[homenet] Paul Wouters' Discuss on draft-ietf-homenet-naming-architecture-dhc-options-21: (with DISCUSS)

Paul Wouters via Datatracker <noreply@ietf.org> Thu, 20 October 2022 05:57 UTC

Return-Path: <noreply@ietf.org>
X-Original-To: homenet@ietf.org
Delivered-To: homenet@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id CD058C15256E; Wed, 19 Oct 2022 22:57:43 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Paul Wouters via Datatracker <noreply@ietf.org>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-homenet-naming-architecture-dhc-options@ietf.org, homenet-chairs@ietf.org, homenet@ietf.org, stephen.farrell@cs.tcd.ie, stephen.farrell@cs.tcd.ie
X-Test-IDTracker: no
X-IETF-IDTracker: 8.18.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: Paul Wouters <paul.wouters@aiven.io>
Message-ID: <166624546383.55524.17919861797763262507@ietfa.amsl.com>
Date: Wed, 19 Oct 2022 22:57:43 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/homenet/qei_qEgC_S7vYcim0-EKDvNz9ZI>
Subject: [homenet] Paul Wouters' Discuss on draft-ietf-homenet-naming-architecture-dhc-options-21: (with DISCUSS)
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.39
List-Id: IETF Homenet WG mailing list <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Oct 2022 05:57:43 -0000

Paul Wouters has entered the following ballot position for
draft-ietf-homenet-naming-architecture-dhc-options-21: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-homenet-naming-architecture-dhc-options/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

This might be my misunderstanding of homenet, so hopefully easy to resolve.

The HNA (hidden primary?) to DM (primary) DNS communication using DNS Update
needs some kind of authentication, TSIG or SIG0 ? While TLS gives you privacy,
the DNS Update cannot be done with only TLS (as far as I understand it). I
don't see any DHCP options to relay authentication information for automatic
deployment? So I don't understand how this would startup and be able to setup a
secure DNS update channel ?

There was also talk about using ACME for TLS certificates, but wouldn't that
require that the HNA already has a provisioned and working homenet domain ?
(possibly more a question for the other draft, but just adding it here in case
the hidden primary to primary is an "almost DNS Update" protocol that uses TLS
instead f TSIG/SIG0.