[DNSOP] extension of DoH to authoritative servers

"zuopeng@cnnic.cn" <zuopeng@cnnic.cn> Tue, 12 February 2019 07:56 UTC

Return-Path: <zuopeng@cnnic.cn>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C62D6124408 for <dnsop@ietfa.amsl.com>; Mon, 11 Feb 2019 23:56:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.889
X-Spam-Level:
X-Spam-Status: No, score=-1.889 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gbF5o1c817Ii for <dnsop@ietfa.amsl.com>; Mon, 11 Feb 2019 23:56:14 -0800 (PST)
Received: from cnnic.cn (smtp13.cnnic.cn [218.241.118.13]) by ietfa.amsl.com (Postfix) with ESMTP id A835A130DBE for <dnsop@ietf.org>; Mon, 11 Feb 2019 23:56:11 -0800 (PST)
Received: from Foxmail (unknown [218.241.103.81]) by ocmail02.zx.nicx.cn (Coremail) with SMTP id AQAAf0Bplq0VfGJcXVEfAA--.22404S2; Tue, 12 Feb 2019 15:56:05 +0800 (CST)
Date: Tue, 12 Feb 2019 15:56:04 +0800
From: "zuopeng@cnnic.cn" <zuopeng@cnnic.cn>
To: dnsop <dnsop@ietf.org>
X-Priority: 3
X-Has-Attach: no
X-Mailer: Foxmail 7, 2, 7, 166[cn]
Mime-Version: 1.0
Message-ID: <2019021215560470371417@cnnic.cn>
Content-Type: multipart/related; boundary="----=_001_NextPart435814428311_=----"
X-CM-TRANSID: AQAAf0Bplq0VfGJcXVEfAA--.22404S2
X-Coremail-Antispam: 1UD129KBjvdXoW7Wr47Jw4DXw13Jw47Ar1fZwb_yoW3JFb_uw 1UCF9xKw4rKF1IgFsak3WxArWjqrW29r4rt3yYvrnru34DAws7Wr4vy3W3ZFy0gasYqF4D Gr9Yk39Fvr4F9jkaLaAFLSUrUUUUUb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUIcSsGvfJTRUUUbmAYjsxI4VWkKwAYFVCjjxCrM7AC8VAFwI0_Jr0_Gr1l1xkIjI8I 6I8E6xAIw20EY4v20xvaj40_Wr0E3s1l1IIY67AEw4v_Jr0_Jr4l8cAvFVAK0II2c7xJM2 8CjxkF64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVW8JVW5JwA2z4x0Y4vE2Ix0 cI8IcVCY1x0267AKxVW8JVWxJwA2z4x0Y4vEx4A2jsIE14v26F4UJVW0owA2z4x0Y4vEx4 A2jsIEc7CjxVAFwI0_GcCE3s1le2I262IYc4CY6c8Ij28IcVAaY2xG8wASzI0EjI02j7Aq F2xKxwAqx4xG67k08I80eVWUJVW8JwAqx4xG64kEw2xG04xIwI0_Jr0_Gr1l5I8CrVC2j2 CEjI02ccxYII8I67AEr4CY67k08wAv7VC0I7IYx2IY67AKxVWUGVWUXwAv7VC2z280aVAF wI0_Jr0_Gr1lOx8S6xCaFVCjc4AY6r1j6r4UM4x0Y48IcxkI7VAKI48JM4xvF2IEb7IF0F y264kE64k0F24lFcxC0VAYjxAxZF0Ex2IqxwCY02Avz4vE14v_GF4l42xK82IYc2Ij64vI r41l4I8I3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUGVWUWwC20s026x8Gjc xK67AKxVWUGVWUWwC2zVAF1VAY17CE14v26r1j6r15MIIYrxkI7VAKI48JMIIF0xvE2Ix0 cI8IcVAFwI0_Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I0E14v26r1j6r4UMIIF0xvE42xK8V AvwI8IcIk0rVWrJr0_WFyUJwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF 7I0E14v26r1j6r4UYxBIdaVFxhVjvjDU0xZFpf9x07be385UUUUU=
X-CM-SenderInfo: x2xr1vlqj6u0xqlfhubq/
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/iCXWGp_OCV81Yh9a_N8BRxb_ovI>
Subject: [DNSOP] extension of DoH to authoritative servers
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Feb 2019 07:56:17 -0000

HI ALL,
RFC8484 《DNS Queries over HTTPS》defines a protocol for sending DNS queries and getting DNS responses over HTTPS. Its primary secnario is between stub resolver and recursive resolver.
I am considering extending the DoH protocal to authoritative servers. To build the trust chain, the child zone publishes a TLSA record instead of a DS record in the parent zone [RFC 6698 may need update]. The TLSA record contains the certificate that identifies the child zone.
In this way, the whole DNS is built on HTTPS which makes DNS more secure. DNSSEC is not necessary anymore and many other problems like fragmentation also will not exist.
The sketch diagram is as followed.  Any comments are welcome!



zuopeng@cnnic.cn