Re: [Doh] DOH and split DNS

Eliot Lear <> Thu, 09 November 2017 11:06 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id D746812F3D0 for <>; Thu, 9 Nov 2017 03:06:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id Y4a85NTWd7IO for <>; Thu, 9 Nov 2017 03:06:09 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id C7F8C12EC8E for <>; Thu, 9 Nov 2017 03:06:08 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple;;; l=3147; q=dns/txt; s=iport; t=1510225569; x=1511435169; h=subject:to:references:from:message-id:date:mime-version: in-reply-to; bh=zbKxuLmG1joCgB4xPtlVPmvPZMJi9cfVTF4+6xj8XXo=; b=SxgRAewNiBEjW1Beiyjk4mcN8eLPV343K3L8CPZMM3h1O4Y6SdnnhAe1 wsuCxeukB3mN8uynuFHZLkNcBlEpBMbHaz09OE0UyQ+JF1orXOKYt0Sqs CRHpLN8TA1uI0Za7WMejpXy0XKHa5lBCV6vP9xWT4wea5NReXS1K2Phdk o=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.44,369,1505779200"; d="asc'?scan'208";a="78753363"
Received: from (HELO ([]) by with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Nov 2017 11:06:05 +0000
Received: from [] ([]) by (8.14.5/8.14.5) with ESMTP id vA9B65nY028558; Thu, 9 Nov 2017 11:06:05 GMT
To: Andrew Sullivan <>,
References: <> <> <>
From: Eliot Lear <>
Message-ID: <>
Date: Thu, 9 Nov 2017 16:35:54 +0530
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="QQsFSLEb6novaOe4LNk92xsHiEu1kvRIO"
Archived-At: <>
Subject: Re: [Doh] DOH and split DNS
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: DNS Over HTTPS <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Thu, 09 Nov 2017 11:06:11 -0000

On 11/6/17 5:30 PM, Andrew Sullivan wrote:
> On Mon, Nov 06, 2017 at 11:13:19AM +1100, Mark Nottingham wrote:
>>  Some careful wording around the configuration mechanism should help.
>> Allowing something like proxy.pac to override DOH doesn't make any sense, given that the primary purpose of DOH is to NOT allow the local network to impose policy on communication with the DNS server.
> That careful wording had better be pretty careful.  I don't believe
> for an instant that most users have a workable theory for which
> resolution mechanism they're using, and if they configure DOH and
> suddenly all the "internal sites" don't work they're going to be
> pretty surprised.
> It strikes me as pretty strange, too, to suggest that, if a user
> configures proxy.pac, they don't want the local network to offer such
> policies.  If the user is prepared to use the proxy, presumably the
> user is prepared to use it to impose local policy, no?

That was my thinking, but I will add that this needs some more
thinking.  proxy.pac files can contain many things to match off of, and
if it's an IP address range, it won't be useful.  If it's a domain name
or wildcard (like then perhaps so.  Also, there
are some corner cases when it might not work- in some environments a
proxy may be required internally.  As such, when something is not
"direct" it might still be within one side of a split DNS fence, as it
were, and so the proxy.pac file would give the wrong answer.