[DNSOP] Re: [EXTERNAL] New Version Notification for draft-tjjk-cared-00.txt

Erik Nygren <erik+ietf@nygren.org> Mon, 22 July 2024 22:48 UTC

Return-Path: <nygren@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 359F1C15198B for <dnsop@ietfa.amsl.com>; Mon, 22 Jul 2024 15:48:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.654
X-Spam-Level:
X-Spam-Status: No, score=-1.654 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BXZX6myqQ_0r for <dnsop@ietfa.amsl.com>; Mon, 22 Jul 2024 15:48:06 -0700 (PDT)
Received: from mail-lj1-f176.google.com (mail-lj1-f176.google.com [209.85.208.176]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6390DC14F6FA for <dnsop@ietf.org>; Mon, 22 Jul 2024 15:48:06 -0700 (PDT)
Received: by mail-lj1-f176.google.com with SMTP id 38308e7fff4ca-2eefeab807dso58437031fa.3 for <dnsop@ietf.org>; Mon, 22 Jul 2024 15:48:06 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1721688484; x=1722293284; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=yCCi9gXyz+pPstbVZ71sj+n82IMnHMuj+VQXQow/qk8=; b=IMCLyk6MlNuRQECwUrGCn6yhW4XkSpQZi83066sOqUk3ABn8lFx3T87B7b/+zfCztm oLncCgajKF7FGEPCsYpgjlexWULfV2IuRXeuNSxoh/NFPh0WJ/WCbGzokQNoTBU+4gwX Q1ymUy9KGkENRU69ZJGPWjJDIb9ceBEDprdQJWvHoR2AQ0wnTCNCDEFWm77R9G3lEclm Nl/dGqcCKN30wVNcLg/q+DN4T6z/VmAqfdH2ktwdX9EcrAjoP1rRt4ngsTGevpwdcZ1U HG6rqSvDGdVjyD/FCMyysi/zEkNTJvBxqPazJeWkyHtZcl5iZduhIjMhQFI36yb/2nm1 5kaA==
X-Gm-Message-State: AOJu0YxT6DnADOCgR68Y7glJamAYmTDERUC9s2tzZ8+DFnO8tg4lGhD8 aXPjCjfTWePbit+uJmKMTi28ikhZ9+koQY4DVNZ0ibH/7TOLhDik9F0EqUgW4kRDgQXwFZsR/h6 2g2se3HfMuOwIp8FI+L113/nrfSk=
X-Google-Smtp-Source: AGHT+IGOghh6yJMWeiDglrz7/GJxBmjCdiClsStd+JKDbKCrCxrRFR6718qqDzqzM1rvj4BlBc3ZCoBSsNtwy/EDj7w=
X-Received: by 2002:a05:6512:3e1e:b0:52b:bf8e:ffea with SMTP id 2adb3069b0e04-52fc406dc89mr875580e87.40.1721688483522; Mon, 22 Jul 2024 15:48:03 -0700 (PDT)
MIME-Version: 1.0
References: <171951314842.227.16506719010762251285@dt-datatracker-ff7f57fbb-ch6dm> <SA1PR00MB1344B00639280305247F898FFAD72@SA1PR00MB1344.namprd00.prod.outlook.com>
In-Reply-To: <SA1PR00MB1344B00639280305247F898FFAD72@SA1PR00MB1344.namprd00.prod.outlook.com>
From: Erik Nygren <erik+ietf@nygren.org>
Date: Mon, 22 Jul 2024 15:47:51 -0700
Message-ID: <CAKC-DJjq+Sm4za7YAamxC_B+dCG3+u7G_5Nm9y4XE2wcGZTcDA@mail.gmail.com>
To: Tommy Jensen <Jensen.Thomas=40microsoft.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="0000000000007971c8061dddd6c4"
Message-ID-Hash: 5XMUM3QN3GSGIIFRS3KJQMKORABIS7ON
X-Message-ID-Hash: 5XMUM3QN3GSGIIFRS3KJQMKORABIS7ON
X-MailFrom: nygren@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop <dnsop@ietf.org>, "Damick, Jeffrey" <jdamick@amazon.com>, Jessica Krynitsky <Jess.Krynitsky@microsoft.com>, "Engskow, Matt" <mengskow@amazon.com>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [DNSOP] Re: [EXTERNAL] New Version Notification for draft-tjjk-cared-00.txt
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/ezVT3SZUt8AswmqzE1hqmTAT5g0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

I think mTLS (client certs) makes sense as a recommendation in
draft-tjjk-cared, but is critical to call out the privacy issues with TLS
client certs in TLS versions prior to TLS 1.3.  (ie, in TLS 1.2 and before
the client certificates are sent in-the-clear in the handshake unless
renegotiation is used.)

The best fix might be to have a "MUST use only TLS 1.3 or above with no
fallback" and call out the risks of doing otherwise in Security
Considerations.

   Erik


On Thu, Jun 27, 2024 at 11:42 AM Tommy Jensen <Jensen.Thomas=
40microsoft.com@dmarc.ietf.org> wrote:

>
> Spoiler alert: we prefer mTLS as the ideal authentication mechanism. I'll
> let the draft speak for itself as to why. Feedback and discussion is
> welcome.
>
> Thanks,
> Tommy
>
> ------------------------------
> *From:* internet-drafts@ietf.org <internet-drafts@ietf.org>
> *Sent:* Thursday, June 27, 2024 11:32 AM
> *To:* Jeffrey Damick <jdamick@amazon.com>; Jessica Krynitsky <
> Jess.Krynitsky@microsoft.com>; Matt Engskow <mengskow@amazon.com>; Tommy
> Jensen <Jensen.Thomas@microsoft.com>
> *Subject:* [EXTERNAL] New Version Notification for draft-tjjk-cared-00.txt
>
> A new version of Internet-Draft draft-tjjk-cared-00.txt has been
> successfully
> submitted by Tommy Jensen and posted to the
> IETF repository.
>
> Name:     draft-tjjk-cared
> Revision: 00
> Title:    Client Authentication Recommendations for Encrypted DNS
> Date:     2024-06-27
> Group:    Individual Submission
> Pages:    11
> URL:      https://www.ietf.org/archive/id/draft-tjjk-cared-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-tjjk-cared/
> HTML:     https://www.ietf.org/archive/id/draft-tjjk-cared-00.html
> HTMLized: https://datatracker.ietf.org/doc/html/draft-tjjk-cared
>
>
> Abstract:
>
>    For privacy reasons, encrypted DNS clients need to be anonymous to
>    their encrypted DNS servers to prevent third parties from correlating
>    client DNS queries with other data for surveillance or data mining
>    purposes.  However, there are cases where the client and server have
>    a pre-existing relationship and each peer wants to prove its identity
>    to the other.  For example, an encrypted DNS server may only wish to
>    accept resolutions from encrypted DNS clients that are managed by the
>    same enterprise.  This requires mutual authentication.
>
>    This document defines when using client authentication with encrypted
>    DNS is appropriate, the benefits and limitations of doing so, and the
>    recommended authentication mechanism(s) when communicating with TLS-
>    based encrypted DNS protocols.
>
>
>
> The IETF Secretariat
>
>
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org
>