Re: [dns-privacy] New Version Notification for draft-peterson-dot-dhcp-00.txt

Brian Haberman <brian@innovationslab.net> Wed, 08 May 2019 11:58 UTC

Return-Path: <brian@innovationslab.net>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC9DA12003F for <dns-privacy@ietfa.amsl.com>; Wed, 8 May 2019 04:58:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=innovationslab-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rf6S9x81p_bm for <dns-privacy@ietfa.amsl.com>; Wed, 8 May 2019 04:58:44 -0700 (PDT)
Received: from mail-qt1-x829.google.com (mail-qt1-x829.google.com [IPv6:2607:f8b0:4864:20::829]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9314E12006A for <dns-privacy@ietf.org>; Wed, 8 May 2019 04:58:44 -0700 (PDT)
Received: by mail-qt1-x829.google.com with SMTP id a17so1818799qth.3 for <dns-privacy@ietf.org>; Wed, 08 May 2019 04:58:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=innovationslab-net.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to; bh=O3HaQgxQug1hP894PqFRo945VTarV1jH3rEkbrKtgzU=; b=DgWrHVRRjNlbgSF5rZYTkO5XarYUZAGkeg1fg8LUFgMVG4SkAZVLugKCtWdCw6HTjZ iBMOpO/6giSeQVwqqe5sAuCiBXVCesMR8S1SwOuDfaaTcE1eE74BMR8Gre0i3HtEAB7t 5ZkyrjPzUR+23wimyXRgOvsMvjq6XSmaT5yHjxyyyLddkmm/p1jOboDnGzPnkQHMKdEB t9BvP+haenYRbPr8y3xfpKadpgs2q/tpIqXwmjeU6Ze8jJcvxO05nnjFJXVTPmK7qG8w xMbmDkQ2cU+fOAwI6aWVkr9Lh0P957RaGcozjUthPwVjLjUnJjZrX8t2PxXjTzKciDTC GOeA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to; bh=O3HaQgxQug1hP894PqFRo945VTarV1jH3rEkbrKtgzU=; b=Ym/z5GiWzrR9EeXCnlcwdPk6i/wU7wAXqdiW8vfJfryzuQxwMhjSmAkpMn7XE7hCpl XmpPFg9xCeM2meCVbx8zBIYya6K69crpYUBjm5xelLAL2A0BjuzWlYq+Ou/EjrGg3d2r kg+4Q4wWR4rpxMST/uyCGyUe6gusMIis9eVhn3heNcnaKcI0oGAlWWB81V4cmc7U1t+2 hJFslbpt0Cb2e213H8vI0zEcie4WjHtAEMP+HXFAp/ZXSdSpdG1ySo2kzZIRh3pW2I5l 3YoWnpUpWzEOW6nRvXul71JXXk6S8ihB43N8o7fH2oJytrSYHdDC53t6nATrYjxGOmz5 lHOQ==
X-Gm-Message-State: APjAAAWzQjeQQCHGDQWVqbDZe80da2ot3eq5PdMM58R64tXYcbyM/a6C 1RqjL5ePSDKUmHQHj5rMtqeCL6FZ/Ps=
X-Google-Smtp-Source: APXvYqwXnMbQA+CJGIBJuin6uANuDT8cfcK5/c1ij9RMlWr5yvfn4N6KGQD4GoEskrLSsl1n7fw6mA==
X-Received: by 2002:aed:3f57:: with SMTP id q23mr11639753qtf.285.1557316723235; Wed, 08 May 2019 04:58:43 -0700 (PDT)
Received: from clemson.local (edge-nat-all.jhuapl.edu. [128.244.87.129]) by smtp.gmail.com with ESMTPSA id c13sm8282748qkk.11.2019.05.08.04.58.42 for <dns-privacy@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 08 May 2019 04:58:42 -0700 (PDT)
To: dns-privacy@ietf.org
References: <155637241515.19889.8043108886886364414.idtracker@ietfa.amsl.com> <9a851741-c4e3-44fd-e659-91e7eec8a88a@gmail.com> <DC146870-7A45-4D1B-856F-43EA4056D2A3@employees.org>
From: Brian Haberman <brian@innovationslab.net>
Openpgp: preference=signencrypt
Autocrypt: addr=brian@innovationslab.net; keydata= mQINBFm5KgYBEACs2icafejrG19L5DRNFq8Q2O+K+LRxjR4qAElZDnXFXNA2ipFWPeT0J2wa KJ+h9UdfhDm8DzULB553CYm+Q3XF1N56TglkIRMZYc7mYXZEr3x7e4fmX4kD4qMjBLG8cL26 rEe3Q0qaiMGY69/4o5coVMT0qmHjgCH1tkG+L2Y8MKr1gFxS18eO8MVoWe1yDKuyxFSElHGB 3mZn4gcqeCaemPGG3CiVNlp4KnijpNcSgvseXbkQEA4IXEsIvUL8MIwOTXg9Gh5cbtisZpuf +4B0LNMUSqWlqyKd9M3KCMj+dW4vsFytc00Z+GyQ+ArOR9GwTdAwJ5qqVODTvbjKqOR1zolJ 1JxLUtSiv7Lx5x2OrCexPYXkzlTkjG9Imtg2XNh55R/JKMC3KU1NQL3nS9tJXeoRWNgWSZrG MsrbeejbqLVb9LblXNpgLciJ96XHMvYAXX7p4LAwivzSRrVg46vErYIAV6EvDvwVENWW8JCU 0vX5iTGfkEwU4KxCa7WAmmD8yiNspHP1J0uk93Sta5K0PuTi7b+EZlCjdrqOEWLGPv6qXlIu FwLLcCaDs3XdVvwgNM+UFRxFH1aOVQQKCiCOCcNlwgYG1u4ZbD2T6hd/d2tOAKu/MNnQVF7d Cfi2BtSjzglLcY61e37zqTM04BgU+LniZ7V99yneM6DM2UzgkwARAQABtClCcmlhbiBIYWJl cm1hbiA8YnJpYW5AaW5ub3ZhdGlvbnNsYWIubmV0PokCQAQTAQoAKgIbAwUJB4YfgAULCQgH AwUVCgkICwUWAgMBAAIeAQIXgAUCWbkqSAIZAQAKCRBo1jycU9GLYQixD/9UX0uiAvbJ+4dK z3Ne3kUdDK0Lk73RGfFgE/ezsc9I6ED82h+arC8pAoDnBWgzTxugZdbexek983bgMq02XFsG pJf7hudeKnB8UmtjTc0j1UUgi129FYyBmINS2Lz1gpEOygFfbeOGLJK5qZJwD3I3O6yN8SUZ uwahXXd1aEB+d1eGhNqxkjQ+L7vdfTlN662GWog3ROMwUbrg0+QAbn/Vlp2iIYO6VERUZ9Yr GfFJX9b9LKa6AHxzAaqFIix1h2wBiIacpIBGU/4+3+wL5zkCbGSRzoIHW8srllj7ehgwwfNx QevibuZWJ4XpHpIxrtsmBO7ERFk8pN7oiQ9M3b2Cg9OBD5vgxyMCHEKIblWyKz8GLtz5357L ORU1EBWB8BoJPBHz3u7bZE+jH9+w5PpI087Ae78KCDkTNj7o2wbkRoYLmLpMo8DOwAumyy5R 2DuRu0cn5Rw5pFjlJkyfM0Wf80Ml/SINrUORWeqSbsHSX8i+Y0Oyt5JNo9NFbgN0Gn/Qo364 I8cLgbvUAyFHwhnmbHB+QXFCGAy73NOQ+g2fCRPeSbihhYa34ugfmd4oa6W2w805ixzM7iGr P+wDB1dhA7eHKVmoo9Kxvm9VzU+2homYGEROd/H6n0BMvWtp1oFh/JvEgZN6dVLg3p+XX5Zj Ggy568bIY4P5kP7pAxh017kCDQRZuSoGARAAtCWxW1cRne/iGbFuibvB8d3upcbCB7oz4LWk LSE20Db2ymn04ici9V+wBSWX57me5jQdwMi/gzVVZcupbzWTg5Yhv7Qt7CKORJLEKo6nULbb 4aEpdOXD9s7wwx+foFjzjtDOH/JYoB+OEe2oW39VmK6EsIx7ClsLf6+cih5yApZHtmV+2M3J YSxD2kCUE619ITFLAkMf203ap5vJ6DDaaKnVoNhF9qV7jlJEceGqHTBG4KkBX/zNCehMIfhr ViY/B2IWAHeuZ99lnCPx2mehGGa4XLjQauUkY9KB7dOq/ODyt+7SL0dfWrOVf3BnU3C308b4 9YdId8KI4dJ30nfXn6ifTK9STZHZE+Mt1sIVmtEguqMXEk/axZmT14x194c7ZPmU/uCQTE3U y1NFs4Yof50WF1ze0CyN2ycmqx11mHjP5+L23TqcdIWmJG+EtdHUAFpu42kbB0fML3Oc/cEU SmWK3WpF5YPljLM2gyh3RXjuiBnaGoJaKTOj5zXQ2G2l3/ijbn9FbqmFup+R352dxUyakXEP xNe3HdyjfyUcy/RJNeZz/lgUIhkxWQjOOU1RIN41RtCKcF9tJjMwgQvI51QmPvf90/6ab3I/ vwEpjlRb4AbuWfPWe89J+Z3TG97V9sntlMcQ6MGiPLbyFpiXIf2150e6FxZdJtipVwY2d/kA EQEAAYkCJQQYAQoADwUCWbkqBgIbDAUJB4YfgAAKCRBo1jycU9GLYfy0EACYrxb4nWtOnIu0 N7rXXo/0ZjaBTyUhJ6hzy2D7rt3vv/qj2ui+N21ui/yMDS928za/XRfP25qN9A1puioHqN4l SAsxwCC3mT9GJXVXVgivg3MeciqBXoOdnk1hUkP1CTKL3qZ9pSuw8bPlNE7+b1xF7Oce37YH +QRVmBXbGwTxtDTCZ9Js0/IpiUtg9QCfmryB1r/fD0TFb8b9aCBuVeKocWSuX9UXRt7zRGM8 BJwOLvdLdGvV8us1imlBKFLai4L8CPgihuc/s7ZB0r3pgW697hXScWhGHF3OUWbPFVkNyivM xtDcq+9ZlUMrxFbwUEABi8NFwvzwn+YJQqlrPiF4xxsScYpnIlfWEuP6Vpp6Z/u5x+1MNyZb oxNWWaevMVeo3tdRV9F6/YFqucw4JQ9HqlCKQ62sW9+e5SSlxGNlV4j9cchG6a4fAZqxL+pS ks+KitK3ap/R4RUG+nbjLlhCwGJIti8lxvdYAoPqjtwEUmMJv4dIl0/2h1495cwBIi7XeRKZ Rx38TV3G3LCx0J8dFhkyTG5TxUZQFgHjznkIX7bzeSQX72MxT0b/tc38yM71WpAgAY+MlHCT FQRKqIQsH/4MFir+g/oV2uPNGwmg0QEOnv9zZ79JJ/nBmuXC2RwUVTtZgtiZXhaP0afvR0eg WPEzptIZZCSmtBOOYkfsAw==
Message-ID: <038e2b4f-4839-2612-664d-9739da5a2dd8@innovationslab.net>
Date: Wed, 08 May 2019 07:58:40 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.6.1
MIME-Version: 1.0
In-Reply-To: <DC146870-7A45-4D1B-856F-43EA4056D2A3@employees.org>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="Alth1LptEKnqb5pLeHVDNgQMSjKNYFT7R"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dns-privacy/xFWaewwmLmP5GY_7v9UakY6lrbI>
Subject: Re: [dns-privacy] New Version Notification for draft-peterson-dot-dhcp-00.txt
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 May 2019 11:58:47 -0000

If an RA option were to carry the IP address of the name server, that
could be done within the framework of RFC 8106. That document already
describes an RA option for advertising DNS servers to clients.

Regards,
Brian

On 4/29/19 5:28 AM, Ole Troan wrote:
>> In a recent discussion in the DoH mailing list around a draft that describes resolver discovery, Martin Thomson made the suggestion[0] to use DHCP and RA options instead to transmit both DNS over HTTP resolver addresses, but more relevant to this WG also DNS over TLS endpoints as well. I have published draft-peterson-dot-dhcp, which describe the relevant DHCPv4, DHCPv6, and RA options to support this.
>>
>> Could I please get feedback, specifically if the WG is in support of it.
> 
> I'm not very keen on yet another DNS configuration option.
> But if you were to do it in the RA, I wonder if it wouldn't be cleaner to do it with the universal RA approach:
> 
> https://tools.ietf.org/html/draft-troan-6man-universal-ra-option-01
> 
> Currently the DNS option is defined as (in CDDL):
>  dns = {
>       dnssl : [* tstr]
>       rdnss : ipv6-addresses : [* tstr]
>       ? lifetime : uint
>  }      
> 
> And you could just add a new attribute for transport:
> 
>  dns = {
>       dnssl : [* tstr]
>       rdnss : ipv6-addresses : [* tstr]
>       ? lifetime : uint
>       transport : "udp" / "tls" / "https"
>  }
> 
> Ole
> 
> _______________________________________________
> dns-privacy mailing list
> dns-privacy@ietf.org
> https://www.ietf.org/mailman/listinfo/dns-privacy
>