Re: [DNSOP] updated to draft-wing-dnsop-structured-dns-error-page-01

Stephane Bortzmeyer <bortzmeyer@nic.fr> Fri, 12 November 2021 14:26 UTC

Return-Path: <bortzmeyer@nic.fr>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3837B3A0A4A for <dnsop@ietfa.amsl.com>; Fri, 12 Nov 2021 06:26:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yjTZ6KcB6wuX for <dnsop@ietfa.amsl.com>; Fri, 12 Nov 2021 06:26:33 -0800 (PST)
Received: from mx4.nic.fr (mx4.nic.fr [IPv6:2001:67c:2218:2::4:12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E907B3A0A63 for <dnsop@ietf.org>; Fri, 12 Nov 2021 06:26:32 -0800 (PST)
Received: from mx4.nic.fr (localhost [127.0.0.1]) by mx4.nic.fr (Postfix) with SMTP id 13662280B77; Fri, 12 Nov 2021 15:26:30 +0100 (CET)
Received: by mx4.nic.fr (Postfix, from userid 500) id 0CAC62814F0; Fri, 12 Nov 2021 15:26:30 +0100 (CET)
Received: from relay01.prive.nic.fr (unknown [10.1.50.11]) by mx4.nic.fr (Postfix) with ESMTP id 05269280B77; Fri, 12 Nov 2021 15:26:30 +0100 (CET)
Received: from b12.nic.fr (b12.users.prive.nic.fr [10.10.86.133]) by relay01.prive.nic.fr (Postfix) with ESMTP id F36B2605B8AC; Fri, 12 Nov 2021 15:26:29 +0100 (CET)
Received: by b12.nic.fr (Postfix, from userid 1000) id E22744008C; Fri, 12 Nov 2021 15:26:04 +0100 (CET)
Date: Fri, 12 Nov 2021 15:26:04 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: Vittorio Bertola <vittorio.bertola=40open-xchange.com@dmarc.ietf.org>
Cc: Petr Špaček <pspacek@isc.org>, dnsop@ietf.org
Message-ID: <YY55fPEe5rhilZFr@nic.fr>
References: <D1CF0779-EAB3-4759-8F50-643E9EC8C490@gmail.com> <d7f55c0d-0746-9c74-2ff1-ebdcec7ad45e@isc.org> <2144593653.33984.1636631982620@appsuite-gw2.open-xchange.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <2144593653.33984.1636631982620@appsuite-gw2.open-xchange.com>
X-Operating-System: Debian GNU/Linux 11.1
X-Kernel: Linux 5.10.0-8-amd64 x86_64
X-Charlie: Je suis Charlie
Organization: NIC France
X-URL: http://www.nic.fr/
X-Bogosity: No, tests=bogofilter, spamicity=0.000016, version=1.2.2
X-PMX-Version: 6.4.9.2830568, Antispam-Engine: 2.7.2.2107409, Antispam-Data: 2021.11.12.140916, AntiVirus-Engine: 5.86.0, AntiVirus-Data: 2021.11.12.5860001
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/pYCU6-SWbFSlA5S6vc92V5XqWJY>
Subject: Re: [DNSOP] updated to draft-wing-dnsop-structured-dns-error-page-01
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Nov 2021 14:26:37 -0000

On Thu, Nov 11, 2021 at 12:59:42PM +0100,
 Vittorio Bertola <vittorio.bertola=40open-xchange.com@dmarc.ietf.org> wrote 
 a message of 24 lines which said:

> I don't want to speak for them (I don't know if they are on this
> list, but they definitely are on ADD) but in past discussions around
> this concept they recognized its potential usefulness (apart maybe
> from a specific browser which seems to have a principle stance
> against DNS filters) but were concerned about the security of the
> mechanism, i.e. the risk that it could be used to present to the
> user a phishing or misleading page,

Moreover, I have serious doubts that DNS configuration errors could be
meaningfully reported to end users. It would be very difficult to make
them understandable and, since we deal with errors in authoritative
servers, the client could not do anything, anyway.

I have nothing against informing users (some will find that useful)
but we should focus on reporting to the zone manager, not to the
client.

So, I don't think interaction with Web browser's authors is required.