[DNSOP] Re: Working Group Last Call draft-ietf-dnsop-structured-dns-error

tirumal reddy <kondtir@gmail.com> Tue, 26 November 2024 13:01 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B4B5C180B5F for <dnsop@ietfa.amsl.com>; Tue, 26 Nov 2024 05:01:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X8dnr-k8xfeh for <dnsop@ietfa.amsl.com>; Tue, 26 Nov 2024 05:01:55 -0800 (PST)
Received: from mail-lf1-x136.google.com (mail-lf1-x136.google.com [IPv6:2a00:1450:4864:20::136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 85541C180B5E for <dnsop@ietf.org>; Tue, 26 Nov 2024 05:01:55 -0800 (PST)
Received: by mail-lf1-x136.google.com with SMTP id 2adb3069b0e04-53dd8b7796dso4165970e87.1 for <dnsop@ietf.org>; Tue, 26 Nov 2024 05:01:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1732626114; x=1733230914; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=NwbFgJkJETTPTz3+iLwkj0Si2Xas4Sx5XhsdNP4vKNw=; b=b0qgU2/bZFyL6xZ3kkAvTXzaYD/0SD+s/ly9EPty7Xoz9laFZ/0VRTHxx+0tIRdWYr v5428RF/bSt9XgZVhBdsbMGzBdd56GoN2F0F8NPFw7eTfRi59DE/RR0qqnKws23JWtPx wCDm56T3dk425t0uBFrkjL4RDaZ2cdAmEUD3RHy/mcLsFFhygYM6S3etWoyAcjRFAlGA hU1m1Z5JUxxrSMKxxsEr51e8Dp5OFGjjTyYkPjV9h4gyHmFvymk95lTCwGIIy4b2ddyz 4OApcbocLev6gNKPCkLF6jvjN+sH/dBBo1/Gn2hHI3bsQjplf8OsbXIeZhQ83GdETN9V HXLQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1732626114; x=1733230914; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=NwbFgJkJETTPTz3+iLwkj0Si2Xas4Sx5XhsdNP4vKNw=; b=ULLRr1quCIIvJ/Z81ZijfHakjOtJrt+c20MNNA8/8eI/M1VT0A+I4v0im5KJlAbIC8 NmlLO1xiEvzXt/RUI6SomVhVa6jDdGfQPmllAszqEnqi+fQO5i+2EnWOm9yFqhqhTWxd o1+9q1jgBN0QqKSRed7NFpEYuJaK8ZKI2VWSA7h99lDImZ/SMhTOfqGzIH1smDktwR12 IxAXA3MWJQU9TsU2PFeTSoVMgQjbf2VQoTUw+wGHLgRebmfKJUvLddY2ziVkig2WioQD hqfGDb1yM/HW+wOd+ATKYpuuGPh8n9qg558+vUmCPtT+a8HSLZdRokUfuVoi1xQz0oqj jSyg==
X-Gm-Message-State: AOJu0YwwX8l24H4YkKZnvFxlXbRt00XBZcPNmrsxrOA8DD/JZCByER+i 1ymZIrs702l7nRxHKA3uNoAsovy/x+GTWNY8zlCHVS9MTODlBsFknfNhIXJA8iBWi9T88SdEvC9 Qe4MkbCIYgmJJLkSo+nV0oF4VILzOpAjJnWc=
X-Gm-Gg: ASbGncvxNch9Lopqshb8ceErFLefHx4o3JqKWuQtw0dPi97p8oqqFZF55pQ5w9M8/nw WOotQI0jy3Adh7CH/KPP0YBG5BLJG+R97
X-Google-Smtp-Source: AGHT+IGopDhmAXD1l18ZVxn8G4ATsPmzvbxUmtxBNSeImAjUpsWqGUScwSu0k4iesDyKy5CsQ8y4FgX3E4Tn/R02hBc=
X-Received: by 2002:a05:6512:224d:b0:539:ea7a:7688 with SMTP id 2adb3069b0e04-53dd35a4580mr8321450e87.1.1732626111691; Tue, 26 Nov 2024 05:01:51 -0800 (PST)
MIME-Version: 1.0
References: <5725b858-a35d-41fa-a5a8-5a61e0ce3a7a@NLnetLabs.nl> <ZyZgzWVmCGVU7yv8@laperouse.bortzmeyer.org>
In-Reply-To: <ZyZgzWVmCGVU7yv8@laperouse.bortzmeyer.org>
From: tirumal reddy <kondtir@gmail.com>
Date: Tue, 26 Nov 2024 18:31:15 +0530
Message-ID: <CAFpG3gfZak0PWEiJQxAFfe5LVJTghwqBm6N6S0UHLCbCsAgvZg@mail.gmail.com>
To: Stephane Bortzmeyer <bortzmeyer=40nic.fr@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000ea88df0627d073e1"
Message-ID-Hash: ZFMDRPTVHQFHKMTTNFVAY5PA5OLWLU67
X-Message-ID-Hash: ZFMDRPTVHQFHKMTTNFVAY5PA5OLWLU67
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: DNSOP Working Group <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Working Group Last Call draft-ietf-dnsop-structured-dns-error
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/t9ObLR2C8Nm2fhUn_5bcn3Bczyo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Thanks Stephane for the review. Please see inline

On Sat, 2 Nov 2024 at 22:59, Stephane Bortzmeyer <bortzmeyer=
40nic.fr@dmarc.ietf.org> wrote:

> On Sat, Oct 26, 2024 at 10:10:43PM +0200,
>  Benno Overeinder <benno@NLnetLabs.nl> wrote
>  a message of 25 lines which said:
>
> > This initiates the Working Group Last Call (WGLC) for
> > draft-ietf-dnsop-structured-dns-error, "Structured Error Data for
> Filtered
> > DNS."
>
> The draft is very useful (users need to be informed) and I think the
> solution chosen (I-JSON in the EXTRA-TEXT) is reasonable. The draft is
> clear. But there are two issues, one being serious.
>
> The "j" field is in natural language but there is no way to tag it wth
> the language used. (RFC 2277, section 4.2). There is a note "If the
> text is displayed in a language not known to the end user, browser
> extensions to translate to user's native language can be used." which
> is useless (the text will probably be short and therefore detecting
> the langague used will be a challenge; also, there are not only
> browsers in the field). I suggest to delete the sentence and either to
> add a field to tag the language (RFC 5646) or, if it's a too important
> change, add a sentence like "The text will be in natural language,
> chosen by the DNS administrator to match its expected audience".
>

Good point, we updated the draft
https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-structured-dns-error/blob/main/draft-ietf-dnsop-structured-dns-error.md
to address both the comments. "l" field is added to indicate the language
used for the JSON-encoded "j" and "o" fields. The text related to browser
extension is deleted.


>
> Less serious, when discussing the alternative (forged IP address and a
> Web page to explain the censorship), the draft says "If an HTTPS
> enabled domain is blocked, the block page is also served over HTTPS.
> In order to return a block page over HTTPS, man in the middle (MITM)
> is enabled on endpoints by generating a local root certificate and an
> accompanying (local) public/private key pair. " All the arguments in
> the draft against using a Web page to inform the user are for
> HTTPS. But the draft should add that, even with HTTP, this "solution"
> raises a privacy problem: the HTTP server will see the IP address of
> the client and the host name requested. (If you read french, this page
> from the government
> <
> https://www.interieur.gouv.fr/Archives/Archives-des-actualites/2016-Actualites/Redirection-vers-la-page-de-blocage-des-sites-terroristes-pour-les-clients-de-l-operateur-orange
> >
> discusses what happened after a configuration error redirecting many
> users to a governement page accusing them of trying to access
> terrorist resources. The governement claims it requested the deletion
> of the HTTP server logfile. Note that this governement promised years
> ago to not log this data.)
>

Thanks, added the privacy issue of sharing the endpoint IP address and
domain name accessed by the user with the HTTPS server.

Cheers,
-Tiru


>
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org
>