[Doh] Mirja Kühlewind's No Objection on draft-ietf-doh-dns-over-https-13: (with COMMENT)

Mirja Kühlewind <ietf@kuehlewind.net> Mon, 13 August 2018 14:58 UTC

Return-Path: <ietf@kuehlewind.net>
X-Original-To: doh@ietf.org
Delivered-To: doh@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id A5100130E0A; Mon, 13 Aug 2018 07:58:58 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: Mirja Kühlewind <ietf@kuehlewind.net>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-doh-dns-over-https@ietf.org, Benjamin Schwartz <bemasc@google.com>, doh-chairs@ietf.org, bemasc@google.com, doh@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.83.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <153417233866.25070.3751592720564238859.idtracker@ietfa.amsl.com>
Date: Mon, 13 Aug 2018 07:58:58 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/Tsr0ooaYjzaOwXWAxIuTsfI3sBs>
Subject: [Doh] Mirja Kühlewind's No Objection on draft-ietf-doh-dns-over-https-13: (with COMMENT)
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.27
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Aug 2018 14:58:59 -0000

Mirja Kühlewind has entered the following ballot position for
draft-ietf-doh-dns-over-https-13: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-doh-dns-over-https/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

One question:
In case DoH doesn't work for some reason, is this supposed to fallback to DNS
over TLS? I guess if the selected host name would allow detection of DNS and
SNI is used, it wouldn't be too hard to block DoH requests....? Is that a
concern?

Also one smallish comment:
As already brought up in the TSV-ART review (Thanks Ferando!) I would recommend
to further clarify this sentence in section 5.1: "Using the GET method is
friendlier to many HTTP cache implementations." What does "friendlier" mean...?
Or at least maybe provide a forward reference to sec 6.1.