[dnsdir] Dnsdir last call review of draft-ietf-masque-connect-ip-08

"R. Gieben via Datatracker" <noreply@ietf.org> Sun, 12 March 2023 09:58 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: dnsdir@ietf.org
Delivered-To: dnsdir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id CB8EFC15270E; Sun, 12 Mar 2023 01:58:22 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "R. Gieben via Datatracker" <noreply@ietf.org>
To: dnsdir@ietf.org
Cc: draft-ietf-masque-connect-ip.all@ietf.org, last-call@ietf.org, masque@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 9.14.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <167861510281.5487.17028350749670459212@ietfa.amsl.com>
Reply-To: "R. Gieben" <miek@miek.nl>
Date: Sun, 12 Mar 2023 01:58:22 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsdir/XNo3mpP0R0ib5kRdWE4GNjGz5MI>
Subject: [dnsdir] Dnsdir last call review of draft-ietf-masque-connect-ip-08
X-BeenThere: dnsdir@ietf.org
X-Mailman-Version: 2.1.39
List-Id: DNS Directorate <dnsdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsdir>, <mailto:dnsdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsdir/>
List-Post: <mailto:dnsdir@ietf.org>
List-Help: <mailto:dnsdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsdir>, <mailto:dnsdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Mar 2023 09:58:22 -0000

Reviewer: R. Gieben
Review result: Ready with Issues

Hello, I've reviewed draft-ietf-masque-connect-ip specifically for DNS issues.
This is mostly contained in a single section: 4.1: IP Proxy Handling.

In that section a two questions popped up when the 'target' variable is a DNS
name and the IP proxy must then perform a DNS lookup:

- Should the IP proxy care about the TTL of the looked up name? I.e. is it OK
if the TTL expires? Potentially the DNS name can then point to a different IP
address? - Should the IP Proxy do a DNSSEC lookup or a plain DNS lookup? Should
this be configurable or can the IP proxy just not care?

Regards,
Miek