Re: [Doh] [DNSOP] New I-D: draft-reid-doh-operator

Paul Vixie <paul@redbarn.org> Sat, 23 March 2019 13:07 UTC

Return-Path: <paul@redbarn.org>
X-Original-To: doh@ietfa.amsl.com
Delivered-To: doh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C8D2412426E; Sat, 23 Mar 2019 06:07:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, NORMAL_HTTP_TO_IP=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RS7ax7mQnfTh; Sat, 23 Mar 2019 06:07:56 -0700 (PDT)
Received: from family.redbarn.org (family.redbarn.org [IPv6:2001:559:8000:cd::5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C19D412008A; Sat, 23 Mar 2019 06:07:56 -0700 (PDT)
Received: from [10.55.45.227] (unknown [88.128.80.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by family.redbarn.org (Postfix) with ESMTPSA id EAE38892C6; Sat, 23 Mar 2019 13:07:53 +0000 (UTC)
In-Reply-To: <20190323113849.GB12400@puck.nether.net>
References: <155218771419.28706.1428072426137578566.idtracker@ietfa.amsl.com> <1914607.BasjITR8KA@linux-9daj> <CA+9kkMAYR19CCCLN00A5Oy_=9Z97FQogCz-vdC=M7Ffn47fTgQ@mail.gmail.com> <1900056.F7IrilhNgi@linux-9daj> <CA+9kkMCgmzjbPM+DTUYuS3OsT+wOCmsyaGPg6fPu=w-ibL=NrA@mail.gmail.com> <5F768C24-4ECF-4369-9D51-B90C4426409B@fl1ger.de> <428d5ff2b5704cdf956a5919e330e4dc@cira.ca> <CAH1iCir4A9Af5FfG4YqiqxjEHDYmqdFZLwa6+Y6HJwLTM0id8w@mail.gmail.com> <2D770C50-FDF8-481F-AFE8-642020A77694@puck.nether.net> <ae1644c6-dd2f-5960-1cc8-39d8126ef543@redbarn.org> <20190323113849.GB12400@puck.nether.net>
X-Referenced-Uid: 738010
Thread-Topic: Re: [DNSOP] [Doh] New I-D: draft-reid-doh-operator
User-Agent: Android
X-Is-Generated-Message-Id: true
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----Q8D79WF91NG8AX6TVYBX1GZZXX7LJT"
Content-Transfer-Encoding: 7bit
From: Paul Vixie <paul@redbarn.org>
Date: Sat, 23 Mar 2019 14:07:50 +0100
To: Jared Mauch <jared@puck.nether.net>
CC: Brian Dickson <brian.peter.dickson@gmail.com>, Jacques Latour <jacques.latour@cira.ca>, Ted Hardie <ted.ietf@gmail.com>, DoH WG <doh@ietf.org>, dnsop <dnsop@ietf.org>, Ralf Weber <dns@fl1ger.de>
Message-ID: <88e50a18-698c-4627-8a4a-adfd97a4e17e@redbarn.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/doh/mYamS8akE4uhJNKRU3Df57-vmAU>
Subject: Re: [Doh] [DNSOP] New I-D: draft-reid-doh-operator
X-BeenThere: doh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: DNS Over HTTPS <doh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/doh>, <mailto:doh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/doh/>
List-Post: <mailto:doh@ietf.org>
List-Help: <mailto:doh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/doh>, <mailto:doh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 23 Mar 2019 13:07:59 -0000

Bind9 with no config file now does the right recursive thing, including dnssec. Knot and unbound and powerdns will not be far behind. We just need to get the word out, to ISPs, Enterprise, SOHO, and end users of Windows, macosx, Linux, and BSD. The hard part will be iOS and Android, due to the permission model and app stores. Those can be last.

⁣Get BlueMail for Android ​

On Mar 23, 2019, 12:39, at 12:39, Jared Mauch <jared@puck.nether.net> wrote:
>On Fri, Mar 22, 2019 at 12:26:47PM -0700, Paul Vixie wrote:
>> 
>> 
>> Jared Mauch wrote on 2019-03-22 11:59:
>> > So my thoughts on this real quick: one of the reasons many people
>are
>> > using centralized services like 8.8.8.8 (for example) is its
>complex
>> > to run these servers properly.
>> 
>> i think those optics are the motive, as you say.
>> 
>> however, it is not complex, as you also say.
>> 
>> the optics have been encouraged.
>> 
>> they are misleading.
>
>I think for you and I it's less complex.  When I discuss things with
>smaller ISPs running DNS isn't even on their list of things anymore,
>similar
>to e-mail and other things where to run the service requires some
>scale.
>
>I've seen some quite large providers be unable to configure some simple
>DNS settings properly.  You have to also look no further than the
>research that Mark Andrews and others have done about standards
>compliance.
>
>I don't think it's as hard as it could be, but it's not as easy either.
>
>- Jared
>
>-- 
>Jared Mauch  | pgp key available via finger from jared@puck.nether.net
>clue++;      | http://puck.nether.net/~jared/  My statements are only
>mine.