Re: [Doh] New version: draft-ietf-doh-resolver-associated-doh-03.txt

Joseph Lorenzo Hall <joe@cdt.org> Sun, 24 March 2019 09:12 UTC

Return-Path: <jhall@cdt.org>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 124A7127984 for <doh@ietfa.amsl.com>; Sun, 24 Mar 2019 02:12:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cdt.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jfbuZUSOTdiC for <doh@ietfa.amsl.com>; Sun, 24 Mar 2019 02:12:33 -0700 (PDT)
Received: from mail-ot1-x331.google.com (mail-ot1-x331.google.com [IPv6:2607:f8b0:4864:20::331]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64C65127971 for <doh@ietf.org>; Sun, 24 Mar 2019 02:12:33 -0700 (PDT)
Received: by mail-ot1-x331.google.com with SMTP id t8so225784otp.7 for <doh@ietf.org>; Sun, 24 Mar 2019 02:12:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cdt.org; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=ESFvFH0+N6SYsBUInrd2NdKv57VXVQpnsesq9FevAlw=; b=L7/6INd2Rwljittf/IrV2gWQUaNeNSH8lHhMmx3Sqs9M+4rovS4qaWtBZrJ7Fla29f JGX872CiKCgISNs1ZZxej6mdMWdXwjy+kSZnAZ9wF5Ure1VOfKv1sug4C9Zdunxo3lxu EwBbGG9+lj6g3FNXOxu+awtkPjT8XrZloH408=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=ESFvFH0+N6SYsBUInrd2NdKv57VXVQpnsesq9FevAlw=; b=ioBgZh0B6eetRNwLY7T02XGLUoh9trx/EPXiRtMz/kS4nsetptUKumHzEdKCiJWeDw l7zpz3cYF4KLlyOw56aNNIcf4BaSu185xVeRzIOVrO+lbNSg5WrXwbFlUHkSXcHbDFky JVUjnCXvhYl8zPvE4dWBoZstN2AILJHbkogLAog9sVjrQVyLI8Bh2Y95DwInFSVOj1jv KNYNYZs8qsPxJc0Rk2NoIcV4wyhYM2DHqbNnCkLNnWa95vkFJsoUcu2XB+EgFr4l1DDw nY2fgeaKez+0OyhbC4iwYGxgRzqMLTkJRl0iu+g3wUEJp10u6ZU0EEARrzmye4gu2fup POTg==
X-Gm-Message-State: APjAAAVAskRkWfoDo5pVM8ousR400ghDbF6cSwrBhDGM123mZo1KsGIe t40EObvXgmJezWclhDq09VxgNLFCSOGHCaxMoNuWV9wuki8=
X-Google-Smtp-Source: APXvYqzWb/biu0Aa041QdPf83l1mx/44QzYnpQsQewZCRHmeO4t2XP7pEvxdFthZEqctQOAz9vFPQ3G5W69E7D+mdC4=
X-Received: by 2002:a9d:368:: with SMTP id 95mr13648279otv.49.1553418752398; Sun, 24 Mar 2019 02:12:32 -0700 (PDT)
MIME-Version: 1.0
References: <155341529409.18062.10657099011172813446@ietfa.amsl.com> <55AE7511-5BDF-4E96-84B3-BD0B6E6C6FE3@icann.org>
In-Reply-To: <55AE7511-5BDF-4E96-84B3-BD0B6E6C6FE3@icann.org>
From: Joseph Lorenzo Hall <joe@cdt.org>
Date: Sun, 24 Mar 2019 10:12:20 +0100
Message-ID: <CABtrr-WX3UVnT1ZEkVoP-njqvBRwDTtd0tofgjjrmX6c=JhKhg@mail.gmail.com>
To: Paul Hoffman <paul.hoffman@icann.org>
Cc: DoH WG <doh@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000ecab0b0584d37cc8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/FlyRO1jcyStdQGqgnjI4ptq5-co>
Subject: Re: [Doh] New version: draft-ietf-doh-resolver-associated-doh-03.txt
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 24 Mar 2019 09:12:36 -0000

Couple of small things:

typo, Intro: "Users typically configure their DNS recursive resolvers with
through automatic configuration"

I don't get the "Do53" abbreviation, but I'll grab you and maybe you can
help me make sense of it (a very small thing considering you could have
said DoPotatoes or whatever).

Are there any outcomes you can see where IANA is compelled to delegate the
SUDNs here? Or where an authoritarian government might require resolvers to
collide, if that makes sense?

In privacy considerations the draft says, "can increase communication
privacy because of the TLS protection." I'm wondering if it makes sense to
say explicitly "confidentiality and integrity" in a parenthetical near
privacy?

Thanks for this work, feel free to respond on-list if helpful!

On Sun, Mar 24, 2019 at 09:20 Paul Hoffman <paul.hoffman@icann.org> wrote:

> The diffs here are what I think have general agreement from the discussion
> about this draft so far, but I may have missed things. Comments are still
> quite welcome.
>
> As for the late discussion of using the URI RRtype instead of TXT, I would
> not know what to put in the "priority" and "weight" values. That alone
> seems enough reason to leave this as a TXT record, but others might
> disagree. It's not a lot of effort to change the text to the URI RRtype,
> but I don't want to do so unless it is actually better than TXT.
>
> --Paul Hoffman
> _______________________________________________
> Doh mailing list
> Doh@ietf.org
> https://www.ietf.org/mailman/listinfo/doh
>
-- 
Joseph Lorenzo Hall
Chief Technologist, Center for Democracy & Technology [https://www.cdt.org]
1401 K ST NW STE 200, Washington DC 20005-3497
e: joe@cdt.org, p: 202.407.8825, pgp: https://josephhall.org/gpg-key
Fingerprint: 3CA2 8D7B 9F6D DBD3 4B10  1607 5F86 6987 40A9 A871