Re: [DNSOP] I-D Action: draft-ietf-dnsop-structured-dns-error-07.txt

Ralf Weber <dns@fl1ger.de> Tue, 14 November 2023 11:06 UTC

Return-Path: <dns@fl1ger.de>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 50304C14CE45 for <dnsop@ietfa.amsl.com>; Tue, 14 Nov 2023 03:06:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.909
X-Spam-Level:
X-Spam-Status: No, score=-6.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ImnQFopTcR7y for <dnsop@ietfa.amsl.com>; Tue, 14 Nov 2023 03:06:36 -0800 (PST)
Received: from smtp.guxx.net (smtp.guxx.net [IPv6:2a01:4f8:a0:322c::25:42]) by ietfa.amsl.com (Postfix) with ESMTP id 4CE71C14CE3F for <dnsop@ietf.org>; Tue, 14 Nov 2023 03:06:34 -0800 (PST)
Received: from [192.168.42.110] (p54b8af55.dip0.t-ipconnect.de [84.184.175.85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by nyx.guxx.net (Postfix) with ESMTPSA id E9DEF5F40523; Tue, 14 Nov 2023 11:06:32 +0000 (UTC)
From: Ralf Weber <dns@fl1ger.de>
To: Ben Schwartz <bemasc=40meta.com@dmarc.ietf.org>
Cc: "\"Gianpaolo Angelo Scalone, Vodafone\"" <Gianpaolo-Angelo.Scalone@vodafone.com>, Tim Wicinski <tjw.ietf@gmail.com>, dnsop@ietf.org
Date: Tue, 14 Nov 2023 12:06:32 +0100
X-Mailer: MailMate (1.14r5998)
Message-ID: <C5676F4B-F200-493E-8E21-61150A80C853@fl1ger.de>
In-Reply-To: <BN8PR15MB3281A77E615C6B633DD9D5DAB3AFA@BN8PR15MB3281.namprd15.prod.outlook.com>
References: <DB9PR05MB8473EE94D86348FF1E8207EAA3AFA@DB9PR05MB8473.eurprd05.prod.outlook.com> <BN8PR15MB32817912282A69869281090DB3AFA@BN8PR15MB3281.namprd15.prod.outlook.com> <CADyWQ+FtytyMmwzBjvW=upDzC1HCbfUXOyD6sEyDK5dr5gQfMw@mail.gmail.com> <BN8PR15MB32814A8A9E26BD1672B8104FB3AFA@BN8PR15MB3281.namprd15.prod.outlook.com> <DB9PR05MB8473050AB3D79D47709D29A4A3AFA@DB9PR05MB8473.eurprd05.prod.outlook.com> <CADyWQ+HhWGHJp=pm2==LHYgTTZKvgeDGWY1EM-k6zA7bZi6R+g@mail.gmail.com> <DB9PR05MB847368E0C6CE75F6E2C251D5A3AFA@DB9PR05MB8473.eurprd05.prod.outlook.com> <BN8PR15MB3281A77E615C6B633DD9D5DAB3AFA@BN8PR15MB3281.namprd15.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/nOawk5Nj2OzCnZB6dDjJHf94IgY>
Subject: Re: [DNSOP] I-D Action: draft-ietf-dnsop-structured-dns-error-07.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2023 11:06:38 -0000

Moin!

On 9 Nov 2023, at 17:46, Ben Schwartz wrote:

> Thus far, I don't think we've heard from any browser vendors who believe that it would be prudent and worthwhile to display server-generated error pages of this kind to ordinary end-users on their personal devices.  Absent that support, I think it would not be sensible for us to try to develop such a mechanism.

Well not sure if it counts as browser vendor, but the POC we showed 2 IETFs ago had a browser displaying a page using a browser plugin. And IMHO I have seen worse browser plugins ;-).


> (If such a browser vendor did appear, I would argue against them on both security and human rights grounds.)

I don’t know what human rights have to do with that, but I don’t see a problem if a browser displays a DNS Error message and then with warnings tells the user that his provider has a page here to get more information. It could even authenticate the domain using DNSSEC or WebPKI.

So long
-Ralf
---
Ralf Weber