Re: [Doh] Seeking input on draft-03

Patrick McManus <pmcmanus@mozilla.com> Thu, 08 February 2018 20:24 UTC

Return-Path: <pmcmanus@mozilla.com>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 234F2127275 for <doh@ietfa.amsl.com>; Thu, 8 Feb 2018 12:24:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.102
X-Spam-Level: **
X-Spam-Status: No, score=2.102 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_SBL_CSS=3.335, SPF_SOFTFAIL=0.665, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zLph5V_SMgLf for <doh@ietfa.amsl.com>; Thu, 8 Feb 2018 12:24:20 -0800 (PST)
Received: from linode64.ducksong.com (linode6only.ducksong.com [IPv6:2600:3c02::f03c:91ff:fe6e:e8da]) by ietfa.amsl.com (Postfix) with ESMTP id 673FF127076 for <doh@ietf.org>; Thu, 8 Feb 2018 12:24:20 -0800 (PST)
Received: from mail-ot0-f182.google.com (mail-ot0-f182.google.com [74.125.82.182]) by linode64.ducksong.com (Postfix) with ESMTPSA id 6008E3A054 for <doh@ietf.org>; Thu, 8 Feb 2018 15:24:18 -0500 (EST)
Received: by mail-ot0-f182.google.com with SMTP id r23so5555669ote.8 for <doh@ietf.org>; Thu, 08 Feb 2018 12:24:18 -0800 (PST)
X-Gm-Message-State: APf1xPCFr+NLRdMUDtXOJ635nCwfZc0+ZrmbrYpYt5oe+O6q2rLSucf5 m3Wj3sOcX0FlplFtOJdX3pBepZeIlZbvpbFBO5Y=
X-Google-Smtp-Source: AH8x226BTyPoIbSkgZ9236rI2XfpWEafedmhFdQDwubVj0mq0Ye39UNScmdYXbz5OLTZTizP/mSDjwtqUkjtjKz/HJ8=
X-Received: by 10.157.81.197 with SMTP id d5mr396062oth.300.1518121457995; Thu, 08 Feb 2018 12:24:17 -0800 (PST)
MIME-Version: 1.0
Received: by 10.74.95.80 with HTTP; Thu, 8 Feb 2018 12:24:17 -0800 (PST)
In-Reply-To: <5855fc09-0518-7fb0-56b6-07a8667cbf31@cs.tcd.ie>
References: <CAHbrMsDwWvtcZy8fpg9gs3o+gc_umi9okJW6rvv+s4T7K9-sVQ@mail.gmail.com> <5855fc09-0518-7fb0-56b6-07a8667cbf31@cs.tcd.ie>
From: Patrick McManus <pmcmanus@mozilla.com>
Date: Thu, 08 Feb 2018 15:24:17 -0500
X-Gmail-Original-Message-ID: <CAOdDvNqS=cQe2a4bkKO2eGK9wih6gcwmQEhU8XHQcs+yk-W7ug@mail.gmail.com>
Message-ID: <CAOdDvNqS=cQe2a4bkKO2eGK9wih6gcwmQEhU8XHQcs+yk-W7ug@mail.gmail.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: Ben Schwartz <bemasc@google.com>, doh@ietf.org
Content-Type: multipart/alternative; boundary="f403043d7ef03aee320564b93248"
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/XJDBgZ9GFiIFjdvWAFSlCSt7bFU>
Subject: Re: [Doh] Seeking input on draft-03
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Feb 2018 20:24:23 -0000

WRT the removal of .wk:

* its previous presence had never been meant as a discovery mechanism of
the form "I know a hostname, therefore I know the URL". origin is a
security primitive for http, but its not an addressing primitive for http
services such as a DoH endpoint.. indeed the DoH server might sensibly wish
to offer multiple URIs on the same host (in the same way some free dns
providers make a variety of resolution policies available with different IP
addresses).  The configuration primitive for a DoH server is the URI - not
origin.

* I had originally included .wk as a bit of future proofing for a use case
not part of the DoH charter (not to enable it, but being sure not to
preclude it at a later time). I have been convinced that .wk is not
necessary for that - and so it was removed from the draft. I regret that
these two things were confused by readers of <= -02 due to my own
composition skills (or lack thereof).

As to Stephen's query - this was both discussed f2f in singapore and
https://github.com/dohwg/draft-ietf-doh-dns-over-https/issues/24 . Of
course there hasn't been consensus declared on the issue - the editors are
just trying to make the newer drafts as closely aligned with the group's
discussion as we can manage as part of the process.

-P


On Thu, Feb 8, 2018 at 2:56 PM, Stephen Farrell <stephen.farrell@cs.tcd.ie>
wrote:

>
>
> On 08/02/18 18:05, Ben Schwartz wrote:
> >
> > One important difference is that draft-03 no longer proposes a
> > ".well-known" entry.  In draft-02 and prior, clients could check for the
> > presence of a DOH service at the default path, given only the domain name
> > of a server.  In draft-03, there is no default path, so clients must be
> > configured with the full URL of the DOH endpoint.
>
> Apologies if I'm forgetting a thread where this was discussed,
> but what's the reason for dropping .well-known? (If there is a
> thread, a pointer to that is a sufficient answer.)
>
> Thanks,
> S.
>
> --
> PGP key change time for me.
> New-ID 7B172BEA; old-ID 805F8DA2 expires Jan 24 2018.
> NewWithOld sigs in keyservers.
> Sorry if that mucks something up;-)
>
> _______________________________________________
> Doh mailing list
> Doh@ietf.org
> https://www.ietf.org/mailman/listinfo/doh
>
>