Re: [DNSOP] [Ext] Authoritative servers announcing capabilities

Tony Finch <dot@dotat.at> Tue, 22 September 2020 13:03 UTC

Return-Path: <dot@dotat.at>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C3E73A1695 for <dnsop@ietfa.amsl.com>; Tue, 22 Sep 2020 06:03:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.918
X-Spam-Level:
X-Spam-Status: No, score=-1.918 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vi3EiDB1rgYa for <dnsop@ietfa.amsl.com>; Tue, 22 Sep 2020 06:03:06 -0700 (PDT)
Received: from ppsw-32.csi.cam.ac.uk (ppsw-32.csi.cam.ac.uk [131.111.8.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 515603A1691 for <dnsop@ietf.org>; Tue, 22 Sep 2020 06:03:06 -0700 (PDT)
X-Cam-AntiVirus: no malware found
X-Cam-ScannerInfo: http://help.uis.cam.ac.uk/email-scanner-virus
Received: from grey.csi.cam.ac.uk ([131.111.57.57]:48440) by ppsw-32.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.136]:25) with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) id 1kKhwj-00090P-2T (Exim 4.92.3) (return-path <dot@dotat.at>); Tue, 22 Sep 2020 14:03:01 +0100
Date: Tue, 22 Sep 2020 14:03:01 +0100
From: Tony Finch <dot@dotat.at>
To: Paul Hoffman <paul.hoffman@icann.org>
cc: "dnsop@ietf.org" <dnsop@ietf.org>
In-Reply-To: <421B7DF6-7BFE-45A8-B78A-B0860485368F@icann.org>
Message-ID: <alpine.DEB.2.20.2009221348500.7889@grey.csi.cam.ac.uk>
References: <676DE8DE-DA20-4162-B81C-C358DC7084E7@icann.org> <294f8ab0-285b-d5f2-705f-5db8c0da584d@uniregistry.com> <2B4B3FF6-44D4-4F08-81D2-718FD33A7CF0@isc.org> <92CA6178-FE2D-407E-97FB-A9E44E2647C7@icann.org> <rjhbfc$2ghk$1@gal.iecc.com> <A9FAB272-BDF6-4584-8175-0DD3D561AEB2@icann.org> <alpine.DEB.2.20.2009210045070.12960@grey.csi.cam.ac.uk> <421B7DF6-7BFE-45A8-B78A-B0860485368F@icann.org>
User-Agent: Alpine 2.20 (DEB 67 2015-01-07)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/dZlLVcnboBL5h5tieHBxUTy5meI>
Subject: Re: [DNSOP] [Ext] Authoritative servers announcing capabilities
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Sep 2020 13:03:08 -0000

Paul Hoffman <paul.hoffman@icann.org> wrote:
> On Sep 20, 2020, at 4:45 PM, Tony Finch <dot@dotat.at> wrote:
> >
> > Why can't you just send client-subnet in a request and look at the answer?
>
> That assumes that an attacker in the middle has not removed the answer.
> The indicator that we used as an initial idea for the capability would
> be signed, meaning that the resolver would expect a client subnet
> response and could act if it didn't get one.

OK, but how would the resolver's reaction differ? I.e. what problem is
caused by resolvers lacking prior knowledge of client-subnet support?

The more general solution for fixing traffic corruption is authenticated
DoT, so it doesn't seem worth the effort to introduce a special mechanism
to protect one EDNS option when DoT can do the job.

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  http://dotat.at/
North Foreland to Selsey Bill: Southwesterly 3, increasing 4 or 5, then 6 or 7
later. Smooth becoming slight, then moderate later. Rain or showers later.
Moderate or good.