Re: [DNSOP] [Doh] [EXTERNAL] Re: New I-D: draft-reid-doh-operator

Patrick McManus <> Mon, 25 March 2019 09:42 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 5B15A120381 for <>; Mon, 25 Mar 2019 02:42:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key) header.b=IiOPKyBG; dkim=pass (2048-bit key) header.b=F7pxWxBF
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id x3R2EdkXldfW for <>; Mon, 25 Mar 2019 02:42:05 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 9C8B312037F for <>; Mon, 25 Mar 2019 02:42:04 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1553506922; cv=none;; s=arc-outbound20181012; b=k3/sCIKtEYHWMw6NdpvluvbtZFbiUi5SaqWhqI3KgZ7TStuUEi0Q2ZR+98a9PDsI80z4GMH6CiElu Xe26YiMtDSc0u6oAvrHixlgUjQQa6Xawq9N6rWlLzLkOP9V92TyScWqX/Bx+8ZapqkkrvHC2cgR5YI gLBj6P5DsUKRHlNVKUVnlVkyB9JNUJzL0GddLxAxOdFCAL3kMcFIc2wJz9ZEMGC7lM+BwuEgcW0/x+ ZXCZu01c4wg2c35/mWM81SDK/+bg6Wzo1JKQAsRgv9XmzKgEUMRFkhuYiELGWUSRyOGU4dI8P8m85p ottVeyu0az7GfW89VYT9QfojJWs1jhQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed;; s=arc-outbound20181012; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:dkim-signature:dkim-signature:from; bh=rmAiNYT0EY5to5juamBJ83H6A5Uk3rbp+xUxnD+y6zA=; b=OLp5qQuxh52lIcp9IpeYRyRiBd/JQfb8vcqY3m4bPVRUU4vVPw0ExgmTq6i55xFpcOLdyQNOMCOUe x259ABIc5BK0L20g6nkZcy1PEK+lzr9hVJGf1NDywrCcb91fQxhK3QBJOp2ScWvDB05SD7fosyUm6g wXMrataptu4Tn/DEXO9YVuT60VAcwPHqPXv+D0qCNVa6prf4OZkfmnmnagEVHTn9Qa4DS0xjnZJwei wM0mcgqMAHnxXhlDazykWxzU57GrHGn08pcuu4eKe4Wg0yPMn0etzMXDZqhtytcUw0GNykoJl8D3sj GsXR3Btl9tMLroTAacLPhGy+wpAcxxg==
ARC-Authentication-Results: i=1;; spf=pass smtp.remote-ip=; dmarc=none; arc=none header.oldest-pass=0;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=duo-1537391512170-ea99bbb3; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:from; bh=rmAiNYT0EY5to5juamBJ83H6A5Uk3rbp+xUxnD+y6zA=; b=IiOPKyBGdEyx1vnPIKuCDhO+Ighi8Sr4VnoSiZrXr7PbboG1CDZagqfpOoRcWO/QQHSxOzSDIDtlC j4VfpO5XCpXOQ4eBe+vuEtYu2+Dcb+M/J4Yljq4NY9fpbj4X3bFH9IjKcSswlC9vHhVt6e3iD813A2 ndm2R49MkcqcGtn0=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=dkim-high; h=content-type:cc:to:subject:message-id:date:from:in-reply-to:references: mime-version:from; bh=rmAiNYT0EY5to5juamBJ83H6A5Uk3rbp+xUxnD+y6zA=; b=F7pxWxBFc9jhJZ29aKPuYgG8mVqxrYUUuKbCPsDtLXvwrlKimbj0MDviPskEslKIY1OcuFYYnF4tz 7lLvAHJjVvXnIy8W5zmnmkGe4vhkEXT0LVlwN+pAZ2CCwlGX+4t2nlcot8Bh+9rUjcCiO9fyMBXtda /OfabzpE11G6m2qxQAsTg2HXvo38tjJX2RkNiEI47/U3yZ+OupKvy9XYvnEy/IbvRJ159y1WjZYhEq B+faEAjQdJafwRFrjxcZ2xBjFeRIVFvk/rGlDwX7B9mTCvz9y8WaC1F7dUxpChMyP+3iE4s7HXdZSg AmwnKYETt0igjz2Q+E2VmwsCjhun+Nw==
X-MHO-RoutePath: bWNtYW51cw==
X-MHO-User: 3ccc314d-4ee2-11e9-908b-352056dbf2de
X-Mail-Handler: DuoCircle Outbound SMTP
Received: from (unknown []) by (Halon) with ESMTPSA id 3ccc314d-4ee2-11e9-908b-352056dbf2de; Mon, 25 Mar 2019 09:42:00 +0000 (UTC)
Received: by with SMTP id j10so940740otq.0 for <>; Mon, 25 Mar 2019 02:42:00 -0700 (PDT)
X-Gm-Message-State: APjAAAXdRhR5zmr/LlRPSwQoTx4Ejt99tvDMAPUMjfCvs8hSADb082f5 zwb/KDf1s7m450d57Biq7XK4Gw3jrDA/PxWWM7U=
X-Google-Smtp-Source: APXvYqwiq6Xjf//zbuD4/5LHpYVtMhGkvOV+xhe8cNKs4F/C540t/op15L9nAFDLi8aaPWOfTnPrun9pn/fLZy9ORYA=
X-Received: by 2002:a05:6830:109:: with SMTP id i9mr14789282otp.96.1553506919888; Mon, 25 Mar 2019 02:41:59 -0700 (PDT)
MIME-Version: 1.0
References: <> <> <> <> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
From: Patrick McManus <>
Date: Mon, 25 Mar 2019 10:41:48 +0100
X-Gmail-Original-Message-ID: <>
Message-ID: <>
To: Ray Bellis <>
Cc: dnsop <>
Content-Type: multipart/alternative; boundary="0000000000001dbc170584e804a1"
Archived-At: <>
Subject: Re: [DNSOP] [Doh] [EXTERNAL] Re: New I-D: draft-reid-doh-operator
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 25 Mar 2019 09:42:08 -0000

On Mon, Mar 25, 2019 at 9:58 AM Ray Bellis <> wrote:

> On 25/03/2019 09:28, Ian Swett wrote:
> > One way DoH may be faster than DoT in the near future is that DoH can go
> > over HTTP/3 via QUIC and avoid head of line blocking like Do53.
> Head of line blocking shouldn't happen on a modern Do53 server.
> See RFC 7766 §
I've seen this confusion before, so I can clear it up!

Ray is (I believe) referring to the flexible re-ordering of DNS
request-reply pairs of a TCP channel.. similar to HTTP/2 (though with less
flexibility in granularity iirc). That addresses hol-blocking problems due
to the time the server spends building replies.

Ian is (I believe) referring to head of line blocking problems related to
TCP's in-order delivery semantic and packet loss. TCP packet loss will
delay the delivery of received packets if there are outstanding unreceived
lower-numbered packets. If the data in these packets are unrelated (e.g.
different DNS request/reply pairs) - that causes head of line blocking to
the application. That's true of http/2 and RFC7766 (anything tcp based
really). QUIC streams provide a mechanism for identifying which sequences
actually need to have that dependency. DoH with H3 would use separate
streams for separate requests (as different HTTP exchanges are inherently
on different streams).

Its a shame that the term hol blocking is used for both scenarios - it has
caused a lot of confusion.