Re: [DNSOP] [Ext] Re: New draft for helping browsers use the DoH server associated with a resolver

Paul Hoffman <paul.hoffman@icann.org> Sat, 25 August 2018 22:22 UTC

Return-Path: <paul.hoffman@icann.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D5966130EE4 for <dnsop@ietfa.amsl.com>; Sat, 25 Aug 2018 15:22:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 25NktI_91Bzu for <dnsop@ietfa.amsl.com>; Sat, 25 Aug 2018 15:22:43 -0700 (PDT)
Received: from out.west.pexch112.icann.org (out.west.pexch112.icann.org [64.78.40.7]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B743B130E44 for <dnsop@ietf.org>; Sat, 25 Aug 2018 15:22:43 -0700 (PDT)
Received: from PMBX112-W1-CA-1.pexch112.icann.org (64.78.40.21) by PMBX112-W1-CA-1.pexch112.icann.org (64.78.40.21) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Sat, 25 Aug 2018 15:22:42 -0700
Received: from PMBX112-W1-CA-1.pexch112.icann.org ([64.78.40.21]) by PMBX112-W1-CA-1.PEXCH112.ICANN.ORG ([64.78.40.21]) with mapi id 15.00.1367.000; Sat, 25 Aug 2018 15:22:42 -0700
From: Paul Hoffman <paul.hoffman@icann.org>
To: dnsop <dnsop@ietf.org>
Thread-Topic: [DNSOP] [Ext] Re: New draft for helping browsers use the DoH server associated with a resolver
Thread-Index: AQHUPMIjdKa4X6mYYU2erGcJ6L/eGw==
Date: Sat, 25 Aug 2018 22:22:41 +0000
Message-ID: <089C5DFB-DA83-45D0-926F-A24E703E6B81@icann.org>
References: <3D4A9165-6EE8-4997-A9F7-DB19632C25F3@icann.org> <5220d889-e587-d6dc-db45-0d76370eabae@nic.cz> <61FF26F6-F2E2-48C8-A4B6-94FC6652D55E@icann.org> <m1ftDKw-0000FDC@stereo.hq.phicoh.net> <B51AD822-48C8-4A1D-9C1A-82F0998965A3@icann.org> <aab25f82-b3dc-87e6-4cc8-f95efb57d9bd@nic.cz> <491639801.32025.1535184747688@appsuite.open-xchange.com>
In-Reply-To: <491639801.32025.1535184747688@appsuite.open-xchange.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [192.0.32.234]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <6E5E72D8B9091841972FDA096988E030@pexch112.icann.org>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/mCPJPvk8vD7m4D80oq9LL66oACY>
Subject: Re: [DNSOP] [Ext] Re: New draft for helping browsers use the DoH server associated with a resolver
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Aug 2018 22:22:46 -0000

Greetings again. Based on the technical input I received, I ripped out the first-guess mechanism and replaced it with one that will work with validating stub resolvers but still work with the same use cases.

It's clear some people here don't have the use cases listed in the draft; that's fine, lots of protocols don't apply to everyone. I do still believe that the folks who spoke up saying that they want their browsers to use DoH servers that are matched with the DNS-over-53 resolvers they chose, and this would allow that.

--Paul Hoffman

The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-hoffman-resolver-associated-doh/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-hoffman-resolver-associated-doh-01
https://datatracker.ietf.org/doc/html/draft-hoffman-resolver-associated-doh-01

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-hoffman-resolver-associated-doh-01