[dnssd] Draft minutes of Seoul meeting

Tim Chown <Tim.Chown@jisc.ac.uk> Tue, 22 November 2016 13:27 UTC

Return-Path: <tim.chown@jisc.ac.uk>
X-Original-To: dnssd@ietfa.amsl.com
Delivered-To: dnssd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4AC52129E32 for <dnssd@ietfa.amsl.com>; Tue, 22 Nov 2016 05:27:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.11
X-Spam-Level:
X-Spam-Status: No, score=-4.11 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, T_DKIM_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=jisc365.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PBDho0j6kbG6 for <dnssd@ietfa.amsl.com>; Tue, 22 Nov 2016 05:27:17 -0800 (PST)
Received: from eu-smtp-delivery-189.mimecast.com (eu-smtp-delivery-189.mimecast.com [207.82.80.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8B9F129E47 for <dnssd@ietf.org>; Tue, 22 Nov 2016 05:27:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jisc365.onmicrosoft.com; s=selector1-jisc-ac-uk; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=LY0rhvgdMdUUBDrCBpv2ap/k9JNrmKfooKcR8my8wyo=; b=Z8kuGEq8LWDH7zzTIhHXYdnANVGWYRTPSupHnlD+5Is5E1JidxvXsFGsGHKn/bcPDwRwSufVArtimQeS7SGZ0iaTkQiWatzFOWwf6amAuDMbTNjZ1/WrP2ouAUcs5/be+qj9ttCXl0Dk7UdcJqAyUNwBWybiQSIn6Zk8QxrjdHA=
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-he1eur01lp0212.outbound.protection.outlook.com [213.199.154.212]) (Using TLS) by eu-smtp-1.mimecast.com with ESMTP id uk-mta-70-ypsREGlCPcWPDx2MbaeLcw-1; Tue, 22 Nov 2016 13:26:57 +0000
Received: from AM3PR07MB1140.eurprd07.prod.outlook.com (10.163.188.14) by AM3PR07MB1140.eurprd07.prod.outlook.com (10.163.188.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.734.2; Tue, 22 Nov 2016 13:26:55 +0000
Received: from AM3PR07MB1140.eurprd07.prod.outlook.com ([fe80::d9ee:f373:b37e:9c77]) by AM3PR07MB1140.eurprd07.prod.outlook.com ([fe80::d9ee:f373:b37e:9c77%15]) with mapi id 15.01.0734.007; Tue, 22 Nov 2016 13:26:55 +0000
From: Tim Chown <Tim.Chown@jisc.ac.uk>
To: "dnssd@ietf.org" <dnssd@ietf.org>
Thread-Topic: Draft minutes of Seoul meeting
Thread-Index: AQHSRMQYA/J6gg1lfUqe6Y9TZQSAvw==
Date: Tue, 22 Nov 2016 13:26:55 +0000
Message-ID: <709A696F-D297-48AA-849F-4E9B8AC8042F@jisc.ac.uk>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3251)
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [194.82.140.195]
x-microsoft-exchange-diagnostics: 1; AM3PR07MB1140; 7:w2qQi8pRUBFbEWtt+u/mR2S2zVEMfm7y97I6EP15b86nRbeb5ITzjjKgiFEsWEoxdJctJasXdHBQmKgQQZqAbwhc5myAQyCq8/kkpHnXY/xQnQ/J/VW+ldxKhCGTR/nJKwnjTXNPJcomkKeeE0wCSQMRaIfokXOY75dxuYM3TDoHGhIZF5hUTmAtVuAHEP5W6KCCSTkx+vTUFduuAeoc8DUON+2YVn7Ay3aWROLeazHGcybbFbktJ+JdgErV4NIWfz/AmmBRJyPRcjkcn3wnxhMxyfc/rp6Hp9XBPVKZmZbjaIBzU47DiM00KhSbEU2uRrn2JVR3Me+bMscxbIEbM9SMLQ7wS8tJ20fKRQdCH6A=; 20:RzHNYo9/LyXVXpMhJVSx0MBM91oHVTa2kt5LZ80LvQvlFNGColN4gAZ+6PVLmU/6dmuJ+JRP3Ny4AiT+CKPi/ZPUrLo/IGdQ/hQADlikQbsdKJlu0g2iP/STXgflMAPdzTX8qxP1WiKc74oBwCeQOd6Un++8ShyA29X14/lY4FQ=
x-ms-office365-filtering-correlation-id: fd984291-1bc6-4612-1dfa-08d412db3ab3
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:AM3PR07MB1140;
x-microsoft-antispam-prvs: <AM3PR07MB11403F0A0B162179650A6883D6B40@AM3PR07MB1140.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(20558992708506)(166708455590820)(192374486261705)(17755550239193);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6060326)(6040307)(6045199)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(6041248)(6061324); SRVR:AM3PR07MB1140; BCL:0; PCL:0; RULEID:; SRVR:AM3PR07MB1140;
x-forefront-prvs: 0134AD334F
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(7916002)(189002)(66654002)(199003)(42882006)(6916009)(6512003)(189998001)(6506003)(74482002)(3660700001)(57306001)(7906003)(7736002)(7846002)(50986999)(86362001)(8676002)(38730400001)(105586002)(2351001)(101416001)(5640700001)(106356001)(551984002)(6116002)(2501003)(81156014)(83716003)(81166006)(1730700003)(5250100002)(3846002)(92566002)(87936001)(102836003)(4326007)(5660300001)(106116001)(606004)(68736007)(97736004)(50226002)(33656002)(36756003)(2906002)(66066001)(2900100001)(110136003)(8936002)(3280700002)(82746002)(104396002)(559001)(579004); DIR:OUT; SFP:1101; SCL:1; SRVR:AM3PR07MB1140; H:AM3PR07MB1140.eurprd07.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
MIME-Version: 1.0
X-OriginatorOrg: jisc.ac.uk
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Nov 2016 13:26:55.6756 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 48f9394d-8a14-4d27-82a6-f35f12361205
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM3PR07MB1140
X-MC-Unique: ypsREGlCPcWPDx2MbaeLcw-1
Content-Type: multipart/alternative; boundary="_000_709A696FD29748AA849F4E9B8AC8042Fjiscacuk_"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnssd/tnI1uyFntqtJHZxikn_0FpPLUzo>
Cc: Ole Troan <otroan@employees.org>
Subject: [dnssd] Draft minutes of Seoul meeting
X-BeenThere: dnssd@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Discussion of extensions to DNS-based service discovery for routed networks." <dnssd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnssd>, <mailto:dnssd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnssd/>
List-Post: <mailto:dnssd@ietf.org>
List-Help: <mailto:dnssd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnssd>, <mailto:dnssd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Nov 2016 13:27:22 -0000

Hi,

Many thanks to Ole for taking these (and for the Easter Egg, which I removed :).

Please let me know of any corrections; I'll upload the final version on Friday.

Tim


IETF97, Seoul
Thursday November 17th 2017
09:30am - 11:00am local time

Minutes: Ole Troan

Chairs’ Introduction
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-chairs-slides-02.pptx

Tim Wicinski deputising for Ralph.
* Document status
  Nothing to note



* Goals
* Agenda
  No comments


Hybrid Unicast/Multicast DNS-Based Service Discovery, Stuart Cheshire
https://tools.ietf.org/html/draft-ietf-dnssd-hybrid-04
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-hybrid-proxy-00.pdf

Question for the group: Change naming of hybrid proxy?
Suggestion:
    s/Hybrid proxy/Discovery proxy
    and Advertising proxy

Tim Chown: You might call it hybrid discovery proxy?
Comments from room (several): Prefer Discovery proxy.

Chairs: 1) Hum if you want to change to discovery proxy?
        2) Hum if not, or
        3) hum if you want something else.
*All hums in agreement for name change.*


DNS Push Notifications, Stuart Cheshire
https://tools.ietf.org/html/draft-ietf-dnssd-push-09
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-dns-push-00.pdf

No comments.


DNS Session Signalling, Stuart Cheshire
https://tools.ietf.org/html/draft-ietf-dnsop-session-signal-01
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-dns-sd-session-signal-00.pdf

Ray: I would still prefer to have the full DNS header. It was Mark Andrews who wanted the abbreviated version.
Mark Andrews: It depends on what the opcode is going to do. You need at least 12 or more bytes.
Stuart: It makes sense, will do another round of editing and will go back to the standard 12 byte header.
Mark A: The last 8 bytes can be payload.
Stuart: If the payload is too short you may have to add padding then?
Mark A: You only need one TLV it is just padding either way.
Stuart: Wireshark/tcpdump will work as expected if the 8 bytes are the standard header, if we used them for payload they wouldn't.
Mark A: I'd be tempted to have a length field after the 4 first bytes.
Stuart: The TLV has lenght (L), but if 0 length would not meet 8 byte minimum. ...
Mark A: I'm thinking of the sum of TLV length. We can deal with it later.
Ray: We got some ideas on this one. Whatever happens we need a wireshark update. What Mark said that 12 bytes was minimum was new to me. So we have to take this offline.

Open question 1 (No additional record section) - slide 3
Problem:
    No TSIG
    No EDNS(0)
    No EDNS(0) Padding option for security RFC7830

Opinions on this problem, please discuss on the DNSOP list.
*Question to be resolved on list. Must be resolved before document can proceed.*


Tim C: Interesting to see what other uses will appear when people become aware of this. To be discussed in DNSO

Sara Dickinson: We have DNS keepalive defined at the moment. Not a great solution. I see this as completely superceeding this.
Rick Taylor: General danger that you are forking the DNS packet format? Let's make it look like the rest of DNS. Separate code path...
Stuart: I'm hearing broad agreement to use the standard 12 byte header.

Open question 2 - does every message require a response?

-> No opinions in the room. Must be resolved on the list.

Open question 3 - Change IDLE TIMEOUT to KEEPALIVE INTERVAL?

-> No comment in room

Bernie Volz: Question 2. For the TCP case the reply has to be acked, so you aren't winning anything of setting a reply.
Stuart / Bernie: Discussion.
Bernie: The only benefit if you send a reply back, is that the client could have a short timeout, cause the client would know it gets a reply.
Tim: Carry on that discussion on the DNSOP list.

Chairs: Stuart has promised a new revision.
Stuart: Umm, yes. I'm working on it. Proxy having some short-comings, e.g. merging links. Stuart discussing possibly future directions this work could take.

Ralph Droms (remote): Moving along a spectrum towards a centralized unicast DNS-SD?
Stuart: Yes. Hard to predict. Expected a move to unicast DNS-SD, but vendors appear OK with mDNS. Lots of things have mDNS support but not a DNS Update client.

Stuart: On future roadmap. We've been talking about how this technology can be helful for Apple's new campus. You don't want to discover everything in a large network. Some sort of sliding window model where I discover where I am, and discover things close to me. I call it an aggregating proxy. ...

Tim: A similar issue at our campus where we have VLAN pooling implemented on the Wireless LAN Controllers, so you can be stood next to someone, yet be in a different subnet.
Ralph: Lots of different ways to put these building blocks together.
Tim: We need a guidance document on how to deploy this in an Enterprise environment.
Ralph: The "aggegate proxy" might have some benefits, possibly being centrally managed.
Stuart: Yes, taking it to the its logical solution, it can be centrally managed in a big iron server. The server could talk to distributed discovery proxies.

* Open discussion continuing about the possible future of this work*

Tim: The BCP document on enterprise/campus scalable DNS-SD would be useful to move forward.
Rick Taylor: Use case for advertising proxies. Container use case, where a composite device creates containers for 3rd party devices.

No conclusion.

Privacy Extensions for DNS-SD, Ralph Droms (remote)
https://tools.ietf.org/html/draft-ietf-dnssd-privacy-00
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-dns-sd-privacy-01.pptx

Six people have read the DNS privacy draft and the pairing draft.

Tim: *Discussion on how scaling can be done*. We have agreement from an AD that someone in the Security Area is going to do a formal review.
Henning Schulzrinne: It would require some level of crypto would be recquired to get this right. And how much pre-configuration would be required.
Tim: If both parties want to communicate this way it is incrementally deployable. The WG need to keep the that in mind.
Ralph: ... You only have to do the set of printers once. It is incremental.
Tim: Described in the pairing document. With the alternative approaches.
Henning S: Can you reuse existing security relationships

Need review.

Device Pairing Using Short Authentication Strings, Ralph Droms (remote)
https://tools.ietf.org/html/draft-ietf-dnssd-pairing-00
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-dns-sd-pairing-protocol-01.pptx

Will also be reviewed in the Security Area.


Stateful Multi-Link DNS Service Discovery, Ted Lemon
https://tools.ietf.org/html/draft-lemon-stateful-dnssd-00
Slides: https://www.ietf.org/proceedings/97/slides/slides-97-dnssd-stateful-multi-link-dns-based-service-discovery-01.pdf

Stuart C: I agree with you. DNS Update seems like a pain in the arse. It is very complicated trying to combine all the updates into something that is efficient. Large precedent to do it over HTTPS.

Tim: Where do we go next on this?

Ted: I think I need to do more homework before the WG takes a serious look at it.
Henning S: Confused what the practical use case is.
Ted: The use case at this point is your device discovers a device inside the home and you want that device to have the same name outside of the home.
I want in my home to publish services available outside of the home.
Henning/Ted: ...discussing the use case. And vendor implementations / security aspects of publishing it in the DNS.
Stuart: Thanks for doing this Ted it is interesting. It is a good area to explore. Happy to work with you here.

*Stuart volunteers to work with Ted on the document*.


Discussion: Other drafts, implementations, and next steps, Chairs
- includes recommendations for using the hybrid proxy in campus environments
- noting https://github.com/pusateri/draft-pusateri-hybridproxy-impl/blob/master/draft-pusateri-dnssd-hyp-impl.txt

Chair reviews where we are with other drafts, milestones and outcomes of today.


Close and summary of actions, Chairs

Chair summarizing actions:
1) The hybrid proxy draft will be submitted to the IESG as the DNS-SD Discovery proxy.  Stuart Cheshire to update -05.
2) Stuart will produce a new I-D on the DNS-SD Advertising Proxy
3) The DNS Push draft is close to being ready for WGLC; chairs to check with authors.
4) Open issues with the DNS Session Signalling draft will be resolved in dnsop; action on Tim Wicinski (dnsop co-chair) to push it forward
5) Chairs to ensure SAAG review of both privacy drafts happen soon; authors to progress work; TLS decision required; implementation reports expected in IETF98.
6) New draft required on stitching links together (from naming perspective); of particular interest in homenet scenario; chairs to solicit authors.
7) Volunteers required to assist Ralph Droms and Tom Pusateri in producing a -00 of BCP for enterprise/campus scenarios
8) Chairs to review WG milestones with AD
9) Chairs will provide shepherd writeup for label interop draft so it can go to the IESG.


Meeting closed at 10:54.