Re: [Doh] [Ext] Fallback to untrusted DOH servers

Paul Hoffman <paul.hoffman@icann.org> Mon, 23 April 2018 14:11 UTC

Return-Path: <paul.hoffman@icann.org>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DCF95126CD6 for <doh@ietfa.amsl.com>; Mon, 23 Apr 2018 07:11:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ik10u5lvGGKQ for <doh@ietfa.amsl.com>; Mon, 23 Apr 2018 07:11:15 -0700 (PDT)
Received: from out.west.pexch112.icann.org (pfe112-ca-2.pexch112.icann.org [64.78.40.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A82441201F8 for <doh@ietf.org>; Mon, 23 Apr 2018 07:11:15 -0700 (PDT)
Received: from PMBX112-W1-CA-1.pexch112.icann.org (64.78.40.21) by PMBX112-W1-CA-1.pexch112.icann.org (64.78.40.21) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Mon, 23 Apr 2018 07:11:13 -0700
Received: from PMBX112-W1-CA-1.pexch112.icann.org ([64.78.40.21]) by PMBX112-W1-CA-1.PEXCH112.ICANN.ORG ([64.78.40.21]) with mapi id 15.00.1178.000; Mon, 23 Apr 2018 07:11:13 -0700
From: Paul Hoffman <paul.hoffman@icann.org>
To: Mateusz Jończyk <mat.jonczyk@o2.pl>
CC: DoH WG <doh@ietf.org>
Thread-Topic: [Doh] [Ext] Fallback to untrusted DOH servers
Thread-Index: AQHT1O4btV7cjbCdoU2f7xFlpQyfG6QNRTMAgAAfwgCAATO4AIAAM2sAgAAEdgCAABSvAA==
Date: Mon, 23 Apr 2018 14:11:13 +0000
Message-ID: <BFBE3B13-15DF-45D5-8E8A-A4DC5B476357@icann.org>
References: <f17cbdf0-cd88-9fa9-c83d-26e2cf13b8c1@o2.pl> <21B4DD30-46B0-4E63-833E-FDE66EF28F95@icann.org> <765e9e5a-9b8c-fa1c-85b5-da824807e609@o2.pl> <CAOdDvNrC6VGQtCYgLOoRvwCGn0kRJuchncFj4m5r_KZ-ig7=NA@mail.gmail.com> <28678acd-f67d-7f95-273f-26ed1115d3ee@o2.pl> <75B0BB57-A222-4328-A155-E5C351DEB7CC@icann.org> <3457562c-5576-18ea-a764-d485d870b5ea@o2.pl> <CAOdDvNqft5RwHcf1Ds-nzCZ=ha1weBTwbP4KzMLoHHwJQt0bVQ@mail.gmail.com> <46145a1e-99a9-405f-9f5c-4b85005feaf9@o2.pl>
In-Reply-To: <46145a1e-99a9-405f-9f5c-4b85005feaf9@o2.pl>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [192.0.32.234]
Content-Type: multipart/signed; boundary="Apple-Mail=_F0A06D2C-7FF1-4430-9722-80C3165FAEE8"; protocol="application/pgp-signature"; micalg="pgp-sha256"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/VbO77FOlvaEiE9Mz3hGiyZwOpKA>
Subject: Re: [Doh] [Ext] Fallback to untrusted DOH servers
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Apr 2018 14:11:17 -0000

On Apr 23, 2018, at 5:56 AM, Mateusz Jończyk <mat.jonczyk@o2.pl> wrote:
> 
> What I am discussing here are modifications to DOH so that adding support for
> discovery would be possible without modifying the future RFC.

Updating RFCs for reasons like this happens all the time in the IETF. Given that we don't know when such an update will happen (and I still believe it will take a long time to reconcile all of the DNS resolver discovery methods), it is better to leave the wording as-is and then update it when the complete document comes out.

--Paul Hoffman