy <dns-privacy-bounces@ietf.org> On Behalf Of Paul
> Hoffman
> Sent: Monday, February 22, 2021 4:28 PM
> To: dprive@ietf.org
> Subject: [EXTERNAL] [dns-privacy] Complete changes to the (no longer just)
> opportunistic ADoT draft
>
> Greetings again. You probably just saw the announcement of draft-ietf-
> dprive-opportunistic-adotq-01. After the discussion on the list about us
> having to make the opportunistic draft track the (unpublished) fully-
> authenticated draft, Peter and I decided it would be easier for the WG to
> keep both ideas in their heads by making a single draft that covers both
> opportunistic and fully-authenticated ADoT.

[SAH] Very basic first question: we do not yet have a finished requirements document for exchanges between recursive resolvers and authoritative servers. I understand the enthusiasm for an opportunistic ADoT draft, but how does the group intend to make sure that it remains in synch with the requirements draft?

Scott