Protocol Action: 'Split DNS Configuration for IKEv2' to Proposed Standard (draft-ietf-ipsecme-split-dns-17.txt)

The IESG <iesg-secretary@ietf.org> Thu, 21 March 2019 10:13 UTC

Return-Path: <iesg-secretary@ietf.org>
X-Original-To: ietf-announce@ietf.org
Delivered-To: ietf-announce@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 2F642130F63; Thu, 21 Mar 2019 03:13:29 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Subject: Protocol Action: 'Split DNS Configuration for IKEv2' to Proposed Standard (draft-ietf-ipsecme-split-dns-17.txt)
X-Test-IDTracker: no
X-IETF-IDTracker: 6.94.1
Auto-Submitted: auto-generated
Precedence: bulk
Cc: David Waltermire <david.waltermire@nist.gov>, The IESG <iesg@ietf.org>, ipsecme-chairs@ietf.org, ekr@rtfm.com, ipsec@ietf.org, david.waltermire@nist.gov, draft-ietf-ipsecme-split-dns@ietf.org, rfc-editor@rfc-editor.org
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Message-ID: <155316320918.10009.13657421622656796922.idtracker@ietfa.amsl.com>
Date: Thu, 21 Mar 2019 03:13:29 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-announce/If0l3OCuhms3XmfYJ5CJpEY-JHE>
X-BeenThere: ietf-announce@ietf.org
X-Mailman-Version: 2.1.29
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-announce/>
List-Post: <mailto:ietf-announce@ietf.org>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Mar 2019 10:13:29 -0000

The IESG has approved the following document:
- 'Split DNS Configuration for IKEv2'
  (draft-ietf-ipsecme-split-dns-17.txt) as Proposed Standard

This document is the product of the IP Security Maintenance and Extensions
Working Group.

The IESG contact persons are Benjamin Kaduk and Eric Rescorla.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-split-dns/





Technical Summary

The IPsecME working group has obsoleted the IKEv1 protocol in favor of
the IKEv2 protocol many years ago. However, IKEv2 never had an option
to send one or more DNS domains from a Remote Access VPN server to the
VPN clients. IKEv1 did have that option via XAUTH/ModeCFG.

This document defines two Configuration Payload Attribute Types for
the IKEv2 protocol that add support for private DNS domains.  These
domains are intended to be resolved using DNS servers reachable
through an IPsec connection, while leaving all other DNS resolution
unchanged.  This approach of resolving a subset of domains using non-
public DNS servers is referred to as "Split DNS".

Working Group Summary


The draft had no controversy. The draft has been discussed frequently on
the mailing list and a lot of comments have been provided on list by
people other than the authors, to include implementors. In addition to
mailing list discussions, the draft has been presented and discussed
during the last 3 IETF (98, 99, 100) meetings. The draft has been
supported by the participants in the room on various hums for the
specific design decisions made in the document.
  
Document Quality\

The document is supported by implementors, and authors also represent a
subset of implementors. Interoperability of the DNS domain has been
confirmed by at least three independent implementations. DNSSEC TA
support has not seen an implementation or interoperability test, but
the format is sufficiently simple that no one is worried.
  
Personnel

The Document Shepherd is David Waltermire. The responsible Area
Director is Eric Rescorla.