Re: [dnsext] draft-bellis-dnsext-dnsproxy-00 - WG Item?

Nicholas Weaver <nweaver@ICSI.Berkeley.EDU> Tue, 04 November 2008 17:41 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C6AFD3A684C; Tue, 4 Nov 2008 09:41:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.286
X-Spam-Level:
X-Spam-Status: No, score=-5.286 tagged_above=-999 required=5 tests=[AWL=-0.538, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y0wjkmhudv7m; Tue, 4 Nov 2008 09:41:58 -0800 (PST)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id ACFB73A67BD; Tue, 4 Nov 2008 09:41:58 -0800 (PST)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KxPr0-000C80-6d for namedroppers-data@psg.com; Tue, 04 Nov 2008 17:38:10 +0000
Received: from [192.150.186.11] (helo=fruitcake.ICSI.Berkeley.EDU) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <nweaver@ICSI.Berkeley.EDU>) id 1KxPqv-000C7A-2s for namedroppers@ops.ietf.org; Tue, 04 Nov 2008 17:38:07 +0000
Received: from [IPv6:::1] (fruitcake [192.150.186.11]) by fruitcake.ICSI.Berkeley.EDU (8.12.11.20060614/8.12.11) with ESMTP id mA4Hb8VG026005; Tue, 4 Nov 2008 09:37:27 -0800 (PST)
Cc: Nicholas Weaver <nweaver@ICSI.Berkeley.EDU>, Ray.Bellis@nominet.org.uk, namedroppers@ops.ietf.org
Message-Id: <52479FB1-3DF7-40C0-AD9B-502BC6E60F75@icsi.berkeley.edu>
From: Nicholas Weaver <nweaver@ICSI.Berkeley.EDU>
To: Ólafur Guðmundsson /DNSEXT chair <ogud@ogud.com>
In-Reply-To: <200811041648.mA4Gmxv9060421@stora.ogud.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v929.2)
Subject: Re: [dnsext] draft-bellis-dnsext-dnsproxy-00 - WG Item?
Date: Tue, 04 Nov 2008 09:37:27 -0800
References: <OFC2B4769A.688DDF76-ON802574F7.004DE059-802574F7.004E250A@nominet.org.uk> <200811041648.mA4Gmxv9060421@stora.ogud.com>
X-Mailer: Apple Mail (2.929.2)
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

On Nov 4, 2008, at 8:48 AM, Ólafur Guðmundsson /DNSEXT chair wrote:

>
>
> Dear colleagues,
> This document http://tools.ietf.org/id/draft-bellis-dnsext-dnsproxy-00.txt
> is within the WG scope.
>
> If you support the adoption of this document AND are willing to work
> towards its progress by reviewing it, please send message to that  
> effect
> to the mailing list.

ACK

> If you have suggestions/recommendations about the scope of the  
> document this
> is a great time for that discussion.

The only one (which I've already mentioned) is bypassibility:  Unless  
the proxy is specifically implementing a security policy (an IDS  
rather than a NAT), the end resolver should be allowed to direct its  
own queries and bypass the proxy completely.



--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>